Skip to content
AiLycée

Trust

Privacy policy

Last updated: September 2026

AiLycée holds information about children. This policy explains, in plain words, what we collect, why, where it lives and what we commit to — for schools, parents and students. It covers the AiLycée dashboard, the mobile apps, the public school directory and this website.

The short version

  • Your school owns its data. We process it on the school's instructions and export all of it on demand.
  • Children's data is minimised: we never store more than a feature needs, and there are no advertising or analytics SDKs in the parent and student apps.
  • AI receives a first name and academic facts. Never a family name, phone number, address, ID number or photo.
  • Nothing written by AI reaches a parent without a teacher's explicit approval or an automatic factual check.
  • You can delete: a full tenant deletion within 30 days of a written request.

1. Who is responsible for what

Each school (the "tenant") is the controller of its own data: students, guardians, staff, grades, attendance, conduct and finances. AiLycée is its processor and acts on the school's instructions. If you are a parent or a member of staff, the school is your first point of contact.

For the public school directory, the demo-request form on this website and admission applications submitted before a school is a customer, AiLycée is the controller.

2. What we store

We store only what running a school requires. Concretely:

  • Identity and contact details for students, guardians and staff — name, date of birth, phone, email, address, national ID where the school records it, and a photo if the school uploads one.
  • Academic data — enrolment, timetable, attendance, marks, term averages, report cards, homework and conduct notes.
  • Financial data — fee structures, discounts and scholarships, installment plans, payments and the receipts issued for them.
  • Communication — announcements, message threads inside school-controlled channels, and a log of notifications sent (who, which channel, when, delivered or not).
  • Documents the school uploads — identity papers, birth certificates, vaccination records — stored in per-tenant object storage behind expiring signed links.
  • Technical data needed for security — authentication events, an audit log of grade changes, payments, receipts, role changes and AI approvals, and error reports.

3. What we do not store

No bank card or bank account details — AiLycée records payments, it does not process them. No advertising identifiers. No behavioural profiles. No third-party analytics or attribution SDKs in the parent and student apps, ever. This website loads no trackers, no ad scripts and no third-party fonts: opening it contacts nobody but us.

4. Children's data — our specific commitments

Student data gets the strictest treatment in the system:

  • Data minimisation: a feature only ever receives the fields it strictly needs. Medical fields are limited to what a teacher must know in an emergency — allergies, blood type, emergency contact.
  • Artificial intelligence receives the child's first name and academic facts only. Never a family name, phone number, address, national ID or photo. This is enforced in the prompt builder and covered by tests.
  • Nothing written by AI reaches a parent without a teacher's explicit approval (report-card comments) or an automatic check that every number in the text exists in the data (weekly digest).
  • Arrears are role-gated to accountants and directors. A parent sees their own balance, in neutral wording, and a debt never blocks a child's access to their grades unless the school explicitly enables that policy.
  • The future AI study tutor will require the parent's explicit consent flag on the student record, will log every session for the school, and refuses non-academic conversation.
  • Students never see risk scores or internal notes written about them.

5. Where the data lives

Schools choose. On the cloud plans, data is hosted in a single European region (Germany), encrypted in transit and at rest, and backed up nightly with 30-day retention. On the Institution plan, it lives on a server inside the school or in the school's own private cloud, and backs up to the school's own NAS.

In both cases one school's data is isolated from every other school's by row-level security in the database, enforced on every query rather than in application code. Data is never moved to another region without the school asking for it.

We do not sell data and we do not share it for marketing or profiling. The only third parties involved are the infrastructure and delivery providers listed on our subprocessors page, each bound by contract.

6. Who can see what

Access follows the role, not the person: parents see their own children; teachers see their own classes; accountants see finance; directors see their school; nobody sees another school. Changes to grades, payments, receipts, roles and AI approvals are written to an audit log the school can inspect and, on the Institution plan, export.

AiLycée staff do not browse tenant data. Access for support requires the school's request, is limited in time, and is recorded.

7. How long we keep it

Academic and financial records are kept for as long as the school needs them — typically the legal retention period for school records in Lebanon. Message and notification logs are kept for 24 months. Authentication and audit logs are kept for 24 months. Bus-tracking location pings, when that feature ships, are kept for 7 days. Backups roll off after 30 days.

When a school leaves, it exports its data as JSON and CSV, and we delete the tenant within 30 days of a written request, backups included at the next rotation.

8. The directory and admission applications

The public directory lists schools, not people. When a parent submits an admission application, the details — the child's first and family name and date of birth, the parent's name and contact, the level applied for and any message — are stored and made available only to the school applied to. If that school has not yet claimed its profile, the application is held until it does. A parent can ask us to delete an application at any time, and we do.

9. Security

Passwords are hashed with Argon2id. One-time codes are short-lived and single-use. Access tokens expire quickly and refresh tokens rotate with reuse detection. Public forms are rate-limited. Receipts and report cards carry a QR code that verifies a document without exposing personal data — the check returns the document type, the school, the issue date, validity and the holder's first name, nothing more. The security page describes this in more detail.

10. Your rights

Parents, students and staff may ask to access, correct or delete their personal data. The school holds the data and is the point of contact; it can act on any of these directly in the dashboard. Where the school cannot help, write to privacy@ailycee.com and we will answer within 30 days. If you believe we have handled children's data badly, tell us — we would rather hear it from you than from anyone else.

11. Changes to this policy

We will post material changes on this page with a new date, and tell schools by email before the change takes effect. Previous versions are available on request.

12. Contact

AiLycée · Beirut, Lebanon · privacy@ailycee.com