π
TeachVault Privacy Policy
Last Updated: August 24, 2026
1. Introduction
Welcome to TeachVault. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our mobile application.
TeachVault is designed for teachers to manage classes, track attendance, and organize student information. We prioritize data security and user privacy in everything we do.
2. Information We Collect
2.1 Information You Provide:
- Account information (email, name)
- Class information (class names, subjects, schedules, and timetable/schedule imports from PDF/CSV/Excel). Import parsing occurs on your device. Records are stored locally by default and may be retained off device when you use an optional signed-in timetable, collaboration, portal, public-link, or backup workflow.
- Student information (names, roll numbers, contact details)
- Attendance records (including attendance method: Manual, QR, or Mixed for analytics)
- Academic Portfolio data (Pro feature): If you use Academic Vault features, you may store conference details, publication information, grant records, speaking engagements, patents, copyrights, consultancy information, student supervision records, certificates, administrative roles, memberships, and other academic achievements. Portfolio data is stored locally by default. Relevant records or files may also be retained off device when you use optional signed-in Academic Registry, Course File/CO-PO, Mentor Workspace, profile-intake, collaboration, public-link, or backup workflows.
2.2 Automatically Collected Information:
- Device information (model, OS version)
- App usage statistics and feature events (for example analytics events emitted by the shipped app configuration)
- Crash reports and diagnostics (if enabled)
- Anti-abuse and reliability telemetry (for example hashed source identifiers, request counters, and response diagnostics)
- TeachVault does not collect location by default and does not sell location data. If you enable optional QR geo-fencing, precise or approximate coordinates, accuracy/capture metadata, and location-integrity signals may be collected only while in use and retained with the relevant class, QR session, or check-in record to verify classroom presence. Location is not used for advertising or background tracking.
- Store purchase and entitlement metadata (for example product ID, transaction/order/original-transaction identifiers, receipt-validation status, and entitlement dates). Payment-card details remain with Apple or Google and are not collected by TeachVault.
- Microphone & speech recognition are not requested in the current store build because voice notes / roll-call voice input are not shipped.
2.3 Information We DO NOT Collect:
- We do not collect sensitive student data (grades, medical info) unless you explicitly enter it
- We do not track your browsing history
- We do not sell your data to third parties
3. How We Use Your Information
We use your information for:
- Providing core app functionality (attendance tracking, class management)
- Providing backups/restores you request or enable
- Improving app performance and fixing bugs
- Sending important updates about the app
- Analyzing usage patterns to improve features
We do not:
- Sell your personal data
- Use your data for advertising purposes
- Share student information with third parties for marketing
Data is disclosed only to service providers for features you enable, recipients you select, legal recipients when required, and explicitly confirmed processors described in this policy.
Important: TeachVault does not use user data for advertising or tracking purposes.
3.1 Smart Attendance Insights (On-Device Analysis)
TeachVault provides "Smart Insights" that analyze your attendance patterns to offer personalized recommendations (e.g., "Monday absences are higher than average").
Privacy-First Design:
- All analysis runs locally on your device using SQL queries
- No attendance data is sent to external servers for analysis
- This Smart Attendance Insights feature does not use a cloud AI/ML model or cloud API for its attendance analysis
- Attendance inputs used by this feature stay on the device during insight generation
This statement is limited to Smart Attendance Insights. It does not describe optional backup, collaboration, portal, public-link, support, or explicitly confirmed cloud-processor features.
4. Data Storage and Security
4.1 Local Storage:
- Teacher/student feature content is stored locally on your device by default. Limited store/bootstrap/security metadata and data from optional cloud workflows may be processed off device as disclosed below.
- We use SQLite for local storage and apply application-level AES-GCM encryption to sensitive fields
- Student contact information and other sensitive fields are encrypted on-device before storage
- If you enable Photo Evidence, captured attendance-evidence photos are stored locally on your device. Captured attendance-evidence image files are not backed up. A backup may retain only database records that reference those local files; restoring that metadata does not restore the images. Optional student-profile photos use a separate managed-photo backup bundle.
4.2 Cloud Storage (Optional):
- You can optionally enable safety backups to Google Firebase Storage, Google Drive, iCloud, or other supported providers
- New signed-in backup files are encrypted before upload, but restore depends on matching secret material held by the originating device. Reinstall, secure-storage reset, or device loss can make the copies impossible to decrypt; they are not clean-device or cross-device recovery.
- Cloud Safety Backup (TeachVault-hosted storage) is provided as a convenience; we may change its availability or per-user limits with reasonable notice. Your backups to your own Google Drive, iCloud, or other third-party storage are not limited by TeachVault.
- You control when and what data is backed up
- You can disable cloud backup at any time
- Some optional cloud-powered features may retain feature content and operational metadata in TeachVault-managed cloud services when you enable or use them. Depending on the feature, this may include class/timetable/attendance/academic records; student, parent, guardian, or mentor contact and address details; profile, meeting, communication, scholarship/financial-concern, academic-progress, medical, blood-group, or medication information; photos/files; QR location, device, session, and check-in metadata; and poll/public-link responses.
- The current production release is not comprehensively end-to-end encrypted; some optional cloud workflows remain server-readable
4.3 Security Measures:
- PIN app lock (optional)
- Screenshot blocking for sensitive screens (optional)
- Auto-lock after inactivity (configurable)
- Secure data transmission (HTTPS/TLS)
5. Data Sharing and Third Parties
We share data only in these limited circumstances:
5.1 Service Providers:
- Firebase (Google) - For authentication, App Check/security, optional cloud backup/storage, QR attendance realtime sync, and optional timetable, collaboration, academic registry/course, mentor/profile-intake, shared/public-link, and Class Polls workflows when those features are enabled
- Sentry - For crash reporting and diagnostics/bug reports you choose to send
- Configured system email provider - For support/system email delivery where enabled
- These providers process data under their applicable published terms, privacy commitments, and any agreements that apply to the service configuration. Their own policies also govern their processing.
5.2 Legal Requirements:
We may disclose data if required by law or to protect rights and safety.
5.3 With Your Consent:
- You can export and share your data (CSV, PDF reports)
- You control what data is shared and with whom
- If you explicitly connect a class to the separate QVault companion service, TeachVault transfers the class name; the full names and roll numbers in the teacher-confirmed selected-class roster; and technical class, handover/link, and roster-integrity identifiers to QVault's separate Firebase project so you can prepare the roster there. This teacher-directed transfer is optional and confirmed before sending. Disconnecting or deleting the TeachVault link does not erase a roster already transferred to QVault; manage or delete that copy in QVault under its applicable controls and policy.
5.4 Camera and Photo Evidence (Optional)
TeachVault may request Camera permission only when you use features that require it:
- Photo Evidence: to capture photo proof linked to attendance (Pro feature)
- Student photos (optional): to add student profile photos for easier identification
QR Attendance note: TeachVault only generates/displays QR codes on the teacherβs device. Students scan the QR code using their own device; TeachVault does not require camera access for QR generation.
TeachVault does not use camera access for advertising or background tracking.
5.5 QR Attendance & Device Binding (Optional)
When teachers enable QR Attendance (Pro feature), the following data is processed:
- Device identifier: a device-specific identifier may be collected to reduce proxy attendance and repeated abuse attempts
- Device binding: the first accepted device used by a student can become their registered device
- Mismatch alerts: if a student attempts to check in from a different device, the teacher may receive an alert
- Location (optional): if geo-fencing is enabled, precise or approximate coordinates plus accuracy/capture metadata may be collected and verified during check-in
- Auth / session metadata: cloud-powered check-in flows may include timestamps, platform details, and authentication/session identifiers needed to validate the request
Important:
- QR attendance data may be stored locally on the teacher's device and, for cloud-powered realtime flows, in TeachVault-managed Firebase services
- TeachVault may store a raw device identifier for active anti-abuse validation and may also derive hashed values for local matching, metrics, or rate limiting
- No advertising identifiers are collected for QR attendance
- Teachers can reset device bindings at any time
6. Your Rights (GDPR/CCPA-aligned)
You have the following rights:
- Right to Access: Request access to personal data TeachVault holds about you, subject to applicable law and identity verification
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Delete your account and covered TeachVault-managed content through the available controls. The in-app local clear flow removes database records and TeachVault-managed student/attendance-evidence photos; exported/imported documents and provider copies require separate deletion. The minimal deletion-enforcement record described below remains.
- Right to Data Portability: Export your data in standard formats
- Right to Restrict Processing: Disable optional cloud features and crash reporting where controls are provided
- Right to Object: Opt-out of optional analytics/crash reporting where controls are provided
- Right to Withdraw Consent: Disable features at any time
To exercise these rights:
- Go to Settings β Advanced Data Control β Delete Account (requests account/cloud cleanup and clears local database records, preferences/security material, and TeachVault-managed student/attendance-evidence photos; exported/imported documents and provider copies require separate deletion)
- Go to Settings β Diagnostics β Toggle crash reporting
- Go to Settings β Backup & Restore β Backup History to review TeachVault backup history. Delete provider copies using the controls in your Google Drive, iCloud, OneDrive, Files, or other provider account
- Contact us at: support@teachvault.app
7. Children's Privacy
TeachVault is designed for teachers and institutions, not for children to use as independent account holders. Teachers may enter student information and may share a teacher-controlled hosted profile-intake link that directly receives student- or guardian-submitted profile information.
- Teachers and institutions are responsible for having the lawful authority, institutional approval, and any required parental or guardian consent before entering student information or inviting a student to a hosted intake flow
- Do not invite a child under 13 to submit information unless the teacher or institution has implemented the parental-consent and other protections required for that use
- We recommend minimizing sensitive student data in the app unless you have the required consent, lawful basis, and institutional approval
- Student names and roll numbers are sufficient for attendance tracking
If you believe student information was submitted without the required authority or consent, please contact us immediately so the applicable records can be reviewed for restriction or deletion.
8. Data Retention
- Local data: Stored until you delete it or uninstall the app
- Cloud backups: Stored until you delete them from the relevant provider/service, subject to provider retention
- Deleted items: May be retained temporarily (e.g., Recycle Bin) based on app features/settings
- Account deletion: Requests account/cloud cleanup and clears local database records, preferences/security material, and TeachVault-managed student/attendance-evidence photos. Exported/imported documents, separately stored backups, and provider-managed records require separate deletion or follow provider retention.
- Deletion-enforcement record: To prevent concurrent or delayed services from recreating deleted records or restoring old email-based privileges, TeachVault retains a minimal server-side security marker containing the Firebase account UID and cryptographic hashes of the account email/recovery credentials. It contains no raw email, name, class, student, attendance, backup content, or uploaded file and is used only to enforce the deletion and suppress stale access.
- Crash reports and performance diagnostics: If off-device diagnostic upload is enabled, records are retained according to the active provider/account configuration. When that upload is disabled, the provider does not receive new reports from that service.
- Operational anti-abuse records (where enabled): Draft, rate-limit, QR, profile-intake, poll, and related security/reliability records may use bounded expiry where configured. Automatic cleanup or TTL is not guaranteed for every collection; some server/provider copies may persist under the applicable retention configuration until cleanup.
9. International Data Transfers
If you enable cloud features:
- Data may be stored on servers in different countries
- We may use Firebase (Google Cloud). Google provides GDPR-related commitments and tooling; TeachVault is designed to support GDPR-aligned use, but TeachVault has not undergone a formal legal compliance audit.
- Network traffic uses HTTPS/TLS. Backup files and selected sensitive fields are encrypted, but the live local database is not fully encrypted by default. Current signed-in backup restore still depends on matching secret material held by the originating device.
- You can avoid uploading teacher/student feature content by keeping optional signed-in cloud, backup, collaboration, portal, and public-link workflows disabled. Store/bootstrap and app-security services (for example Firebase initialization and App Check) may still process limited device, network, and security metadata, so local-only content use does not guarantee that no international service processing occurs.
10. Changes to This Privacy Policy
We may update this privacy policy from time to time. We indicate the current version by:
- Updating the "Last Updated" date
- Making the updated policy available in the app and on the applicable public policy page
Where a notice or renewed consent is implemented or legally required for a particular material change, TeachVault may also show an in-app notice or ask you to accept the updated terms. Continued use after an update has the effect provided by applicable law; an update does not replace consent where renewed consent is legally required.
11. Contact Us
If you have questions about this privacy policy or your data:
- Email: support@teachvault.app
- In-App: Settings β Feedback & Support β Report a Bug
- Response time: We aim to respond promptly; legally protected requests are handled within the applicable timeframe
For GDPR/CCPA-aligned requests:
- Email: support@teachvault.app
- We process requests within the timeframe required by applicable law (commonly 30 days where that rule applies)
π Privacy Summary
- Teacher/student feature content stays on your device by default; limited store/bootstrap/security metadata and optional cloud workflows are disclosed above
- Cloud backup and cloud-powered collaboration/share features are optional and disclosed above
- We never sell your data
- You can clear local database records and TeachVault-managed photos in the app; exported/imported documents and provider backups require separate removal
- Designed to support GDPR/CCPA-aligned access, export, and deletion requests
- No ads, no advertising tracking
Β© 2026 TeachVault.app by Dr. Dishant Pandya