Privacy Policy
ClassRoots is a school-operations platform made by Aadyash Technologies Private Limited. It is used by schools, and through them by parents, teachers and office staff. This policy says what we collect, where it goes, who else touches it, and what you can do about it.
We have tried to write it so that a principal signing a contract, a parent installing the app, and a teacher dictating a homework note can each find the sentence that applies to them. Where something is not as good as it should be yet, we say so rather than imply otherwise.
1. Who is responsible for what
Your school decides what information about its students, parents and staff is entered into ClassRoots, and why. Under India’s Digital Personal Data Protection Act, 2023, that makes the school the data fiduciary for that information and ClassRoots its data processor: we process it on the school’s instructions, and the school is responsible for collecting any consent it needs from parents and guardians before enrolling a child.
For the small amount of information we collect directly — a parent’s phone number at sign-in, device details, error reports — we are responsible ourselves.
2. What we collect
Everything below is either entered by your school, entered by you, or generated by using the apps.
- About students (entered by the school): name, class and section, roll number, date of birth, photo, parent and guardian names and phone numbers, attendance, marks and report cards, fee schedules, concessions and payments, leave, pickup and late-arrival requests, homework, early-years daily logs (meals, nap, mood, bathroom, medication given, items to bring), weekly learning logs (what the child worked on in each learning area, highlights, social and emotional notes), bus boarding records (tapped on, tapped off, or did not travel — no location), admission enquiries the school records and applications parents submit through a school’s online admission form (the questions are the school’s own and can include health details such as allergies or medication, and identity numbers where the school asks for them), and certificates the school issues.
- About parents: your phone number (used to sign in with a one-time code), your name, your email if you give it, your preferred language, a push-notification token for your device, the messages you send to teachers, the photos and comments you post in Moments, homework you submit for your child, and your fee payments — amount, status and Razorpay reference, never your card or bank details, which Razorpay handles entirely.
- About teachers and staff (entered by the school): name, phone, email, role, subjects and classes, date of joining, attendance and leave (including, where the school has turned on the location check, how far the phone was from the school at the moment of a self check-in tap — the position itself is measured and discarded, never kept; see section 3), salary and payroll records, and — where the school uses ClassRoots for payroll and statutory filings — government and bank identifiers such as Aadhaar number, PAN and bank account details. See section 8 for how those are protected.
- From your device: app version, device model and operating system, and error reports if the app crashes. From the web portals: sign-in events, the browser and IP address of each session, and an audit trail of important actions — who published a circular, who changed a fee, who turned a setting off.
3. What we do not collect
- Your location, with one narrow exception. Bus boarding works by a staff member tapping a child on and off; there is no GPS tracking of buses, children or staff. The exception: if a school turns on the location check for staff check-in, the staff app sends a single position fix at the moment a staff member taps “I’m in”, so the school can tell whether they were at the school. It is taken only at that tap, only when the school has turned the check on, and only after the staff member has allowed location for the app. We keep the distance from the school and whether it was within the school’s radius — not the position itself, which is discarded once measured. Nothing is recorded at any other time.
- Your contacts, photos or files, other than the ones you choose to attach.
- Card numbers, UPI PINs or bank passwords. Payments are completed on Razorpay’s own screens.
- Anything for advertising. There are no advertising or tracking SDKs in the apps, and we do not sell or rent personal data to anyone.
4. How we use it
To run your school’s day: deliver circulars and notifications, record and report attendance, manage fees and receipts, run exams and report cards, handle leave and pickup requests, share homework and daily logs, record bus boarding, issue certificates, pay staff and track expenses.
To keep the platform safe: sign you in, prevent abuse, investigate problems and keep an audit trail. To support you: answer questions from parents and schools. To meet legal obligations, including statutory school and financial records.
5. Where your information is stored, and who processes it
We run ClassRoots on a small number of specialist providers. Each one is listed below with where the processing happens and what it receives. We are precise about geography because it is often asked: your school’s files are stored in India; the database and application servers are in Singapore; and some processing happens in the United States, Germany and Australia. We do not claim that all data stays in India.
- Render (Singapore) — database and application servers — all platform data.
- Amazon Web Services, S3 (Mumbai, India) — file storage — photos, attachments, voice recordings and generated PDFs. The storage is private; files are served through short-lived signed links.
- MSG91 (India) — SMS — your phone number, to deliver the one-time sign-in code.
- Razorpay (India) — payments — the amount, fee reference and payer contact for online fee payments. Card and bank details are entered on Razorpay’s screens and never reach us.
- Expo, Google Firebase Cloud Messaging and Apple Push Notification service (United States) — push notifications — your device token and the text of each notification.
- Zoho Mail (Australia) — email — messages we send you, and support conversations.
- Sentry (Germany) — error reports — technical details of app and server crashes. We scrub personal information before sending, but a report can include an account identifier and the screen that failed.
- Anthropic (United States) — AI text features — see section 6.
- OpenAI (United States) — voice transcription — see section 6.
Each provider processes data only on our instructions and under terms that prohibit using it for their own purposes. We will update this list before adding a provider.
6. AI features — exactly what each one sends, and the switch
Some ClassRoots features use a large language model from Anthropic (Claude) or speech-to-text from OpenAI (Whisper). This section lists every one, because the answer to “what does the AI see” is different for each.
- Voice circular (staff app and web portal): the principal’s recording goes to OpenAI for transcription; the transcript, the school’s name and the requested tone go to Anthropic to draft the circular and a Tamil or English translation. The principal reviews the draft before anything is published.
- Homework by voice (staff app): the teacher’s recording goes to OpenAI; the transcript goes to Anthropic to fill in subject, title, description and due date. The teacher reviews before posting.
- Daily log by voice (staff app, early-years classes): the teacher’s recording goes to OpenAI; the transcript goes to Anthropic to fill in the meals, nap, mood and note fields. A recording naturally names the child and may describe medication given. The teacher reviews before saving.
- Weekly log by voice (staff app, Montessori and early-years classes): the teacher’s recording goes to OpenAI; the transcript and the names of the school’s learning areas go to Anthropic to sort what the child worked on under each area, with highlights and a note. A recording names the child and describes their week. The teacher reviews before saving, and nothing reaches a parent until the teacher publishes it.
- “Draft for me” (web portal): the principal’s rough notes and the school’s name go to Anthropic to draft a circular.
- Automatic translation of circulars (web portal): when a circular is published without the school supplying its own translations, the title and body go to Anthropic and the translation is published to parents alongside the original. This translation is not reviewed by a person before parents see it. Schools that want every translation checked should supply their own, or turn AI features off.
- Report-card remark suggestions (web portal): the student’s name, class, subject marks, rank and co-scholastic grades for that exam go to Anthropic to suggest a remark. A teacher or principal edits and saves it; nothing reaches a parent automatically.
- Ask AI in the report builder (web portal): the question typed by the staff member and the list of report fields available to their role go to Anthropic. No student records are sent; the report itself runs on our servers afterwards.
- ClassRoots Insights — the Morning Pulse, class briefs and the parent “For you” digest: switched on separately by the school. The facts are computed on our servers; to phrase them, a student’s first name, class label and the computed numbers go to Anthropic — never contact details, date of birth or photos. Parent-facing insights are a second, separate switch, and every activation is recorded.
- AI Assistant in the parent app: your question, your child’s name, class and roll number, and their recent circulars, events, homework, fee amounts and due dates, and marks go to Anthropic so the answer can be grounded in them.
- Help assistant in the web portal: the staff member’s question and our own help articles go to Anthropic. No school data is sent unless it is typed into the question.
Free text goes as written. The structured data each feature sends is listed above, but a circular’s body, a dictated note or a question typed into an assistant is sent exactly as it was written or spoken — including any names, numbers or details in it.
Under the commercial API terms we use, neither Anthropic nor OpenAI uses these requests to train their models. They may retain a request briefly for abuse monitoring under their own policies.
The switch. A principal can turn every AI feature off at once in the web portal, under Settings → Modules → AI features. It is on unless the school turns it off. When it is off, ClassRoots does not send any of that school’s information to Anthropic or OpenAI: dictation buttons disappear, circulars publish without automatic translation, Insights use fixed wording, help answers come from keyword search, and the parent AI Assistant is unavailable. The setting is enforced on our servers, not only hidden in the apps, and each change is recorded in the school’s audit log.
Turning it off stops the AI providers only. It does not move the database out of Singapore or stop error reports going to Germany.
7. Children’s information
Students do not use ClassRoots themselves; parents and schools do. Information about a student is visible only to that student’s linked parents, to authorised staff at the student’s school according to their role, and to the ClassRoots operations team where strictly required for support, security or legal compliance. We do not use children’s information for advertising, profiling, or any purpose beyond running the school’s own services.
Student photos are uploaded by the school, stored privately, and served through short-lived links. A school can mark a child as “no photo consent”, after which the photo is not shown anywhere in the apps or the portal. Photos are shown unless the school records that consent was not given, so schools should set this when a parent asks.
8. Teachers’ and staff information
Payroll needs sensitive identifiers. Where a school records Aadhaar, PAN or bank details for its staff, those are visible only to the principal, correspondent and office roles at that school — not to other teachers. They are encrypted in transit and protected by role-based access controls; at rest they sit in the database in Singapore like other records. We do not yet apply an additional field-level encryption to these identifiers, and we would rather say so than imply otherwise. They are never sent to an AI provider.
9. Security
Encryption in transit everywhere. Sign-in by one-time code; portal passwords are stored only as salted hashes. Each school’s data is isolated by tenant checks on every request, and roles limit what each staff member can see. File storage is private and served through expiring links. Important actions are audit-logged.
We do not hold certifications such as ISO 27001 or SOC 2 and do not claim to; we will say so plainly if that changes. No system is perfectly secure. If we learn of a breach affecting your data, we will tell the affected school without undue delay.
10. How long we keep it
For as long as your school uses ClassRoots, and afterwards for as long as needed to hand the data back and to meet legal obligations. When a school leaves, it can export its records and ask us to delete the rest; we delete on request rather than on a fixed schedule, and confirm in writing when it is done.
Some records must be kept longer by law — attendance registers, fee receipts, certificate registers and payment records — and we keep those for the statutory period even after a deletion request.
11. Deleting your account
Parents can delete their account in the app (Profile → Delete Account) or by writing to support@classroots.ai. Deleting your account removes your sign-in and personal profile; your child’s school records belong to the school and remain with it. Teacher and staff accounts are managed by the school.
12. Your rights
You can ask to see, correct or delete personal information about you. For information entered by your school, ask the school first — it is the fiduciary and can act immediately, and we will help it do so. For anything else, write to support@classroots.ai. We aim to respond within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
13. Cookies and website analytics
The web portals use a first-party session cookie to keep you signed in; there are no advertising or third-party cookies. classroots.ai uses Vercel Analytics, which counts page views without cookies or personal identifiers. If you book a demo through our website, the booking is handled by Cal.com under its own privacy policy.
14. Changes to this policy
We update the “Last updated” date whenever this policy changes, and tell schools directly when a change affects what we send to a provider or which providers we use.
15. Contact
Aadyash Technologies Private Limited — support@classroots.ai. For privacy requests, put “Privacy” in the subject line.