Trust

You are holding data about children

So are we, on your behalf. Here is exactly what that means — in the architecture, not just in a policy document.

One database per school

Your data is not a set of rows in a shared table with a column naming your school. It is a separate database with separate credentials. There is no query anyone could write, or forget to filter, that returns another school's students alongside yours.

No advertising, no tracking, no model training

The parent portal carries no third-party trackers. Parents opening a link about their child are not an audience to be sold. We do not train AI models on your data, and neither does our AI provider.

Export whenever, without asking

Students, classes, invoices, payments — all exportable to CSV or JSON from inside the app, by you, at any time. No support ticket, no fee, no notice period. Data you cannot get out is data you do not really control.

Deletion means the database is gone

Close your account and after 30 days your database is dropped. Not flagged inactive, not moved to cold storage. Per-school databases make the right to be forgotten a single operation with no way to miss a table.

You choose the region

A school in the EU can hold its data in the EU. Region is chosen when the workspace is created, so data residency is a setting rather than a support conversation.

Encrypted, and access is logged

Encrypted in transit and at rest. Passwords hashed with bcrypt. Database credentials encrypted before we store them. Every meaningful action in the app is written to an audit log that you can read.

The questions schools actually ask

Can your staff read our students' records?
Only when we need to in order to support you, and every access is logged. Support staff are never given accounts inside your workspace — they sign into a separate console — so “who touched this record” always has an honest answer.
What happens if a parent asks you to delete their child's data?
Point them to your school: you hold the relationship and the records, and you can delete or correct anything from inside the app. If they contact us directly, we tell them the same thing rather than acting behind your back.
Do you need a signed DPA?
Our data processing agreement forms part of the terms automatically, so nothing needs signing to be covered. If your board or a regulator wants a countersigned copy, ask and we will send one.
What if Schoolory goes away?
Your export is a plain CSV or JSON file and your database is standard SQLite — not a proprietary format that only we can read. That is deliberate: a lock-in you cannot leave is not a partnership.

Read the actual documents

Each one opens with a plain-English summary, then the full text underneath.

Something not covered? support@schoolory.com

We are a small company and we do not have a compliance department to hide behind. That cuts both ways: no certifications to wave at you yet, and no committee between you and a straight answer.