← Back to EduSupervise

Privacy Policy

Effective September 25, 2026. Plain English. If you want the legal version with defined terms and jurisdiction clauses, email privacy@edusupervise.ashbi.ca.

What we collect

EduSupervise is a duty-scheduling app for K-12 schools. We collect what we need to do that job and nothing else.

  • Email — your login, your reminder delivery channel.
  • Name — your display name on the duty roster and in coverage broadcasts.
  • Phone — only if you opt in to SMS reminders. Most users don't.
  • School name + identifier — to keep your school's data separate from other schools' (multi-tenant isolation).
  • Duty schedule data — who covers what shift, when, and where.
  • Notification log — which reminders fired, when, and whether they were delivered. This is for the app, not for advertisers.

What we DON'T collect

  • No advertising IDs. No third-party trackers. No Facebook Pixel.
  • No location data. We don't track where you are. (The duty location is a school room number, set by the admin — not your GPS.)
  • No student or child data. EduSupervise is for staff scheduling only. The students you supervise are referenced by class name (set by the admin), never tracked as individual records.

Where your data is stored

Your school's data lives in a private Postgres database hosted on our VPS (Ashbi Inc., Toronto). The database is encrypted at rest. Backups are encrypted with the same standard (AES-256) and stored off-host.

Each school is a separate tenant. Other schools cannot see your school's data. Staff at your school can see the roster and schedule they need to do their jobs — school admins see more than teachers. We use Postgres row-level security to enforce tenant isolation at the database level — there is no application code path that can read across tenants.

Third-party services

EduSupervise uses a small number of third-party services to deliver the product. Each one receives only the data it needs to do its job.

  • Mailgun (email delivery) — receives your email and the message body. Sends transactional email (reminders, coverage alerts, account notifications).
  • Stripe (web billing only) — would receive billing details for paid plans. EduSupervise is free during the beta, so no billing details are collected. Stripe is never used inside the phone apps.
  • Apple Push Notification service (APNs) — receives a device token from the iOS app and the notification payload. Apple's privacy policy governs that data.
  • Google Firebase Cloud Messaging (FCM) — receives a device token from the Android app and the notification payload. Google's privacy policy governs that data.
  • Mozilla / browser push services (Web Push only) — receives a per-browser subscription endpoint and a public VAPID key. The notification payload is encrypted so the push service cannot read it.

Data retention

We keep your data while your account is active. Delete your own account at /account/delete. That starts a 30-day grace period, then we delete the account. School records that other people still use are kept. If you were the last person at a school, email privacy@edusupervise.ashbi.ca and we will remove the leftover school records.

Audit logs (who did what, when) are retained for 365 days during the free beta. We retain them for debugging, not for compliance surveillance.

Your rights

  • Export — there is no self-serve JSON dump. Email privacy@edusupervise.ashbi.ca if you need a copy of your data.
  • Delete — delete your own account at /account/delete. That starts a 30-day grace period. Email privacy@edusupervise.ashbi.ca if you need leftover school records removed after everyone has left.
  • Correct — change your phone number on Preferences. To change your name or email, write privacy@edusupervise.ashbi.ca.
  • Analytics — we do not collect product analytics in the current release. There is nothing to opt out of.

Children's data

EduSupervise is a staff tool. We do not knowingly collect personal data from anyone under 18. School admins who reference students by name are responsible for compliance with their district's student data policies; we provide the tool, not the policy.

Changes to this policy

We will email all school admins at least 30 days before any material change takes effect. The "Effective" date at the top of this page is the source of truth — refresh it from time to time.

Contact

Questions, complaints, or formal privacy requests: privacy@edusupervise.ashbi.ca. We respond within 5 business days.

Ashbi Inc. · Toronto, Canada · September 25, 2026