Privacy Policy

Version 2026-09-15 · Effective 2026-09-15

How Classeno handles personal information, for schools and for the people whose records a school keeps in it.

1. Our two roles

Classeno is operated by [LEGAL ENTITY NAME], [ADDRESS]. We handle personal information in two different roles, and this policy covers both.

  • For a school. The records a school keeps in its workspace — students, guardians, teachers, classes and attendance — belong to that school. The school decides what to collect and why; we handle it on the school's behalf and on its instructions.
  • For ourselves. The account information of the people who sign in to Classeno, and the technical records we need to run the service securely, are handled by us for our own purposes as described below.

If your child attends a school that uses Classeno, or you teach at one, contact that school first. They control their records; we cannot change or release them without their instruction.

2. What a school keeps in its workspace

A school chooses what to enter. Classeno provides fields for:

  • People: legal name, preferred name, email address, phone number and status.
  • Households and relationships, so a student can be linked to the guardians who are contacted.
  • Students: their person record, household, and any free-text notes the school adds.
  • Teachers: their person record, skills, locations and availability.
  • Classes, sessions, attendance, rooms and other resources.
  • Files a school uploads to import any of the above, and the results of those imports.
  • An audit record of who changed which entry and when, including the values before and after the change.

Classeno is not built to hold health information, government identifiers or payment card numbers, and schools are asked not to enter them.

3. What we collect about account holders

  • Email address, and a password stored only as a scrypt hash — never the password itself.
  • If you use Google sign-in: your Google account identifier and the verified email address Google reports. We never receive your Google password.
  • The date and version of the Terms and this Privacy Policy you accepted.
  • Which workspaces you belong to and your role in each.
  • The profile answers given during workspace setup, such as the school's name and how it operates.

4. Technical information

  • Activity logs: when an action was attempted, whether it succeeded, and a reference used to investigate errors and abuse. These logs do not record the visitor's IP address.
  • A security log of identity events — successful and failed sign-ins, password reset requests, email verification and Google sign-in. Each entry records the IP address the request came from, the account or email address involved, and the time. It is append-only, so entries cannot be altered afterwards.
  • Sign-in protection counters, which record the number of recent attempts against a key derived from the request address and the account.
  • Session records with their expiry, so a session can be ended.
  • For calendar subscriptions: a hash of the subscription token, when it was last used, and how often it is being fetched.

5. Cookies and browser storage

Classeno sets only what sign-in requires. There are no advertising or cross-site tracking cookies.

  • classeno_session — your signed-in session, HTTP-only, up to 7 days.
  • classeno_csrf — protects against cross-site request forgery, same lifetime.
  • classeno_pending_registration — ties an unfinished registration to your browser, up to 24 hours.
  • Two short-lived cookies during Google sign-in, which expire within 10 minutes.
  • In your browser's local storage: your light or dark appearance choice and the workspace you last had open. These never leave your browser.

6. Why we use this information

  • To provide the service: authenticate you, show your workspace, build schedules and calendar feeds.
  • To send service messages: email verification, password resets, invitations, and notices about security or account changes.
  • To keep the service secure: rate limiting, abuse investigation and audit records.
  • To support you when you ask for help, and to fix defects.
  • To meet legal obligations.

We do not sell personal information, and we do not use it for advertising or automated decisions about individuals.

7. Consent

When you create an account, you consent to the handling described here. A school is responsible for the consent needed to enter other people's information into its workspace, and for telling those people how it uses Classeno.

You may withdraw consent for your own account at any time by closing it, subject to any legal or contractual records we must keep. Withdrawing consent may mean we can no longer provide the service to you.

8. Students who are minors

Schools using Classeno commonly teach children. Classeno does not create accounts for students, does not market to them, and does not contact students or guardians on its own behalf — messages come from the school through its workspace.

Before entering a minor's information, the school must obtain consent from a parent or guardian, as required by the law that applies to it. A guardian who wants to see, correct or delete their child's records should contact the school. If a school asks us to help, we will act on its instruction.

9. Service providers

We keep this list short, and each provider receives only what it needs:

  • Google — optional sign-in. Google confirms your identity and verified email address.
  • Resend — delivery of the service emails described above, receiving the recipient address and message content.
  • [HOSTING PROVIDER] — servers, database and backups in [REGION].
  • [AI PROVIDER] — used only if a school chooses setup assistance during onboarding, and receiving only the school profile answers. Student, guardian and teacher records are never sent.

We require these providers to protect the information and to use it only to provide their service to us. We may also disclose information where the law requires it, or to establish or defend legal claims.

10. Where information is processed

Classeno's servers and backups are located in [REGION]. Some of the providers above may process or store information outside Canada, including in [COUNTRIES]. While information is in another country it is subject to that country's laws, and may be accessible to its courts and authorities. Contact us at privacy@[DOMAIN] for information about our practices in this regard.

11. How long we keep it

  • Sessions expire after 7 days; password reset links after 1 hour; email verification links after 30 minutes; invitations after 7 days.
  • An unfinished registration is removed 24 hours after its link expires; completed or cancelled ones within 7 days.
  • Calendar subscription tokens last until they are revoked or expire.
  • Workspace records are kept while the workspace is open, and deleted within [30] days of its closure, except where the law requires us to keep them longer.
  • Workspace audit records are kept for [PERIOD]. The identity security log is kept for [PERIOD]. Server logs are kept for [PERIOD]. Backups age out within [PERIOD].

12. How we protect it

  • We do not store readable copies of passwords or private calendar access keys.
  • Each workspace's data is separated, and every request is checked against the workspace it names.
  • Session cookies are protected from page scripts, safeguards prevent unauthorized requests, and connections are encrypted.
  • Sign-in attempts are rate limited, and changes to records are written to an audit trail.
  • Access by our staff is limited to those who need it to operate and support the service.

No system is perfectly secure, but we work to protect information in proportion to its sensitivity.

13. Your rights

Under Canadian privacy law you may ask for access to the personal information we hold about you, ask us to correct it if it is wrong, and ask how we have used and disclosed it. Write to privacy@[DOMAIN]. We will respond within [30] days, and we may need to verify your identity first.

For records held in a school's workspace, please ask the school. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or to the privacy regulator of your province.

14. If something goes wrong

If a breach creates a real risk of significant harm, we will report it as the law requires and notify affected workspace owners without undue delay, with what we know and what we are doing. A school remains responsible for notifying the people in its own records where that is required of it.

15. Changes to this policy

We may update this policy. The version in force when you accepted it is recorded with your account, and we will give notice of material changes to workspace owners before they take effect. Our Terms of Service are published alongside this policy.

16. Contact

Privacy questions and requests: privacy@[DOMAIN] · [LEGAL ENTITY NAME], [ADDRESS]. The person accountable for personal information at Classeno is [NAME OR ROLE].

Back to sign in