# Privacy Policy (Schooler) **Effective date:** 2026-02-23 This Privacy Policy explains how **Schooler** (“we”, “us”, “our”) collects, uses, and shares information when you use Schooler (the “Service”). **Provider:** Chayanut Apiwatnatragool (individual developer) **Contact:** aungshome@outlook.com **Country/Jurisdiction:** Thailand ## 1) What Schooler does Schooler helps students access information posted by teachers and schools (for example: announcements and schedules). ## 2) Information we collect ### 2.1 Information from Google Sign-In (OAuth) When you sign in with Google, we receive basic profile information such as: - **Name** - **Email address** - **Profile picture** ### 2.2 Account and school-related attributes (if configured) To operate the Service, we may store account attributes and permissions such as: - **role** (e.g., student/teacher/admin) - **class**, **department**, **year/grade** - optional identifiers such as **personnel ID** and **tags** (if your school setup uses them) ### 2.3 OAuth account identifiers and token data To link your account and keep sign-in working, we may store: - OAuth **provider** and **provider account ID** - OAuth token metadata (such as **expiry** and **scope**) If stored, OAuth access/refresh tokens are stored **encrypted** on the backend. ### 2.4 Content you provide (links) Schooler may store or display links you submit (for example, **Google Drive links**) and related metadata such as who posted it and when. We do not host Google Drive files ourselves. Access to linked files depends on the sharing settings set by the file owner, and Google’s own policies and terms apply. ### 2.5 Cookies / similar storage (authentication) We use cookies and/or similar storage technologies to keep you signed in and to secure sessions (for example, authentication/session tokens). We do **not** use cookies for advertising/marketing purposes. ### 2.6 Basic logs and technical data When you use the Service, servers and infrastructure may process basic technical logs such as: - IP address - device/browser information (user agent) - timestamps and requested pages/endpoints - error logs for debugging and security ## 3) How we use information We use the information we collect to: - authenticate users (Google OAuth) and operate accounts - provide core features (showing announcements, schedules, and school information) - enforce permissions and access control - secure the Service, prevent abuse, and troubleshoot issues - communicate with you about important changes or issues (when needed) ## 4) Where data is processed (hosting) - The **frontend** may be hosted on **Vercel** (a hosting provider). - The **backend (FastAPI)** is **self-hosted by the Provider** (run and managed by the developer), along with its database (for example, PostgreSQL). ## 5) How we share information We do not sell your personal data. We may share information only in these situations: 1. **Service providers**: hosting and infrastructure providers (e.g., Vercel for the frontend) process data as needed to deliver the Service. 2. **With your direction**: if you post information or links through the Service, it may be visible to other users according to access controls. 3. **Legal and safety**: if we believe disclosure is reasonably necessary to comply with law, respond to lawful requests, protect rights/safety, or prevent abuse/security incidents. ## 6) Data retention Data retention is **admin-controlled**. We may keep data as long as needed to operate the Service, comply with legal obligations, resolve disputes, and enforce policies. If you would like to request deletion or correction of your data, contact: **aungshome@outlook.com**. We will make reasonable efforts to honor requests, subject to admin controls and legal/security requirements. ## 7) Security We use reasonable administrative and technical measures to protect information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. ## 8) Children’s privacy Schooler is intended for educational use. If you are a parent/guardian and believe a child has provided personal information without appropriate permission, contact **aungshome@outlook.com**. ## 9) International data transfers Hosting/infrastructure providers may process data on servers located outside Thailand. By using the Service, you understand your information may be processed in other countries, which may have different data protection laws. ## 10) Your rights and choices Depending on applicable law, you may have rights to access, correct, or delete your personal data. To make a request, email **aungshome@outlook.com**. You can also manage certain profile information via your Google account settings. ## 11) Changes to this Privacy Policy We may update this Privacy Policy from time to time. We will update the effective date at the top when changes are made. ## 12) Contact If you have questions or requests about privacy, contact: **aungshome@outlook.com**