Legal
Privacy Policy
Last updated: 19 August 2026
This Privacy Policy is written for families, teachers, and school administrators — and for Google Play, App Store, and similar listings. It explains what Prottoy collects, why, who can see it, and how to request access or deletion.
Privacy highlights
- Your institution owns its student, staff, and family records. Prottoy processes them only to provide the academic service.
- We do not sell personal information. We do not use student or family data for advertising, profiling, or marketing to children.
- Students and children use Prottoy through their school or guardian account — not as a public social network.
- Guardians see only their own children. Staff see only what their role allows.
- To delete an app account, email prottoy.admin@gmail.com from the address or phone linked to that account.
1. Who we are and what this covers
Prottoy (“we”, “us”) is an Academic OS for educational institutions. The product helps schools run attendance, fees and collections, notices, exams and results, people records, and day-to-day operations for admins, teachers, finance staff, students, and guardians.
This policy applies to:
- The Prottoy mobile apps, including the Android app listed on Google Play
- iOS, Windows, and macOS apps when they are available
- Any signed-in web product we operate for institutions
- The public website at www.prottoyos.com
- Email or other messages you send to us, including prottoy.admin@gmail.com
The developer name for store listings is Prottoy. If you have questions about this policy, contact us at the address in Section 16.
2. Who controls student data
Like other academic platforms, Prottoy is built for schools — not as a consumer social app. When an institution uses Prottoy:
- The institution owns and controls the education records it puts in Prottoy (student, staff, and guardian information). The institution decides what to enter, who may have an account, and which role can see which records.
- Prottoy processes that information on the institution’s instructions, to operate attendance, fees, notices, exams, people, and related features.
- The institution is responsible for obtaining any consent required from parents or guardians under its own rules and applicable law before creating accounts for children or students.
If you are a parent, student, or teacher, most requests to review, correct, or delete school records should go to your institution first. We will help the institution carry out a valid request.
3. Information we collect
We collect only what is needed to run Prottoy for your institution or to operate this website. We do not require children to provide more personal information than is reasonably necessary to use the school features their institution has enabled.
A. Information the institution or a user provides
Depending on role and how the institution uses Prottoy, this may include:
- Account and identity. Name, username, role (owner, admin, teacher, finance, auditor, student, guardian), class or section, profile photo if uploaded, password or PIN (stored in a protected form, not shown in plain text).
- Contact details. Phone number, email address, and mailing address when the institution records them.
- Student and family records. Enrollment and admission details, guardian relationships (so a parent sees only their own children), and similar directory information the school chooses to keep.
- Attendance. Presence, absence, incomplete sessions, and institution summaries.
- Fees and collections. Invoices, unpaid balances, receipts, payment history, and notes the school records for cash, bKash, bank, or counter collection. We do not ask website visitors for payment card numbers. If a payment goes through a provider such as bKash, that provider processes the payment under its own terms.
- Academics. Notices, exams, marks, calculated results, and published result cards.
- Operations. Staff appointment records, payroll or expense entries, print lists, and branding the institution uploads (logo, name, letterhead).
- Support messages. Name, contact details, and the content of emails or in-app requests you send us.
B. Information collected automatically from the apps and website
- App and device information. App version, operating system, device type, language, time zone, and identifiers needed to sign you in, keep you signed in, and deliver notifications.
- Usage and diagnostics. Feature activity (for example, opening attendance or fees), crash logs, performance data, IP address, and date/time of requests — used to keep the service reliable and secure.
- Website logs. Pages visited and standard server logs when you use www.prottoyos.com.
We do not collect precise GPS location for advertising. Approximate location may be inferred from IP address for security and service operation.
4. How we use information
We use personal information to:
- Provide the Academic OS: accounts, roles, attendance, fees, notices, exams, people, print, and related school workflows
- Show each user only what their role is allowed to see (for example, a guardian’s own children, a teacher’s classes, finance’s collections)
- Authenticate users, reset access, and protect accounts against misuse
- Send service messages the institution enables, such as notices or fee updates
- Diagnose crashes, improve reliability, and support the institution
- Reply to sales, partnership, and support requests
- Comply with law and enforce our terms
We may create de-identified or aggregated statistics (for example, that a feature is widely used) that do not identify a student or family. We do not use student records to train public advertising or consumer marketing models.
6. What we never do
- We never sell or rent personal information.
- We never use student, child, or guardian records for behaviorally targeted ads or third-party advertising.
- We never place third-party ads in signed-in student or guardian school views.
- We never require a child to provide extra personal details as a condition of using basic school features their institution has already set up.
- We never make a student’s account visible to the general public.
7. Children and student records
Prottoy is intended for educational institutions and the adults who run them (admins, teachers, finance, guardians). Children and students use Prottoy only because their school (or a parent/guardian acting with the school) creates or links an account for a legitimate educational purpose — attendance, fees, notices, and results.
The Android app is not a game, social network, or entertainment product directed at children acting on their own. We do not knowingly allow a child to create an institution workspace without school or guardian involvement.
The institution must provide any notices and obtain any parent or guardian consent required by its policies and by law before it enters a child’s information or lets a child sign in. If you believe we have collected a child’s information without proper school or guardian authority, email prottoy.admin@gmail.com and we will work with the institution to delete or correct it.
Parents and guardians may review, request correction of, or request deletion of their child’s school records by contacting the institution. If the institution asks us to help, we will.
8. Google Play Data safety
The table below is meant to match the Data safety section in Google Play. “Collected” means Prottoy or the institution may collect that type through the app. “Shared” means we transfer it to a third party other than a service provider acting only on our instructions — for example a payment provider when a fee is paid through that provider.
| Data type | Examples in Prottoy | Purpose |
|---|---|---|
| Name | Student, staff, and guardian names | App functionality |
| Email address | Account or support contact, if the school records one | App functionality, account management |
| Phone number | Sign-in, guardian contact, institution directory | App functionality, account management |
| User IDs | Account IDs, role IDs, institution IDs | App functionality, security |
| Address | Address the school stores for a person or campus | App functionality |
| Photos | Optional profile or institution branding images | App functionality |
| Education info | Class, attendance, exams, marks, results, notices | App functionality |
| Financial info | Fee invoices, balances, receipts, collection method | App functionality |
| Other user content | Notices, notes, support messages | App functionality, customer support |
| App activity | Screens opened, feature use | Analytics, app functionality |
| Crash logs and diagnostics | Error reports, performance | Analytics |
| Device or other IDs | Install or session identifiers | App functionality, security |
| Approximate location | Inferred from IP, not GPS advertising tracking | Security, app functionality |
Data is encrypted in transit. Account credentials are stored in a protected form. Users can request deletion as described in Section 13.
9. App permissions
The Android app may request system permissions needed to provide the service. Typical examples include:
- Internet / network. Required to sign in and sync attendance, fees, notices, and results.
- Notifications. Optional. Used for school notices or reminders the institution enables. You can turn these off in system settings.
- Photos or files. Optional. Used only if you or the institution upload a profile image, logo, or similar file.
- Camera. Optional. Used only if a feature lets you capture an image (for example a document or profile photo) rather than picking one from the library.
Prottoy does not need access to your contacts, microphone, or precise GPS in order to run core school features. If a permission is optional, you can deny it and continue using the rest of the app.
10. Security
We design Prottoy with role-based access so that not everyone in an institution can see everything. We use encrypted connections (HTTPS) where the product is served over the internet, access controls for our systems, and protected storage for passwords and PINs.
No method of transmission or storage is perfectly secure. Institutions should use strong passwords or PINs, limit who has owner or admin access, and tell us promptly at prottoy.admin@gmail.com if they suspect unauthorized use.
11. How long we keep information
- School records. Kept for as long as the institution’s workspace is active, and afterward only as long as the institution instructs us, as needed for a requested export, or as required by law. When the institution asks us to close the workspace, we delete or de-identify the associated personal data within a reasonable period, except where we must retain a limited record (for example, to complete a legal request or prove we deleted an account).
- App diagnostics. Crash and performance logs are kept only as long as needed to fix issues and keep the service stable.
- Website and support email. Kept as long as needed to reply and operate the site, then deleted or archived with limited access.
12. Your choices and rights
- In the app. Users can update profile details the institution allows them to edit, and can sign out. Guardians see only linked children.
- Through the school. Parents, students, and staff should ask the institution to access, correct, or delete education records. This is the same model used by student information systems worldwide.
- Through us. Account holders and institutions can email prottoy.admin@gmail.com to ask what personal information we hold, to correct it, or to delete an account as described below. We may need to verify identity and, for student records, confirm the request with the institution.
- Website visitors can stop using the site at any time.
13. Account and data deletion
Google Play requires a clear way to request deletion of an app account and associated personal data. You can do that without using the app.
How to request deletion
- Email prottoy.admin@gmail.com with the subject “Delete my Prottoy account”.
- Include the phone number or email used to sign in, the institution name, and your role (admin, teacher, guardian, student, or other).
- We will verify that you control the account. We may ask the institution to confirm before deleting school-owned student records.
What we delete. After a verified request we delete the account credentials and personal data we hold for that user, except:
- Records the institution is legally required to keep, which remain under the institution’s control until the institution instructs us otherwise
- Limited information we must retain for security, fraud prevention, accounting, or legal compliance (for example, that a deletion request was completed)
Uninstalling the app from a device does not delete your school account. A guardian or staff member who leaves an institution should also ask the institution admin to remove their access.
Institution owners who want the entire school workspace deleted should write from the owner account and say so clearly. That request removes the institution’s Prottoy workspace, not only one user.
14. Where information is processed
Prottoy is offered primarily to educational institutions in Bangladesh. Information may be stored or processed on servers in Bangladesh or in another country where our infrastructure or service providers operate. We take steps intended to keep that information protected wherever it is processed.
15. Changes
We may update this policy as Prottoy grows. The “Last updated” date at the top will change when we do. If a change is material, we will provide a more prominent notice — for example a notice in the app or on this page. Continued use of Prottoy after an update means the new policy applies.
16. Contact
Privacy, parent, or Play Store data questions:
prottoy.admin@gmail.com
Website: www.prottoyos.com
Privacy Policy URL for store listings:
https://www.prottoyos.com/privacy