VidyaSchool Docs
Legal Policies

Privacy Policy

Effective Date: August 18, 2026  |  Last Updated: August 18, 2026

PRIVACY & COMPLIANCE SUMMARY: VidyaSchool and BlazeNeuro are committed to the highest standards of student data privacy, security, and institutional confidentiality. We process personal and academic records strictly to deliver educational management services in full compliance with applicable student privacy regulations (including FERPA, COPPA, and the Digital Personal Data Protection Act). We do not sell student data, nor do we monetize personal information through behavioral advertising.

1. Scope & Data Fiduciary Details

This Privacy Policy ("Policy") delineates how VidyaSchool and its operating entity BlazeNeuro ("Company", "We", "Us", or "Our") collect, store, process, safeguard, disclose, and govern the personal information of students, parents, legal guardians, educators, librarians, accountants, and school administrators (collectively "Users", "You", or "Data Principals") across our web platform (vidyaschool.vercel.app), native mobile applications (Android/Kotlin, iOS, PWA), backend APIs, student information systems, fee gateways, and related digital services (the "Platform").

2. Information We Collect

To provide authenticated school operations and academic portals, we collect data across several distinct categories:

A. Identity & Profile Information:

Full legal names, institutional email addresses, hashed authentication credentials, profile avatars, student admission numbers, roll numbers, assigned class grades and section divisions, gender, and date of birth.

B. Guardian & Emergency Contact Coordinates:

Parent/guardian names, verified telephone/mobile contact numbers, residential physical addresses, emergency contact designations, and commuter transit preferences (e.g., school bus route zone, transit stop, walking permissions).

C. Academic & Institutional Records:

Classroom attendance registers, quarterly/term exam marks, grading schemas, cumulative GPAs, class ranks, teacher remarks, report card digital signatures, library book checkouts/fines, and academic certificates.

D. Financial & Transaction Logs:

Tuition fee ledgers, fee structures, concession/scholarship waivers, order IDs, payment status flags, and gateway transaction references. (Note: We do not store raw credit card numbers or UPI PINs; all sensitive payment credentials are tokenized directly by licensed payment aggregators like Razorpay).

E. User-Generated Study Content:

Teacher lecture notes, drawing canvas vector strokes, uploaded PDF syllabus materials, community discussion messages, and administrative complaint tickets.

F. Technical, Session & Telemetry Data:

IP addresses, device user-agents, browser fingerprints, operating system specifications, session cookies (better-auth.session_token), Firebase Cloud Messaging (FCM) push tokens, and error telemetry via Sentry.

We process personal data strictly under valid legal bases including institutional educational necessity, contractual fulfillment of student portal services, legal compliance, and explicit consent:

  • Core Educational Delivery: Administering student onboarding, maintaining daily attendance registers, recording grades, publishing report cards, and delivering lecture notes.
  • Guardian Communications & Safety: Dispatching real-time attendance alerts, emergency school closure broadcasts, and fee due reminders via WebPush, SMS, and email.
  • Financial Administration: Facilitating tuition collections, reconciling school accounts, and generating official digital tax receipts.
  • Identity & Account Security: Enforcing Role-Based Access Controls (RBAC), blocking unauthorized intrusions, preventing rate limit abuse, and securing multi-device sessions.
  • Regulatory Auditing: Complying with statutory educational records retention mandates and institutional accounting audits.

4. Children's Privacy, FERPA & Parental Consent

Given that VidyaSchool is utilized by minors in elementary, secondary, and senior secondary schools:

  • Institutional Authority / In Loco Parentis: When schools register student accounts, the educational institution acts as the intermediary authority and warrants that it has secured valid parental/guardian consent under applicable child data privacy statutes (including the Children's Online Privacy Protection Act - COPPA, Family Educational Rights and Privacy Act - FERPA, and equivalent international frameworks).
  • No Commercial Exploitation: Student records and user profiles are never subjected to behavioral profiling, commercial data mining, or targeted advertising.
  • Parental Inspection: Parents and verified legal guardians possess the statutory right to inspect their child's academic records, request corrections to incorrect marks or contact details, or request account suspension through their school registrar.

5. Data Sharing, Subprocessors & Third Parties

WE DO NOT SELL, RENT, OR MONETIZE PERSONAL DATA. We share data strictly with vetted sub-processors and institutional stakeholders to operate the Platform:

Hosting & Database Infrastructure
Neon Serverless PostgreSQL & Vercel Edge Cloud. Data encrypted in transit (TLS 1.3) and at rest (AES-256).
Payment Processing Gateway
Razorpay Software Private Limited. PCI-DSS certified tokenized payment execution.
Push & Email Dispatch Networks
Google Firebase Cloud Messaging (FCM) & Resend SMTP Infrastructure for transactional alerts.
Cloud Document Storage
AWS S3 / Cloudinary for secure storage of uploaded student syllabus PDFs and avatars.

We may also disclose information where required by law, subpoena, court order, or to prevent imminent physical harm, fraud, or cybersecurity attacks against the institution.

6. Cookies, Session Tokens & Device Tracking

The Platform uses strictly necessary first-party cookies and session tokens to preserve authentication integrity and provide multi-device security:

  • better-auth.session_token: Encrypted session identifier used to maintain active logins and protect role boundaries.
  • theme: Stores user preference for Dark, Light, or Sepia mode.
  • Session Management: Users can inspect all active logged-in devices, IP locations, and user-agents via the Login Accounts & Sessions Portal and remotely revoke individual or all other devices with one click.

7. Data Retention, Archiving & Deletion

We retain personal data for the duration of the student's active enrollment at the affiliated institution. Upon student graduation, transfer, or formal withdrawal:

  • Active portal access tokens are invalidated.
  • Academic grade ledgers, report cards, and financial payment receipts are retained in encrypted institutional archives for the duration mandated by applicable statutory educational and tax auditing laws (typically 5 to 7 years).
  • Non-essential transient telemetry and expired session logs are purged automatically on rolling 30-day to 90-day cycles.

8. Data Security & Cryptographic Safeguards

Our Multi-Layered Security Architecture Includes:

  • End-to-End Transport Encryption: All data transmissions are enforced over HTTPS / TLS 1.3.
  • Storage Encryption: Database fields, passwords (salted bcrypt/Argon2), and document buckets utilize AES-256 encryption at rest.
  • Role-Based Access Control (RBAC): Strict middleware firewalls ensure students cannot view gradebooks of peers or access administrative/fee management consoles.
  • Automated Rate Limiting: Intelligent edge firewalls mitigate brute-force attempts and denial-of-service floods.

9. Your Rights & Data Subject Access

Depending on Your jurisdiction and applicable data protection laws, You and Your legal guardians possess the following enforceable rights:

  • Right of Access & Audit: The right to review all profile information, academic records, and fee receipts associated with Your account.
  • Right to Rectification: The right to request correction of inaccurate contact numbers, addresses, or misrecorded marks through institutional ticketing channels.
  • Right to Data Portability: The right to request an export of academic transcripts and note summaries in standardized formats (PDF/JSON).
  • Right to Revoke Session Access: The right to instantly revoke any connected device session via the security dashboard.

10. International Data Transfers

VidyaSchool cloud infrastructure is hosted in premier data centers located in India, the European Union, and the United States. Where cross-border data routing occurs to deliver cloud compute and database scaling, such transfers are governed under Standard Contractual Clauses (SCCs) and robust data processing agreements ensuring equivalent levels of privacy protection.

11. Policy Modifications & Grievance Officer

We may periodically update this Privacy Policy to reflect regulatory amendments or new platform capabilities. When changes occur, the "Last Updated" date will be refreshed, and institutional administrators will receive electronic notices.

Data Protection & Grievance Redressal Officer

For privacy audit requests, data removal inquiries, parental consent questions, or grievance escalations, contact our designated Data Protection Officer:

VidyaSchool Data Protection & Privacy Cell (BlazeNeuro)
Attention: Grievance & Compliance Officer
Legal Escalations: legal@blazeneuro.com
Corporate Portal: https://blazeneuro.com

On this page