Privacy Policy
Last updated: August 3, 2026
This Privacy Policy explains how Nepfex Pvt. Ltd. ("GyanMul", "we", "us") collects, uses, discloses, and safeguards information when a school, and the staff, students, and parents connected to it, use the GyanMul web platform and the GyanMul mobile apps (Android and iOS). By using GyanMul, you agree to the practices described here.
1. Who this policy covers
GyanMul is a school management platform used by schools (as customers) and, through them, by school administrators, teachers, students, and parents/guardians (as end users). A school that signs up for GyanMul acts as the data controller for the records it enters — GyanMul acts as a data processor on the school's behalf. See our Data Processing Agreement for the terms governing that relationship.
2. Information we collect
We collect the categories of information below. Exactly what is collected depends on your role and how your school configures GyanMul.
Student data
- Identity and enrollment information: full name, date of birth, gender, class/section, roll number, enrollment status
- Family and contact information: guardian names, phone numbers, and relationship to the student
- Academic records: attendance, homework and assignment submissions, exam results, report cards, and grade history
- Financial records tied to the student: fee structure, invoices, and payment history
- Photos submitted through the app (e.g. homework attachments, profile photo) and, where enabled, a student ID photo
- Health or special-needs notes, only where a school explicitly chooses to record them
Teacher and staff data
- Identity and employment information: full name, contact details, role, subjects/classes assigned
- HR and payroll records: attendance, leave requests, salary and payslip data, where the school uses these modules
- Account credentials and authentication data (see Section 4)
Parent / guardian data
- Identity and contact information: full name, phone number, email address
- Relationship to one or more students
- Payment information when paying fees online (processed by our payment provider — GyanMul does not store full card numbers)
- Messages sent to and from school staff through the platform
School information
- School profile: name, address, contact details, logo, and branding
- Operational configuration: academic structure, grading scale, fee structure, class/section list
- Aggregate usage and administrative data (e.g. storage used, active accounts)
3. How we use information
- To provide the core functionality of GyanMul: attendance, academics, fees, communication, and the features your school has enabled
- To authenticate accounts and enforce role-based access, so each person only sees the data their role permits
- To send notifications you or your school has opted into (attendance alerts, fee reminders, announcements, messages)
- To power Gurubaa features, scoped strictly to your school's own data and your role's existing permissions — see Section 8
- To maintain and improve platform reliability, security, and performance
- To comply with legal obligations and respond to lawful requests
We do not sell student, teacher, or parent personal information to third parties, and we do not use student data for behavioral advertising.
4. Authentication
GyanMul uses Supabase Authentication to manage sign-in for all accounts. Authentication data (email address, hashed password, session tokens) is handled by Supabase's authentication infrastructure on our behalf, under the same processor obligations described in Section 9. We do not store plaintext passwords. Sessions are managed using secure, time-limited tokens on both the web platform and the mobile apps.
5. Push notifications
The GyanMul mobile apps can send push notifications for events like attendance alerts, new homework, messages, and announcements, where your school has these features enabled and your device has notification permissions granted. You can disable push notifications at any time in your device's system settings or within the app's notification preferences. Disabling push notifications does not affect your ability to see the same information inside the app.
6. Analytics and crash reporting
We use limited, privacy-conscious analytics and crash reporting to understand how GyanMul is performing and to fix issues quickly. This may include anonymized or pseudonymized technical data such as device type, app version, operating system version, and crash logs. Crash reports are used solely to diagnose and fix defects and are not used to build advertising profiles.
TODO: name the specific analytics/crash-reporting vendor(s) in use here once finalized, and update the Cookie Policy's third-party table to match.
7. Where and how data is stored
- Structured records (student, staff, academic, financial data) are stored in a managed PostgreSQL database provided by Supabase, protected by row-level security policies that enforce the same role-based access controls used throughout the platform.
- Files and documents (homework attachments, report card PDFs, certificates, profile photos) are stored in Amazon S3, in access-controlled buckets, delivered only via short-lived, signed URLs scoped to an authorized viewer.
- Backups are automated and encrypted, consistent with our Cloud Backup practices described on the platform overview.
8. Gurubaa (our AI assistant) and your data
Gurubaa features (lesson planning, question generation, report writing, performance analysis, and the chat assistant) operate only within your school's own data, scoped by the same role-based permissions enforced everywhere else in the platform. Your school's data is never used to train or fine-tune any underlying AI model, and is not shared with the AI provider beyond what is needed to generate the specific response you requested. Any action Gurubaa proposes that would change data or notify someone requires your explicit confirmation before it happens.
9. Data security
- Encryption in transit: all traffic between the web platform, mobile apps, and our servers is encrypted using TLS.
- Encryption at rest: databases and file storage are encrypted at rest by our infrastructure providers.
- Access control: row-level security and role-based permissions restrict every query to only the data a given account is authorized to see.
- Least-privilege administration: internal access to production data is limited to what is operationally necessary and logged.
10. Data retention
We retain personal data for as long as your school maintains an active GyanMul account, plus a limited period afterward to allow for account recovery and to meet legal, financial, and academic record-keeping obligations. Academic records (results, report cards, certificates) may be retained longer where a school requests we do so to support alumni verification requests. See our Account Deletion Policy for how to request deletion, and what happens to your data when you do.
11. Your rights
Subject to applicable law, you (or, for a student, your school or guardian acting on your behalf) have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your data, subject to the retention obligations described in Section 10
- Object to or restrict certain processing
- Request a copy of your data in a portable format
Because schools act as the data controller for student, staff, and parent records, requests are generally directed to your school first. If you are unable to reach your school, contact us at info@gyanmul.com and we will assist or route your request appropriately.
12. Children's data
GyanMul is used by schools to manage records belonging to students, including children under the age of 13. See our dedicated Children's Privacy page for how we handle this responsibly, including the role schools and parents play in consenting to and overseeing a student's data.
13. International users and GDPR
GyanMul is built primarily for schools in Nepal. Where GyanMul is used by, or processes data belonging to, individuals in the European Economic Area or United Kingdom, our GDPR Compliance page describes the additional rights and safeguards that apply.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above, and where changes are material, we will notify school administrators directly.
15. Contact us
For any privacy question or request, contact our privacy team at info@gyanmul.com, or write to us at Nepfex Pvt. Ltd., Kathmandu, Nepal.
Questions about this policy? Contact us at info@gyanmul.com.