Privacy Policy

Last updated: August 24, 2026

1. Privacy summary

This summary is for convenience. It does not replace the full policy below.

  • SchoolParent.ai reads new school-related emails from a Gmail or Microsoft account you connect, and uses artificial intelligence to produce summaries, extract dates and events, generate reminders, and answer your questions about that information.
  • You connect Gmail or Microsoft using the provider’s secure OAuth process. We never see or store your email password. You can disconnect at any time.
  • We send school activity information and reminders to you on WhatsApp.
  • AI-generated output may be incomplete or inaccurate. Always check important information against the original school communication.
  • We do not sell your personal data. We do not use it for advertising. We do not use school communications to send you marketing without a lawful basis.
  • We do not use your school email content, children’s information, AI prompts, AI outputs or embeddings to train our own AI models. OpenAI does not use our API customer content to train its models.
  • School-related information is kept for the relevant school term and is then deleted from active systems, subject to the retention schedule in Section 14.
  • You can disconnect an email account or delete your account and associated data at any time.

2. Who we are and how to contact us

SchoolParent.ai is a brand owned and operated by Strait Labs Limited. In this policy, “we”, “us”, and “our” mean Strait Labs Limited, trading as SchoolParent.ai.

FieldDetail
Registered legal nameStrait Labs Limited
Registered addressStore 22, 4A, South Barrack Road, Gibraltar GX11 1AA
Company number126691
REID numberGICO.126691-59
Websitewww.schoolparent.ai
Privacy contactschool.parent101@gmail.com

Complaints and supervisory authorities

You may contact us first about any concern. You also have the right to lodge a complaint with a data protection supervisory authority:

  • Gibraltar: the Gibraltar Regulatory Authority (GRA) on dpo@gra.gi
  • United Kingdom: the Information Commissioner’s Office (ICO), for individuals in the UK
  • European Union: the supervisory authority of the EU member state of the individual’s residence or the place of the alleged infringement

You may also have the right to complain to the data protection authority responsible for your country or region.

3. Who the service is for

SchoolParent.ai is intended for adults aged 18 or over who are parents, legal guardians or authorised carers, and who have lawful authority to receive and manage a child’s school communications and to provide the related information to us.

Children cannot create SchoolParent.ai accounts, and we do not knowingly collect personal information directly from children. We nevertheless process information about children, because the school communications the service is built around relate to children. This policy addresses children’s information in Section 7.

4. What personal data we collect

CategoryWhat it includes
Parent / account holder dataName, email address, WhatsApp number, account and login information (passwords are stored as a hash), timezone, reminder preferences, and onboarding status.
Child dataThe child’s name, year or group, school sender email addresses you configure, and optional teacher names and keywords used to route school messages.
School communication contentThe content of school-related emails that pass our sender filter, including subject lines, message text and sender addresses.
Attachments and extracted textSupported PDFs, images and documents attached to those emails, and text extracted from them, including via optical character recognition (OCR).
Special category dataCertain school communications may contain special category or otherwise sensitive information about a child (see Section 8).
Email and OAuth metadata / tokensOAuth access and refresh tokens, expiry times, and mailbox sync or watch metadata used to keep your Gmail or Microsoft connection working. We never store your email password.
AI outputsSummaries, extracted events, reminders and chatbot responses generated from school communications.
EmbeddingsNumerical representations of processed content created so the chatbot can retrieve relevant school information.
Messaging dataThe message content we send to you on WhatsApp, and delivery metadata such as delivery status logs.
Device, app and diagnostic dataIP address for security and rate limiting, and operational server logs. We do not collect advertising device identifiers and we do not use a third-party crash analytics SDK.
CookiesAn authentication cookie or token required to keep you signed in. We do not currently use advertising cookies or third-party web analytics SDKs.
Support and security logsFeedback you submit in the app, and security and system logs used to protect and operate the service.
Billing / subscription dataNone. The service is free during beta and we do not collect payment card or billing data.

5. How we collect data and where it comes from

We collect personal data in the following ways:

  • Directly from you, when you register, configure your account, connect an email account, verify WhatsApp, set preferences, submit feedback, or contact support.
  • From your connected Gmail or Microsoft account, when we access new school-related communications through OAuth.
  • From those school communications and their attachments, which may contain information about your child.
  • From WhatsApp, in the form of delivery metadata.
  • From security controls such as IP-based rate limiting and operational logs.

6. Why we use your data and our lawful basis

We process personal data for the purposes set out below. For each activity we identify our lawful basis under Article 6 of the UK GDPR, EU GDPR and Gibraltar GDPR. Where special category data is involved, an additional Article 9 condition is required and is addressed in Section 8.

Processing activityPurposeLawful basis
Connecting your Gmail or Microsoft accountTo access the school-related communications you ask us to processPerformance of a contract
Processing school emails and attachmentsTo generate summaries, reminders and extracted eventsPerformance of a contract
Providing chatbot functionalityTo answer your questions about stored school informationPerformance of a contract
Sending notifications and remindersTo deliver the service functionality you have requested via WhatsAppPerformance of a contract
Maintaining your accountTo provide access to the servicePerformance of a contract
Security monitoring and fraud preventionTo protect users, systems and dataLegitimate interests
System logs, diagnostics and performance monitoringTo maintain, secure and improve the serviceLegitimate interests
Customer support and troubleshootingTo resolve issues and assist youPerformance of a contract and legitimate interests
Compliance with legal obligationsTo comply with applicable law and regulatory requirementsLegal obligation
Processing children’s data / special category dataSee Sections 7 and 8Art. 6: performance of a contract and legitimate interests. Art. 9: explicit consent is collected separately during signup

7. Children’s data

The Service is intended for use by adults aged 18 years or older acting as parents, legal guardians, or authorised carers who have the legal authority to provide any child-related data.

While emails processed through the service may contain information relating to children, SchoolParent.ai does not knowingly collect information directly from children. The Service may process personal information relating to children where such information appears within school communications provided by the parent or guardian.

Authority to provide a child’s information

By using the service in relation to a child, you confirm that you are the parent, legal guardian or authorised carer of that child, or that you otherwise have lawful authority to receive and manage the child’s school communications and to provide the related information to us. Where there is a dispute about authority, or a rights request involving a child, we may ask for reasonable information to verify your authority before acting.

Children’s rights

Children have their own rights under data protection law, including rights of access, rectification, erasure, restriction and objection. Transparency and rights owed to a child are not discharged simply by informing the parent. We will handle requests involving a child’s data with those rights in mind, and we may need to verify identity and authority before responding, particularly where a communication also contains information about other people.

8. Special category and sensitive data

Some school communications may contain special category data or otherwise sensitive information, for example: health information, allergies, disability, special educational needs, dietary requirements that may reveal religion or health, or safeguarding-related information. Special category data requires both a lawful basis under Article 6 and a separate condition under Article 9.

RequirementPosition
Special categories that may be processedCategories that may appear in school communications, including health, allergies, disability, SEN, religion (including via dietary information), and safeguarding-related content
Article 6 lawful basisPerformance of a contract and legitimate interests
Article 9 conditionExplicit consent is collected separately during signup

9. Artificial intelligence, the chatbot and AI memory

We use artificial intelligence to help summarise school communications, identify dates and actions, generate reminders, and answer your questions about stored school information. To provide chatbot functionality, we store processed email content, summaries, embeddings, and extracted information. This data is used solely to provide the Service. This allows users to ask questions (for example, “What’s happening this week?”) and retrieve relevant information. You are interacting with an automated system; where you use the chatbot, you are interacting with AI.

No significant automated decisions

SchoolParent.ai does not use AI to make decisions about children, parents or users that produce legal or similarly significant effects. The service does not decide school attendance, eligibility, discipline, medical treatment, safeguarding action, admission or educational outcomes.

Model training

We do not use your school email content, attachments, children’s information, AI prompts, AI outputs or embeddings to train our own AI models. OpenAI does not use our API customer content to train its models.

PointPosition
AI provider and legal entityOpenAI, LLC (API)
RoleProcessor
Processing regionEurope
What is sentSchool email subject and body, relevant attachment text, user questions, and retrieved context needed to answer
Typical modelsChat and summaries: gpt-4o-mini (or a configured successor). Embeddings: text-embedding-3-small (or a configured successor)
Provider retention of prompts / outputsDefault OpenAI API retention of approximately 30 days
Training restrictionOpenAI does not use this API customer content to train its models
Embeddings storageStored in our PostgreSQL database using pgvector, hosted with our backend infrastructure on AWS in Europe
OCR providerGoogle Cloud Vision may process supported attachment images or PDF pages to extract text

10. Email access and permissions

We connect to your Gmail or Microsoft account using the provider’s secure OAuth process. We never see or store your email password, and you can revoke access at any time through your Google or Microsoft account settings. Access to systems and data is restricted using least-privilege controls, and we do not manually review inboxes except where required for technical support you have requested, security investigations, or a legal or regulatory obligation.

Data minimisation

SchoolParent.ai is designed to process only the information reasonably necessary to provide the Service. We encourage users to connect only email accounts used for school-related communications and to configure the school sender addresses for each child. We only store emails whose sender matches those addresses.

PointPosition
OAuth scopes requestedGmail: https://www.googleapis.com/auth/gmail.readonly. Microsoft: Mail.Read and User.Read
Level of accessRead-only access to mail via OAuth. We do not send email from your account
How school emails are identifiedExact match of the sender address against the school sender emails you configure per child
Treatment of non-school emailsNot stored. Non-matching messages are not kept for AI memory
Attachments / OCRSupported attachments on stored school emails may be parsed. OCR via Google Cloud Vision is used when enabled
Historical emails on first connectionNot processed. We only process new messages after you connect
Effect of disconnectingStops ongoing mailbox sync and removes OAuth tokens. Previously stored school emails, summaries and embeddings remain until term-end deletion or until you delete your account
Effect of deleting your accountDisconnects providers, deletes stored account data including emails, embeddings, child profiles and related records, and removes stored attachment files from our object storage where applicable

11. Messaging channels (WhatsApp)

We send relevant reminders and school activity information to your WhatsApp number. This may include the child’s name, event details, required clothing or items, dates, times and related reminders. Telegram is not offered in the current product.

PointPosition
Messaging integration usedWhatsApp Business Platform / Cloud API (Meta)
Access by intermediariesMeta provides the messaging infrastructure and processes message content and metadata as needed to deliver the service
EncryptionCommunications with our systems and Meta use TLS in transit. WhatsApp Business API encryption characteristics are those of Meta’s product and differ from consumer end-to-end encrypted personal chats
Channel controlsYou can disable reminder messages via reminder preference settings. Disconnecting WhatsApp or deleting your account stops further service messages

12. Who we share your data with

We do not sell your personal data. We share the minimum information reasonably required with providers used to operate the service, including:

  • Email providers (Google Gmail and Microsoft Outlook)
  • Messaging platform (Meta WhatsApp Cloud API)
  • Cloud hosting and infrastructure (AWS in Europe for backend, database and object storage; Vercel for the website)
  • AI processing (OpenAI, LLC)
  • OCR and document processing (Google Cloud Vision)
  • Software development and CI tooling (GitHub) for building and deploying the service, not for storing school mailboxes

Each provider is engaged under terms that require it to protect personal data in accordance with applicable data protection law, and, where the provider acts as our processor, under Article 28-compliant processor terms.

Access to customer data by authorised personnel is limited to situations where technical support, security investigations, legal obligations, or user-requested troubleshooting require it.

ProviderServiceRoleRegionData sharedChild / SCDTransfer mechanism
GoogleGmail OAuth, Pub/Sub, Cloud VisionProcessor (for data we send for OCR and mailbox sync we operate); Google also acts as an independent controller of your Google accountEurope where available; some Google processing may occur outside EuropeOAuth tokens; school mail we process; attachment images or PDF pages for OCRYesAdequacy decisions and/or Standard Contractual Clauses where required
MicrosoftOutlook / Microsoft GraphProcessor (for mailbox access we operate); Microsoft also acts as an independent controller of your Microsoft accountEurope where available; some Microsoft processing may occur outside EuropeOAuth tokens; school mail we processYesAdequacy decisions and/or Standard Contractual Clauses where required
MetaWhatsApp Cloud APIProcessor for message delivery we instruct; Meta also operates the WhatsApp platformDepends on Meta’s service configurationOutbound notifications, reminders, OTP and related delivery metadataYesAdequacy decisions and/or Standard Contractual Clauses where required
Amazon Web ServicesHosting, database, object storageProcessorEuropeHosted application data, database records and attachmentsYesProcessing in Europe. SCCs if any residual transfer occurs
VercelWebsite hostingProcessorWebsite delivery (request metadata)Website hosting and request metadataLimitedAdequacy decisions and/or Standard Contractual Clauses where required
OpenAI, LLCSummaries, embeddings, QnAProcessorEuropeContent required for summaries, embeddings and answersYesProcessing in Europe under OpenAI’s API terms. SCCs if any residual transfer occurs

13. International transfers

Our core hosting and OpenAI API processing are configured in Europe. Some service providers may still process data outside the United Kingdom, Gibraltar, or the European Economic Area. Where this occurs, SchoolParent.ai takes reasonable steps to ensure appropriate safeguards are in place, including reliance on adequacy decisions, Standard Contractual Clauses, or equivalent lawful transfer mechanisms where required.

14. Retention and deletion

SchoolParent.ai follows a term-based retention approach for school-related information. At the end of each school term, school- related data associated with that term — including email content processed by the service, attachments and extracted text, AI-generated summaries, calendar events and reminders, and chatbot memory, embeddings and related processed data — is deleted from active systems, unless retention is required by law or you have specifically requested otherwise.

You can also delete your account at any time, which deletes associated personal data from active systems as described below, subject to limited backup and log retention.

Data categoryRetention period
School term data (emails, attachments, extracted text, summaries, events, reminders, embeddings, chatbot memory)Deleted from active systems at the end of the relevant school term, subject to legal requirement or user request. Also deleted if you delete your account
Account detailsUntil you delete your account
OAuth tokensRetained until you disconnect the email account or delete your account, then deleted
Non-school emails accessed during filteringNot retained
In-app feedbackDeleted with your account
Support emails you send to usUp to 24 months
Security and system logsUp to 90 days
Analytics dataNot used
Messaging delivery logsUp to 90 days
BackupsEncrypted backup copies may remain for up to 30 days as part of standard disaster-recovery processes and are then automatically deleted
Data retained by processorsOpenAI retains API prompts and outputs for approximately 30 days. Other processors retain data according to their terms and our instructions
Inactive accountsWe do not currently auto-delete inactive accounts. You may delete your account at any time

15. Security

We implement multiple layers of technical and organisational security measures designed to protect user data. These measures include:

  • TLS encryption for data transmitted between systems
  • Encryption at rest provided by cloud infrastructure providers
  • OAuth authentication for Gmail and Microsoft integrations
  • Hashed password storage
  • Role-based access controls
  • Least-privilege access principles
  • Secure cloud hosting infrastructure
  • Operational monitoring and logging
  • Backup and recovery systems

While no online service can guarantee absolute security, we continuously work to maintain and improve our security practices.

Our security approach is informed by industry-standard cybersecurity and cloud security practices. Team members involved in platform security and infrastructure management maintain relevant technical security certifications and training, including TAC Security CASA Tier 2 certification.

SchoolParent.ai has been designed using privacy-by-design and data-minimisation principles. The Service is designed to process only the information required to provide its functionality while limiting retention periods and restricting access to authorised personnel.

16. Your rights

Subject to the conditions in data protection law, you — and, where applicable, your child — may have the following rights in relation to personal data:

  • the right to be informed about how personal data is used (this policy);
  • access to a copy of the personal data held;
  • rectification of inaccurate or incomplete data;
  • erasure of data in certain circumstances;
  • restriction of processing in certain circumstances;
  • objection to processing carried out on the basis of legitimate interests;
  • data portability where applicable; and
  • withdrawal of consent, where we rely on consent, at any time.

To exercise these rights, contact us at school.parent101@gmail.com.

17. Cookies, analytics and marketing

We use an authentication cookie or token so you can stay signed in to SchoolParent.ai.

We do not currently use:

  • advertising cookies;
  • third-party web analytics SDKs; or
  • marketing pixels.

If this changes, we will update this policy and, where required, seek appropriate consent. We do not use school communications to send you marketing.

18. Third-party links, services and app stores

The service relies on third-party providers, and you may encounter third-party consent screens and links — for example, the Google or Microsoft OAuth consent screen, or links to external websites. These third parties have their own privacy notices, and their handling of your information is governed by those notices rather than this one. This does not reduce our responsibilities for the processors we appoint to deliver the service. We are not responsible for the independent privacy practices of third-party services outside our control.

19. Changes to this policy

We may update this Privacy Policy from time to time. We will notify users of significant changes where appropriate.

Copyright 2026 SchoolParent.ai ©. SchoolParent.ai is a brand owned and operated by Strait Labs Ltd.