This Privacy Policy explains how SkuulMaster ("SkuulMaster", "we", "us")
handles personal information in the SkuulMaster Staff mobile application
(the "App"). The App lets authorized school staff — teachers and school leaders —
carry out their daily work: taking attendance, entering marks and reports, messaging, recording
pastoral/welfare notes, and (for finance and leadership roles) school operations — each
user seeing only what their role allows.
SkuulMaster Staff is intended for authorized school staff.
Accounts are provisioned by your school — the App does not offer self-service account
creation.
1. Information we collect
Information you provide
- Phone number — used to sign you in. We send a one-time verification
code to confirm it's you.
Information created when you use the App
- One-time login codes — generated for sign-in. They are stored only in
a hashed (irreversible) form, expire shortly, and are single-use.
- Account & session identifiers — to keep you signed in and link you to
your staff record, your school, and your assigned role(s).
- Limited security/technical data — e.g. the IP address of a sign-in attempt
and basic event timestamps, kept for security and abuse prevention; app version and device type.
- On-device preferences — your notification settings, language choice, and
active role are stored locally on your device (not used for tracking). Work captured offline is
stored on your device until it syncs when you reconnect.
School information you work with
Through the App you view and enter your school's operational records — attendance,
marks and reports, messages, pastoral/welfare notes, and (depending on your role) fees/finance and
staff/HR information. This information is owned and managed by your school.
SkuulMaster displays and processes it on the school's behalf; the school is the controller
of that data, and you may access only the data your role permits.
2. What we do NOT do
- We do not show advertising or include advertising SDKs.
- We do not use third-party analytics, tracking, or advertising-identifier SDKs in the App.
- We do not sell your personal information.
3. How we use information
- To authenticate you and keep your session secure.
- To show and let you record your school's information, scoped to your role.
- To send your one-time login code by SMS.
- To maintain security, prevent abuse, and operate and improve the App.
4. SMS messages
Login codes are delivered by SMS through our messaging provider (EgoSMS). Standard message
and data rates from your carrier may apply. We send these messages only to complete a sign-in
you requested.
5. Service providers
We share the minimum data needed with vendors that operate the service under our instructions:
- Supabase — cloud database, authentication, and secure server functions that
store your account data and serve the App's content.
- EgoSMS — delivery of one-time login codes by SMS.
We do not sell or rent personal information to third parties.
6. Data security
- All data is transmitted over encrypted connections (HTTPS/TLS).
- One-time codes are stored hashed; they are never logged or displayed.
- Role-based access controls ensure each staff member can only see the data their role permits.
7. Data retention & deletion
We keep your account and sign-in data while your account is active. You can request deletion of
your staff account and associated personal data at any time — see
Data & Account Deletion. Note that your school's
underlying records are controlled by the school; requests to change or remove those should be
directed to the school.
8. Students' and others' information
As part of your job, the App lets you work with school records about students and colleagues on
your school's behalf. That information belongs to the school. We do not knowingly permit students to
create their own staff accounts, and the App is not directed at children.
9. Your choices & rights
- Access or correct your own staff contact details by contacting us or your school.
- Correct school records through your school's normal processes (the school controls that data).
- Request deletion of your account — see Data & Account Deletion.
- Sign out at any time from More → Profile → Sign out.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the
"Last updated" date above and, where appropriate, by notice in the App.
11. Contact us
Questions or requests about this policy or your data:
support@skuulmaster.com.