Legal
Privacy notice
What personal data the product processes, why, on what lawful basis, and what a person can ask us to do about it.
This document has not been written, and nothing on this page is a legal term.
It is a placeholder with a real address, so that every link to it works and nobody has to invent one later. The text that belongs here has to be drafted by a qualified lawyer for the entity that sells this product and the countries it sells into. A plausible looking policy written by anyone else would read as finished, be relied on, and fail the first time it was needed.
Verifiable
What the software actually does
Each line is checkable against the file named beside it, so a reviewer can confirm it rather than take it on trust.
Personal data is stored in MongoDB Atlas and in AWS S3 in ap-south-1, Mumbai. The database host, bucket, region and key prefix this deployment is actually pointed at are printed from the running configuration on /admin/privacy, under the retention schedule.
src/features/admin/privacy-queries.ts
Passwords are hashed with argon2id and cannot be read back by anyone, including a super admin.
src/server/auth.ts
Session tokens are stored hashed, never in plaintext, so a database backup is not a set of live sessions.
src/server/auth.ts
No object in the bucket is publicly readable. Every image and every export is a short lived signed URL issued after an entitlement check.
src/server/s3.ts
No third party analytics script, tag manager or advertising pixel runs in the browser. Product events are recorded on the server only.
src/server/analytics.ts
Names, addresses, marks, comments, file names, amounts and signed URLs are never written to an application log. Identifiers are.
src/server/observability.ts
A per user data export and a per user erasure exist, both audited, and erasure removes the student objects in storage by identifier.
src/server/gdpr.ts
After an erasure the database is read back and searched for the person in every collection, and the erasure is certified complete only if nothing is found. The person is given a certificate saying which collections lost rows, which kept rows without their identity, and how many stored files went.
src/server/gdpr.ts
Every retention period names what enforces it: a daily sweep, an object lifecycle rule in the bucket, the life of the account, or a statutory minimum that nothing may delete on a timer. A period enforced by nothing is reported as a defect rather than shown as a blank.
src/server/data-subjects.ts
Consent is recorded one row per purpose per person, with the policy version in force at the time, and a withdrawal is stamped rather than deleted.
src/server/consent.ts
Every export carries a visible Aurethia watermark naming the account and the date, and an invisible per copy fingerprint, both recorded against the account. Every question read on screen carries the Aurethia mark with the account address and a short account code, which resolves in the same trace.
src/features/worksheet-builder/export.ts
Tenant data is filtered by tenant at the repository layer on every read and every write, so one institute cannot see another.
src/server/repo.ts
Third parties
Who else touches personal data
Anything that receives personal data and is not us belongs on this list. Adding a service to the product without adding it here is the mistake the list exists to make visible.
MongoDB Atlas
The application database.
ap-south-1, Mumbai
Amazon Web Services, S3
Question images, uploaded work and generated papers.
ap-south-1, Mumbai
Stripe
Card payments on the international path.
Per Stripe terms
Razorpay
Card and UPI payments on the India path.
India
The transactional email provider
Sign in links, invitations, invoices and reminders.
To be named once the provider is chosen
Retention
How long each class of data is kept
A number marked as a legal minimum is a lawyer's or an accountant's answer and cannot be shortened by a product decision. Each line also says what enforces it, because a period nothing acts on is a sentence in a policy rather than a promise.
auth session: 30 days
Product choice. The session lifetime in server/auth.ts.
A scheduled job deletes these every day. It deletes rows from authSessions.
auth token: 1 days
Product choice. Reset and invitation tokens expire far sooner and the row is swept daily.
A scheduled job deletes these every day. It deletes rows from invitations.
export artifact: 30 days
Product choice. The storage lifecycle rule in 15 section 5 expires the FILE; this sweep expires the ROW that names it.
A scheduled job deletes these every day. It deletes rows from exportJobs.
exam reminder: 60 days
Product choice. A reminder stamp only has to outlive the window it guards, which is at most fourteen days, so a second message cannot be sent; the notification itself is the record of what the child was told.
A scheduled job deletes these every day. It deletes rows from examReminders.
temp upload: 1 days
Product choice. The tmp prefix lifecycle rule.
An expiry rule on the object store deletes the files. The tmp/ prefix lifecycle rule on the bucket, per 15 section 5. There is no row: an abandoned upload is a file and nothing else.
student work: while the account exists
For as long as the enrolment exists, then to the institute retention policy.
It lives as long as the account does, and the erasure ends it.
attendance: while the account exists
For as long as the enrolment exists.
It lives as long as the account does, and the erasure ends it.
invoice: 2557 days
LEGAL MINIMUM. Seven years is the common floor across the markets in scope, and the exact figure per market is a question for the accountant.
This is a legal minimum, so nothing deletes it automatically.
payment: 2557 days
LEGAL MINIMUM. As invoice.
This is a legal minimum, so nothing deletes it automatically.
audit event: 2557 days
Product choice aligned to the money retention, so a financial dispute still has its trail.
This is a legal minimum, so nothing deletes it automatically.
consent: 2557 days
LEGAL. The evidence of a lawful basis outlives the processing it authorised.
This is a legal minimum, so nothing deletes it automatically.
analytics event: 400 days
Product choice. Long enough for a year on year comparison, short enough not to be a shadow profile.
Not held in the application database. The log pipeline. server/analytics.ts emits events to the logger and writes no collection, which is why no sweep can exist for this class and why saying so is the only honest entry.
application log: 30 days
Product choice. Long enough for an investigation, short enough to bound exposure.
Not held in the application database. The log pipeline retention setting. Nothing in this database holds an application log line.
For the drafter
What this document has to answer
Each line is a question the build team could not answer and a lawyer will need answered. They are listed rather than guessed at.
The data controller, and whether the institute or the platform controls the student records. This one answer changes the whole document and it has not been given.
The lawful basis for each purpose. Consent is the wrong basis for the fee ledger and the right one for optional AI processing, and the notice has to say which is which.
The position on children specifically. The age of digital consent runs from 13 to 16 across the markets in scope and THE PRODUCT DOES NOT MODEL IT AT ALL: it stores no date of birth, on any record, so it cannot tell a fifteen year old from a nine year old. What it does instead is in server/consent.ts, and it is one rule: an institute student is a child by definition, between Grade 1 and Grade 12, so a consent whose subject is a student is granted by their guardian and never by themselves. Counsel has to say whether that is sufficient per market, and if it is not, the answer is a date of birth field and a jurisdiction, which is a build.
The subprocessor list, which the facts panel on the privacy page states from the code rather than from memory.
International transfers. Data is stored in Mumbai and customers are in the United Kingdom, the European Union and the Gulf, so a transfer mechanism has to be named.
The retention schedule, which server/data-subjects.ts states per data class alongside what enforces each period, including the seven year figure on invoices that is an accountant question and not an engineering one.
How a person exercises access, portability, rectification, erasure and objection, and the address they write to.
The supervisory authority a complaint goes to.
Ownership
Who writes it
To be instructed by the client. A data protection specialist, because most data subjects here are children.
Versioning
How you can tell what you agreed to
This is version 0.1, in force from 1 Aug 2026. Nobody accepts one document on its own, so what is recorded against an account is the whole set in force at that moment, stamped with every document's version. The set today is acceptable-use 0.1, privacy 0.1, refunds 0.1, security 0.3, terms 0.1.
If you have an account, your settings screen shows which version you accepted and when, and asks again when the set moves on. Nothing is ever rewritten in place: a new acceptance is a new record, because the old one is the evidence of what was true then.
Elsewhere