Legal

Privacy Policy

Effective May 2026

We build software for institutions that handle sensitive operational data. This policy explains, in plain language, what we collect and why.

What this policy covers

This policy describes how Gatkul Apps ("we", "us") handles information when you visit gatkul.app, register for a product, or use a Gatkul workspace (including the EduOS mobile app, com.gatkul.eduos). It covers the EduOS Android and iOS apps available on the Google Play Store and Apple App Store. Product-specific data handling may include additional terms agreed with your institution.

Information we collect

We may collect: (a) contact details you submit (name, email, phone, institution name); (b) usage data on our marketing site; (c) operational data entered into product workspaces by you or your institution, including student records, attendance, grades, and messages; (d) device push notification tokens (FCM/APNs) used solely to deliver school notifications to your registered devices — tokens are associated with your account and deleted when you log out or delete your account; (e) location data (foreground-only, Android/iOS) when you use the staff attendance check-in or school bus tracking features — location is read only while those features are active, is never tracked in the background, and is not shared with advertisers or third parties. Payment processing is handled through established payment providers; we do not store full card numbers on our servers.

AI Assistant and OpenAI data processing

The EduOS AI Learning Assistant feature is powered by OpenAI. When you use this feature, your messages and prior conversation context are transmitted to OpenAI's API to generate tutoring responses. OpenAI is a sub-processor of Gatkul Apps for this purpose and processes data under OpenAI's data processing agreement. We do not use your AI conversation data to train OpenAI models. AI conversations are stored in your school's EduOS workspace and can be reviewed by your school administrator for safety and compliance. Before using the AI assistant, you will be shown a consent screen and asked to acknowledge this data processing. Consent is recorded against your account — once you give consent, it applies across all devices you use to sign in. You will not be prompted again on new devices.

Minor users (students under 18)

EduOS is used in schools and may be accessed by students under 18 years of age. We process student data under the direction of the school (as data controller) and in accordance with applicable law, including India's Digital Personal Data Protection Act 2023 (DPDPA) and, where applicable, the US Children's Online Privacy Protection Act (COPPA). Schools are responsible for obtaining any required parental consent before enrolling students. The AI assistant feature for student accounts requires a one-time in-app acknowledgment before first use; this consent is stored server-side against the account and cannot be bypassed by clearing device storage or signing in on a new device. Parents with linked accounts can review their child's AI conversation history within the app. We do not knowingly collect personal data from children for advertising purposes.

How we use information

We use submitted information to respond to inquiries, provision and support workspaces, improve our products, and communicate about onboarding or service updates. Location data is used exclusively for the specific in-app feature that requested it (attendance check-in or bus tracking) and is not used for profiling or advertising. Push notification tokens are used exclusively to deliver notifications from your school to your device. We do not sell personal information to third parties.

Sharing & sub-processors

We share data with service providers who help us operate infrastructure, email, analytics, and payments — only as needed to deliver the service. Named sub-processors include: OpenAI (AI assistant message processing), Firebase / Google (push notifications via FCM), and cloud infrastructure providers for hosting and storage. Institutions using EduOS retain ownership of their operational data subject to their agreement with us. A full sub-processor list is available on request at hello@gatkul.app.

Retention & security

We retain information for as long as needed to provide services and meet legal obligations. AI conversation history is retained while your account is active and is permanently deleted when you delete your account. Device push tokens are deleted on logout and account deletion. We apply industry-standard safeguards including encryption in transit (TLS), encryption at rest, access controls, and tenant isolation for institutional workspaces. See our Security page for posture details.

Your rights and choices

You may request access, correction, or deletion of personal information by contacting hello@gatkul.app or through the account deletion feature in the app (Settings → Delete Account). Account deletion permanently removes your messages, AI conversations, device tokens, and profile data. Workspace users should also contact their institution administrator, who controls role-based access within the product. Indian residents may exercise rights under the DPDPA 2023 including the right to access, correct, and erase personal data.

Updates

We may update this policy as our services evolve. Material changes will be reflected on this page with an updated effective date. If changes affect how we process student data or AI conversation data, we will notify schools via email.

Questions? Contact us · Security