Privacy policy
How SchoolDuty handles personal information and school-related content. This page is a plain-language overview—not legal advice, and not a replacement for terms your institution agrees to.
Last updated August 4, 2026
01Scope
This summary describes our approach to privacy for people who visit the site, create an account, or use SchoolDuty as part of an institution (for example as an owner, admin, teacher, student, or parent).
02Information we process
To run the service we process account details (such as email), profile and role information, organisation membership, parent–student links and registration requests, fee and payment records, and teaching and learning data you add—courses, classes, enrollments, uploaded PDFs, assignments and submissions, exams and grades, and student achievements (such as XP, levels, streaks, and badges). Direct and group messages, and Lexi assistant chat turns, are different: we store only their encrypted form (see “Encrypted conversations”), plus the surrounding delivery or conversation metadata needed to run those features.
03How we use it
We use this information to authenticate users, enforce organisation and role-based access, deliver features you expect (courses, materials, notifications, grades, achievements, assistant chats, and—for owners and admins—institution analytics), and keep the platform reliable and secure. We do not sell your personal information.
04Organisation access
The product is built so members typically only access data belonging to their institution and to the courses or classes they are permitted to see. Direct and group messages and Lexi assistant chats are end-to-end encrypted in the browser, so their content is not readable by us or by institution staff. Your school’s administrators are responsible for invitations, membership, and many day-to-day data decisions.
05Encrypted conversations
Direct and group messages in the in-app messenger, and Lexi’s assistant chat turns, are end-to-end encrypted. Content is encrypted in your browser with a key only you hold (and, for messenger chats, the other people in that conversation). SchoolDuty cannot read that content — and neither can your institution's owners or admins. Because of this we cannot search, moderate, export, or restore encrypted conversation content. We still process the surrounding details we need to run the features: who is in a messenger conversation, when messages were sent and read, typing and online status, public encryption keys, and assistant conversation titles and course selections. When you chat with Lexi, your browser decrypts prior turns and sends plaintext only for that request to our AI provider so a reply can be generated; we do not store those turns in readable form. Your private key is stored in your browser and backed up on our servers only in a form that can be opened with a recovery code we never receive. If you lose that recovery code and your browser data, that conversation history cannot be recovered by anyone, including us. Encryption protects content against access to our servers and database; it cannot protect a device, browser, or account that someone else controls.
06Institution analytics and engagement
Owners and admins can view aggregated institution analytics drawn from operational data already in the product—such as membership growth, grades, assignment activity, fee balances when fees are enabled, and engagement signals from student achievements. These overviews are scoped to their organisation and do not include the private content of AI assistant conversations. Students may choose a fictional organisation display name for the leaderboard or hide themselves from ranking in Settings; that choice does not remove their underlying activity records used for XP and achievements.
07Parents, children, and payments
A parent only receives child-scoped access after the institution verifies the relationship. Child registration requests may include identity, contact, relationship, and consent details. When an institution enables fees, it is the merchant of record and Stripe processes hosted onboarding and payments. SchoolDuty stores invoice, tax-rate, payment-status, refund, dispute, and receipt references, but not complete card, bank, or Stripe identity-verification details. Institutions choose their tax rates, refund policy, retention, and lawful basis for child data.
08Hosting and service providers
Application data (accounts, courses, materials, chats, and related records) is hosted on Supabase in the European Union — region eu-west-1 (Ireland). Payments use Stripe on the institution’s connected account. Language responses for Lexi use Google Gemini; optional voice features use Deepgram. Institutions evaluating SchoolDuty may request a data-processing agreement (DPA) and current subprocessor details by emailing arkasar@teiemt.gr.
09AI assistant & providers
When someone uses Lexi, their browser decrypts stored turns and may send the current prompt, selected course context, and retrieved excerpts from institution materials to Google Gemini to generate a reply. Optional voice input and spoken replies may send audio or text to Deepgram. Lexi chat turns are stored only as ciphertext on our servers. SchoolDuty does not use these prompts or school materials to train AI models, and we operate these integrations under provider terms that do not use API customer content to train their foundation models. Grounded answers can still be incomplete or wrong — treat them as study support (see the Terms).
10Your choices
Depending on your region you may have rights to access, correct, or delete certain personal data. Many requests are handled through your organisation or account settings. For privacy questions, DPA requests, or other compliance inquiries, contact your school administrator or email arkasar@teiemt.gr.
We may update this summary as features change. Institutions may request a data-processing agreement (DPA), retention details, and the current subprocessor list by emailing arkasar@teiemt.gr. For binding contractual terms, rely on agreements and notices that apply to your organisation.