Privacy Policy
Applies to all mobile applications published by Mobilise App Lab Private Limited
This Privacy Policy explains how Mobilise App Lab Private Limited (“Mobilise”, “we”, “us”, “our”) collects, uses, stores and protects information in the mobile applications we publish for schools and other educational institutions (each, the “App”).
The same policy applies to all of our Apps, including those built for faculty and staff and those built for students and parents. Each App is provided to the users of a single institution, and each institution runs its own separate installation of the underlying school management system.
Not every feature described here exists in every App. The features and permissions available to you depend on which App you have installed, which modules your institution has enabled, and the role assigned to your account. Sections that do not apply to your App simply do not apply to you.
1. Who We Are
Mobilise App Lab Private Limited develops and publishes the Apps. The information handled through an App originates from, and belongs to, the institution that issued your account. We handle that information to operate the App and provide the services described below.
2. Accounts and Access
Our Apps are closed systems. Accounts are created and issued by your institution — there is no public sign-up, and an App cannot create an account on its own. You sign in using credentials your institution has given you, together with a mobile number registered with that institution. If you are not a member of a subscribing institution, you cannot use the App.
3. Information We Collect
3.1 Information you provide
- Mobile number — used to identify which institution and account you belong to at sign-in.
- One-time password (OTP) — sent to your registered mobile number to verify your identity.
- User ID / admission number and password — used to sign in and to change your password.
- Content you submit — this varies by App and role, and may include leave requests, attendance entries, marks and remarks, lesson plans and daily tasks, assignments and homework, diary notes, material and purchase requests, gate pass and visitor entries, transport requests, feedback and support queries.
- Photos and documents — only the images or files you explicitly choose to capture or attach, for example a supporting document for a leave application.
3.2 Information provided by your institution
- Your record with the institution — such as your name, employee or admission number, class, section, subject or department, designation, reporting manager, guardian details where applicable, and contact details already held in the institution’s system.
3.3 Information collected automatically
- Push notification token — a device token issued by Google Firebase Cloud Messaging so your institution can send you notifications. This token is deleted when you sign out.
- Basic device and connection information — device type, operating system version and network availability, used to deliver notifications, adapt the App’s behaviour when you are offline, and support you when you report a problem.
3.4 Records you access as part of your role
Some Apps and roles allow you to view records belonging to other people — for example, a teacher viewing the attendance, marks or remarks of students in their class, or a parent viewing their own child’s records. Those records belong to the institution and are shown to you strictly for your role. We do not use them for our own purposes, do not use them for advertising, and do not share them with anyone other than the institution.
What our Apps do not do:
- We do not track you in the background or build a location history.
- We do not access your contacts, call logs, SMS messages or calendar.
- We do not use advertising identifiers, and our Apps contain no advertising.
- We do not run behavioural analytics or profiling. Analytics is disabled in our Apps.
- We do not collect or store card, UPI or bank account details — see Section 6.
- We do not sell, rent or trade personal information — ever.
4. Device Permissions
An App asks for a permission only at the point the related feature needs it, and only for the purpose set out below. You may decline or later revoke any permission from your device settings; only the related feature will stop working.
| Permission | Why it is needed |
|---|---|
| Camera | To take a photo for an attachment, and — where the feature exists — to scan a QR code for gate pass or visitor check-in. |
| Photos / Storage | To attach an image or document already on your device, and to open or save files such as circulars, diary notes and digital library material. |
| Notifications | To receive circulars, notices, approval requests and other institutional communication. |
| Location | Requested only by Apps that include transport or bus-related features, and only while you are actively using such a feature. It is never used for background tracking and no location history is stored. If your institution has not enabled such a feature, no location information is used. |
| Network access | To communicate with your institution’s server. Our Apps require an internet connection. |
5. How We Use Information
- To verify your identity and sign you in securely.
- To provide the features enabled for your App, your institution and your role.
- To show you the correct records and hide those you are not authorised to see.
- To send notifications about circulars, approvals and other institutional communication.
- To route your requests to the correct approving authority within your institution.
- To diagnose problems and provide technical support when you contact us.
We do not use your information for marketing, advertising, profiling or automated decision-making.
6. Fee and Other Payments
Where an App offers fee payment, selecting it opens your institution’s own secure payment page inside the App’s browser window. The payment is completed on that page, operated by your institution and its payment provider.
The App itself never sees, collects or stores your card number, UPI ID, net-banking credentials or any other payment instrument details. Those details are handled entirely by the payment provider under its own terms and privacy policy. We receive only the payment status recorded by your institution.
7. Information Stored on Your Device
Our Apps store a limited amount of data locally on your device:
- Your signed-in session and the profile information returned by your institution’s server.
- Your push notification token.
- A small local database used to keep recently viewed information available and reduce repeated downloads.
- Simple preference flags, such as whether you have already seen the welcome screen.
This local data is erased when you sign out, and it is removed entirely if you uninstall the App. Your password is never stored on your device.
8. Sharing and Disclosure
We share information only in these limited situations:
- With your institution — which operates the systems the App connects to and is the source and owner of the records shown in the App.
- With Google Firebase Cloud Messaging — a Google service used solely to deliver push notifications to your device. Only the notification content and your device token are processed. See the Firebase Privacy and Security and Google Privacy Policy.
- With your institution’s payment provider — only where you choose to make a payment, and only on that provider’s own page, as described in Section 6.
- When required by law — if we are legally obliged to disclose information by a valid order of a court or competent authority.
Each institution’s data is kept separate. We do not combine data across institutions, and we do not share your information with advertisers, data brokers or any other third party.
9. Data Security
- All communication between the App and institutional servers uses encrypted HTTPS/TLS connections.
- Sign-in is protected by mobile-number verification with a one-time password, together with your credentials.
- What you can see inside the App is limited by your role — you are shown only what your role permits.
No method of transmission or storage is completely secure. While we take reasonable and appropriate measures to protect your information, we cannot guarantee absolute security.
10. Data Retention
Records held by your institution are retained for as long as your account is active, and thereafter in accordance with the institution’s own record-retention policy and applicable law. Your push notification token is retained while the App is installed and you are signed in, and is deleted when you sign out. Data held on your device is cleared when you sign out or uninstall the App.
11. Children’s Privacy
Some of our Apps are provided to students, including students under the age of 18. These Apps are made available only through the student’s institution, using an account the institution has issued. We do not knowingly allow anyone to register independently, and we do not seek any information from a child beyond what the institution already holds and what the child submits as part of normal school work — for example homework, a leave request or a diary note.
We do not use children’s information for advertising, marketing, profiling or any commercial purpose. We do not sell it, and we do not share it outside the institution except as described in Section 8.
A parent or legal guardian may contact the institution, or contact us at the address in Section 14, to review the information held about their child, ask for it to be corrected, or ask for the child’s account to be closed.
12. Your Rights and Account Deletion
You may, at any time:
- Request access to the personal information held about you.
- Request correction of information that is inaccurate or out of date.
- Withdraw any permission you have granted, from your device settings.
- Sign out to clear all App data stored on your device.
- Request deletion of your account and associated personal data.
To request account and data deletion, email ashish.sharma@mobilise.co.in from your registered email address, with your name, your institution, and your employee or admission number, using the subject line “Account Deletion Request”.
We will acknowledge your request within 7 working days and action it within 30 days. Please note that some records must be retained by your institution to meet legal, statutory, academic or employment obligations; where this applies, we will tell you which records are retained and why. Deleting your account removes your access to the App.
13. Changes to This Policy
We may update this Privacy Policy from time to time — for example, if a feature changes what information an App uses. When we do, we will revise the “Last updated” date at the top of this page. If a change is significant, we will provide notice within the App. Please review this page periodically.
14. Contact Us
If you have any question, concern or complaint about this Privacy Policy or about how your information is handled, please contact us:
Mobilise App Lab Private Limited
Email: ashish.sharma@mobilise.co.in