Privacy Policy

Last updated24 September 2026
BrandClassRoots
CompanyAadyash Technologies Private Limited

ClassRoots is a school-operations platform made by Aadyash Technologies Private Limited. It is used by schools, and through them by parents, teachers and office staff. This policy says what we collect, where it goes, who else touches it, and what you can do about it.

We have tried to write it so that a principal signing a contract, a parent installing the app, and a teacher dictating a homework note can each find the sentence that applies to them. Where something is not as good as it should be yet, we say so rather than imply otherwise.

1. Who is responsible for what

Your school decides what information about its students, parents and staff is entered into ClassRoots, and why. Under India’s Digital Personal Data Protection Act, 2023, that makes the school the data fiduciary for that information and ClassRoots its data processor: we process it on the school’s instructions, and the school is responsible for collecting any consent it needs from parents and guardians before enrolling a child.

For the small amount of information we collect directly — a parent’s phone number at sign-in, device details, error reports — we are responsible ourselves.

2. What we collect

Everything below is either entered by your school, entered by you, or generated by using the apps.

  • About students (entered by the school): name, class and section, roll number, date of birth, photo, parent and guardian names and phone numbers, attendance, marks and report cards, fee schedules, concessions and payments, leave, pickup and late-arrival requests, homework, early-years daily logs (meals, nap, mood, bathroom, medication given, items to bring), weekly learning logs (what the child worked on in each learning area, highlights, social and emotional notes), bus boarding records (tapped on, tapped off, or did not travel — no location), admission enquiries the school records and applications parents submit through a school’s online admission form (the questions are the school’s own and can include health details such as allergies or medication, and identity numbers where the school asks for them), and certificates the school issues.
  • About parents: your phone number (used to sign in with a one-time code), your name, your email if you give it, your preferred language, a push-notification token for your device, the messages you send to teachers, the photos and comments you post in Moments, homework you submit for your child, and your fee payments. For a payment made online, that is the amount, status and Razorpay reference; your card or bank details are entered on Razorpay’s screens and never reach us. For a payment made straight to the school’s UPI ID, it is the payment screenshots you share and what is read from them (transaction id, amount, date, who paid and who was paid), or the transaction id and amount you type, plus any note you add. A screenshot shows whatever your UPI app puts on it — usually your name, your UPI ID, your bank and the payment note, sometimes more — so crop out anything the school does not need, such as other transactions or a balance, before you share it.
  • About teachers and staff (entered by the school): name, phone, email, role, subjects and classes, date of joining, attendance and leave (including, where the school has turned on the location check, how far the phone was from the school at the moment of a self check-in tap — the position itself is measured and discarded, never kept; see section 3), salary and payroll records, and — where the school uses ClassRoots for payroll and statutory filings — government and bank identifiers such as Aadhaar number, PAN and bank account details. See section 8 for how those are protected. Where staff record the school’s expenses: the amount, supplier, invoice number and GSTIN they enter, and the bill photos or PDFs they attach.
  • From your device: app version, device model and operating system, and error reports if the app crashes. From the web portals: sign-in events, the browser and IP address of each session, and an audit trail of important actions — who published a circular, who changed a fee, who turned a setting off.

3. What we do not collect

  • Your location, with one narrow exception. Bus boarding works by a staff member tapping a child on and off; there is no GPS tracking of buses, children or staff. The exception: if a school turns on the location check for staff check-in, the staff app sends a single position fix at the moment a staff member taps “I’m in”, so the school can tell whether they were at the school. It is taken only at that tap, only when the school has turned the check on, and only after the staff member has allowed location for the app. We keep the distance from the school and whether it was within the school’s radius — not the position itself, which is discarded once measured. Nothing is recorded at any other time.
  • Your contacts, photos or files, other than the ones you choose to attach.
  • Card numbers, UPI PINs or bank passwords. Online payments are completed on Razorpay’s own screens, and a payment to the school’s UPI ID is made in your own UPI app.
  • Anything for advertising. There are no advertising or tracking SDKs in the apps, and we do not sell or rent personal data to anyone.

4. How we use it

To run your school’s day: deliver circulars and notifications, record and report attendance, manage fees and receipts, help the school’s office check the payment screenshots parents share, run exams and report cards, handle leave and pickup requests, share homework and daily logs, record bus boarding, issue certificates, pay staff, and track expenses, including reading the bills staff scan.

To keep the platform safe: sign you in, prevent abuse, investigate problems and keep an audit trail. To support you: answer questions from parents and schools. To meet legal obligations, including statutory school and financial records.

5. Where your information is stored, and who processes it

We run ClassRoots on a small number of specialist providers. Each one is listed below with where the processing happens and what it receives. We are precise about geography because it is often asked: your school’s files are stored in India; the database and application servers are in Singapore; and some processing happens in the United States, Germany and Australia. We do not claim that all data stays in India.

  • Render (Singapore) — database and application servers — all platform data.
  • Amazon Web Services, S3 (Mumbai, India) — file storage — photos, attachments, voice recordings, payment screenshots parents share, bills staff attach, and generated PDFs. The storage is private; files are served through short-lived signed links.
  • MSG91 (India) — SMS — your phone number, to deliver the one-time sign-in code.
  • Razorpay (India) — payments — the amount, fee reference and payer contact for online fee payments. Card and bank details are entered on Razorpay’s screens and never reach us.
  • Expo, Google Firebase Cloud Messaging and Apple Push Notification service (United States) — push notifications — your device token and the text of each notification.
  • Zoho Mail (Australia) — email — messages we send you, and support conversations.
  • Sentry (Germany) — error reports — technical details of app and server crashes. We scrub personal information before sending, but a report can include an account identifier and the screen that failed.
  • Anthropic (United States) — AI features, text and images — see section 6.
  • OpenAI (United States) — voice transcription — see section 6.

Each provider processes data only on our instructions and under terms that prohibit using it for their own purposes. We will update this list before adding a provider.

6. AI features — exactly what each one sends, and the switch

Some ClassRoots features use a large language model from Anthropic (Claude), which works with text and can also read images, or speech-to-text from OpenAI (Whisper). This section lists every one, because the answer to “what does the AI see” is different for each.

  • Voice circular (staff app and web portal): the principal’s recording goes to OpenAI for transcription; the transcript, the school’s name and the requested tone go to Anthropic to draft the circular and a Tamil or English translation. The principal reviews the draft before anything is published.
  • Homework by voice (staff app): the teacher’s recording goes to OpenAI; the transcript goes to Anthropic to fill in subject, title, description and due date. The teacher reviews before posting.
  • Daily log by voice (staff app, early-years classes): the teacher’s recording goes to OpenAI; the transcript goes to Anthropic to fill in the meals, nap, mood and note fields. A recording naturally names the child and may describe medication given. The teacher reviews before saving.
  • Weekly log by voice (staff app, Montessori and early-years classes): the teacher’s recording goes to OpenAI; the transcript and the names of the school’s learning areas go to Anthropic to sort what the child worked on under each area, with highlights and a note. A recording names the child and describes their week. The teacher reviews before saving, and nothing reaches a parent until the teacher publishes it.
  • Bill scanning (staff app): when a staff member scans a bill while recording an expense, the photo or PDF of the bill and the names of the school’s expense categories go to Anthropic to fill in the amount, shop, invoice number, GSTIN, date, a short description and a suggested category. The staff member reviews them before saving, and the bill is kept with the expense.
  • “Draft for me” (web portal): the principal’s rough notes and the school’s name go to Anthropic to draft a circular.
  • Automatic translation of circulars (web portal): when a circular is published without the school supplying its own translations, the title and body go to Anthropic and the translation is published to parents alongside the original. This translation is not reviewed by a person before parents see it. Schools that want every translation checked should supply their own, or turn AI features off.
  • Report-card remark suggestions (web portal): the student’s name, class, subject marks, rank and co-scholastic grades for that exam go to Anthropic to suggest a remark. A teacher or principal edits and saves it; nothing reaches a parent automatically.
  • Ask AI in the report builder (web portal): the question typed by the staff member and the list of report fields available to their role go to Anthropic. No student records are sent; the report itself runs on our servers afterwards.
  • ClassRoots Insights — the Morning Pulse, class briefs and the parent “For you” digest: switched on separately by the school. The facts are computed on our servers; to phrase them, a student’s first name, class label and the computed numbers go to Anthropic — never contact details, date of birth or photos. Parent-facing insights are a second, separate switch, and every activation is recorded.
  • AI Assistant in the parent app: your question, your child’s name, class and roll number, and their recent circulars, events, homework, fee amounts and due dates, and marks go to Anthropic so the answer can be grounded in them.
  • Payment screenshots (parent app): when you pay the school’s UPI ID and share a screenshot of the payment in the app, the image goes to Anthropic to read the transaction id, amount, date, who paid, who was paid and whether the payment went through. We send the image alone, without adding your child’s name, your name or the fee — but the image shows whatever your UPI app shows, usually your name, UPI ID and bank, and the payment note, which names the fee and your child if you paid with the QR code in the app. The fee is marked as reported, and reminders for it stop, as soon as you share the screenshot — before anyone at the school has looked at it. The school’s office sees the screenshot next to what was read, checks it, and confirms before any receipt is issued; nothing is marked paid from an image. If you would rather not share a screenshot, you can type the transaction id and amount instead, and no image is sent.
  • Help assistant in the web portal: the staff member’s question and our own help articles go to Anthropic. No school data is sent unless it is typed into the question.

Free text goes as written. The structured data each feature sends is listed above, but a circular’s body, a dictated note or a question typed into an assistant is sent exactly as it was written or spoken — including any names, numbers or details in it.

Images go as captured. A payment screenshot or a bill photo is sent with everything visible in it — other transactions, a balance, a phone number — not only the details we ask for. We shrink it and remove its location data first; a PDF bill is sent as it is.

Under the commercial API terms we use, neither Anthropic nor OpenAI uses these requests — text, recordings or images — to train their models. They may retain a request briefly for abuse monitoring under their own policies.

The switch. A principal can turn every AI feature off at once in the web portal, under Settings → Modules → AI features. It is on unless the school turns it off. When it is off, ClassRoots does not send any of that school’s information to Anthropic or OpenAI: dictation buttons disappear, circulars publish without automatic translation, Insights use fixed wording, help answers come from keyword search, and the parent AI Assistant is unavailable. Payment screenshots still reach the school’s office, where a person reads them instead, and bills can still be attached to an expense, with their details typed in by hand. The setting is enforced on our servers, not only hidden in the apps, and each change is recorded in the school’s audit log.

Turning it off stops the AI providers only. It does not move the database out of Singapore or stop error reports going to Germany.

7. Children’s information

Students do not use ClassRoots themselves; parents and schools do. Information about a student is visible only to that student’s linked parents, to authorised staff at the student’s school according to their role, and to the ClassRoots operations team where strictly required for support, security or legal compliance. We do not use children’s information for advertising, profiling, or any purpose beyond running the school’s own services.

Student photos are uploaded by the school, stored privately, and served through short-lived links. A school can mark a child as “no photo consent”, after which the photo is not shown anywhere in the apps or the portal. Photos are shown unless the school records that consent was not given, so schools should set this when a parent asks.

8. Teachers’ and staff information

Payroll needs sensitive identifiers. Where a school records Aadhaar, PAN or bank details for its staff, those are visible only to the principal, correspondent and office roles at that school — not to other teachers. They are encrypted in transit and protected by role-based access controls; at rest they sit in the database in Singapore like other records. We do not yet apply an additional field-level encryption to these identifiers, and we would rather say so than imply otherwise. No feature sends these identifiers to an AI provider. Bill scanning (section 6) sends whatever a staff member chooses to scan, so it is for bills only: staff should not scan payroll documents, such as salary slips or bank letters, with it.

9. Security

Encryption in transit everywhere. Sign-in by one-time code; portal passwords are stored only as salted hashes. Each school’s data is isolated by tenant checks on every request, and roles limit what each staff member can see. File storage is private and served through expiring links. Important actions are audit-logged.

We do not hold certifications such as ISO 27001 or SOC 2 and do not claim to; we will say so plainly if that changes. No system is perfectly secure. If we learn of a breach affecting your data, we will tell the affected school without undue delay.

10. How long we keep it

For as long as your school uses ClassRoots, and afterwards for as long as needed to hand the data back and to meet legal obligations. When a school leaves, it can export its records and ask us to delete the rest; we delete on request rather than on a fixed schedule, and confirm in writing when it is done.

Some records must be kept longer by law — attendance registers, fee receipts, certificate registers and payment records — and we keep those for the statutory period even after a deletion request.

Payment screenshots, and the bills attached to expenses, are kept with the fee or expense record they belong to, like other payment records — including a screenshot shared for a payment the school did not confirm.

11. Deleting your account

Parents can delete their account in the app (Profile → Delete Account) or by writing to support@classroots.ai. Deleting your account removes your sign-in and personal profile; your child’s school records, including fee records and any payment screenshots you shared, belong to the school and remain with it. Teacher and staff accounts are managed by the school.

12. Your rights

You can ask to see, correct or delete personal information about you. For information entered by your school, ask the school first — it is the fiduciary and can act immediately, and we will help it do so. For anything else, write to support@classroots.ai. We aim to respond within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

13. Cookies and website analytics

The web portals use a first-party session cookie to keep you signed in; there are no advertising or third-party cookies. classroots.ai uses Vercel Analytics, which counts page views without cookies or personal identifiers. If you book a demo through our website, the booking is handled by Cal.com under its own privacy policy.

14. Changes to this policy

We update the “Last updated” date whenever this policy changes, and tell schools directly when a change affects what we send to a provider or which providers we use.

15. Contact

Aadyash Technologies Private Limited — support@classroots.ai. For privacy requests, put “Privacy” in the subject line.