Privacy Policy for the AppySchool Mobile Apps
This is the privacy policy for the AppySchool mobile applications listed on Google Play and the Apple App Store, including school-branded (white-label) versions of the same apps that we publish. It is not a messaging-app policy and it does not apply to WhatsApp or any unrelated product.
The AppySchool website privacy notice is published separately at appyschool.in/privacy.html.
1. Who we are
AppySchool is a school operations platform used by educational institutions, their staff, and parents or guardians. The mobile apps let parents follow a child’s school activity and let staff manage classroom work.
These apps are provided by:
VARCHINNO Technologies Private Limited
WeWork, Rajapushpa Summit, Financial District, Manikonda,
Hyderabad, Telangana 500032, India
Google Play / App Store identifiers covered by this policy include:
- AppySchool Parent — Android package
com.varchinno.appyschool.parent - AppySchool Staff — Android package
com.varchinno.appyschool.staff - School-branded builds of the same apps that we publish for a school (for example Little Florets, Sanskriti, or Kites), which use the same data practices described here
2. Privacy contact
For privacy questions, access requests, correction requests, or complaints about this policy, contact:
- Email: contact@appyschool.in (preferred)
- Email: contact@varchinno.com
- Phone: +91 95503 04242
- Postal: VARCHINNO Technologies Private Limited, WeWork, Rajapushpa Summit, Financial District, Manikonda, Hyderabad, Telangana 500032, India
Please include “Privacy” in the subject line. We aim to respond within 7 business days.
3. What this policy covers
This policy describes how AppySchool accesses, collects, uses, stores, and shares personal information when you install or use the AppySchool Parent App or Staff App.
AppySchool is provided to a school under a service arrangement. The school is the institution that decides which student, parent, and staff records are stored. We process that information to operate the platform for the school. Some requests (for example changing a child’s official school record) must be handled by the school as well as, or instead of, by us.
Accounts are created for parents/guardians and school staff. A parent typically signs in with a mobile number and password, or with a one-time password (OTP) sent to the registered mobile number or email. Registration uses the student ID or staff ID issued by the school, a mobile number, and a password, together with the school’s AppySchool school ID.
4. What this app does not collect
AppySchool is a school parent/staff app. It does not:
- Read, upload, or sync your phone’s address book or contacts
- Collect “status messages” or a social profile for public sharing
- Share your live device location with contacts
- Access the parent or staff phone’s GPS to track that person
- Sell personal information to advertisers or data brokers
5. Information we collect
We collect only what is needed to run the school services you and the school use. Categories below match how the apps actually work.
5.1 Account and identity information (you provide, or the school provides)
- Mobile number, password, and (where used) OTP
- Email address, when the school or you have recorded one
- Name, student ID / staff ID, roll number, class/section, gender, date of birth, date of joining
- Parent or guardian names, residential and permanent address
- Profile photograph, if the school or user has uploaded one
- School / institute ID used to connect the app to the correct school server
5.2 Student academic and school-life information
- Attendance and leave applications
- Homework, assignments, and files you or staff upload
- Marks, assessments, report-card data, remarks, and TestZone / online exam attempts
- Timetable, school documents, notices, and notifications
- Photo albums of school activities shared by staff with parents
- Grievances / concerns you raise and related staff replies
- In-app chat messages between parent and staff, and optional messages to the in-app school assistant
5.3 Health-related information (school records)
Staff may enter student health-profile measures (for example height, weight, or other fields the school configures) so that parents can view them. This is school health-record data, not data from a medical device or Health Connect on your phone.
5.4 Fees and payments
- Fee structures, amounts due, amounts paid, receipts, payment dates, and payment mode
- When you pay from the app, we send the school, student, and fee identifiers needed to start the transaction to the payment gateway configured for that school (see Section 8)
We do not store full card numbers, CVV, UPI PINs, or net-banking passwords on AppySchool servers. Those details, if entered, are handled by the payment processor.
5.5 Transport location (not your phone’s GPS)
- School bus / vehicle location: if the school uses AppySchool transport tracking, the app shows the vehicle’s current coordinates that the school’s GPS device reports to our servers. The app does not read the parent’s or teacher’s phone GPS for this purpose.
- Pickup point: a parent or staff user may drop a pin on a map to save a student’s pickup location and a notification radius. Those map coordinates are stored on our servers so the school can notify you when the vehicle is nearby.
5.6 Device and push-notification information
To send school alerts and keep you signed in, the app collects:
- A device identifier (unique device ID)
- Device model / name and operating system (Android or iOS)
- App version and application ID
- Firebase Cloud Messaging (FCM) token on Android, or Apple Push Notification service (APNs) token on iOS
Access tokens are stored on the device (AsyncStorage). Refresh tokens are stored in the device keychain/keystore when available. Authentication credentials are sent to the school’s AppySchool server over HTTPS.
The app does not include a separate advertising or analytics SDK such as Firebase Analytics or Crashlytics. Standard server logs (for example IP address, time, and request URL) may be generated when the app talks to our servers, for security, debugging, and service operation.
5.7 Files you choose to upload or download
If you upload assignment files, notification attachments, or album photos, those files are sent to our servers and stored with a cloud file host (Amazon S3 via time-limited signed URLs). If you download a file, the app may ask for storage access on older Android versions so the file can be saved on the device.
5.8 Information we do not collect from the device
The Android app requests Internet, notifications, and (on Android 12 and below) storage for downloads. It does not request contacts, microphone, SMS, or fine/coarse location permission. On iOS, photo-library access is requested only to upload photos for albums and assignments.
| Data type | Collected? | Purpose |
|---|---|---|
| Name, phone, email, address, student/staff ID | Yes | Account, school records, communication |
| Photos and files you or staff upload | Yes, when you use those features | Albums, assignments, profile, notices |
| Approximate/precise location from your phone GPS | No | Not used. Bus location comes from the school vehicle tracker. Pickup pin is chosen on a map. |
| Pickup map coordinates / vehicle tracker coordinates | Yes, if transport is enabled | Show bus location; notify when the vehicle is near the pickup point |
| Contacts / address book | No | — |
| Payment card details | Not stored by us | Processed by the school’s payment gateway |
| Device ID, model, OS, app version, push token | Yes | Login session, push notifications, support |
| Student health-profile fields entered by the school | Yes, if the school uses that module | Show health profile to authorised staff and parents |
| Chat and concern messages | Yes, if you use those features | Parent–staff communication and school support |
6. How we use information
We use the information above to:
- Create and authenticate parent and staff accounts
- Show the correct school’s data after you enter the school ID
- Deliver attendance, homework, results, notices, fees, transport, documents, and similar school services
- Send push notifications, and (where the school has enabled them) SMS or email alerts
- Process fee payments through the school’s payment gateway
- Enable parent–staff chat and optional in-app assistant replies
- Operate, secure, troubleshoot, and improve the apps and servers
- Comply with law and the school’s instructions as our customer
We do not use app data for third-party advertising. We do not sell personal information.
7. Device permissions
- Internet — required to load school data from AppySchool servers.
- Notifications — optional; used for attendance, fees, transport, and other school alerts via Firebase Cloud Messaging (Android) or APNs (iOS).
- Storage (Android 12 and below) — optional; used to save downloaded files such as receipts or assignments.
- Photo library (iOS) — optional; used when staff or parents upload photos for albums or assignments.
You can refuse optional permissions. Related features (push alerts, downloads, or photo upload) will not work until permission is granted.
8. Sharing and third parties
We share information only as needed to provide the service:
- Your school. Parent, student, and staff records are visible to authorised users at that school (for example administrators and allotted teachers), according to the school’s roles and permissions.
- Other AppySchool users at the same school. For example, a concern you raise is visible to the staff member you select; chat messages are visible to the other party in that thread.
- Service providers that process data for us, listed below. They may process data only to provide their service to AppySchool.
- Legal and safety. We may disclose information if required by law, court order, or to protect the school, students, or the integrity of the service.
8.1 Third-party services used by the apps
| Service | What it is used for | Data involved |
|---|---|---|
| Google Firebase Cloud Messaging (FCM) | Android push notifications | FCM registration token, device/app identifiers needed to deliver a notification. See Firebase privacy. |
| Apple Push Notification service (APNs) | iOS push notifications | APNs device token. See Apple’s privacy information for APNs. |
| Google Maps SDK | Display maps for bus tracking and pickup-point selection | Map display may involve IP address and map interaction data processed by Google. See Google Privacy Policy and Google Maps/Earth Additional Terms. |
| Amazon Web Services (S3) | Storage of uploaded files (assignments, albums, attachments, documents) | The file content and metadata required to store and retrieve it |
| Payment gateways configured for the school (including Razorpay where the school uses it) | Online fee collection (UPI, card, net banking, wallet) | Student/fee identifiers, amount, and payment status. Card/UPI secrets are handled by the gateway. See Razorpay Privacy Policy when Razorpay is used. |
| SMS / email delivery providers (used by the school’s AppySchool backend) | OTP login and school alerts when the school has enabled SMS or email | Mobile number or email and the message content |
| Hosting / cloud infrastructure for AppySchool servers | Store and process school data and app API traffic | The categories listed in Section 5, under our instructions |
If you use the optional in-app assistant chat, your messages in that thread are sent to our servers so a response can be generated. Those messages are school-support communications, not public posts.
We do not use Google Analytics, Facebook SDK, or advertising SDKs in these apps.
9. Children’s and student data
AppySchool is intended for adults: parents, guardians, and school staff. It is not directed at children as a consumer social app. Children do not create independent Play Store accounts through this app.
The apps nevertheless process student data, including data about minors, because that is the school record the parent or teacher is authorised to see. Typical student data includes name, class, attendance, academic results, photos from school albums, leave records, and, where the school uses it, health-profile information.
We process this information:
- On the instructions of the school that enrolled the student
- To provide the parent/guardian visibility the school has enabled
- In line with applicable Indian law, including the Digital Personal Data Protection Act, 2023, where it applies
We do not use student data for advertising. We do not share student data with other schools or with the public. School photo albums are visible to authorised parents and staff of that school, not to a public social feed.
If you believe a child’s data is inaccurate or should not be in the app, contact the school first, and copy contact@appyschool.in if you also need us to act on the account.
10. Security
We take reasonable technical and organisational measures to protect personal information, including:
- HTTPS / TLS for data in transit between the app and our servers
- Authentication tokens; refresh tokens stored in the device keychain/keystore when available
- Android backup of app data disabled (
allowBackupis false) - Role-based access so school users see only what their permissions allow
- Time-limited signed URLs for file uploads to cloud storage
- Regular backups of school data on our servers
No method of transmission or storage is 100% secure. If we become aware of a security incident that affects your personal information, we will notify the school and, where required by law, affected users.
11. Data retention
We keep personal information only as long as needed for the purposes in this policy, the school’s instructions, and legal requirements.
- App account and device/push tokens: while the account is active and the app remains registered for notifications. Device tokens are removed or marked inactive when you log out or the token is replaced. Local tokens on the device are cleared on logout.
- Student, parent, and staff school records (attendance, marks, fees, chat, albums, documents, transport pickup point, and similar): for the life of the school’s AppySchool subscription and for any additional period the school requires for academic, fee, or statutory records (often several years after a student leaves).
- Payment records: retained as needed for accounting, tax, chargebacks, and dispute handling (typically at least 8 years in India where books of account rules apply).
- Server logs: typically up to 90 days unless a longer period is needed for security investigation.
If a category of data must be kept after an account is deleted (for example a fee receipt required for tax or a record the school is legally required to retain), we will keep only what is necessary for that purpose and will not use it for ordinary app features.
12. Account and data deletion
How to request deletion of your AppySchool app account and associated personal data
Email contact@appyschool.in with the subject line AppySchool Account Deletion Request.
Include:
- Your full name
- Registered mobile number used to sign in
- School name and School ID (if you know it)
- Student ID or staff ID
- Whether you want (a) app login deleted only, or (b) app login plus personal data we hold for that account
You may also phone +91 95503 04242 or write to the address in Section 2.
What happens after a valid request:
- We will verify that the request comes from the account holder (or a parent/guardian or school administrator authorised to act).
- We will delete or deactivate the app login so the account can no longer be used to sign in.
- We will delete personal data tied to that app account that we control as the platform operator (for example device/push tokens, app credentials, and profile data stored for app access).
- Deleting the app account is not the same as freezing or temporarily disabling it. We do not treat “logout” or turning off notifications as deletion.
Because AppySchool stores official school records on behalf of the school:
- Academic, attendance, fee, and similar student records may need to be retained by the school even after the parent app login is deleted. Those records are the school’s institutional data.
- If you also want the school to erase or correct a student’s underlying record, you must request that from the school. We will coordinate with the school when the request is valid and lawful.
We complete deletion requests within 30 days of verification, unless a shorter period is required by law or a longer period is needed to confirm identity or to preserve data we are legally required to keep (security, fraud prevention, tax, or a school’s statutory record-keeping). We will tell you if any data is retained and why.
Uninstalling the app from your phone removes local data on that device. It does not by itself delete your account on our servers. Use the email request above for that.
13. Your rights
Subject to applicable law (including the Digital Personal Data Protection Act, 2023) and the school’s role as the institution holding the education record, you may request to:
- Access personal information we hold about you
- Correct inaccurate personal information
- Delete your app account and associated personal data, as described in Section 12
- Withdraw consent for optional processing (for example push notifications) by changing device settings or contacting us
Send these requests to contact@appyschool.in.
14. Data stored in India and transfers
AppySchool servers and school data are operated for schools in India. Some subprocessors (for example Google, Apple, Amazon, or a payment gateway) may process limited technical or payment data on infrastructure outside India. Where that happens, it is only to provide the functions described in this policy.
15. Changes to this policy
We may update this policy when the apps, our providers, or the law change. The “Last updated” date at the top will change. For material changes, we will provide notice in the app or on this page. Continued use of the apps after an update means you acknowledge the revised policy.
The previous policy hosted at
https://config.appyschool.in/parentalappprivacypolicy.jsp is withdrawn. This page
is the current public privacy policy for the AppySchool mobile apps.
16. Contact
VARCHINNO Technologies Private Limited
AppySchool — Parent App and Staff App
WeWork, Rajapushpa Summit, Financial District, Manikonda,
Hyderabad, Telangana 500032, India
Privacy and deletion: contact@appyschool.in
Phone: +91 95503 04242