Complete this against the exact release candidate and every included SDK. This worksheet is not legal advice and must be approved by the service operator, school, privacy reviewer, and child-safety reviewer before submission.
Current Native Foundation
- account email and display name are returned after secure sign-in.
- school names and account roles are returned for authorised accounts.
- random QR or barcode values are decoded locally for approved app routes.
- camera frames are not stored or uploaded by the native scanner.
- lasting native sessions are stored in Keychain or Android Keystore-backed encryption.
- authenticated school data remains on the shared server.
- no advertising or cross-app tracking SDK is included.
- no analytics SDK is included.
- no student photo workflow is included.
Apple App Privacy Review
For each applicable data type, record whether it is collected, linked to an identity, used only for app functionality, retained, shared with a processor, and covered by deletion/correction. Review at least:
- contact information for staff accounts.
- user ID and account role.
- school and student teaching records available to authorised users.
- diagnostics or crash data, if a service is added later.
- purchases or subscription status, if enabled later.
Do not declare that data is absent merely because it stays on the shared server; store declarations must match the complete app service.
Google Play Data Safety Review
Record for each applicable data type:
- collection and sharing status.
- required or optional status.
- purpose.
- encryption in transit.
- account deletion path.
- retention and correction process.
Confirm that the declaration matches the privacy policy, app permissions, network behaviour, backend, support tools, and every third-party SDK.
Permission Text
- Camera: scan Band Licence QR codes and barcodes without storing camera images.
- Microphone: the web Lesson Notes workflow may request access only after a Teacher/Administrator deliberately arms one approved teaching date, covering its combined writable lessons and rehearsals, in the explicit opt-in deployment. Audio/raw transcript content is temporary and processed only by the authenticated loopback engine on the app host. The first native clients still do not declare or request native microphone permission; adding it requires native-specific purpose text, permission, cleanup and store evidence.
- Photos/media: do not request for student profiles or scanning.
- Location, contacts, advertising ID: do not request.
Any later SDK or permission change reopens this review.