Smart AI Campus Privacy Policy
This Privacy Policy describes how Smart AI Campus ("we", "us", "our") collects, uses, stores and protects information when you use our website (smartaicampus.app), our mobile and web applications, and any related services (collectively, the "Service"). Smart AI Campus is a multi-tenant Smart Institution Operating System used by educational institutions to manage attendance, cohorts, staff, students and parents.
Where you access the Service through an institution that has subscribed to Smart AI Campus, that institution is the controller of the personal data processed within their tenant; we act as a processor on their behalf. By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
1. What This Policy Covers
This Privacy Policy applies to information collected through the Smart AI Campus website, mobile apps, and any communications between you and our team. It does not apply to third-party websites or services that may be linked from within the Service.
2. Information We Collect Automatically
When you use the Service we automatically collect certain technical information, which may include:
- Device fingerprint — a derived hash of device attributes (model, OS version, unique device identifiers) used to bind a student account to one physical device and to detect proxy attendance attempts.
- Log data including IP address, browser type, the pages or screens you visited and the time of your visit.
- Usage data such as features used, time spent in the app and crash reports.
- Cookies and similar technologies on the website used to remember your preferences and improve the Service.
3. Information You Provide to Us
We collect information that you (or your institution) provide directly to us, such as:
- Account details — name, email address, phone number, password (stored hashed) and the institution you belong to.
- Role context — your tenant roles (Super Admin, Institute Admin, HOD, Teacher, Student, Parent) and any departmental scoping.
- Academic data — cohort membership, course and subject enrolments, attendance scans, leave requests and approvals.
- Parent-linking data — secure invite tokens, the relationship you declared and admin verification status.
- Communications — support tickets, help-desk messages and any content you submit through the Service.
4. How We Use Your Personal Information
We use the information we collect to:
- Provide, operate, maintain and secure the Service for your institution.
- Generate the right dashboard for your role and respect your capability-based permissions.
- Validate attendance scans (TOTP window, device fingerprint, cohort enrolment) and flag suspected proxy activity.
- Maintain immutable audit logs of administrative actions for compliance and dispute resolution.
- Send transactional communications (security alerts, leave updates, attendance warnings) and operational notifications.
- Detect, prevent and address technical issues, abuse and fraud.
- Comply with legal obligations applicable to us or your institution.
5. How We Share Your Personal Information
We do not sell your personal data — ever. We share information only with trusted parties strictly necessary to deliver the Service:
Your institution
Within a tenant, data is shared between roles (Admin, HOD, Teacher, Student, Parent) only to the extent each role's capabilities require. Tenants are isolated from each other — no cross-tenant data sharing ever occurs.
Group companies
Our affiliates that operate under the same data-protection policies and confidentiality obligations.
Service providers
Carefully selected vendors that help us run the Service, including:
- Apple — for App Store distribution.
- Google (Android, Firebase Authentication, Firestore, Cloud Functions, FCM, Analytics, App Check) — for Play Store distribution, authentication, database, backend logic, push notifications, analytics and abuse prevention.
- Cloud hosting providers — for secure storage and delivery of the Service.
We may also disclose information when required by law, regulation, legal process or governmental request.
6. Lawful Bases for Processing
For users in the European Union, United Kingdom and similar jurisdictions, we process personal data on one or more of the following lawful bases: performance of a contract with you, legitimate interests in operating and improving the Service, compliance with legal obligations, and your consent where required.
7. Individual Rights
Depending on your jurisdiction, you may have the following rights:
Review and update your data
You can review and edit most personal information directly inside the app's account settings.
Delete your data
You can request deletion of your account and associated personal data at any time.
Restrict processing
You can ask us to limit the way we use your information.
Data portability
You can request a copy of your personal data in a structured, machine-readable format.
Right to object
You can object to certain types of processing, such as direct marketing.
8. Contact for Individual Rights Requests
To exercise any of the rights described above, please email privacy@smartaicampus.app from the email address associated with your account. We will respond within the timeframe required by applicable law.
9. Links to Other Applications
The Service may contain links to third-party websites or applications. We are not responsible for the privacy practices of those third parties and encourage you to read their privacy policies before sharing any personal information.
10. Security
We implement industry-standard technical and organisational measures to protect your personal information, including encryption in transit, hashed passwords, strict Firestore security rules, role- and capability-based access controls, Firebase App Check on all client traffic, device fingerprinting for student accounts, and routine security reviews. Administrative actions write to an immutable audit log. No method of transmission or storage is 100% secure, but we work hard to protect your data.
11. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Service. You can request deletion at any time. We may retain certain information for longer where required by law or for legitimate business purposes such as fraud prevention.
12. Options for Ending Communication
You can opt out of promotional emails at any time by clicking the unsubscribe link in any marketing message or by adjusting notification preferences in your account settings. You will continue to receive transactional and security messages required to provide the Service.
13. Data Transfer and Storage
Smart AI Campus is operated from India and your personal information may be processed and stored on servers located in India and other jurisdictions where our service providers operate. By using the Service you consent to such transfer and processing.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date above. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
15. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at privacy@smartaicampus.app.
Copyright & Trademarks. All Smart AI Campus content, brand marks and logos are the property of Smart AI Campus and are protected by applicable intellectual-property laws.