When a school adopts software for its students, one question deserves a concrete answer: where do the records go, and who can see them? A vague answer will not do — and nor will a comforting one that turns out to be wrong.
A correction, stated plainly. An earlier version of this post described a deployment model in which each school's data sat on hardware the school itself controlled. That is not how PDP Shikshya runs: the platform is hosted and managed by us on cloud infrastructure we select and operate. We have rewritten this post, and our Privacy Policy and Terms, to describe what it genuinely does. The privacy story is still a good one — just not the one we told.
Where the data actually lives
The platform is hosted and managed by PDP Shikshya Pvt. Ltd. on cloud infrastructure we choose. We are responsible for running it: deployments, updates, backups, monitoring and security controls. Uploaded files and media — photos, documents, submitted homework — may be held in managed object storage rather than alongside the application, which is how the platform is normally configured.
Every school is a separate tenant, and each school's data is logically segregated from every other school's, with commercially reasonable measures to stop one school's users reaching another's records. A school that needs its data to remain on its own infrastructure should raise that before deployment; it changes how the platform is installed and is agreed separately.
The school owns its data
The school keeps all right, title and interest in everything it and its users put into the platform; nothing transfers ownership to us. This is contractual, not goodwill. We receive only the limited rights needed to run the service on its behalf — operating the platform and its AI features, authenticating users, security, support and maintenance. We do not sell school or student data, or process it for commercial purposes unrelated to running the service.
What reaches an AI provider
Several features are powered by third-party enterprise AI providers. Before an educational prompt is sent to one, the platform is designed to remove, mask or pseudonymise direct student identifiers — names, roll numbers, email addresses, phone numbers — so what travels is the substance of a question rather than the identity of the child asking it.
Be precise about the limit of that, though. We do it to the extent it is technically feasible, and technically feasible is not the same as always: a student can write an identifying detail into free text in a way no scrubber reliably catches. Complete anonymisation is not achievable in every circumstance. The honest commitment is commercially reasonable safeguards, not a perfect filter.
We will not disclose school or student data to an AI provider for training publicly available foundation models, unless a school authorises it in writing. Anonymised or aggregated operational information that cannot reasonably identify a person or a school may be used to improve the platform. And when the tutor answers from the national curriculum, no model was trained on those books: passages are retrieved as the question is asked, and the answer cites book, chapter and page.
Who can see what
- Teachers see the classes and departments they are responsible for, not the whole school
- Parents see their own children
- Students see themselves
- School administrators create, correct and deactivate accounts, and decide which staff may see which records
- Access is role-based, and sensitive actions are logged for audit where technically feasible
Parents and students go through the school
Where the law or school policy provides for it, parents and guardians can ask to see, correct or delete a student's data — by contacting the school, not us. That is not deflection: the school owns the records and decides who may access them, so we act on its instructions rather than around it, and assist it with lawful requests.
Security, and what we will not claim
We maintain a security programme sized to the service: encrypted transmission over public networks, role-based access control, authentication controls, secure backups, monitoring, vulnerability management, audit logging where technically feasible, and incident-response procedures. Staff with access to school data are authorised for it, bound by confidentiality obligations, and given only what their role requires.
No online service can promise perfect security, and we will not pretend otherwise. If we confirm an incident materially affecting a school's data, we investigate without undue delay, contain it, and tell the school as soon as reasonably practicable, sharing what we know so far as the law permits.
Leaving, and what offline actually means
If a school ends its agreement, we make its data available for export in a commercially reasonable format on written request, then securely delete or anonymise it within a commercially reasonable period — except where the law requires retention, or where copies persist in backups through their normal retention cycle.
One last clarification, because the old post confused two things. The app keeps working through a dropped connection not because of where it is hosted, but because attendance, homework and notes are written to the device first and synced when the network returns.
The full detail is in our Privacy Policy and Terms of Use; for a subscribing school, the signed Agreement governs wherever those summaries differ. If something there does not match what the platform actually does, we would rather hear about it than be believed.
