School Techy
School Techy
Modules
AdmissionsStudent InformationFees & FinanceAttendanceExaminationsTimetableTransportHostelLibraryHR & Payroll
Solutions
Colleges Universities Coaching institutes Mobile app Integrations
Company
Pricing All features About Case studies Security Resources Blog Partners Contact Sign in
Start free trial
Legal

Acceptable Use Policy

Short, and mostly obvious. It exists because a platform that sends messages to thousands of parents needs a line somewhere, and because the alternative is finding out where the line was after somebody crossed it.

Last updated 31 July 2026
Scope

Who this applies to

Everyone using the platform: the subscribing school, every account it creates, and anyone reaching the API or the mobile apps with its credentials. Schools are responsible for their own users — including what those users upload and what they send to parents.

This policy forms part of the Terms of Use.

Prohibited

What you may not do

Content

  • Upload or store anything unlawful, or anything you have no right to hold.
  • Upload malware, or content designed to interfere with anyone's system.
  • Store material that sexualises, exploits or endangers a child. This is the one thing here that leads to immediate termination and a report to the authorities, without notice and without discussion.
  • Use the platform to harass, bully or threaten a student, parent or member of staff.

Access and security

  • Attempt to reach another school's workspace, or any data your role has not been granted.
  • Probe, scan or penetration-test the service without our written permission. Shared infrastructure means a test against us is a test against every other school on it.
  • Bypass rate limits, authentication or any other control.
  • Share login credentials, or create accounts for people who should not have them. A shared login destroys the audit trail, which is the thing that answers "who changed this mark?" six months later.
  • Scrape the platform, or use automation to extract data at a volume the export tools already serve.

Commercial

  • Resell, sublicense or white-label the platform without a partner agreement.
  • Copy, reverse engineer or use it to build a competing product.
  • Misrepresent your student count or plan tier to avoid charges.
Messaging

The SMS and WhatsApp rules — read these

This section has more practical consequence than everything above it, because breaking it gets your school's sender ID blocked by the operator, not by us — and getting it unblocked is slow.

  • Message people who gave you their number for this purpose. A parent who enrolled a child expects fee reminders and absence alerts. They did not consent to unrelated marketing.
  • No bulk promotional messaging to purchased, scraped or inherited lists. Ever.
  • Use registered DLT templates. Indian regulation requires the sender ID and the template to be registered before an SMS can be delivered at all. Sending outside an approved template does not fail loudly — the operator discards it silently while the send count still reports success, which is why a campaign can appear to work and reach nobody.
  • Honour opt-outs. A parent who asks to stop receiving non-essential messages must stop receiving them. Genuinely essential communication — an absence, a fee due, an emergency — is a different category and continues.
  • Do not impersonate another school, a government body or a payment provider.
  • Emergency channels are for emergencies. A school that uses the emergency broadcast for routine notices trains its parents to ignore it, and the one time it matters, they will.
Security research

Responsible disclosure

If you find a security flaw, we want to hear about it. Email support@schooltechy.com with enough detail to reproduce it.

We will not pursue you — legally or otherwise — if you report a genuine finding in good faith, access no more data than is needed to demonstrate it, do not degrade the service for other schools, and give us a reasonable chance to fix it before publishing.

We will acknowledge within 48 hours, tell you honestly what we found when we looked, and credit you if you want the credit. A security review of this product has previously found real defects, including a mobile login path that issued a privileged token without honouring a two-factor requirement. Both were fixed at the root rather than patched at the call site. Any product of this size that claims never to have had a finding either has not looked or is not saying.

Enforcement

What happens if this is breached

Proportionate, and in this order wherever the situation allows it:

  1. We contact you. Most breaches of this policy are a member of staff not knowing the rule, and a conversation fixes it.
  2. We restrict the specific capability — outbound messaging, say — while it is resolved.
  3. We suspend the account, for serious or repeated breaches. Suspension freezes access; it does not delete data.
  4. We terminate, for the most serious cases, under the Terms of Use. No refund applies.

Two things skip the ladder entirely and are acted on immediately: child sexual abuse material, and an active attack on the platform or on another school's data.

Where we act, we will tell you what we did and why, unless a legal obligation stops us.

Questions, or unsure whether something is allowed: ask first at support@schooltechy.com. Nobody has ever been penalised for asking.