Privacy Policy

ClassGuard, built by Kryft. Version 2026-10 · last updated 6 October 2026.

This policy explains what information ClassGuard collects, why, how long we keep it, who can see it, and what choices you have. We wrote it in plain words. If anything is unclear, write to hello@kryft.dev.

Short versions: for parents · for children.

1. Our promises

  • We never sell data. Not to advertisers, not to data brokers, not to anyone.
  • We never show ads, and there are no advertising or tracking tools in ClassGuard.
  • We never use your data or your child's data to train AI models.
  • No photo, video or voice of a child is ever stored by us. Focus tracking runs entirely on the phone; only numbers leave it (for example "focused 82% of the class").
  • Live class video and audio are never recorded. They pass through our video service only while the class is happening.
  • Data is used only to run classes, keep children safe during class, and make reports, and it is deleted on a fixed schedule (section 8).

2. Who we are

ClassGuard is built and run by Kryft, a limited liability partnership registered with the Securities and Exchange Commission of Pakistan (SECP), CUIN 0347008. Kryft's registered office address will be published here once its registration is complete; until then, contact us at hello@kryft.dev. Kryft is not connected to any other company with a similar name.

3. Who is responsible for your data

  • When a school uses ClassGuard, the school decides how its students' and staff's data is used. The school is the controller and Kryft is its processor: we handle the data only on the school's instructions and under our School Data Agreement. Questions about a school's records should go to the school first; we will help them answer.
  • When a parent signs up a family directly (without a school), Kryft is the controller for that family's data.
  • For parents, teachers and school admins' own accounts, Kryft is the controller.

4. Who ClassGuard is for, and children's accounts

ClassGuard is used by schools, teachers, parents and students. A child can never create their own account. Student accounts are made only by a school (with roll numbers) or by a parent for their own child. Adults who sign up confirm that they are adults.

Before a school can add students, a school administrator must confirm that the school has the permission of the students' parents to use ClassGuard. In addition, focus tracking stays switched off for a child until a parent linked to that child agrees to it in the app. A parent can withdraw that agreement at any time in Settings → Privacy, and focus tracking stops straight away.

5. What we collect

Account information

  • Name, email address and password (stored only as a one-way scrambled "hash", never readable).
  • An optional profile picture or emoji.
  • For students: name, roll number, school, grade, section, classes, and up to two parent email addresses provided by the school.
  • Your role (parent, teacher, student, school admin) and which school or family you belong to.

The student's phone (Android)

To lock the phone during class and show parents that it is working:

  • Phone model, Android version, app version, and a scrambled device identifier.
  • Battery level, network quality, and whether the needed permissions are switched on.
  • Lock and unlock events, PIN exits, and warnings if the lock is tampered with or switched off.
  • Which allowed apps were opened during class, and the count of notifications from other apps during class. We never read the content of notifications or messages.

Classes

  • Schedules, attendance, when a student joined and left a class, and whether their camera and microphone were connected.
  • Focus numbers from the phone's own focus check: a score per minute, how long attention was away, and when (section 6).
  • Chat messages, poll answers and raised hands in class.
  • Homework and class materials, students' handed-in work (files or photos), marks and teacher comments, teacher notes about a student.
  • Focus Stars, streaks, badges and the shared checklist between a student and their parents.

Support and safety

  • Help requests you send us, with any pictures you attach and basic device details.
  • Security records: who changed what in a school's settings, and sign-in attempts (to stop password guessing).
  • IP addresses, used only to limit repeated attempts, kept no longer than one day in our own systems.
  • Crash reports from the app: the error message and where in the app it happened. Crash reports do not include names, emails or other personal details.

Notifications

  • If you turn on phone or browser alerts: a delivery token for your device, and your alert and quiet-hours settings.

Billing (schools)

  • The school's name, contact email and phone, number of seats used, and invoices.

6. The camera and focus tracking (please read)

On Android, ClassGuard can check whether a student is looking at the class. It uses Google ML Kit, which runs entirely on the phone:

  • The phone's camera picture is examined on the phone, at most twice a second (less when the child is steadily focused), and immediately thrown away.
  • No picture, video frame, face measurement or voice ever leaves the phone or reaches us.
  • Only numbers are sent: a focus score per minute, how many times and for how long attention was away, and whether more than one person seemed to be in view.
  • Google states that ML Kit may send Google basic, anonymous usage statistics (for example, that the feature ran and how fast) and may download updated models. These contain no pictures and no personal details.
  • Focus tracking is off until a linked parent agrees, and it can be switched off by the parent at any time.

The same camera is also used for the live class video, which goes to the teacher through our video service while the class runs and is never recorded.

What we do Why Legal reason (EU/UK GDPR)
Accounts, classes, schedules, attendance, homework, reports To provide ClassGuard to schools and families Contract with you or your school; the school's public-interest or legitimate education task
Lock the student phone during class The service a school or parent chose Contract; the school's education task
Focus tracking (numbers only) To help teachers and parents support a child's attention Consent of the parent (and the school's confirmation)
Security records, rate limits, tamper alerts To keep accounts and children safe and stop misuse Legitimate interest in security
Crash reports and service health To find and fix problems Legitimate interest in a working service
Billing To charge schools for seats Contract; legal obligations to keep accounts
Emails and alerts Class reminders, safety alerts, reports, account messages Contract; you control alert types and quiet hours

We do not use data for advertising, profiling for marketing, selling, or training AI models.

8. How long we keep data

Data Kept for
Detailed focus data, distraction details, class chat and polls, phone and lock events, join/leave details 90 days
Weekly and monthly reports, attendance, marks and handed-in work, teacher notes, Focus Stars per class 1 year
Notifications in the app 90 days
Finished checklist tasks 30 days
Help requests Closed after 14 days without activity; pictures deleted 90 days after closing; the request deleted 1 year after closing
Crash reports and server error records 30 days
IP addresses for rate limits Up to 1 day
Account details While the account exists

The full table is in our retention schedule. When an account is deleted, it is switched off immediately and its data is erased by our automatic clean-up (it runs every hour); it is gone from our backups within 30 days.

9. Who can see what

  • Parents see their own children's schedules, attendance, focus summaries, reports, homework and notes.
  • Teachers see the students in the classes they teach.
  • School admins see their own school only. One school can never see another school's data.
  • Students see their own classes, work, stars and messages from their teacher and parents.
  • Kryft staff look at data only to provide support you ask for, keep the service secure, or when the law requires it.

10. Service providers we use

We use a small number of providers to run ClassGuard (full list: service providers):

  • Cloudflare — hosting, database, file storage, live video relay, and email delivery.
  • Google — ML Kit on the phone (section 6), and Firebase Cloud Messaging for Android alerts (when alerts are switched on).
  • Browser makers' push services (Google, Mozilla, Apple) — to deliver web alerts, if you turn them on.

They may process data in countries other than your own, including the United States. We rely on their data protection agreements, including the European Commission's Standard Contractual Clauses, to protect it.

11. Your rights

You can:

  • See and download your data: Settings → Download my data (parents, teachers, school admins). Parents' downloads include their children's data.
  • Correct it: edit your profile, or ask your school to correct school records.
  • Delete your account: Settings → Delete my account, or follow these steps.
  • Withdraw consent for focus tracking at any time: Settings → Privacy.
  • Object to or ask us to limit some uses.
  • Complain to a data protection authority. In the EU or UK, this is the authority in your country.

For school accounts, we pass requests to the school and help it respond. We answer every request within 30 days.

12. Security

All connections are encrypted. Passwords and PINs are stored only as hashes. Files are private and shared only through short-lived links. Every request is checked for the user's role and school. More detail: security overview.

If a data breach puts people at risk, we will tell affected schools and families without undue delay, and the relevant authority when the law requires it (within 72 hours in the EU and UK).

13. Cookies and similar technology

The ClassGuard website and web app do not use advertising or tracking cookies. The web app stores your sign-in on your own device so you stay signed in. The classguard.dev website stores nothing.

14. Changes to this policy

When we change this policy, we update the date at the top. If a change affects how children's data is used, we ask parents for their agreement again in the app before it applies.

15. Contact

Kryft (SECP CUIN 0347008) · hello@kryft.dev