Privacy policy
What a school's data is used for, who can read it, and what happens to it afterwards — in the same plain words the rest of this site uses.
Draft. This policy describes exactly how Onflows behaves today, but it is still under legal review ahead of general availability. If your school needs a signed data processing agreement now, ask us before you upload anything.
Who holds the data
The school does. A school's records — its students, guardians, staff, attendance, fees and documents — belong to that school. Onflows stores and processes them on the school's instructions, and does not sell them, rent them, or use them to train anything.
That distinction matters most for children. The school decides what is collected and obtains whatever consent the law requires from a parent or guardian; we hold what the school puts in, and act on what the school tells us to do with it.
What is stored
- What your school enters: student and guardian records, staff records, admissions, attendance, marks, fee invoices and receipts, circulars, homework, and files uploaded to a student's documents.
- Account data: the name, email address and role of each person you invite, and the password hash for their sign-in.
- An audit trail: who changed what, and when. Corrections to money and to records are kept as corrections rather than as edits.
Who can read it
Only people your school has invited, and only what their role permits. Permissions are checked when an action runs, not when a menu is drawn, so a role cannot be widened by guessing a URL.
Between schools, separation is enforced by the database rather than by our application code. Every record carries the school's identifier and the database refuses a read that crosses schools — a mistake in our code cannot expose one school's records to another.
Our own staff access production data only where it is necessary to operate or support the service, and such access is logged.
Who else processes it
- Supabase — the managed Postgres database and file storage the service runs on.
- A transactional email provider — for invitations, password resets and notifications. It receives the recipient address and the content of that message, and nothing else.
We do not use advertising networks, and there are no third-party trackers on a school's portal.
How long it is kept
For as long as your school keeps it. Onflows does not hard-delete: closing an academic year archives it, a student who leaves keeps their history, and a wrong receipt is corrected by a reversal or a refund that stays visible. That is a deliberate property — an audit is not possible over records that can quietly disappear.
If your school leaves Onflows, you can export your data, and we will delete it on request. Tell us and we will confirm when it is done.
Your school's rights
A school can see, correct and export everything it has put into Onflows from inside the product. Where a parent or a member of staff asks to see or correct their own data, that request goes to the school, which holds it — and the school can act on it directly.
Questions, or a request about your data
Write to hello@onflows.app. If you are already using Onflows and it is about your school's records specifically, care@onflows.app reaches the people who can act on it.