Official Google Play Store Policy Document
Privacy Policy
Last updated: October 9, 2026 • Applies to HCMS Portal (Mobile Application for Teachers, Academic Staff & Parents)
🛡️ Notice Regarding Educational Privacy & Family Protection
The HCMS Portal is an institutional education management platform connecting teachers, school staff, and parents. We are committed to safeguarding student educational records, parental information, and educator data in strict accordance with the Google Play Developer Policies (User Data & Families Policies), COPPA (Children’s Online Privacy Protection Act), and the Digital Personal Data Protection Act, 2023 (DPDP Act).
This Privacy Policy describes how Ardent Education Foundation ("We", "Our", or "Us"), operating the Hauna Curriculum Management System (HCMS), collects, uses, stores, protects, and handles data when you use the HCMS Portal mobile application (the "Service").
1. Scope of the Application & User Roles
The Service provides structured, role-segregated educational workflows tailored to three user groups:
🎓 Teachers & Educators
Record daily student attendance, evaluate formative developmental skills across 10 curriculum themes, complete professional training courses, and download completion certificates.
🪪 Academic & Field Staff
Manage campus visits, task checklists, teacher training schedules, school onboarding, and administrative operations.
👨👩👦 Parents & Guardians
Access via registered phone or student roll number to view attendance, inspect 10-theme developmental milestones, download official PDF progress reports, book Parent-Teacher Meetings (PTM), view school events & holidays, participate in Mother Workshops, and read school circulars.
2. Authentication & Multi-Tenant Data Isolation
Access to the application is strictly authenticated:
- Teachers & Staff: Log in using registered mobile phone numbers or employee usernames with encrypted passcodes.
- Parents & Guardians: Log in using either their registered parent mobile phone number or the student's official Roll Number assigned by the school upon enrollment. On initial login, parents create a secure personal passcode. Sibling student records are automatically linked when associated with the same parent contact number.
- Data Isolation: Parents can only access records strictly belonging to their verified enrolled child or registered siblings. Teachers can only view students enrolled in their assigned school campus and grades. No cross-institutional or unauthorized third-party access is permitted.
3. Information We Collect and Process
A. Student Educational Records (Entered by Teachers)
- Student Identifiers: Child's first and last name, roll number, admission number, and enrolled grade/class (e.g., H1, H2, H3).
- Attendance Records: Daily classroom attendance logs (present, absent, leave).
- Developmental Milestone Ratings: Teacher formative evaluations across 10 curriculum themes (e.g., Phonics, Pre-Math, Fine & Gross Motor Skills, Cognitive, Social-Emotional development).
B. Parent & Guardian Information
- Contact & Login Identifiers: Registered parent phone number and/or student roll number (used solely for login authentication, sibling account linking, and emergency school alerts).
- Parent-Teacher Communications & PTM: Parent-Teacher Meeting (PTM) booking requests, chosen consultation time slots, notes, and direct feedback messages submitted to the school.
- Workshops & Sessions: Access to curated Mother Sessions, home learning guidance schedules, and meeting join links (conducted via Google Meet).
C. Teacher & Staff Professional Information
- Profile & Credentials: Full name, phone number, qualification, employee designation, and assigned school.
- Professional Development: Training module attendance, scores, and digital certificates.
- Operational Availability: Active session timestamp and online presence status during application usage to coordinate academic schedules and mentor support.
D. Device & Technical Diagnostics
- Push Notification Tokens: Firebase Cloud Messaging (FCM) device registration tokens utilized exclusively to deliver school circulars, training alerts, and student attendance notifications. Tokens are unlinked upon logout or account deletion.
- Zero Tracking or Hardware Fingerprinting: The application does not collect device hardware identifiers (such as IMEI, MAC address, Android ID, or Advertising ID / AAID) and does not embed any third-party analytics or crash diagnostics SDKs.
4. Google Play Families Policy & Child Safety Standards
Because early childhood developmental records are accessed within the application, we enforce strict child-safety protections:
- Zero Advertisements: The HCMS Portal is 100% ad-free. There are no third-party banner ads, video ads, or behavioral monetization trackers.
- No In-App Purchases: The app has zero micro-transactions or paid purchases.
- No Open Social Networks: There is no public chat, social feed, or open messaging. All communication is strictly private between parents and school personnel.
- Approved Google SDKs Only: The application uses only Google Firebase (Firestore, Cloud Messaging, Auth), fully compliant with Google Play Families Policy and COPPA standards.
- Pedagogical Enrichment Content: Any educational videos, rhymes, or mother workshop sessions in the app are pre-screened, non-violent, age-appropriate, and hosted on secure school cloud infrastructure.
5. How We Use Data
All information is used solely for legitimate educational operations and parental reporting:
- To display academic and attendance progress to verified parents.
- To generate and export printable student term progress report cards in PDF format.
- To coordinate PTM consultations between parents and educators.
- To broadcast official school circulars and announcements.
We never sell, rent, monetize, or share user or student data with data brokers or commercial third parties.
6. Data Security & Storage
- Encryption in Transit: All communications between the app and cloud servers are secured using industry-standard TLS 1.3 / HTTPS encryption (usesCleartextTraffic="false").
- Encryption at Rest: Cloud databases and files are stored on Google Cloud Firestore with AES-256 encryption.
- Authentication Security: User passcodes are hashed using cryptographic SHA-256 algorithms. Plaintext passcodes are never stored.
- Local Device Storage: Active authentication sessions and recent push notifications (up to 50) are stored locally in secure device storage (SharedPreferences) and are wiped upon user logout or account removal.
7. Account and Data Deletion (User Rights)
In accordance with Google Play's User Data & Account Deletion policies, all users (Teachers, Staff, and Parents) have the right to request deletion of their account and associated personal data:
- In-App / Administrative Request: Parents can request account de-linking and record archiving directly through their school's administrative office upon student withdrawal or transfer.
- Online / Email Request: Any user can submit a formal account and data deletion request by emailing our Data Privacy Officer at hauna.preschool@gmail.com with the subject line "Account Deletion Request".
- Processing Timeline: Deletion requests are fulfilled within 30 days. Non-personal academic compliance records (such as completed grade archives required by educational authorities) are retained only as required by statutory educational regulations.
8. Contact Information
For inquiries, privacy questions, or data protection concerns, please contact:
- Organization: Ardent Education Foundation
- Platform: HCMS Portal (Hauna Curriculum Management System)
- Email: hauna.preschool@gmail.com
- Application: HCMS Portal (Version 1.0.54+)
- Official Address: Ardent Education Foundation, Bangalore, Karnataka, India