ClassMate Privacy Policy
Last updated: July 4, 2026
This Privacy Policy explains what data the ClassMate mobile application ("the App") collects, why we collect it, and how we use it. The App is operated by Tony Aboud ("we," "us"). By using the App you consent to the practices described here.
1. Data we collect
We collect the following categories of data so the App can function:
- Contact info — email address, name, phone number. A phone number is verified by SMS code when you link it after signing in; it is used for account security (2FA linking) and SMS password reset. The same phone number may back more than one account (for example, family members who share a phone).
- User content — direct messages, voice messages, photos, files, announcement posts, and school mail ("CMail") messages with their attachments that you create or send inside the App.
- Student records — for student users: grades, attendance, schedule, assignments, exams, certificates issued by your school's teachers.
- Parent linkage — for parent users: the list of children you are approved to view. School staff (teachers and administrators) at your child's school can see your name, phone number, and email as the child's emergency/contact details.
- Staff notes — teachers and administrators can write internal pedagogical notes about a student. Each note is private to the staff member who wrote it — other staff, students, and parents cannot read it — and it stays inside the student's school.
- AI conversation data — the messages that students and teachers send to the NOVA AI tutor and the responses received. We use this data to deliver tutoring responses through Anthropic's Claude API and to track token usage.
- Purchase data — subscription tier, top-up purchases, and entitlement state, processed through Apple's StoreKit and synchronised via RevenueCat.
- Identifiers — a user ID generated by our server. We do not collect device advertising identifiers (IDFA / IDFV).
- Diagnostics — crash logs and basic error telemetry to keep the App working.
2. Why we collect it
- App functionality — to display your schedule, grades, messages, and announcements; to authenticate you; to power the NOVA AI tutor; to process purchases.
- Account management — login, password reset, role-based permissions (student, teacher, parent, secretary, admin).
- Communication — sending in-app notifications when something happens that involves you (a new grade, an announcement, a new direct message).
- Service improvement — anonymised error and performance data so we can fix bugs.
We do not use your data for advertising or for any kind of cross-app tracking. We do not sell your data.
3. Who we share it with
We share data only with the third-party processors required to run the App:
- Anthropic — your messages to NOVA are sent to Anthropic's Claude API to generate tutoring responses. See Anthropic's privacy policy.
- Apple / Google Play / RevenueCat — in-app purchase transactions are processed by Apple or Google and synced through RevenueCat. See Apple, Google, and RevenueCat.
- Resend — transactional emails (password reset, account verification). See Resend's privacy policy.
- Twilio — SMS password reset codes when you choose SMS as your reset channel. See Twilio's privacy policy.
- Railway — our application server and database are hosted with Railway. See Railway's privacy policy.
- Firebase (Google) — push notification delivery. A per-device push token is stored so we can deliver notifications to your device. See Firebase privacy.
- Sentry — crash reports and error telemetry (device model, OS version, stack traces — never passwords or message content). See Sentry's privacy policy.
Within your school, your data is visible according to your role. Teachers and administrators see their school's students — grades, attendance, insights, and the student's parent contact details — to do their job. Staff notes about a student are visible only to the staff member who wrote them. Parents see their own children's records (linked through an approved parent-child relationship). Students only see their own data. School mail (CMail) is delivered only to the audience its sender chose inside the school. No data ever crosses school boundaries.
4. Data retention
We retain your account data while your account is active. If you delete your account (contact us at the email below), we permanently delete your personal data within 30 days, except where retention is required for legal or accounting reasons (for example, purchase records for tax purposes).
5. Your rights
You can request a copy of your data, request correction or deletion, or withdraw your consent at any time by emailing the contact address below. We will respond within 30 days.
6. Children's privacy
ClassMate is intended for students at participating schools, including users under 16. Student accounts are created by the school administrator on the student's behalf. No advertising or third-party tracking is used in the App. Parents linked to a student account can view and manage that student's interactions with the App.
7. Security
We use HTTPS in transit, password hashing (bcrypt) at rest, JWT-based authentication, and role-based authorisation on every endpoint. Passwords and tokens are never logged. The server hardens against brute-force attacks with per-IP rate limits on credential endpoints.
8. International transfers
Our server is hosted in the United States. By using the App you consent to your data being processed in the United States and in the countries where our processors operate.
9. Legal basis and governing law
We process personal data in accordance with the Israeli Protection of Privacy Law, 5741-1981, including Amendment 13 (in force August 2025), under which student educational records are treated as sensitive information. School records (grades, attendance, schedules) are collected and owned by the school; ClassMate processes them on the school's behalf and instructions. We maintain data-security practices appropriate to a database containing sensitive information, honour data-subject rights under the Law (access, correction, deletion), and report security incidents as the Law requires. This policy is governed by the laws of the State of Israel.
10. Changes to this policy
If we make material changes to this policy we will update the "Last updated" date at the top and, where appropriate, notify users in-app.
11. Contact
Questions or requests? Email support@classmateapp.org.