Last updated 27 July 2026. This page replaces any earlier version.

1. Who we are and what this covers

Aedura is a school learning platform. Your school gives you an account; you use it to study, take quizzes, talk to your teachers and ask the AI tutor for help. This page covers the Aedura learning platform (the app you are reading this in) and the personal information it holds about you.

Aedura is operated by [operating legal entity and registered address to be confirmed]. Your school and Aedura have a written agreement that decides which of them is the Data Fiduciary and which is the Data Processor for your records under India's Digital Personal Data Protection Act, 2023 (DPDP): [allocation of Fiduciary / Processor roles in the school agreement to be confirmed]. In practice, your school decides who is enrolled, what marks are recorded and who at the school can see them; Aedura runs the software that stores it.

What this page does not cover

Your login credentials are not stored in the learning platform's database. Your email address, password and login sessions live in a separate Aedura identity service. The learning platform only keeps a mirror of your name, email and role so it can show them in the app, and it trusts a signed token (RS256 JWT) issued by that identity service to know who you are. Anything about how passwords are stored, reset or expired is governed by that service, not this page: [link to the identity service's own notice to be confirmed].

2. What we collect, and why

This list is built from the platform's actual database, not from a template. The table names are included so a technically-minded parent, teacher or auditor can check us. Not every field applies to every account — a teacher has no mastery scores, a student has no teaching plans.

CategoryWhat is actually storedWhyWhere (tables)
Who you areYour name, email address, role (student / teacher / admin / parent) and the school you belong to.To sign you in, show your name to your class and teachers, and decide what you are allowed to see.user_directory
School record (students)Admission / student ID, scholar number, class and section, roll number, house, blood group, home address, photo, commute type, and your parents' or guardians' names and contact numbers.To place you in the right class, produce registers and report cards, and let the school reach your guardian.student_profiles
Your work and marksQuiz attempts including every answer you chose and your score, assignments and submissions, gradebook marks and teacher remarks, exam entries, hints you revealed, and questions you reported or submitted.To mark your work, show you your results, and give teachers the class picture.quiz_attempts, quiz_assignments, submissions, gradebook_entries, grades, hint_reveals, question_reports, user_question_submissions
What you have learnedPer-chapter mastery scores and competency state, the evidence behind them, topics you have ticked as done, feedback you were shown, misconceptions the system thinks you hold, and an AI-generated learning profile (strengths, weaknesses, recommendations, risk flags).To decide what to revise with you next, when to revise it, and to tell you and your teacher where you stand.student_competency_state, competency_evidence, student_topic_mastery, student_topic_completion, feedback_events, concept_misconceptions, student_active_misconceptions, misconception_occurrences, student_learning_profiles, student_learning_observations, student_goals, student_roadmaps
What you ask the AI tutorThe exact question you type, the context sent with it (your class, subject, recent performance), the tutor's answer, and the full back-and-forth of tutor chat threads.To answer you, to keep your conversation history, and to draw learning insights from what you find hard.ai_tutor_queries, ai_tutor_contexts, ai_chat_threads, ai_chat_messages
How you studyFocus / study sessions and the events inside them (start, pause, distraction, finish), attendance records, planner and to-do items, study windows, and planned sessions.To build your study plan, show you your own habits, and flag to the school if you stop showing up.study_focus_sessions, study_focus_events, student_attendance, student_planner_items, student_study_windows, planned_sessions
Messages and noticesChat messages and reports, class announcements and timeline posts, community channel messages and reactions, parent–teacher messages, leave / OD / resource requests, and notification records.To deliver the message, keep a record for the school, and moderate misuse.chat_messages, chat_message_reports, comm_messages, comm_reactions, comm_message_reads, announcements, timeline_items, parent_teacher_threads, parent_teacher_messages, leave_applications, od_requests, resource_requests, notification_events, notification_deliveries
CalendarYour calendar events (school and personal), exam dates, and — only if you connect one — a link to your external Google calendar with the access tokens needed to write to it.To show your timetable, exams and study blocks in one place, and to push them to your own calendar if you ask us to.student_calendar_events, lms_user_calendar_events, exam_calendar_events, student_external_calendar_connections
Device and technicalBrowser push-notification endpoint and keys if you enable notifications, plus a log of API requests: which account, which school, the path, status, timing and the IP address the request came from. Your browser's user-agent string is stored with a push subscription and with your acceptance of this notice.To send notifications you asked for, keep the service up, and investigate abuse or outages.push_subscriptions, api_request_logs, terms_acceptances
Consent and auditWhich version of this notice you accepted, when, from what IP address and browser; plus audit records of sensitive administrative actions.To show that consent was obtained and to hold administrators accountable.terms_acceptances, audit_logs, noir.audit_events

We do not ask you for, and the platform has no field for, your religion, caste, biometrics, government ID numbers, or payment card details. Fee records hold invoice and payment amounts and status only.

3. How AI uses what you write

Aedura's tutor, quiz generation, learning profiles, study plans and report summaries are produced by large language models. Being plain about what that means:

  • Your typed question is sent to an AI model. When you ask the tutor something, the text you wrote is sent to a model, together with context about you — typically your class and subject, the topic you are on, and recent performance signals. The question, the context and the answer are stored in the platform.
  • Tutor conversations are kept. Whole threads are stored so you can scroll back, and so the system can see which topics you keep getting stuck on.
  • Your data feeds automated judgements about you. Your answers, mastery scores and study behaviour are summarised by a model into a learning profile: strengths, weaknesses, recommended actions and risk flags. Your teachers and school admins can read that profile. It is a machine's opinion, it can be wrong, and it should never be treated as a final verdict on you.
  • AI answers can be wrong. Explanations, generated questions and marking suggestions may contain mistakes. Check them against your textbook and your teacher.
  • Aedura's AI routing service. AI requests go through Aedura's own AI service (internally called Noir), which forwards them to a third-party model provider. The provider currently configured for this deployment is [AI model provider(s) currently in use to be confirmed].
  • We do not sell your data, and we do not use it for advertising. Whether the third-party model provider is contractually barred from training on content sent to it is set by our agreement with them: [no-training / zero-retention terms with the model provider to be confirmed].

4. Who can see your data

  • You. Your own profile, marks, mastery, tutor history and planner.
  • Your teachers. Staff at your school with the relevant permission can see your marks, attendance, mastery and learning profile for the classes they teach, and messages sent in shared channels.
  • Your school's admins. School administrators and the school owner can see records across the school, including profiles, attendance, fees and audit logs.
  • Your parents or guardians. Where the school links a guardian account, guardians can see the student's progress and message teachers.
  • Aedura staff. A small number of Aedura personnel can access production data when needed to operate the service, fix faults or respond to a support request. Administrative actions are logged.
  • Other schools cannot. Every record is tagged with a school (organisation) id, and every query is scoped to the school on your signed token. Shared curriculum content is the exception: the question bank and chapter tree are common material, not anyone's personal data.

5. Third parties your data touches

  • The AI model provider — receives tutor questions, the context sent with them, and the learning signals used to generate profiles, plans and summaries (see section 3).
  • Google Calendar — only if you connect it. If you link an external calendar, Aedura stores an access token and refresh token for that account (encrypted at rest) and writes your study blocks and exams to the calendar you choose. You can disconnect it; ask us to delete the stored tokens (see section 8).
  • Your browser's push service — if you turn on push notifications, your browser vendor's push service (Google, Mozilla, Apple, or Microsoft, depending on your browser) receives the notification in order to deliver it to your device. Aedura stores the endpoint URL and keys that service gives us.
  • Cloud hosting and email delivery — the platform, its database and its outbound email run on third-party infrastructure: [hosting region and sub-processor list to be confirmed].
  • Website analytics — the web app loads Vercel Analytics and Speed Insights, which measure page views and page-load performance.

We do not sell personal data, and we do not share it with advertisers or data brokers. We may disclose data where the law requires it.

6. How long we keep things

Different kinds of data are kept for different lengths of time, because they serve different purposes — a chat message and an exam mark should not have the same lifespan. Where a period is enforced automatically, a scheduled job deletes the data without anyone having to ask. Where it is on request, the data stays until a school or guardian asks us to remove it, or the school's engagement with Aedura ends.

  • AI tutor conversations — 6 months. Your questions to the tutor and the conversation history (including the structured records behind them) are deleted after 180 days. Enforced automatically.
  • Chat messages and chat reports — 90 days. Enforced automatically.
  • Notification records — 90 days. Enforced automatically.
  • Academic records — the student's enrolment, plus 12 months. Marks, quiz attempts, mastery and competency data, and learning profiles are kept while the student is enrolled and for one year afterwards, so that a full academic year, report cards and transfer documents remain available. After that they are deleted or anonymised. On request today — this one is not yet automated.
  • Roster and profile details — the school's engagement, plus 90 days. Name, class, roll number and guardian contact details are removed within 90 days of a school leaving Aedura or a student being unenrolled. On request today.
  • Technical and security logs — 90 days. Request logs, IP addresses and device/browser information. On request today.
  • Push notification subscriptions are removed when you turn notifications off or the browser subscription expires. Linked Google Calendar access is deleted immediately when you disconnect it.
  • Consent records — 3 years. We keep a record that consent was given (who, which version, when) for three years after it stops being relevant, because that record is how we can demonstrate we had permission. Keeping it is a protection for you, not additional profiling.
  • Backups. Data can persist in encrypted backups after deletion from the live database, for [backup retention window to be confirmed].

Retention periods are deployment settings, so an individual school may require shorter ones. The team-facing inventory (docs/DATA_INVENTORY.md) records which categories are automated and which are still manual, rather than papering over the gap.

7. Students under 18

Most students using Aedura are children under DPDP, which requires verifiable consent from a parent or lawful guardian before a child's personal data is processed, and prohibits tracking, behavioural monitoring for advertising, and targeted advertising directed at children.

  • Your school obtains guardian consent. The school enrols students and is the party that collects and holds guardian consent. Aedura does not verify guardian identity itself. The school-side consent record is kept: [school consent-collection process and record location to be confirmed].
  • What the acceptance on this page is. Clicking accept records that this account was shown this version of this notice, with the date, IP address and browser. It is supporting evidence for the school's record — it is not, on its own, guardian consent.
  • No advertising, no ad profiling, ever. Aedura shows no adverts and builds no advertising profiles. The behavioural data described above (focus sessions, attendance, mastery) exists to teach and to alert the school — nothing else.
  • Guardians can ask. A parent or guardian can ask the school, or us, for a copy of their child's data, for corrections, or for deletion — see section 8.

8. Your rights, and how to actually use them

Under DPDP you (or your guardian, on your behalf) can ask for:

  • Access — a summary of the personal data we hold about you and who it has been shared with.
  • Correction and completion — fixing data that is wrong or out of date.
  • Erasure — deletion of your data, except where the school or the law requires it to be kept (academic records usually are).
  • Withdrawal of consent — for anything we do on the basis of consent, such as a linked external calendar or push notifications.
  • Grievance redressal — a complaint handled by us before you escalate to the Data Protection Board of India.

How to ask

  1. Start with your school. For anything in your school record — name, class, marks, attendance, guardian contact — the school is the fastest and usually the correct route, because the school controls those fields.
  2. Or write to us at [privacy / grievance contact email to be confirmed], addressed to [name of Aedura's grievance officer / Data Protection Officer to be confirmed]. Say which account you mean and what you want done.
  3. Response time. We will acknowledge and act within [response SLA to be confirmed]. There is no self-service export or delete button in the app yet; requests are handled by a person.

Things you can already do yourself, right now: disconnect a linked external calendar, turn push notifications off in your browser, and edit your own planner, goals and notes.

9. How your data is protected

What is true today, without dressing it up:

  • Traffic between your browser and Aedura is encrypted in transit (HTTPS).
  • Sign-in uses signed tokens (RS256) issued by the separate identity service; the learning platform never sees your password.
  • Every record carries a school id and API queries are scoped to the school in your token, so one school cannot read another's data.
  • What each role may see is enforced per endpoint by named permissions carried in your token.
  • External calendar access and refresh tokens are encrypted at rest.
  • API requests are logged with account, path, status, timing and IP, and sensitive admin actions are written to audit logs.
  • Rate limits apply to API and AI endpoints to limit abuse.

We make no claim to any security certification, and we do not claim the platform is unbreachable. Independent audit status: [security audit / certification status to be confirmed]. Breach handling follows [breach notification process and timeline to be confirmed]; DPDP requires notification to the Data Protection Board and to affected people.

10. Terms of use

  • Your account is yours alone. Do not share your password or let someone else use your account. Tell your school at once if you think someone else has got in.
  • School accounts belong to the school. Your school can suspend or remove your access, for example when you leave.
  • Use it honestly. Do not use the AI tutor to have your assessed work done for you where your school forbids it, do not try to reach other students' records, do not attack or overload the service, and do not post abusive, harassing or illegal content in chats and channels. Messages can be reported and moderated.
  • Content ownership. Curriculum content, question banks and the software are Aedura's or its licensors'. Work you write stays yours; you give Aedura permission to store and process it in order to run the service as described here.
  • AI output is guidance, not authority. Marks and academic decisions are your school's, made by people. AI suggestions can be wrong.
  • Availability. The service is provided as-is and may be unavailable during maintenance or faults. Service-level commitments to your school, if any, are in the school's agreement: [uptime commitment to be confirmed].
  • Governing law and limits of liability: [governing law, jurisdiction and liability terms to be confirmed by counsel].

11. Changes to this notice

When this notice changes in a way you need to know about, the version string at the top changes and you will be asked to read and accept it again. Your previous acceptances are kept, so there is a record of exactly which text you agreed to and when. Questions about any of it: [privacy / grievance contact email to be confirmed].