Privacy Policy
1. Who operates the app
Aerial View-6 Infotech Private Limited operates the Av6 School App. The app talks to our service at blossoms-service.av6.co.in. Records are stored in our MySQL database. Files are stored on Hetzner object storage when the server is not running in development mode.
2. Who uses the app
People sign in with a username and password that the school issues. This app has no registration screen. The account types the server supports are teacher, student, guardian, supervisor, and super admin. The phone is used to run attendance, routines, student records, and fees.
A student record is not the same thing as a login. The school holds the student file. A parent or guardian is a person linked to that file (name, phone, email, and relationship). This app does not provide a separate parent account screen.
3. Information in the account
We store the account holder’s name, username, a bcrypt hash of the password, optional email, profile image, role, school, and branch. We do not store the password in plain text.
On sign-in we create a JSON Web Token and a server session. The session stores a refresh token, IP address, and user agent. The access token is built to last one year. The app keeps that token on the phone until logout.
4. Student and child information
For a student, the database can hold:
- name, student code, admission number, class, school, and branch
- date of birth and gender
- phone, email, address, and PIN code
- photograph
- blood group
- provisional diagnosis
- Aadhaar number and Aadhaar image
- birth certificate
- parent or guardian name, relationship, phone, and email
- attendance, including a photograph taken at check-in or check-out
- fee amounts, payment status, and a receipt PDF
- assessment notes (strength, weakness, and remarks) when that screen is used
The student details screen is built to show Aadhaar number, blood group, provisional diagnosis, address, phone, email, and parent or guardian names when the server sends them.
This information is for running the school. It is available to a signed-in user whose role is allowed to open that record. We do not operate a separate children’s mode or an age gate in the app.
The current product is a school operations app that handles children’s records.
5. Attendance and location
Teacher check-in and check-out send a photograph, the attendance time, precise location coordinates (latitude and longitude), and an address derived from that location. The attendance information and the reference to the uploaded photograph are stored with the teacher attendance record. Attendance photographs are stored in our Hetzner object storage, with the corresponding file link or path stored in our database.
Student check-in and check-out send a photograph and the attendance time. Student location is not collected as part of student attendance. Student attendance photographs are uploaded to our Hetzner object storage, and the corresponding file link or path is stored in our database as part of the student's attendance information.
Location is collected only for teacher attendance functionality, including check-in, check-out, and displaying the teacher's location on the attendance map. We do not collect student location for attendance and we do not use attendance location information for advertising.
6. Fees
Staff can record a school fee as cash or UPI, with an amount, date, and transaction reference. We store that on the student invoice and generate a PDF receipt. The receipt URL is saved on the invoice.
The phone can show a UPI QR code built from the school’s UPI id, business name, and amount. We do not receive the payer’s UPI PIN, card number, or bank password through this app. The database has columns that can store a card number, card expiry, cardholder name, bank name, and cheque number if another system sends them. This app’s payment form does not send those card fields.
7. WhatsApp
If a staff member taps “Send to WhatsApp,” the phone opens WhatsApp with the student name, student code, fee amounts, status, and receipt link, addressed to the number entered on that screen. Our server is not called for that tap. WhatsApp then processes the message under its own terms.
8. Notifications
If you allow notifications, the app obtains an Expo push token for the device and sends that token, together with the device platform and the signed-in user account, to our server.
We store the Expo push token in our database so that we can send operational push notifications to devices where the user is signed in.
A user may be signed in on more than one device. Each device can have a different push token, and each active device token may be stored separately. As a result, the same notification may be delivered to more than one device associated with the same user account.
When a user logs out from a device, the push token for that device is removed from our server. Push tokens associated with a disabled account are also removed.
If a device receives a new push token, the stored token may be updated or replaced so that notifications continue to be delivered correctly.
Expo and Firebase Cloud Messaging may process the push token and notification data as part of delivering notifications to the device. We use push tokens only for application functionality and operational notifications, not for advertising.
9. How we use information
We use it to authenticate users, show the right school and branch, mark attendance, show routines and student records, record fees, generate receipts, and send operational messages. We do not use it for advertising. This application does not sell personal information.
10. Who else receives it
- Our own service and MySQL database.
- Hetzner, for stored files, when the server is not in development mode.
- Google, for the Android map and for turning a teacher coordinate into an address.
- Expo and Firebase Cloud Messaging, for the push token the app requests. We do not keep that token.
- WhatsApp, only after a staff member sends a receipt.
- The phone’s dialer or email app, if a staff member taps a student phone number or email.
11. Security
Passwords are stored as bcrypt hashes. API calls to our service use HTTPS. The access token is how later requests are authorized.
12. Retention
The access session is built to last one year unless it is revoked. School records (the student file, attendance, fees, assessments, and uploaded files) are kept until the school deletes them. There is no automatic purge in the application. Retention period requires confirmation from the school. We do not state a backup period. Backup retention cannot be verified from the application source.
13. Account deletion and student records
Logout clears the token and cached profile on the phone.
There is no Delete Account function. Signing out, or asking us to close a login, does not delete the student file, attendance, photographs, fees, or assessment notes. Those belong to the school’s record of the child, not to the staff member’s login.
To ask us to close a login, email help@aerialview6.com with the school name and username. We will disable that login. We will not promise that the student file is erased. A request to erase a student file has to be handled with the school, and we will keep what the school is required to keep once that period is confirmed. We will not describe a login as deleted if we only disable it and keep the same data available.
14. Requests
Email help@aerialview6.com to ask what account data we hold, to correct a record, or to close a login. Camera, location, and notifications can be turned off in Android settings. Teacher photo attendance and the map will not work without location and camera. The rest of the app still opens.
15. On the phone
The app stores the access token, a permission value, the profile, and school settings (including the school UPI id) in on-device storage that the app does not encrypt. Logout removes those items. Theme settings remain. Recent screens are held in memory for a few minutes. This mobile app does not use browser cookies.
16. Changes
We will change the effective date on this page when the policy changes. If a change materially expands how we use personal information, we will give any notice the law requires.
17. Contact
Aerial View-6 Infotech Private Limited
Ahemedpur (Kagas Road), Chotolinepara, Ahemedpur, Birbhum, West Bengal 731201, India
help@aerialview6.com
https://aerialview6.com/