eScholr Privacy Policy

Last updated: 4 August 2026

This Privacy Policy explains how eScholr (“the App”, “we”, “us”) collects, uses, and protects information when a school and its users (administrators, teachers, students, parents, and staff) use the App.

eScholr is school management software. Each school that uses eScholr is the data controller for its own students’, parents’, and staff members’ information. eScholr acts as a data processor, storing and processing that data only as instructed by the school, and only to provide the App’s functionality. If you are a student or parent with a question about your data, contact your school first - they control access, corrections, and deletion requests.

1. Information We Collect

Account & identity data - name, email, role (student/parent/teacher/staff/admin), and a school-assigned ID, provided by the school when your account is created.

Personal & demographic data - date of birth, gender, and nationality, where the school records these for a student, staff member, or applicant.

Contact & family data - phone number, postal/home address, parent/guardian contact details, emergency-contact name and phone, and student–parent relationships, for communication and pickup/emergency purposes.

Academic records - attendance, grades, marks, timetable assignments, homework/assignment submissions, and library borrowing records, as entered by school staff.

Financial data - fee invoices and payment status, visible only to authorized finance staff and the relevant family.

Health data - where a school configures it, an admissions applicant may be asked to upload a medical record as part of the enrolment documents. This is optional per-school, stored only for the school that requested it, and treated as sensitive.

Uploaded documents - files attached to admissions applications and other records (e.g. certificates, transcripts, supporting documents), stored for the school.

Messages - the content of messages you send through the app’s in-app messaging (e.g. staff–parent communication) is stored so recipients can read it.

Profile photos - optionally uploaded by staff/admins for student and staff profile pictures, using your device’s camera or photo library.

Authentication data - your login session is secured with a token stored in your device’s encrypted secure storage (OS keychain). If you enable biometric login (Face ID / fingerprint), the biometric scan is processed entirely by your device’s operating system - eScholr never receives or stores your fingerprint or face data. Only a local “biometric login enabled” flag is stored.

Push notification tokens - a device token used to deliver alerts (e.g., new grades, attendance, announcements). No message content is stored by the push provider beyond delivery.

Diagnostic data - eScholr does not run its own analytics or crash-reporting SDK and does not collect usage analytics. If you have Google Play’s diagnostic collection enabled in your device settings, Google may provide us aggregate crash and performance reports for the app; that collection is governed by Google’s own policies, not ours.

2. Permissions the App Requests, and Why

PermissionPurpose
CameraTake a profile photo for a student/staff record, or scan a library book barcode (librarian role only)
Photo libraryChoose an existing photo for a profile picture
Biometric (Face ID / fingerprint)Optional faster sign-in; processed on-device only, never transmitted
NotificationsDeliver school alerts (attendance, grades, announcements)

We do not request microphone, location, contacts, or call/SMS access, and we do not access these even if your device permission is generally on.

3. How We Use Information

We do not sell personal data, and we do not use student data for advertising.

4. Data Storage & Security

Data is stored with Supabase, our database and backend provider, using row-level security so that each school can only access its own data, and each user role can only access the data permitted for that role. Data in transit is encrypted (HTTPS/TLS). Session tokens are stored in your device’s OS-level secure storage.

5. Data Sharing

We share data only with:

We do not share data with advertisers or data brokers.

6. Children’s Privacy

eScholr is used by schools to manage student records, which may include children under 13. Student accounts are created and controlled by the school, which is responsible for obtaining any parental consent required under applicable law (e.g., COPPA, GDPR-K) before enrolling a student. Parents/guardians may contact their school to review, correct, or request deletion of their child’s data.

7. Data Retention

School data is retained for as long as the school’s account with eScholr is active, plus any period required by the school’s own record-keeping policy or applicable law. Schools may request full deletion of their data by contacting us.

8. Your Rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data. Requests should be directed to your school first, since they control the underlying records; the school may coordinate with us to fulfill the request.

9. Changes to This Policy

We may update this policy as the App changes. Material changes will be reflected in the “Last updated” date above.

10. Contact Us

Codarti
support@codarti.com
Lusaka, Zambia