Legal

    Privacy policy

    Last updated: June 2026. Qalabash exists to help schools run. Protecting the data that schools, teachers, and parents trust us with is part of that. This page explains what we collect, how we store it, who can see it, and the choices you have.

    Who we are

    Qalabash is operated by the Qalabash team, based in Douala, Cameroon. Each school using Qalabash is the data controller for the information it enters. Qalabash acts as the data processor, hosting and serving that data on the school's behalf under the terms of these policies and any signed data-processing agreement.

    What we collect

    We collect the information schools enter into their workspace: student records (name, date of birth, class, guardian contact, fee history), teacher records (name, contact, assigned classes), attendance, grades, timetables, discipline notes, communications between staff and parents, and uploaded documents such as report cards or photos. We also collect basic account information (email, name) for every user who signs in, and standard technical logs (IP address, browser, timestamps) needed to operate and secure the service.

    How we store it

    Data is stored on managed cloud infrastructure with encryption at rest and in transit (TLS 1.2 or higher). Every school has its own logical workspace, isolated by row-level security at the database level: a query from one school's account cannot return another school's rows, even by accident or misconfiguration in the application code.

    Who can see what

    School administrators see everything in their school's workspace. Teachers see only the classes they are assigned to. Parents see only their own children's records. Qalabash staff do not browse school data; access is limited to a small number of engineers and is logged. We will only access an individual school's data to provide support that the school has requested, or to investigate an abuse or security report.

    Minors

    Qalabash is designed to be used by adults (school staff and parents or guardians) on behalf of students. Students do not create their own accounts. Information about minors is provided by the school and the parents who interact with the platform. We do not show advertising to anyone, and we do not profile students for any purpose other than the academic reporting the school itself configures.

    What we do not do

    We do not sell data. We do not run advertising. We do not share school data with third parties for marketing. We do not use school data to train third-party AI advertising models. When we use AI features inside the product (for example, to help summarise a parent message), we use providers under data-processing agreements that prohibit them from training on or retaining the data beyond the request.

    Retention

    School workspaces are retained for as long as the school is an active customer, plus a 30-day grace period after cancellation during which data can be exported. After that period, the workspace and its records are permanently deleted from production systems within 60 days. Backups are rotated on a 30-day cycle.

    Your rights

    Parents and teachers can request to see, correct, or delete their own account data by emailing the school administrator, or directly to privacy@qalabash.io if the school is unreachable. School administrators can export or delete any record in their workspace from the settings page. Formal data-processing agreements are available on request.

    Contact

    For privacy questions, write to privacy@qalabash.io or use the contact page. We respond within one business day.

    Have questions? We're here to help.

    Talk to a human — we'll guide you through everything from setup to scaling.

    Contact us