Security & privacy

What we do with your data. And what we will never do.

Mon School handles children's data. This page describes, without jargon or unverifiable promises, where it is hosted, who can access it and how you stay in control.

GDPR · Hosted in the European Union

The facts, one by one.

Each point below matches a real mechanism in the product — not an intention.

Hosted in Europe

The database and files are hosted by Supabase, eu-west-1 region (Ireland). The website is served by Vercel. Transactional emails go through Resend.

Supabase · eu-west-1

Role-based access, verified on the server

Five roles: head teacher, teacher, parent, pupil, platform administrator. A parent sees only their linked children; a teacher only their classes. Checks happen on the server, not in the screen.

Server-side checks

Parent-child links approved by the school

No automatic matching by name. The parent makes a request with a class code; a teacher or the head teacher approves it. No pupil list is ever exposed.

Human approval

Private files

Photos, PDFs and excuse documents are stored in a private space and served only through signed links valid for one hour. No permanent public URL.

1-hour signed links

No public profile, no ranking

No child profile is visible outside their school. Points and skills show individual progress; there is never a ranking between pupils.

No competition

Minimal data

For a pupil: name, class, school work. No home address, no national ID number, no health or location data. The pupil account is created by the school, never by the child.

Data minimisation

Notifications on your terms

Everyone sets what they receive: in the app, by email (instant or daily digest), as push on their device. Nothing is sent to third parties.

Set per person

Export and deletion on request

Access, rectification, erasure, objection and portability: a request to hello@monschool.app or to your school is enough. Schools have CSV and PDF exports.

GDPR rights
Negative promise

What we will never do.

These commitments are in every school contract. They are also how the product is built: there is no button to bypass them.

  • Sell or pass on data, to anyone
  • Show advertising to pupils or families
  • Profile children or compare them publicly
  • Create a pupil account without going through the school
  • Link a parent to a child without human approval
  • Move data outside the European Union for hosting

We do not claim any certification (ISO 27001 or other) that we have not obtained. What we state here can be verified in the product and in our contracts.

The legal framework

Mon School is published by AJ SRL, a company established in Belgium: the GDPR applies whatever the school's country. For Cameroonian schools, Law No. 2010/012 on cybersecurity and cybercrime applies in addition, not instead.

  • The school remains the data controller; AJ SRL acts as processor
  • A data processing agreement (DPA) is provided to every school
  • Retention: account = contract duration + 12 months; messages = per the school's setting; technical logs = 12 months
  • Contact for personal data: hello@monschool.app

A security question?

Your DPO, your head teacher or you yourself can write to us. We reply by email, with technical details if you ask for them.

hello@monschool.appWrite to us
Request a demo