Your privacy and the privacy of your students matter. This policy explains in plain language what data SchoolTrack stores, where it lives, how long it's kept, and who can see it.
When you use SchoolTrack, the following data is stored in your school's private Firebase database:
Passwords: all logins (admin, teacher, and parent) are handled by Firebase Authentication. Passwords are never stored in your school's records — not even by the admin. The initial password is shown to the admin once at account creation for sharing; after that, the only way to change a password is a secure reset email.
If you configure the optional email feature, messages are sent through EmailJS using your own EmailJS account. Recipient email addresses and message contents pass through EmailJS's servers when you send a message. This is optional and off by default.
If your school enables online tuition payments, invoice amounts, descriptions, and due dates are shared with Stripe to generate a checkout session. When a parent pays, Stripe collects and stores their card details directly — SchoolTrack never sees or stores card numbers. We receive only confirmation that a specific invoice was paid, which we record against your school's billing records. See Stripe's Privacy Policy for how Stripe handles payer information.
As the school administrator, you are responsible for ensuring your use of SchoolTrack complies with student privacy laws in your jurisdiction (such as FERPA and COPPA in the US, or GDPR in the EU).
⚠️ Before onboarding a real school, have a qualified lawyer review this policy and your obligations. In particular: FERPA/COPPA compliance for US schools, whether you need parental consent to store children's records in Firebase, data-residency requirements (Firestore data is hosted in the US), and whether your school requires a formal Data Processing Agreement. SchoolTrack is an early-stage product and this policy is not legal advice.
SchoolTrack does not use advertising cookies, analytics trackers, or third-party ad scripts. Firebase Authentication stores a login token on your device so you stay signed in. If your school enables online payments, Stripe's checkout page may set its own cookies while you're on stripe.com — that's controlled by Stripe, not SchoolTrack.
You can permanently delete your school's data at any time from Settings → Reset All Data inside the app, which clears both your device cache and your Firebase records. To delete your admin login account entirely, contact us and we'll remove it.
We may update this Privacy Policy from time to time. The date at the top reflects the last revision. Continued use of SchoolTrack after changes take effect constitutes acceptance of the revised policy.
If you have questions or concerns about your privacy, please contact us.