Privacy Policy
Last updated: September 26, 2026
1. Who We Are
EdHelfy ("we", "our", "us") is an educational institution management platform that helps manage students, attendance, fees, academics, and more. Our website is edhelfy.com. For schools that use EdHelfy's WhatsApp integration, the school (for example, Blumen International Kids School) is the data controller for its students' and staff's data, and EdHelfy acts as its data processor.
2. Data We Collect
We collect data necessary to provide our service:
- Account data: Email address, password (hashed), full name, and — for staff who use WhatsApp confirmations — a confirmation PIN (hashed)
- School data: Educational institution name, address, phone, logo
- Student data: Names, class, section, roll numbers, date of birth, parent contacts, addresses
- Operational data: Attendance records, fee records, exam marks, timetables, staff attendance and leave records, and — where a school uses payroll — staff salary figures
- Usage data: AI feature usage counts (no content is stored)
We do not collect credit card numbers, government IDs, biometric data, or browsing history.
3. How We Store Data
- Cloud: Data is stored in an industry-standard managed cloud database hosted in Australia. All connections use TLS encryption. Diagnostic error reports (section 5) are processed separately, in the European Union.
- Local: A copy is cached in your browser's local storage for offline access. Sensitive fields (student names, contacts) are encrypted at rest using industry-standard authenticated encryption with a key derived from your password.
- API keys: If you use your own AI API key in App Settings, it is stored only on your device. EdHelfy's server-side AI keys are stored as encrypted secrets, never in the database.
4. How We Use Data
Your data is used solely to provide the EdHelfy service:
- Displaying and managing student records, attendance, fees, and academics
- Generating reports, receipts, and ID cards
- AI chat features (when enabled) — your prompts are sent to the configured AI provider but are not stored by EdHelfy after the response is returned
- Sending transactional emails (signup approval, team invites)
We never sell, rent, or share your data with third parties for advertising or marketing.
5. Third-Party Services
EdHelfy relies on a small set of industry-standard cloud sub-processors for database hosting, authentication, website delivery, transactional email, and error monitoring. All sub-processors are contractually bound by data-protection terms aligned with this policy. Our current sub-processor list is available on request to privacy@edhelfy.com.
- AI providers (when enabled): when you enable the AI assistant, your prompts are sent to the AI provider you or your administrator configure. Prompts are handled per that provider's privacy policy; EdHelfy does not retain prompt content after the response is returned.
- Error monitoring (always on): when something goes wrong in the app, a diagnostic report is sent to our error-monitoring provider so we can fix it. A report contains the error message and technical details such as the page address, app version and environment — not your records. Before a report leaves your browser we automatically remove email addresses and long number sequences, and blank out fields labelled as names or contact details. That filtering is pattern-based, so we cannot guarantee it catches a name that happens to appear inside an error message. These reports are processed in the European Union and are never used for advertising.
- Meta Platforms (only if your school enables WhatsApp messaging): WhatsApp messages between the assistant and the school's registered users — staff, and any parents/guardians or students the school chooses to link — are carried by Meta under Meta's terms. Because those messages are about school records, they can include a student's name, and for a linked parent they include that parent's own child's records. Messages sent to the school's WhatsApp number from numbers that are not registered are always carried by Meta in the same way; the assistant's replies to them are carried too, but only when your school has turned on admission replies. See section 6.
6. WhatsApp Business Messaging
EdHelfy offers an optional WhatsApp assistant that a school (such as Blumen International Kids School, the operator of this WhatsApp Business account) can enable for its authorized staff — and, where the school chooses, for parents/guardians and students. Here is exactly how it handles data:
- Who can use it: Only people whose WhatsApp number a school administrator has explicitly registered — either linked to an EdHelfy account (a staff account, or a parent/guardian or student account the school itself invited), or, for parents/guardians, registered directly from the contact number the school already holds on the student's own record. A number registered from the student record can ask about that family's own children only, and can report an absence or a fee payment for them (see below), and loses access the moment the school removes it or the contact on the student record changes. If a school turns on admission replies, a number that is not registered receives replies the assistant is instructed to build only from the admission information that school has published and its public profile details (name, address, motto, phone, email and website) — never any student or school record. Otherwise the assistant does not reply to unregistered numbers.
- Parents and students (own family only): A linked parent/guardian can ask about their own child only — attendance, fees, exam marks, the class timetable, and the school's saved assessment of that child (the teacher's rating and written comment per category, and when an assessment was last sent to the parent); a linked student can ask about their own records. This mirrors exactly what the school has already made visible to them in the EdHelfy app, and nothing more: the assistant cannot answer about any other family's child and does not accept photos from family numbers. Reporting an absence is the one thing a parent can ask the assistant to record. If a parent says their child will be away, the assistant repeats back the child, the dates and any reason given and asks the parent to confirm; nothing is recorded unless the parent confirms, and the assistant files only what it repeated back. This files the same absence notice the parent can already file in the app, and it does not change the school's attendance register: school staff review the notice and decide, exactly as they do for one filed in the app. A parent can also tell the assistant they have paid a fee. It repeats back the amount, the payment method, any reference given and which fee it applies to, and asks the parent to confirm; nothing is sent unless they confirm. This files the same payment report the parent can already file in the app, and it does not mark the fee paid or change any amount owed: school staff verify the payment and decide. Unlike the app, the assistant cannot accept a payment screenshot, so a report made this way carries only what the parent typed. When the school decides on an absence notice or a payment a parent reported, the assistant tells them. If the parent has messaged the assistant in the previous 24 hours it sends this straight away; otherwise WhatsApp does not allow it to start a conversation, so it tells them the next time they message. The decision is the same one already shown in the app, and the assistant is not told why a request was refused, so it does not give a reason. The reason a parent types is passed to school staff and shown back to that parent in the app; the assistant does not repeat it in later replies. Answers exclude contact numbers, addresses, and email addresses, and each number has a daily question limit. An archived (former) student is not available on this surface. The school controls the list and can unlink any number at any time, which cuts off access immediately.
- Forwarded documents (staff only): When a staff member forwards a photo of a class register, admission list, or fee sheet, the image is retrieved from Meta and sent to our AI provider (Google Gemini) to read its text into structured records. Photos from a number linked to a parent or student are not processed at all. Those records are placed in an in-app review queue; nothing is imported until a school administrator reviews and confirms it. The raw photo is not retained after processing.
- Questions (staff): A linked staff member can ask about their own school's records (attendance, fees, marks, timetable). The assistant answers using only what that staff member is already permitted to see. Answers exclude contact numbers, addresses, and email addresses.
- Staff attendance, leave and own pay: A staff member can also ask about staff attendance and staff leave requests. A school administrator sees these for the whole staff, exactly as in the app; every other staff member sees only their own records. A teacher or accountant can additionally ask about their own pay — their monthly salary, their loss-of-pay days for a month, and their own attendance breakdown. This is the same information the "My Pay" screen already shows them in the app, and it is strictly self-scoped: the assistant has no way to look up another person's salary, whoever is asking. Because a reply containing salary information stays in your WhatsApp chat history on your phone, treat it as you would a payslip.
- The daily briefing (administrators only): A school administrator can send brief (or "daily briefing", "update", "news") to the assistant to receive the school's daily briefing — the same list the Daily briefing window already shows them in the app, which can name students (for example, a student absent several days running) and state amounts still to collect. For the next 24 hours the assistant then sends it again at the school's briefing times, whenever something needs attention; replying brief off stops it. If a school sends WhatsApp messages from its own WhatsApp Business number, its administrators with a registered number also receive the briefing at those times without asking; outside a conversation WhatsApp allows only a short pre-approved message, so that one carries counts only — no names — and replying brief brings the full briefing. Only administrators ever receive it: before every send the assistant re-checks that the number still belongs to an active administrator of that school.
- Typed changes (proposals) — staff only: A linked staff member can also type an instruction — for example "mark class 3 present today". The assistant never acts on this by itself. It turns the instruction into a proposed change in the same in-app review queue as forwarded documents. For changes to fees or the school calendar, a school administrator must review and confirm the proposal before anything is written. For attendance, the staff member can also confirm their own proposal by reply, and so can an administrator for a notice — see the next points.
- The noticeboard (administrators only): A school administrator can send notices (or "noticeboard", "posts") to see the school's latest notices, and post a new one by sending notice: followed by the text (staff notice: for staff only). The assistant posts the administrator's own words exactly as typed — nothing is rewritten, and no AI model is used — and first shows the whole notice and who will see it. It is published only when the administrator replies YES with their confirmation PIN. A notice posted this way is the same as one posted in the app: families see it in the app, and those who have turned on notifications get the usual notice alert. It can be edited or deleted in the app like any other notice.
- Confirming by reply: For attendance, and for an administrator's notice, the person can apply their own proposal by replying YES together with a confirmation PIN. The change is then written immediately, without a separate in-app step. At that moment the assistant re-checks that the person's account is still active and that their role permits the change — for a notice, that they are still an administrator of that school; for attendance, that their role permits attendance changes and, for a class teacher, that the class is one of their own. These are the same permissions that govern what they can do inside EdHelfy, so confirming by WhatsApp never lets someone do more than they already could in the app — it changes where the approval happens, not what they are allowed to do. The assistant can never delete anything, and every change it makes remains visible and can be corrected in the app.
- Your confirmation PIN: This is separate from your device PIN and is used only to confirm WhatsApp changes. We store it hashed, never in plaintext, and we mask it before writing our audit log. Please note that a PIN you type into WhatsApp stays visible in your own WhatsApp chat history on your phone and the school's, so do not reuse a PIN from anywhere else. You can change it at any time in Settings, which also ends any confirmation session already open.
- What we store: the registered phone numbers and who each is linked to (an opt-in list the school administrator controls); for staff who use confirmations, a hashed confirmation PIN; a short-lived record of which change is awaiting your reply; each proposed change and its outcome; and a security audit log of each message the assistant answers for a registered number (the message text, which data tools ran, and processing size; messages from numbers that are not registered are never written to it). Proposed changes and audit-log entries are both kept for 90 days and then deleted automatically. A school administrator can review what families asked the assistant and what it replied — the question, the answer, and when it was asked — so the school can see what parents need help with and check that the answers they were given are correct. An administrator can clear that list at any time; clearing hides those questions from the list without deleting them, and they are deleted automatically with the rest after 90 days. An administrator can also permanently delete every question and reply from one family, for example when that family asks for them to be erased. Questions asked by staff are never shown to anyone else: a teacher asking about their own pay, attendance or leave is private to them, and for staff we keep the question only and never the reply. Messages the assistant could not answer — including, when a school has not turned on admission replies, messages from numbers that are not registered — are kept for the school's administrators to read and act on (such as an admission enquiry), for the same 90 days, then deleted automatically. When a school has turned admission replies on, messages from unregistered numbers and the assistant's replies to them are kept in the school's inbox for those same 90 days. Either way, a school administrator can delete messages they have marked handled once they are more than a day old. For the daily briefing we keep, for 90 days, when an administrator asked for it and whether they turned it off, and when each scheduled briefing was sent and whether it was delivered; the text of a scheduled briefing is held only until it has been sent, and is then deleted. We do not store the assistant's replies to staff, the contents of forwarded photos, or your PIN in readable form.
- Third parties: WhatsApp messages are carried by Meta Platforms under Meta's terms; reading documents, answering questions, and interpreting typed instructions use Google Gemini. Because messages travel over WhatsApp, information a registered user sends or receives — which can include a student's name, and for a linked parent their own child's attendance, fees or marks — passes through Meta. When a school has turned admission replies on, a typed message from an unregistered number, together with up to three of that number's earlier messages from the previous ten minutes, may also be sent to Google Gemini to compose the reply, whatever it is about. Both are used solely to provide this feature.
- When the assistant messages you: it replies to the messages you send it. Beyond that it sends only what is described above — a decision on a parent's absence notice or payment report, and the daily briefing an administrator asked for — and only within 24 hours of that person's own last message, as WhatsApp requires. The one exception is a school that sends from its own WhatsApp Business number, whose administrators receive the daily briefing at the school's briefing times without asking (see above). Otherwise a registered number that never writes to the assistant never receives anything from it, and the assistant sends families no reminders or announcements on its own.
- Turning it off: A school administrator can unregister any number at any time in Settings, which immediately cuts off access for that number.
Every change begins with a person and is approved by a person. The assistant never deletes, and WhatsApp data is never used for advertising, and is never sold or shared.
7. Your Rights
You have the right to:
- Access: Export all your educational institution's data at any time (Settings → Data & Backup → Backup)
- Portability: Download your data in JSON or CSV format
- Correction: Edit any record directly in the app. A parent or guardian — and, where the school allows it, a student — can also suggest a correction to a child's photo, address or parents' names from the child's profile, and a parent or guardian also to the child's date of birth, giving a reason, which only a school administrator can approve. Phone numbers and email addresses are not changed this way: they are how a family signs in, so the school changes them only after checking who is asking. A suggestion changes nothing by itself: it is reviewed by the school staff who may edit that child's record, and the profile changes only if one of them approves it. The person who suggested it is told whether it was approved, and if it was not, the reason the school gave
- Deletion: Request complete deletion of your account and all associated data (Settings → Account → Delete Account)
- Withdraw consent: Stop using the service at any time; your data remains exportable
8. Data Retention
- Your data is retained as long as your account is active
- Archived fee records and old attendance data may be offloaded to your browser's local cache for performance, but remain accessible
- The WhatsApp assistant's proposed changes, its security audit log, messages it did not answer (section 6), and messages from unregistered numbers with the assistant's replies to them, are kept for 90 days and then deleted automatically
- The records of the daily briefing on WhatsApp (section 6) are kept for 90 days and then deleted automatically, and a scheduled briefing's text is deleted as soon as it has been sent. An administrator's "brief off" is kept until they send brief again, because it is their standing choice not to receive it
- If a school converts a message from an unregistered number into an admission enquiry, the message and any assistant reply are copied into that enquiry's follow-up notes (for a conversation, every message in it and each reply), where they are kept with the school's own admission records rather than deleted after 90 days
- A suggested correction (section 7) that nobody has decided is closed after 30 days, and the person who suggested it is told. It is also closed, within a day, if the student is archived or the person who suggested it can no longer suggest changes for that child (for example, they are no longer linked to the student); such a suggestion can never be approved. Thirty days after the school decides, the suggested details, the school's reason and the reference to the suggested photo are deleted, keeping only the fact that a suggestion was made and its outcome. A suggested photo is deleted once no open suggestion uses it — normally within a day or two of the decision; an approved photo becomes the student's photo
- When a student's record is deleted, the student's photo is deleted 30 days later. The delay lets an accidental deletion be undone with the photo intact
- If you delete your account, all cloud data is permanently removed within 30 days — including your WhatsApp confirmation PIN, any open confirmation session, and the audit log entries for your school
- Local browser data is cleared immediately on account deletion
9. Security
- All data in transit is encrypted via TLS
- Sensitive fields are encrypted at rest using industry-standard authenticated encryption
- Passwords and WhatsApp confirmation PINs are hashed with a modern, industry-standard algorithm and are never stored in plaintext
- After several incorrect PIN attempts in a row, WhatsApp confirmations are locked for a short period that grows with each further failure
- Server-side access controls ensure each school can only access its own data
- Admin functions require superadmin verification
10. Cookies
EdHelfy uses only essential local storage for authentication session management. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
11. Children's Data
Most of the people whose records EdHelfy holds are children. Under India's Digital Personal Data Protection Act, the school that enters a student's information acts as the Data Fiduciary for that data — including the responsibility to obtain verifiable parental consent — and EdHelfy acts as its Data Processor, handling that data only on the school's instructions. We do not independently collect data from children.
We do not track or profile children. EdHelfy performs no behavioural monitoring or profiling, builds no advertising audiences, and serves no advertising of any kind. This applies equally to the WhatsApp assistant described in section 6.
Where a school links a parent's or guardian's WhatsApp number (section 6), that person receives only their own child's information, only when they ask for it, and only what the school has already made visible to them in the app. Deciding whom to link — including whether a student is old enough to hold their own WhatsApp account, which Meta's terms require — rests with the school as Data Fiduciary.
12. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. Continued use of the service after changes constitutes acceptance.
13. Contact
For privacy questions, data export requests, or account deletion:
- Email: privacy@edhelfy.com
- Or use the in-app "Delete Account" feature in Settings