Campus Shield AI
Campus management platform

Privacy Policy

Effective date: 14 August 2026  ·  Last updated: 14 August 2026

Who controls your data. Campus Shield AI is used under the direction of an institution — a school, college or coaching centre. The institution decides what is recorded about its students, staff and parents, and is the data controller for those records. Campus Shield AI operates the platform as a data processor acting on the institution's instructions.

This matters when you want something changed or deleted: for teacher, student, parent and driver accounts, your institution's administrator is the first point of contact. See Your rights.

1. Scope

This policy covers the Campus Shield AI mobile application (Android and iOS) and the web administration console at campusshieldai.in. Both are backed by the same Google Firebase project.

Accounts are provisioned by the institution. There is no public self sign-up for students, parents, teachers or drivers — an administrator creates each account and issues its credentials. The only public form is an institution's own request for access, which is reviewed before an institution workspace is created.

2. What we store

2.1 Institution profile

Institution name, type, address, contact phone and email, the institution's login code, and an optional logo image uploaded by an administrator.

2.2 Account and profile data

RoleStored about them
Administrators Name, email address, login ID, role, and the institutions they administer.
Teachers Name, internal staff ID, phone number, optional recovery email, and the classes and subjects they are assigned to teach.
Students Name, roll number, class and section, a guardian phone number, links to their parent account(s), and a sign-in account whose password is set and resettable by an administrator.
Parents / guardians Name, phone number, optional email, an optional separate WhatsApp number, a WhatsApp consent and opt-out flag, and the list of children they are linked to.
Bus drivers Name, phone number, and the bus route assigned to them.

Passwords are handled by Firebase Authentication and are never stored in readable form by the platform.

2.3 Attendance, remarks and academic records

2.4 Guardian phone numbers

A guardian phone number is entered by the institution against a student record. It is used to contact the guardian about that student and, where WhatsApp consent has been recorded, to deliver attendance alerts (see 2.6).

Changing a student's guardian number revokes any previously recorded WhatsApp consent until an administrator makes a fresh, explicit consent decision for the new number. Consent does not silently follow a phone number to a different person.

2.5 Push notifications

When you install the mobile app, Firebase Cloud Messaging issues the device a registration token. We store that token against your account so notifications reach the right device. Tokens are stored per device, are never readable by any app user, and are removed when you sign out, when the device is re-registered by another account, or when the messaging service reports the token as no longer valid.

Notifications are used for attendance alerts, announcements, and student pickup and drop-off updates.

2.6 WhatsApp messages

For attendance alerts only — a student marked absent or late — the platform can send a linked guardian a WhatsApp message. To deliver it, the guardian's phone number and the message text are sent to the Meta WhatsApp Cloud API, operated by Meta Platforms, Inc., which is the delivery channel. Meta's handling of that data is governed by Meta's own terms and privacy policy.

WhatsApp messages are sent only where the institution has recorded the guardian's consent and the guardian has not opted out. Consent and opt-out are recorded per student and can be changed by an administrator at any time. Student accounts are never messaged over WhatsApp.

2.7 Bus location (drivers only)

Location is collected from drivers only, and only on the driver screen during an active trip. No other role's location is collected at any time.

2.8 Diagnostics

The mobile app uses Firebase Crashlytics in release builds to report crashes. A crash report contains the error and stack trace, the device model and operating system version, and a crash-reporter installation identifier. It is used to diagnose faults and is not used to profile users.

The web console does not include Crashlytics. It uses Firebase App Check with reCAPTCHA Enterprise to verify that requests come from the genuine console rather than an automated client; this involves Google assessing the browser's interaction with the page.

Firebase records standard operational logs for the requests our servers handle.

3. What we do not collect

4. How the data is used

We do not use institution data to train machine-learning models, and we do not use it for any purpose the institution has not asked for.

5. Who the data is shared with

RecipientWhat they receiveWhy
Google Firebase
(Google LLC)
All platform data — accounts, records, files, notification tokens, crash reports Our cloud infrastructure provider: authentication, database, file storage, push delivery and hosting
Meta Platforms, Inc.
(WhatsApp Cloud API)
A consenting guardian's phone number and the alert text To deliver attendance alerts over WhatsApp
OpenStreetMap Map tile requests from the device while viewing a bus map To display the map background

That is the complete list. We may also disclose data where we are legally required to do so, or where it is necessary to investigate a security incident.

Data is stored in the Firebase project campus-shield-3fb98. The database is hosted in Google's asia-south1 (Mumbai, India) region; some backend functions run in Google's United States region, so data may be processed there in transit.

6. Who can see what

Access is enforced on the server by Firebase Security Rules, not merely hidden in the interface. Every institution is a separate tenant, and no account can read another institution's data.

RoleCan see
Administrator Everything within their own institution.
Teacher Only the classes and subjects they are assigned: that class's attendance, remarks, timetable and roster. Not other classes, and not other teachers' records.
Student Only their own records — their attendance, their class timetable, notices addressed to them, and their own bus status.
Parent / guardian Only the records of the children linked to them.
Bus driver Only their assigned route and its boarding list. Not attendance, remarks or the wider roster.

Campus Shield AI staff hold administrative access to the Firebase project in order to operate and support the service. We access institution data only when necessary to run the platform or to respond to a support or security request.

7. How the data is protected

No system can be guaranteed completely secure. We do not claim any formal security certification for the platform.

8. How long it is kept

9. Students and children's data

Students are genuine users of Campus Shield AI, and in a school setting some of them are children.

The institution is the data controller for student records under India's Digital Personal Data Protection Act, 2023; Campus Shield AI acts as the data processor on the institution's instructions.

10. Your rights

You can ask to access, correct, or delete the personal data held about you, and to withdraw consent where processing is based on it — most directly, WhatsApp messaging.

We aim to provide an initial response within 7 hours. Resolution time depends on the nature, urgency, and complexity of the request.

11. Deleting an account

An institution administrator can permanently delete the institution account — including every teacher, student, parent and driver account it manages and all of its data — from the app's settings, after re-entering their password and confirming.

An administrator can also submit a deletion request without using the app:

Account deletion request form:
https://campusshieldai.in/account-deletion

This form and the web console are for institution administrators. If you are a teacher, student, parent or driver, your institution's administrator deletes your account for you — see Your rights.

12. Changes to this policy

If we change how data is handled, we will update this page and change the "Last updated" date above. Material changes will also be noted in the app's release notes. This page always reflects the practices currently implemented.

13. Contact

For data access, correction or deletion requests, or any privacy question or complaint:

If your request concerns records held by a specific institution, that institution is the data controller and is the fastest route — but you may always write to us and we will forward it and follow up.