Legal

Privacy Policy

Effective: May 2026 · Last Updated: July 2026

We build software for institutions that handle sensitive operational data. This policy explains, in plain language, what we collect and why.

What this policy covers

This policy describes how Gatkul Apps ("we", "us") handles information when you visit gatkul.app, register for a product, or use a Gatkul workspace (including the EduOS mobile app, com.gatkul.eduos). It covers the EduOS Android and iOS apps available on the Google Play Store and Apple App Store. Product-specific data handling may include additional terms agreed with your institution.

Information we collect

We may collect: (a) contact details you submit (name, email, phone, institution name); (b) usage data on our marketing site; (c) operational data entered into product workspaces by you or your institution, including student records, attendance, grades, and messages; (d) device push notification tokens (FCM/APNs) used solely to deliver school notifications to your registered devices — tokens are associated with your account and deleted when you log out or delete your account; (e) location data (foreground-only, Android/iOS) when you use the staff attendance check-in or school bus tracking features — location is read only while those features are active, is never tracked in the background, and is not shared with advertisers or third parties. Payment processing is handled through established payment providers; we do not store full card numbers on our servers.

AI Assistant and OpenAI data processing

The EduOS AI Learning Assistant feature is powered by OpenAI. AI features process only the information necessary to generate responses. User and institutional data is handled according to this privacy policy and applicable agreements with each institution. When you use this feature, your messages and prior conversation context are transmitted to OpenAI's API to generate tutoring responses. OpenAI is a sub-processor of Gatkul Apps for this purpose and processes data under OpenAI's data processing agreement. AI conversations are processed through OpenAI's API. In accordance with our configuration and OpenAI's applicable API policies, customer content submitted through the API is not used to train OpenAI's models. Sensitive school information is not used to train third-party models unless separately disclosed. AI conversations are stored in your school's EduOS workspace (tenant-isolated per institution) and may be reviewed by authorized school administrators in accordance with your institution's policies for safety, compliance, and educational oversight. Before using the AI assistant, you will be shown a consent screen and asked to acknowledge this data processing. Consent is recorded against your account — once you give consent, it applies across all devices you use to sign in. You will not be prompted again on new devices.

Minor users (students under 18)

EduOS is used in schools and may be accessed by students under 18 years of age. We process student data under the direction of the school (as data controller) and in accordance with applicable law, including India's Digital Personal Data Protection Act 2023 (DPDPA) and, where applicable, the US Children's Online Privacy Protection Act (COPPA). For EduOS institutional workspaces, the school or educational institution acts as the data controller for operational school records, and Gatkul Apps acts as a data processor/service provider except where we collect information directly for our own business operations (such as support requests or account administration). Schools are responsible for obtaining any required parental consent before enrolling students. The AI assistant feature for student accounts requires a one-time in-app acknowledgment before first use; this consent is stored server-side against the account and cannot be bypassed by clearing device storage or signing in on a new device. Parents with linked accounts can review their child's AI conversation history within the app. We do not knowingly collect personal data from children for advertising purposes.

How we use information

We use submitted information to respond to inquiries, provision and support workspaces, improve our products, and communicate about onboarding or service updates. Location data is used exclusively for the specific in-app feature that requested it (attendance check-in or bus tracking) and is not used for profiling or advertising. Push notification tokens are used exclusively to deliver notifications from your school to your device. We do not sell personal information to third parties.

Tracking

Gatkul Apps does not use your personal information for cross-app or cross-website tracking. We do not use advertising identifiers, third-party advertising SDKs, or sell personal information for targeted advertising.

Diagnostics

When crash reporting is enabled in a production release, we may collect diagnostic information — such as crash reports and application performance data — to improve reliability. Where third-party crash reporting services (such as Sentry) are enabled, they process only the information necessary to diagnose application issues. If crash reporting is not enabled for a given release, no diagnostic crash data is collected or transmitted.

Sharing & sub-processors

We share data with service providers who help us operate infrastructure, email, and product features — only as needed to deliver the service. Named sub-processors include: OpenAI (AI assistant responses), Firebase Cloud Messaging (push notifications), Amazon Web Services (hosting and file storage), LiveKit (virtual classroom, where enabled), and Sentry (crash reporting, where enabled). Where information is processed outside your country, we implement appropriate contractual and technical safeguards in accordance with applicable law. Institutions using EduOS retain ownership of their operational data subject to their agreement with us. A current list is published at gatkul.app/subprocessors.

Retention & security

We retain information for as long as needed to provide services and meet legal obligations. AI conversation history is retained while your account is active and is deleted when you delete your account, subject to any institutional retention requirements described above. Device push tokens are deleted on logout and account deletion. We apply industry-standard safeguards including industry-standard encrypted transport (TLS), encryption at rest, access controls, and tenant isolation for institutional workspaces. If we become aware of a security incident affecting personal information, we will investigate promptly and notify affected institutions where required by applicable law and contractual obligations. See our Security page for posture details.

Your rights and choices

You may request access, correction, or deletion of personal information by contacting hello@gatkul.app or through the account deletion feature in the app (Settings → Delete Account). When you delete your account, personal data associated with your account is deleted unless your school is legally required to retain certain institutional records under applicable law or its contractual obligations. Workspace users should also contact their institution administrator, who controls role-based access within the product. Indian residents may exercise rights under the DPDPA 2023 including the right to access, correct, and erase personal data.

Cookies and similar technologies (website)

The gatkul.app marketing website uses cookies and similar technologies only for essential functionality — for example, remembering your language preference. We do not use third-party advertising cookies or cross-site tracking pixels on this site. Authenticated product workspaces use secure session and authentication technologies necessary to maintain signed-in sessions and protect accounts.

Updates

We may update this policy as our services evolve. Material changes will be reflected on this page with an updated effective date. If changes affect how we process student data or AI conversation data, we will notify schools via email.

Privacy: hello@gatkul.app · Security: security@gatkul.app · Sub-processors · Security