1. Information we collect

Account information

When a school adds you or you sign in, we collect your name, mobile number, role (administrator or teacher), and the school you belong to, along with optional details such as employee ID, department and designation.

Authentication data

We verify your identity using a one-time password (OTP) sent to your mobile number, and we store a securely hashed session token so you stay signed in. We never store your OTP, and passwords are stored only as a salted bcrypt hash.

Information you enter

As part of running a class, teachers enter student records (name, roll number, gender, guardian details), attendance, marks and report data. This information is provided and controlled by the school.

Device & usage data

To operate and secure the service we automatically record technical data for each request — a device identifier, device OS, app version, IP address, the action performed and a timestamp. We do not store the contents of your requests.

2. How we use information

We do not sell your personal information, and we do not use student data for advertising.

3. Legal basis & consent

We process information to perform our agreement with the school that engages us, to pursue our legitimate interest in operating a secure service, and to meet legal obligations. Where required by applicable law (including India’s Digital Personal Data Protection Act, 2023), processing is carried out on the basis of consent obtained by the school as the data fiduciary, with Guru Maytri acting as a data processor on the school’s behalf.

4. How we share information

We share information only as needed to run the service:

5. Student data & children

Guru Maytri is intended for use by school staff, not by students. Student records are entered and owned by the school, which acts as the data controller/fiduciary and is responsible for obtaining any consents required from parents or guardians. We process student data solely to provide the service to the school and under the school’s instructions, and we apply the same security and retention safeguards described in this Policy.

6. Data security

We protect information with industry-standard measures, including encryption of traffic in transit, hashed passwords and session tokens, role-based access control, rate limiting, request size limits and security headers. While no method of transmission or storage is perfectly secure, we work to safeguard your data and to respond promptly to any incident.

7. Data retention

We keep personal information for as long as your account is active and as needed to provide the service. Operational request logs are retained for a limited period (by default 90 days) and then deleted. When an account is deleted, we revoke its access and scrub identifying personal details; certain school-owned academic records may be retained by the school as required for its records or by law.

8. Your rights (access, export, deletion)

Subject to applicable law, you may access, correct, export or delete your personal information. We have built two of these rights directly into the app:

You may also exercise these and other rights (such as correction or withdrawal of consent) by contacting us using the details below. We will respond within the timelines required by applicable law.

9. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the service after an update means you accept the revised Policy.

10. Contact us

If you have questions about this Policy or wish to exercise your rights, email us and we’ll be happy to help.

Email us business@gurumaytri.com