Alumno OS

Privacy Policy

Last updated: 28 July 2026

Introduction

Alumno OS is a school management platform. This policy explains what personal information we handle, why we handle it, and the choices you have. It applies to alumno.app and to the Alumno OS application.

Who we are, and our role

Alumno OS is operated by The Schools Trust (“we”, “us”). Our role depends on the information in question.

For most of the information held in Alumno OS — the details of families, parents, students, applicants and their communications — the school using Alumno OS decides why and how that information is handled. In data-protection terms the school is the “controller” and Alumno OS is a “processor” acting on the school’s instructions. If you are a parent or applicant, please contact your school with questions about your information; the school can also ask us to act on its behalf.

For the staff accounts that sign in to Alumno OS, and for the operation and security of the service itself, we act as the controller.

Information we process

  • Account information — the names, work email addresses, roles and permissions of the school staff who use Alumno OS.
  • School records — information schools enter or import about families, parents, students, applicants and enquiries, such as names, contact details, dates of birth, relationships, admissions and enrolment details, and notes. Where a school records it, this can include special-category information (for example health or learning-support needs); Alumno OS protects such information with field-level access controls.
  • Communications — where a school connects email, calendar or WhatsApp, the messages and events exchanged with families are logged against the relevant records.
  • Technical information — sign-in sessions, security and audit logs, and the information needed to operate and protect the service.

How we use information

  • To provide Alumno OS to schools, under our contract with the school.
  • To keep the service secure, prevent misuse, and meet our legal obligations.
  • Where the law requires consent — for example certain communications, or special-category data — it is obtained by the school and recorded in Alumno OS.

We do not use school records or communications to advertise to anyone, and we do not sell personal information.

Google user data (Gmail and Google Calendar)

If your school uses Google Workspace and an administrator connects it, staff can link their mailbox and calendar so that correspondence with families is captured in Alumno OS. When this is enabled:

  • We request access only after your Google Workspace administrator has reviewed and trusted the Alumno OS application for your domain.
  • We use Gmail access to identify and log email correspondence with families already in your school’s Alumno OS records, and to send replies you choose to send from within Alumno OS. We do not read or retain mail beyond what is necessary for that purpose.
  • We use Google Calendar access to show and create events for scheduling and bookings.
  • Access tokens are stored encrypted, and the school can switch access off at any time, which stops all further access.

Alumno OS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In line with Limited Use, information obtained through Google APIs is used only to provide and improve these features for you. It is never used for advertising, is never sold, and is not used to train generalized artificial-intelligence or machine-learning models. No human reads this data except with your explicit consent, where necessary for security or to comply with the law, or in aggregated and anonymized form for internal operations.

Our approach to AI

Schools have to collect and check a certain amount of paperwork — a passport or national ID to confirm a child’s identity and right to be in the country, and the records that go with it. It is necessary work, and it is slow: someone types a long document number off a scan and copies out an expiry date, for every child, every year.

We use AI to take the typing out of that, and only that. When a passport, national ID, visa or residence permit is uploaded — by the school, or by a family through the parent portal — our AI reads four things from it: what kind of document it is, the name printed on it, its number and its expiry date. Those are the details a school has to check and record anyway. It is not asked for the photograph, nationality, place of birth or anything else on the page, and none of that is stored from the reading.

A person always checks what the AI read. The four values appear in ordinary editable boxes, and a member of school staff confirms or corrects them before they count as the school’s record of the document. When a family uploads through the portal, we read it as it arrives so the boxes are already filled in when staff open it — until they have checked it, the document is marked pending review and the values are shown as something the AI suggested, not as the school’s record. No decision about a child is ever made by AI.

Health and medical documents are never sent to AI. Neither are school reports, references, or any other file a family uploads. Identity documents are the single exception, for the single purpose described above.

All of our AI processing takes place in the European Union. Our AI provider acts only on our instructions: your family’s information is not used to train anyone’s models, and it is not kept once a request has been answered.

A school can switch AI off completely. Where a school has done so, none of the above happens at all — its staff enter every document’s details by hand, and no information from that school reaches an AI provider for any purpose. A family can also ask their school to exclude them individually, and we will honour that.

How we share information

We share information only with the service providers that help us run Alumno OS, under contracts that require them to protect it:

  • Supabase — database, authentication and file storage (EU region).
  • Vercel — application hosting (EU region).
  • Google Cloud (Vertex AI) — the AI features, such as summaries, list building and search answers. Processing is pinned to the European Union, and under our agreement Google acts only as a processor: your data is not used to train its models and is not kept once a request has been answered.
  • Google — for schools that connect Google Workspace (email and calendar).
  • Brevo — sends email announcements, and Alumno’s own emails when a school has no working mailbox.
  • Meta — for schools that connect WhatsApp.
  • Cloudflare — stores our nightly off-site backup, so a problem at our main provider can never lose a school’s data. The backup is encrypted before it leaves our systems and Cloudflare cannot read it.
  • GitHub — provides the temporary machine that runs our automated nightly backup job (and, for schools that turn on the copy to their own Google Drive, the job that prepares and delivers it). To build a backup the job has to assemble the data before it can encrypt it, so for the few minutes each job takes, an unencrypted copy exists on that machine. The machine is provided by GitHub outside the European Union and is destroyed when the job finishes. See “Where your data is stored” below.
  • An email delivery provider, to send service email on a school’s behalf.

We do not sell personal information, and we do not share it for advertising. Some providers above apply only when a school chooses to enable the related integration.

Where your data is stored

Alumno OS is hosted in the European Union (Frankfurt, Germany), and the AI features run in the European Union too. Our nightly off-site backup is held by Cloudflare, encrypted, on a bucket configured for European storage. Where a provider processes data outside the EU, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses.

There is one exception we want to be explicit about, because it is the only point at which a school’s data leaves Europe. The backup files described above are put together by an automated job each night, and that job currently runs on a temporary machine provided by GitHub outside the European Union. Building a backup means gathering the data together before it can be encrypted, so for the few minutes the job takes, an unencrypted copy of a school’s records and files exists on that machine. Nobody signs in to it, it is used for nothing else, and it is destroyed when the job ends. We are moving this job to a machine in Europe; until then the transfer relies on the same safeguards described above.

How long we keep it

We keep a school’s records for as long as the school uses Alumno OS and as the school instructs. When a school leaves, we return or delete its data in line with our agreement. Information with a shorter useful life, such as unconverted enquiries, is kept for a shorter period, and security and audit logs are kept for a limited time.

How we protect it

Access is protected by authentication and role-based permissions, and schools are isolated from one another at the database level (row-level security). Data is encrypted in transit and at rest, and stored credentials such as mailbox tokens are additionally encrypted. We keep an audit trail of changes.

Children’s information

Schools record information about students, who may be children, in order to run admissions and day-to-day school operations. Alumno OS processes this on the school’s instructions and does not use it for any other purpose. Alumno OS is a tool for schools and is not directed at children.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal information, and to receive a copy of it. Because schools control most of the information in Alumno OS, please make these requests to your school; we will help the school fulfil them. For information we control — staff accounts and the service itself — contact us using the details below. You also have the right to complain to your local data-protection authority.

Cookies

Alumno OS uses only the cookies it needs to work — chiefly to keep you signed in and to remember which school you are working in. We do not use advertising or cross-site tracking cookies.

Changes to this policy

We may update this policy from time to time. We will change the date at the top and, for significant changes, let schools know.

Contact us

Questions about this policy or your information: privacy@alumno.app.