Privacy Policy
1. Introduction
1.1 This Privacy Policy describes how Skubo collects, uses, stores, shares, and protects Personal Data in connection with the Skubo mobile application, web platform, and related software and services.
1.2 Skubo is a student-safety and communication service for Schools and for Parents and legal guardians of enrolled Students. Because the Platform processes the Personal Data of Students under eighteen (18) years of age, we apply heightened safeguards as described in this Policy.
1.3 This Policy forms part of, and should be read together with, the Skubo Terms and Conditions. The terms not defined here carry the meanings given in the Terms and Conditions. By installing, registering for, or using the Platform, you confirm that you have read and understood this Policy.
1.4 This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000, and the rules made under them, and constitutes an electronic record requiring no physical or digital signature.
2. Definitions
2.1 “Student” means a student under eighteen (18) years enrolled at a School using the Platform whose data is processed through Skubo.
2.2 “Personal Data”, “Data Principal”, “Data Fiduciary”, “Data Processor”, and “Consent” carry the meanings given under the DPDP Act.
2.3 “Parent” means a parent or lawful guardian of a Student;
2.4 “School” means an educational institution registered on the Platform; and
2.5 “Authorised School User” means School staff granted access to the Platform for legitimate educational, safety, or administrative purposes.
3. Roles Under the DPDP Act
3.1 Skubo acts as a Data Fiduciary for Personal Data processed through the Platform. The School may act as a joint or independent Data Fiduciary for data it controls, including enrolment records it maintains.
3.2 In respect of a Student, the Parent exercises the rights of the Data Principal on the Student’s behalf, as permitted under the DPDP Act.
3.3 Our service providers (such as hosting, mapping, and notification providers) act as Data Processors on our behalf under written contracts imposing confidentiality and security obligations.
4. Personal Data We Collect
4.1 Account data of Parents and Authorised School Users: Name, contact details (including email address and phone number), relationship to the Student, credentials, and, for verification purposes, proof of relationship to the Student and the School’s accreditation records.
4.2 Student data, collected only after the dual consents described in Clause 6: (a) Identity data, including name, class, enrolment details, and the Student’s QR-coded gate pass, used to verify identity at pickup; (b) Photographs captured, uploaded, or shared through the Platform; (c) Daily activity data, including entry/exit times, location within permitted zones, and attendance records; (d) Medical and dietary notes the school or parent chooses to record.
4.3 Location data: (a) Location data, always captured from staff devices; (b) Live location of the school bus during transport routes, shared from the bus coordinator's device and shown to linked parents for safety; and (c) Geotag of gate entries captured from the scanning staff member's device. Skubo never continuously tracks a student, and the parent app never asks for location permission.
4.4 Technical data: Device type, operating system, app version, IP address, log data, and diagnostic information collected automatically to operate, secure, and improve the Platform.
4.5 Financial data: Fee Structure and Fee receipts.
4.6 Communications: Messages, notifications, and correspondence exchanged through or with the Platform, including grievances addressed to us.
4.7 Live Streaming data: Live video of classroom activities, streamed via Amazon IVS from the school's device to linked parents in real time during the day. Live streams are a separate flow from the photos and videos posted to the gallery.
4.8 Ancillary Data: (a) Email address post joining the waitlist on the website; and (b) Standard request log (IP address, user agent, timestamp) generated by AWS for security and rate-limiting.
5. How We Collect and use Personal Data
5.1 (a) Directly from you, when you register an Account, complete verification, upload Content, or communicate with us; (b) From the School, when it enrols a Student and provides enrolment and identity information; (c) Automatically from the device and the Platform, in the case of location, activity, technical, and log data; and (d) Through the Platform’s QR-code scanning features, in the case of gate-entry verification data.
5.2 Storage and Security: All Skubo data is stored on Amazon Web Services (AWS) in the Mumbai region (ap-south-1). Photos and videos sit in private S3 buckets with encryption at rest; structured data sits in DynamoDB. Personal data does not leave India in the normal course of operations, save for one exception, described at Clause 5.4(a): requests made to the Skubo parent chatbot may be processed by AWS Bedrock capacity elsewhere in the Asia-Pacific region, always within AWS’s own infrastructure.
We use, in particular: (a) OTP-only login: Passwords are not stored in Skubo, as we follow an OTP login mechanism; (b) Role-based access: Every API call checks who is asking and what they're allowed to see. Every profile can view and may edit the data pertaining to their profile; (c) Encryption in transit: All traffic between the apps, the website and our servers is over HTTPS / TLS 1.2+; (d) Encryption at rest: S3 and DynamoDB are encrypted using AWS-managed keys; (e) Logging and monitoring: Access to back-end systems is logged.
5.3 Third-party services: Skubo runs on a small number of third-party services. We pick them carefully and limit what we share.
- 5.3.1 Amazon Web Services (AWS), Mumbai region: Hosts our compute, storage, databases, image delivery and notification infrastructure.
- 5.3.2 Amazon SES: Sends transactional email (OTPs, school invites, waitlist replies).
- 5.3.3 Amazon SNS and Expo Push: Deliver push notifications to your phone via Apple's APNs and Google's FCM. Amazon SNS is the primary transport; Expo Push is a fallback for app versions without a native device token. The notification body is always generated by Skubo.
- 5.3.4 AWS Bedrock (Mistral AI, Amazon Nova, Moonshot AI): Powers SkuboAI — the Skubo parent chatbot, Today’s Story, the Weekly Digest, staff writing aids, and Smart Import roster processing — described in full at Clause 5.4.
- 5.3.5 Amazon IVS (Interactive Video Service), Mumbai region: Carries live video of classroom activities from the school's device to linked parents in real time. Only parents linked to a stuednt at that school can watch.
- 5.3.6 Weather services (Open-Meteo, ipwho.is / ipapi.co, OpenStreetMap Nominatim): The parent app shows an ambient weather backdrop. To pick it, your device contacts these services directly: the IP-lookup services (ipwho.is / ipapi.co) receive your IP address, used for approximate, city-level location; Open-Meteo receives approximate coordinates to return the local weather; Nominatim turns a city or pincode into coordinates. The app never asks you for location permission for this - device GPS is read only if you had already granted it for another reason. Only an IP address, approximate coordinates, or a city/pincode is ever sent - never names, photos, or account details.
- 5.3.7 Fee Payment: Skubo does not use a payment gateway or aggregator, and we never hold or move parent funds. Fee invoices are settled directly between you and your school through your own UPI app.
- 5.3.8 Google Maps Geocoding API: Our servers use this service to turn the coordinates reported by the school-bus tracker and by gate and bus scan events into a human-readable street name, shown on the live bus map and on a Student’s day timeline. Only coordinates are sent — never a Student’s or Parent’s name or any other identifying data — and the result is cached for thirty (30) days to limit repeat calls.
- 5.3.9 MSG91: Delivers the one-time password (OTP) SMS used for sign-in. MSG91 receives only the phone number being verified and is registered under India’s SMS Distributed Ledger Technology (DLT) framework.
5.4 SkuboAI — automated summaries and the Skubo assistant: Every SkuboAI feature runs on AWS Bedrock inside our own AWS account, pinned to the Mumbai region (ap-south-1) except where stated at (a) below. We use no AI vendor or model outside AWS Bedrock. AWS Bedrock does not use the content we send it to train its models, and the underlying model providers have no access to our inputs or outputs. Bedrock’s optional prompt-and-completion logging is disabled for our account, so the prompts themselves are not stored.
- (a) The Skubo parent chatbot runs on Amazon Nova Lite through Bedrock’s Asia-Pacific cross-region inference profile. Unlike every other Platform feature, a chatbot request may therefore be processed by AWS Bedrock capacity elsewhere in the Asia-Pacific region and is not guaranteed to stay within India, though it never leaves AWS’s own infrastructure (Clause 5.2). We send the Student’s first name; the Parent’s own typed messages and up to the last twenty (20) turns of that conversation; activity titles, types, descriptions, and times; the text, author name, and timestamp of teacher activity-log entries; attendance and gate-scan timestamps and the name of the scanning staff member; and the daily report’s mood, meal notes, nap duration, and teacher notes. Only the count of photographs is sent, never a photograph itself. The chatbot is stateless: we do not store the conversation on our servers.
- (b) Today’s Story, a daily summary, is generated on Mistral AI’s Ministral 3 14B model, on demand, in the Mumbai region. We send the Student’s full name and age, the date, attendance status and notes, the daily report together with the name of the staff member who recorded it, and the day’s activity timeline including teacher log entries. Only the count of photographs is sent, never a photograph. The generated summary is stored in our own database and auto-deletes after ninety (90) days (Clause 10).
- (c) The Weekly Digest is generated the same way, on the same in-region model. It additionally sends the Student’s upcoming events (type and location), homework (titles and due dates), and the status and amount of any fee invoice. Stored on the same ninety (90)-day auto-delete.
- (d) Writing aids offered to Authorised School Users — an activity-description suggestion or a homework idea — send only the class subject, age range, and activity title or type. No Student-identifying data is sent, and nothing is stored.
- (e) Smart Import, available only to School administrators through the web console, structures an uploaded roster spreadsheet using Moonshot AI’s Kimi model through AWS Bedrock in the Mumbai region. That spreadsheet may contain Students’ names, dates of birth, admission numbers, gender, and Parent names and phone numbers. The data transits only AWS infrastructure and is never sent to a Moonshot-operated endpoint.
We never send any SkuboAI feature a Student’s or Parent’s photographs or videos, login credentials or one-time passwords, precise device location, health or medical notes, or messages exchanged between a Parent and an Authorised School User. Every SkuboAI output is descriptive only: it does not score, rank, or profile a Student, and no output is used to make an automated decision about a Student or a Parent with a legal or similarly significant effect. See Clause 7.4.
6. Consent and Lawful Basis
6.1 Dual consent for Student data: We do not process any Personal Data of a Student unless both (a) The School has enrolled the Student and authorised processing for legitimate educational, safety, and administrative purposes, and (b) The Parent has given free, informed, specific, unconditional, and verifiable consent under the DPDP Act, on the Student’s behalf, to the relevant processing activities.
6.2 Scope of parental consent: By signing in and enabling the relevant permissions, the Parent consents on the Student’s behalf to: (a) Tracking the Student’s location; (b) Capturing, posting, and sharing photographs; (c) Scanning the Student’s QR-coded gate pass to verify identity and record gate-entry at pickup; and (d) Recording the Student’s daily activity.
6.3 Control and withdrawal: Where the Platform allows, consent may be given for some features and withheld for a few others; disabling a permission may limit the related feature. A Parent may withdraw any consent at any time through Platform settings or by contacting us under Clause 14. Withdrawal takes effect prospectively, does not affect the lawfulness of prior processing, and may make all or part of the Platform unusable for that Student.
6.4 Other lawful bases: We may also process Personal Data where necessary to comply with a legal obligation, to respond to a medical or safety emergency involving a Student, or on other lawful grounds permitted under the DPDP Act.
6.5 Verification: We may take reasonable steps to verify that a person is a Student’s Parent or lawful guardian and that a School is genuine, and may record relationship proofs and accreditation records for this purpose.
7. Purposes of Processing
7.1 We process Personal Data solely for the following purposes: student safety, including real-time location tracking, transport monitoring, and emergency response; identity verification, attendance, and gate-entry authentication, including through QR-code gate-pass scanning; communication between Schools and Parents, including sharing photographs of school events; administration and operation of the Platform, including Account management and support; security, fraud prevention, and enforcement of our Terms and Conditions; and compliance with legal obligations.
7.2 Purpose limitation: Student data is processed solely for the student-safety, educational, communication, and administrative purposes stated above and for no incompatible purpose.
7.3 Protections for Students: We do not process a Student’s data in any way likely to harm the Student’s well-being, and we do not undertake behavioural monitoring of Students or targeted advertising directed at Students beyond the safety and educational purposes stated in this Policy and the Terms and Conditions.
7.4 Automated summarisation: The SkuboAI features described in Clause 5.4 use automated language-generation services to turn information a School has already recorded about a Student into a plain-language summary for that Student’s Parent, and to answer a Parent’s questions about their own Student. This forms part of the communication purpose stated in Clause 7.1. These features are descriptive only: they do not score, rank, or profile a Student, they are not used for behavioural monitoring within the meaning of Clause 7.3, and no output of theirs is used to make an automated decision about a Student or a Parent.
8. Sharing and Disclosure
8.1 We do not sell Personal Data. We share Personal Data only as follows: with the relevant School and authorised Parents, in accordance with the Platform’s features and permissions; with Data Processors acting for us (such as hosting, mapping, and notification providers) under confidentiality and security obligations; with governmental or law-enforcement authorities where required by applicable law, limited to what is necessary; and in connection with a merger, acquisition, or reorganisation of our business, subject to this Policy and applicable law.
8.2 Third-party services integrated with the Platform operate under their own terms and privacy practices, for which we are not responsible. We encourage you to review them.
9. Data Security
9.1 We implement reasonable technical and organisational security measures - including encryption, access controls, and secure infrastructure - to protect Personal Data against unauthorised access, disclosure, alteration, or loss. However, no system is wholly secure, and we cannot guarantee absolute security.
9.2 You are responsible for keeping your Account credentials confidential and must notify us immediately of any unauthorised use or suspected security breach of your Account.
10. Data Retention and Deletion
10.1 We retain Personal Data only as long as necessary for the purposes in this Policy, to meet legal obligations, or until consent is withdrawn or the Student leaves the School, whichever is earlier, after which the data is deleted or anonymised.
10.2 Upon termination or deletion of an Account, we delete or anonymise the relevant Personal Data in accordance with Clause 10.1, except where retention is required by law.
10.3 Retention schedule: Without limiting Clause 10.1, the following automatic schedule applies in the ordinary course, on its own, whether or not anyone asks us to: (a) attendance records and daily reports auto-delete up to ninety (90) days from the relevant date; (b) faster-moving day-to-day records — activity-log entries, gate and bus scan entries, and complaint records — auto-delete sooner, up to thirty (30) days; (c) notifications auto-delete between four (4) hours and sixty (60) days depending on notification type, and a School’s admin console activity log auto-deletes up to ninety (90) days; (d) gallery photographs, and the SkuboAI-generated summaries and digests described in Clause 5.4, auto-delete up to ninety (90) days from when they are posted or generated; (e) a School’s own fee ledger entry auto-deletes ninety (90) days after the related invoice or payment is settled, cancelled, or fails verification — an outstanding invoice, or a payment still pending verification, is never auto-deleted while it remains unresolved; and (f) roster and reference data — a School’s own record of its classes, Students, Parents, and staff — is retained for as long as the School’s Account with Skubo stays active.
10.4 Account deletion. A Parent or Authorised School User may delete their own Account at any time; deletion is immediate and cannot be undone. The only exception: the last remaining active owner of a School must first transfer ownership of the School, or contact us, before their Account can be deleted. On deletion, we remove the Account holder’s personal identity and active sessions immediately; the remaining linked data is purged in the background, completing shortly after. A School’s own operational records — attendance, activity logs, and fee ledgers — are retained by the School with the deleted user’s identity anonymised, consistent with Clause 10.1, and continue to follow the schedule at Clause 10.3.
11. Your Rights
11.1 Subject to the DPDP Act, you (and a Parent/Guardian acting on a Student’s behalf) have the right to: access a summary of the Personal Data processed and the processing activities undertaken; correct, complete, or update Personal Data; erase Personal Data that is no longer necessary for the stated purposes; withdraw consent at any time as described in Clause 6.3; grievance redressal through the contact in Clause 14; and nominate another individual to exercise these rights in the event of death or incapacity.
11.2 To exercise any right, use the Platform settings or contact us under Clause 14. We will respond within the timeframes prescribed by law. If you are not satisfied with our response, you may approach the Data Protection Board of India in accordance with the DPDP Act.
12. Data Breach Notification
12.1 In the event of a Personal Data breach, we will notify the Data Protection Board of India and affected Data Principals in the form and within the timeframes required by applicable law, and will take reasonable steps to mitigate harm.
13. Changes to This Policy
13.1 We may update this Policy from time to time. Where changes are material, we will give reasonable notice through the Platform or by other appropriate means. Continued use of the Platform after the changes take effect constitutes acceptance of the updated Policy; where the changes require fresh consent under applicable law, we will seek it.
14. Grievance Redressal and Contact
14.1 In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, questions, requests, and grievances regarding Personal Data or this Policy may be addressed to our Grievance Redressal Personnel/Department at help@Skubo.app. We will acknowledge and respond within the timeframes prescribed by law.
15. Governing Law
15.1 This Policy is governed by the laws of India, including the DPDP Act, 2023 and the Information Technology Act, 2000. Subject to applicable law, the courts at Gurugram, Haryana have exclusive jurisdiction, consistent with the Skubo Terms and Conditions.
2026 Skubo. All rights reserved.