Home · Security & privacy

Security & privacy

Your child's data, kept where it belongs.

Kindred is designed for India's Digital Personal Data Protection Act (DPDPA, 2023) from the first line of code. We host in India, encrypt in transit, enforce strict per-row access, and never share data with third parties for advertising or analytics.

Where your data lives

All school, parent, child and message data is stored in a Supabase Postgres database provisioned in the Mumbai (ap-south-1) region. No replicas outside India. Daily encrypted backups, also in-region.

Who can see what

We enforce row-level security at the database level — not just in the app. A parent's session can only ever read rows tied to their own child. A teacher can read rows for the class they teach. Even an exploit in the front-end app cannot return another family's data.

What we never do

Your DPDPA rights

You can request a full export of every record we hold about you and your child, correct anything that's wrong, or ask us to delete it. We honour requests within 30 days. Full details in our privacy policy.

Operational controls

Vendors we use

The list is short by design. Each is a data processor with a narrow purpose:

That's it. No advertising SDKs, no behavioural-analytics SDKs, no chat widgets that read your messages.

For your school's data-protection officer

We're happy to share our security architecture document, processor list with data-processing agreements, and pen-test summaries on request. Email privacy@kindredschool.in.

Bring DPDPA-native to your school.

Most school software was built before DPDPA existed. Kindred wasn't.

Read the DPDPA guide →