Privacy Policy
Last updated: August 24, 2026
1. Privacy summary
This summary is for convenience. It does not replace the full policy below.
- SchoolParent.ai reads new school-related emails from a Gmail or Microsoft account you connect, and uses artificial intelligence to produce summaries, extract dates and events, generate reminders, and answer your questions about that information.
- You connect Gmail or Microsoft using the provider’s secure OAuth process. We never see or store your email password. You can disconnect at any time.
- We send school activity information and reminders to you on WhatsApp.
- AI-generated output may be incomplete or inaccurate. Always check important information against the original school communication.
- We do not sell your personal data. We do not use it for advertising. We do not use school communications to send you marketing without a lawful basis.
- We do not use your school email content, children’s information, AI prompts, AI outputs or embeddings to train our own AI models. OpenAI does not use our API customer content to train its models.
- School-related information is kept for the relevant school term and is then deleted from active systems, subject to the retention schedule in Section 14.
- You can disconnect an email account or delete your account and associated data at any time.
2. Who we are and how to contact us
SchoolParent.ai is a brand owned and operated by Strait Labs Limited. In this policy, “we”, “us”, and “our” mean Strait Labs Limited, trading as SchoolParent.ai.
| Field | Detail |
|---|---|
| Registered legal name | Strait Labs Limited |
| Registered address | Store 22, 4A, South Barrack Road, Gibraltar GX11 1AA |
| Company number | 126691 |
| REID number | GICO.126691-59 |
| Website | www.schoolparent.ai |
| Privacy contact | school.parent101@gmail.com |
Complaints and supervisory authorities
You may contact us first about any concern. You also have the right to lodge a complaint with a data protection supervisory authority:
- Gibraltar: the Gibraltar Regulatory Authority (GRA) on dpo@gra.gi
- United Kingdom: the Information Commissioner’s Office (ICO), for individuals in the UK
- European Union: the supervisory authority of the EU member state of the individual’s residence or the place of the alleged infringement
You may also have the right to complain to the data protection authority responsible for your country or region.
3. Who the service is for
SchoolParent.ai is intended for adults aged 18 or over who are parents, legal guardians or authorised carers, and who have lawful authority to receive and manage a child’s school communications and to provide the related information to us.
Children cannot create SchoolParent.ai accounts, and we do not knowingly collect personal information directly from children. We nevertheless process information about children, because the school communications the service is built around relate to children. This policy addresses children’s information in Section 7.
4. What personal data we collect
| Category | What it includes |
|---|---|
| Parent / account holder data | Name, email address, WhatsApp number, account and login information (passwords are stored as a hash), timezone, reminder preferences, and onboarding status. |
| Child data | The child’s name, year or group, school sender email addresses you configure, and optional teacher names and keywords used to route school messages. |
| School communication content | The content of school-related emails that pass our sender filter, including subject lines, message text and sender addresses. |
| Attachments and extracted text | Supported PDFs, images and documents attached to those emails, and text extracted from them, including via optical character recognition (OCR). |
| Special category data | Certain school communications may contain special category or otherwise sensitive information about a child (see Section 8). |
| Email and OAuth metadata / tokens | OAuth access and refresh tokens, expiry times, and mailbox sync or watch metadata used to keep your Gmail or Microsoft connection working. We never store your email password. |
| AI outputs | Summaries, extracted events, reminders and chatbot responses generated from school communications. |
| Embeddings | Numerical representations of processed content created so the chatbot can retrieve relevant school information. |
| Messaging data | The message content we send to you on WhatsApp, and delivery metadata such as delivery status logs. |
| Device, app and diagnostic data | IP address for security and rate limiting, and operational server logs. We do not collect advertising device identifiers and we do not use a third-party crash analytics SDK. |
| Cookies | An authentication cookie or token required to keep you signed in. We do not currently use advertising cookies or third-party web analytics SDKs. |
| Support and security logs | Feedback you submit in the app, and security and system logs used to protect and operate the service. |
| Billing / subscription data | None. The service is free during beta and we do not collect payment card or billing data. |
5. How we collect data and where it comes from
We collect personal data in the following ways:
- Directly from you, when you register, configure your account, connect an email account, verify WhatsApp, set preferences, submit feedback, or contact support.
- From your connected Gmail or Microsoft account, when we access new school-related communications through OAuth.
- From those school communications and their attachments, which may contain information about your child.
- From WhatsApp, in the form of delivery metadata.
- From security controls such as IP-based rate limiting and operational logs.
6. Why we use your data and our lawful basis
We process personal data for the purposes set out below. For each activity we identify our lawful basis under Article 6 of the UK GDPR, EU GDPR and Gibraltar GDPR. Where special category data is involved, an additional Article 9 condition is required and is addressed in Section 8.
| Processing activity | Purpose | Lawful basis |
|---|---|---|
| Connecting your Gmail or Microsoft account | To access the school-related communications you ask us to process | Performance of a contract |
| Processing school emails and attachments | To generate summaries, reminders and extracted events | Performance of a contract |
| Providing chatbot functionality | To answer your questions about stored school information | Performance of a contract |
| Sending notifications and reminders | To deliver the service functionality you have requested via WhatsApp | Performance of a contract |
| Maintaining your account | To provide access to the service | Performance of a contract |
| Security monitoring and fraud prevention | To protect users, systems and data | Legitimate interests |
| System logs, diagnostics and performance monitoring | To maintain, secure and improve the service | Legitimate interests |
| Customer support and troubleshooting | To resolve issues and assist you | Performance of a contract and legitimate interests |
| Compliance with legal obligations | To comply with applicable law and regulatory requirements | Legal obligation |
| Processing children’s data / special category data | See Sections 7 and 8 | Art. 6: performance of a contract and legitimate interests. Art. 9: explicit consent is collected separately during signup |
7. Children’s data
The Service is intended for use by adults aged 18 years or older acting as parents, legal guardians, or authorised carers who have the legal authority to provide any child-related data.
While emails processed through the service may contain information relating to children, SchoolParent.ai does not knowingly collect information directly from children. The Service may process personal information relating to children where such information appears within school communications provided by the parent or guardian.
Authority to provide a child’s information
By using the service in relation to a child, you confirm that you are the parent, legal guardian or authorised carer of that child, or that you otherwise have lawful authority to receive and manage the child’s school communications and to provide the related information to us. Where there is a dispute about authority, or a rights request involving a child, we may ask for reasonable information to verify your authority before acting.
Children’s rights
Children have their own rights under data protection law, including rights of access, rectification, erasure, restriction and objection. Transparency and rights owed to a child are not discharged simply by informing the parent. We will handle requests involving a child’s data with those rights in mind, and we may need to verify identity and authority before responding, particularly where a communication also contains information about other people.
8. Special category and sensitive data
Some school communications may contain special category data or otherwise sensitive information, for example: health information, allergies, disability, special educational needs, dietary requirements that may reveal religion or health, or safeguarding-related information. Special category data requires both a lawful basis under Article 6 and a separate condition under Article 9.
| Requirement | Position |
|---|---|
| Special categories that may be processed | Categories that may appear in school communications, including health, allergies, disability, SEN, religion (including via dietary information), and safeguarding-related content |
| Article 6 lawful basis | Performance of a contract and legitimate interests |
| Article 9 condition | Explicit consent is collected separately during signup |
9. Artificial intelligence, the chatbot and AI memory
We use artificial intelligence to help summarise school communications, identify dates and actions, generate reminders, and answer your questions about stored school information. To provide chatbot functionality, we store processed email content, summaries, embeddings, and extracted information. This data is used solely to provide the Service. This allows users to ask questions (for example, “What’s happening this week?”) and retrieve relevant information. You are interacting with an automated system; where you use the chatbot, you are interacting with AI.
No significant automated decisions
SchoolParent.ai does not use AI to make decisions about children, parents or users that produce legal or similarly significant effects. The service does not decide school attendance, eligibility, discipline, medical treatment, safeguarding action, admission or educational outcomes.
Model training
We do not use your school email content, attachments, children’s information, AI prompts, AI outputs or embeddings to train our own AI models. OpenAI does not use our API customer content to train its models.
| Point | Position |
|---|---|
| AI provider and legal entity | OpenAI, LLC (API) |
| Role | Processor |
| Processing region | Europe |
| What is sent | School email subject and body, relevant attachment text, user questions, and retrieved context needed to answer |
| Typical models | Chat and summaries: gpt-4o-mini (or a configured successor). Embeddings: text-embedding-3-small (or a configured successor) |
| Provider retention of prompts / outputs | Default OpenAI API retention of approximately 30 days |
| Training restriction | OpenAI does not use this API customer content to train its models |
| Embeddings storage | Stored in our PostgreSQL database using pgvector, hosted with our backend infrastructure on AWS in Europe |
| OCR provider | Google Cloud Vision may process supported attachment images or PDF pages to extract text |
10. Email access and permissions
We connect to your Gmail or Microsoft account using the provider’s secure OAuth process. We never see or store your email password, and you can revoke access at any time through your Google or Microsoft account settings. Access to systems and data is restricted using least-privilege controls, and we do not manually review inboxes except where required for technical support you have requested, security investigations, or a legal or regulatory obligation.
Data minimisation
SchoolParent.ai is designed to process only the information reasonably necessary to provide the Service. We encourage users to connect only email accounts used for school-related communications and to configure the school sender addresses for each child. We only store emails whose sender matches those addresses.
| Point | Position |
|---|---|
| OAuth scopes requested | Gmail: https://www.googleapis.com/auth/gmail.readonly. Microsoft: Mail.Read and User.Read |
| Level of access | Read-only access to mail via OAuth. We do not send email from your account |
| How school emails are identified | Exact match of the sender address against the school sender emails you configure per child |
| Treatment of non-school emails | Not stored. Non-matching messages are not kept for AI memory |
| Attachments / OCR | Supported attachments on stored school emails may be parsed. OCR via Google Cloud Vision is used when enabled |
| Historical emails on first connection | Not processed. We only process new messages after you connect |
| Effect of disconnecting | Stops ongoing mailbox sync and removes OAuth tokens. Previously stored school emails, summaries and embeddings remain until term-end deletion or until you delete your account |
| Effect of deleting your account | Disconnects providers, deletes stored account data including emails, embeddings, child profiles and related records, and removes stored attachment files from our object storage where applicable |
11. Messaging channels (WhatsApp)
We send relevant reminders and school activity information to your WhatsApp number. This may include the child’s name, event details, required clothing or items, dates, times and related reminders. Telegram is not offered in the current product.
| Point | Position |
|---|---|
| Messaging integration used | WhatsApp Business Platform / Cloud API (Meta) |
| Access by intermediaries | Meta provides the messaging infrastructure and processes message content and metadata as needed to deliver the service |
| Encryption | Communications with our systems and Meta use TLS in transit. WhatsApp Business API encryption characteristics are those of Meta’s product and differ from consumer end-to-end encrypted personal chats |
| Channel controls | You can disable reminder messages via reminder preference settings. Disconnecting WhatsApp or deleting your account stops further service messages |
12. Who we share your data with
We do not sell your personal data. We share the minimum information reasonably required with providers used to operate the service, including:
- Email providers (Google Gmail and Microsoft Outlook)
- Messaging platform (Meta WhatsApp Cloud API)
- Cloud hosting and infrastructure (AWS in Europe for backend, database and object storage; Vercel for the website)
- AI processing (OpenAI, LLC)
- OCR and document processing (Google Cloud Vision)
- Software development and CI tooling (GitHub) for building and deploying the service, not for storing school mailboxes
Each provider is engaged under terms that require it to protect personal data in accordance with applicable data protection law, and, where the provider acts as our processor, under Article 28-compliant processor terms.
Access to customer data by authorised personnel is limited to situations where technical support, security investigations, legal obligations, or user-requested troubleshooting require it.
| Provider | Service | Role | Region | Data shared | Child / SCD | Transfer mechanism |
|---|---|---|---|---|---|---|
| Gmail OAuth, Pub/Sub, Cloud Vision | Processor (for data we send for OCR and mailbox sync we operate); Google also acts as an independent controller of your Google account | Europe where available; some Google processing may occur outside Europe | OAuth tokens; school mail we process; attachment images or PDF pages for OCR | Yes | Adequacy decisions and/or Standard Contractual Clauses where required | |
| Microsoft | Outlook / Microsoft Graph | Processor (for mailbox access we operate); Microsoft also acts as an independent controller of your Microsoft account | Europe where available; some Microsoft processing may occur outside Europe | OAuth tokens; school mail we process | Yes | Adequacy decisions and/or Standard Contractual Clauses where required |
| Meta | WhatsApp Cloud API | Processor for message delivery we instruct; Meta also operates the WhatsApp platform | Depends on Meta’s service configuration | Outbound notifications, reminders, OTP and related delivery metadata | Yes | Adequacy decisions and/or Standard Contractual Clauses where required |
| Amazon Web Services | Hosting, database, object storage | Processor | Europe | Hosted application data, database records and attachments | Yes | Processing in Europe. SCCs if any residual transfer occurs |
| Vercel | Website hosting | Processor | Website delivery (request metadata) | Website hosting and request metadata | Limited | Adequacy decisions and/or Standard Contractual Clauses where required |
| OpenAI, LLC | Summaries, embeddings, QnA | Processor | Europe | Content required for summaries, embeddings and answers | Yes | Processing in Europe under OpenAI’s API terms. SCCs if any residual transfer occurs |
13. International transfers
Our core hosting and OpenAI API processing are configured in Europe. Some service providers may still process data outside the United Kingdom, Gibraltar, or the European Economic Area. Where this occurs, SchoolParent.ai takes reasonable steps to ensure appropriate safeguards are in place, including reliance on adequacy decisions, Standard Contractual Clauses, or equivalent lawful transfer mechanisms where required.
14. Retention and deletion
SchoolParent.ai follows a term-based retention approach for school-related information. At the end of each school term, school- related data associated with that term — including email content processed by the service, attachments and extracted text, AI-generated summaries, calendar events and reminders, and chatbot memory, embeddings and related processed data — is deleted from active systems, unless retention is required by law or you have specifically requested otherwise.
You can also delete your account at any time, which deletes associated personal data from active systems as described below, subject to limited backup and log retention.
| Data category | Retention period |
|---|---|
| School term data (emails, attachments, extracted text, summaries, events, reminders, embeddings, chatbot memory) | Deleted from active systems at the end of the relevant school term, subject to legal requirement or user request. Also deleted if you delete your account |
| Account details | Until you delete your account |
| OAuth tokens | Retained until you disconnect the email account or delete your account, then deleted |
| Non-school emails accessed during filtering | Not retained |
| In-app feedback | Deleted with your account |
| Support emails you send to us | Up to 24 months |
| Security and system logs | Up to 90 days |
| Analytics data | Not used |
| Messaging delivery logs | Up to 90 days |
| Backups | Encrypted backup copies may remain for up to 30 days as part of standard disaster-recovery processes and are then automatically deleted |
| Data retained by processors | OpenAI retains API prompts and outputs for approximately 30 days. Other processors retain data according to their terms and our instructions |
| Inactive accounts | We do not currently auto-delete inactive accounts. You may delete your account at any time |
15. Security
We implement multiple layers of technical and organisational security measures designed to protect user data. These measures include:
- TLS encryption for data transmitted between systems
- Encryption at rest provided by cloud infrastructure providers
- OAuth authentication for Gmail and Microsoft integrations
- Hashed password storage
- Role-based access controls
- Least-privilege access principles
- Secure cloud hosting infrastructure
- Operational monitoring and logging
- Backup and recovery systems
While no online service can guarantee absolute security, we continuously work to maintain and improve our security practices.
Our security approach is informed by industry-standard cybersecurity and cloud security practices. Team members involved in platform security and infrastructure management maintain relevant technical security certifications and training, including TAC Security CASA Tier 2 certification.
SchoolParent.ai has been designed using privacy-by-design and data-minimisation principles. The Service is designed to process only the information required to provide its functionality while limiting retention periods and restricting access to authorised personnel.
16. Your rights
Subject to the conditions in data protection law, you — and, where applicable, your child — may have the following rights in relation to personal data:
- the right to be informed about how personal data is used (this policy);
- access to a copy of the personal data held;
- rectification of inaccurate or incomplete data;
- erasure of data in certain circumstances;
- restriction of processing in certain circumstances;
- objection to processing carried out on the basis of legitimate interests;
- data portability where applicable; and
- withdrawal of consent, where we rely on consent, at any time.
To exercise these rights, contact us at school.parent101@gmail.com.
17. Cookies, analytics and marketing
We use an authentication cookie or token so you can stay signed in to SchoolParent.ai.
We do not currently use:
- advertising cookies;
- third-party web analytics SDKs; or
- marketing pixels.
If this changes, we will update this policy and, where required, seek appropriate consent. We do not use school communications to send you marketing.
18. Third-party links, services and app stores
The service relies on third-party providers, and you may encounter third-party consent screens and links — for example, the Google or Microsoft OAuth consent screen, or links to external websites. These third parties have their own privacy notices, and their handling of your information is governed by those notices rather than this one. This does not reduce our responsibilities for the processors we appoint to deliver the service. We are not responsible for the independent privacy practices of third-party services outside our control.
19. Changes to this policy
We may update this Privacy Policy from time to time. We will notify users of significant changes where appropriate.