Kindred is designed for India's Digital Personal Data Protection Act (DPDPA, 2023) from the first line of code. We host in India, encrypt in transit, enforce strict per-row access, and never share data with third parties for advertising or analytics.
All school, parent, child and message data is stored in a Supabase Postgres database provisioned in the Mumbai (ap-south-1) region. No replicas outside India. Daily encrypted backups, also in-region.
We enforce row-level security at the database level — not just in the app. A parent's session can only ever read rows tied to their own child. A teacher can read rows for the class they teach. Even an exploit in the front-end app cannot return another family's data.
You can request a full export of every record we hold about you and your child, correct anything that's wrong, or ask us to delete it. We honour requests within 30 days. Full details in our privacy policy.
The list is short by design. Each is a data processor with a narrow purpose:
That's it. No advertising SDKs, no behavioural-analytics SDKs, no chat widgets that read your messages.
We're happy to share our security architecture document, processor list with data-processing agreements, and pen-test summaries on request. Email privacy@kindredschool.in.
Most school software was built before DPDPA existed. Kindred wasn't.
Read the DPDPA guide →