Skip to main content

Trust

Security & data protection

SchoolerHub holds information about children. This page describes the controls we actually operate — no certifications we don't hold, no claims we can't stand behind.

Per-school separation

Every record belongs to exactly one school. The application scopes each request to the signed-in user's school, so one school's staff cannot reach another school's data.

Role-based access

School administrator, staff, teacher and parent roles each reach only the modules and records their role requires. Authorisation is checked per action, not just per page.

Private document storage

Uploaded certificates and documents are stored on a private disk outside the public web root. They are served only through authenticated routes that verify the requester may see that specific record.

Encryption in transit

All traffic to schoolerhub.com and app.schoolerhub.com is served over HTTPS/TLS. Backups are stored encrypted at rest.

Secure authentication

Passwords are stored as salted one-way hashes — neither we nor your administrator can read them. Sessions are protected against fixation and forms against cross-site request forgery.

Activity logging

Significant actions are recorded with the acting user and timestamp, giving schools an audit trail of who did what.

Reversible deletion

Most records use soft deletion, so a record removed by mistake can be restored rather than lost.

Data residency

Application data is hosted in India. The exceptions are WhatsApp delivery, handled by Meta, and transactional email — both limited to the data described in our privacy policy.