Security
Version 1.0, effective 5 October 2026.
Schools trust Dein School with information about children and families. This page describes how we protect it. It is written for school leaders and parents, not only for technical readers.
Each school's data is kept separate
Every school's records sit behind database rules that check, on every request, which school the signed in person belongs to and what role they have. A person from one school cannot read another school's data, even by crafting their own requests. An automated test suite checks these rules for every role before changes are released.
Access is off until the school grants it
- Parents see only their own children's records.
- Staff start with no access. The school's administrator grants each staff member the features they need, such as attendance or fees, and can take access away at any time.
- When access is removed, the person is signed out of the app within about a minute.
Signing in
- Staff, administrators and parents sign in with a one time password sent to their registered mobile number, so there is no password to guess or reuse.
- Each school may also have one emergency administrator account, for when no administrator can receive an SMS. It signs in with a password and works only for that school.
- Sign in attempts are rate limited. Repeated wrong codes lock the attempt, and repeated requests from one number or one network are slowed down.
- Accounts are created by the school, not by self sign up.
Encryption
- All traffic between your device and Dein School is encrypted with TLS.
- Data is encrypted at rest by our hosting providers.
Files
Uploaded documents, photos, certificates and attachments are stored privately. The app shows them through links that expire after a few minutes, so a copied link stops working. School logos are the one exception, because they are shown on printed and shared documents.
Location
Live bus location is broadcast to parents during a trip and is never stored. When a trip ends, there is no record of where the bus went. The driver's phone shares its location only while a trip runs. A parent who shows their own position on the bus map keeps it on their phone, and it is never sent to us.
Accountability
Changes to attendance, marks, staff records, access permissions and library records keep a record of who made the change and when.
Where data is stored
Our database is hosted with Supabase on infrastructure provided by Amazon Web Services, in Mumbai, India. Our Privacy Policy names every provider we use and what each one does.
If something goes wrong
If we discover a breach affecting school data, we will tell the affected schools without undue delay, and within 24 hours, with what we know and what we are doing about it. We will report the incident to CERT-In where the law requires. Our Data Processing Agreement sets out these commitments.
Reporting a vulnerability
If you believe you have found a security problem in Dein School, please email info@deinxtechnologies.com with a description and the steps to reproduce it. Please:
- give us reasonable time to fix the problem before sharing it with anyone;
- use only test data or your own account, and never access, change or delete data belonging to others;
- avoid anything that degrades the Service for schools, such as load testing or spam.
We will acknowledge your report, keep you informed, and we will not take legal action against research done in good faith under these rules.