Legal
Schoolmate Privacy Policy
Last updated: August 23, 2026
This policy explains what personal information the Schoolmate mobile app and the Schoolmate school application collect, why we process it, and who it is shared with. Schoolmate is provided to schools: each school decides which of its administrators, teachers, guardians, students and drivers receives an account, and which school records are entered into it. The public schoolmate.agency marketing site is covered by its own separate privacy notice.
Who we are
Schoolmate is a school management platform published by Schoolmate, operating from Rabat, Morocco.
For any question about this policy or about information held about you, write to contact@schoolmate.agency. Postal address: 46 Avenue Okba, 3rd floor, Apt 18, Agdal, Rabat, Morocco. Phone: 06 64 24 33 52.
What this policy covers
The Schoolmate Android application, the Schoolmate web application that schools sign in to, and the servers behind them.
Schools subscribe to Schoolmate and provision the accounts their staff, families and students use. The school decides what is recorded about its pupils and staff; Schoolmate processes those records to operate the service for that school.
Information we process
Account and sign-in information: username, password (kept only as a cryptographic hash, never in readable form), the role your school assigned you, session and authentication tokens, and your preferred language.
Profile information for administrators, moderators, teachers, guardians, students and drivers: first and last name (including the Arabic spelling where the school records it), date of birth, gender, profile picture, address, phone number, email address, and school identifiers such as admission number, admission date and Massar identifier.
Optional student details a school may choose to record, including blood group and medical notes. These fields are entered by the school, not requested by Schoolmate.
The family links between a guardian and the students they are responsible for.
School records created through the year: attendance sessions and daily attendance, grades, exams, homework, report cards, teacher remarks, class and teacher timetables, announcements, alerts, and school documents.
Messages exchanged inside the app, together with files, images and other media attached to them or uploaded to a school media library.
School-fee records: fee definitions, amounts due and paid, the payment method recorded (cash, bank transfer, cheque, online or other), receipt and transaction references, payment dates and staff notes. Schoolmate does not collect or store bank card numbers and does not process card payments — fee payments are recorded by school staff after they take place.
Push-notification data: the Firebase Cloud Messaging registration token of your device, the platform it runs on, the app language and when it was last seen. This is what allows a notification to reach the right device.
Location, for bus drivers only: where a school uses the transport module and a driver starts a route in the app, the driver device shares its position, speed, heading and accuracy while that route is running, so the school and the families on the route can see where the bus is. The app asks for location permission first, this applies to driver accounts only, and it stops when the route ends. No other role has location collected.
Technical information: our servers keep ordinary access logs — IP address, date and time, the address requested, and browser or app details — along with error diagnostics, so that we can run the service, investigate faults and protect it against abuse.
Why we process it
To provide the features your school has enabled: attendance, grades and report cards, homework and exams, timetables, messaging, announcements, documents and media, fee tracking and, where used, bus tracking.
To create and secure accounts, keep you signed in, and apply the permissions your school assigned to your role.
To notify you about what concerns you — a new message, a new grade, a homework deadline, a fee reminder, a school announcement.
To keep the service running and safe: diagnosing errors, preventing abuse, and maintaining backups.
To answer support requests from a school or from you.
Who can see what
Schoolmate separates data by school. An account can only reach records that belong to its own school.
Inside a school, what you can see depends on the role and permissions the school gave you: teachers see the classes assigned to them, guardians and students see their own records and messages, administrators and moderators see what their permissions allow.
Your school decides who holds an administrator account, and administrators can view and change the school records described above.
Service providers we use
Google, through Firebase Cloud Messaging, delivers push notifications to devices. To do that, your device registration token and the content of the notification are handled by Google messaging infrastructure, which operates internationally.
A hosting provider runs the servers that hold the database and the uploaded files, and provides the network that serves the application. Uploaded files are stored on those servers rather than in a separate third-party file service.
Formspree receives messages sent through the contact form on the public schoolmate.agency website. It is not used by the mobile app or by the school application.
No other analytics, advertising or tracking service is embedded in the mobile app or in the school application.
We do not sell personal data
We do not sell personal data, we do not share it for third-party advertising, and the app carries no advertising or ad-tracking components. School data is used to operate the service for the school it belongs to, and for nothing else.
Security
Traffic between the app and our servers travels over encrypted HTTPS connections, passwords are stored as cryptographic hashes rather than in readable form, and access is restricted by school and by account role.
We take reasonable technical and organisational measures to protect personal information. No online service can be guaranteed completely secure, and we do not claim otherwise.
Keeping and deleting information
Schools administer the accounts they provision and the school records they enter. To see, correct or delete information about you or your child, contact your school first — it controls its own records — or write to contact@schoolmate.agency and we will help.
School records are kept for as long as the school uses Schoolmate and needs them for the school year and for its own educational, legal, accounting and audit obligations. After deletion, some information may persist for a period in backups and in security or transaction logs before it is removed in the ordinary course.
We do not state a single fixed retention period covering every record: how long something is kept follows the school need for that record and the obligations above.
Students and children
Schoolmate is used by schools, and the records a school enters include information about pupils, many of whom are minors. We do not offer accounts directly to children: student accounts are created and controlled by the school, which decides who has one and what is recorded.
A guardian who wants to know what the school records about their child, or wants it corrected or removed, should ask the school, which can act on the record directly. We assist schools with those requests when they ask us to.
Processing outside Morocco
Push notifications are delivered through Google Firebase Cloud Messaging, which operates internationally, so notification content and device registration tokens may be processed outside Morocco. The remaining processing takes place on the servers our hosting provider runs for us.
Changes to this policy
We update this page when the way Schoolmate handles information changes. The date at the top of the page shows the latest revision.
Contact us
Email: contact@schoolmate.agency.
Phone: 06 64 24 33 52 / 06 54 04 56 97.
Address: 46 Avenue Okba, 3rd floor, Apt 18, Agdal, Rabat, Morocco.