Privacy Policy (English)
MS Academy AssistantMS Academy provides educational center operations tools through our Assistant mobile application for academy staff. This policy explains what data we collect, why we collect it, and how we protect it.
This app is for authorized staff only. Students and parents use a separate app with its own privacy policy at /privacy.
1. Data We Collect
- Account identifiers: assistant phone number, Firebase Auth user ID, email used for authentication, role/permission, and related session credentials.
- Staff profile: display name and account status needed to operate the app.
- Operational academy data: centers, groups/classes, student records, attendance, payments, lecture sessions, exams/homework follow-up, and reports that staff create or access as part of academy work.
- Verification & messaging: phone number and, when used, Telegram chat identifiers needed to deliver OTP / account messages via our official assistant bot (not for advertising).
- Push notifications: device FCM tokens to send service notifications related to academy operations.
- Diagnostics & security: crash reports and app diagnostics (Firebase Crashlytics), App Check / device integrity signals, and anti-tamper security signals where enabled, to protect accounts and academy data.
- Local device storage: secure session data and temporary offline lecture/attendance data cached on the device until synced to our servers.
We do not require an advertising ID for core product features, and we do not use the app for third-party advertising.
2. How We Use Data
- Authenticate staff and maintain secure single-device sessions.
- Provide core staff features: centers, groups, students, lectures, attendance, payments, follow-up, reports, and related operations.
- Send service notifications and OTP / credential messages when needed.
- Improve reliability and security, and prevent abuse or unauthorized access to academy records.
- Comply with applicable legal obligations.
3. Data Storage & Security
- Cloud processing via Google Firebase (Authentication, Firestore, Cloud Functions, Cloud Messaging, Crashlytics, App Check).
- Telegram may be used as a delivery channel for bot-based staff verification.
- Data in transit is protected with HTTPS / TLS.
- Access is limited by staff role/permission and least-privilege server roles.
4. Data Sharing
- We do not sell personal data.
- Data is shared only with service providers needed to operate the app (notably Google Firebase and Telegram for bot delivery when used), under their respective terms.
- Staff may view student and parent operational data only as required for academy operations and according to their assigned permission.
- We may disclose data when required by law or to protect users and the academy.
5. Student Data Handled by Staff
Assistants may access and update student-related operational records (for example attendance, payments, and academic follow-up) solely to run academy services. That processing is part of providing education operations and is limited by role-based permissions.
6. Data Retention
- Staff account and operational records are retained while the account is active and as needed for academy operations or legal requirements.
- Sessions, FCM tokens, offline lecture caches, and diagnostic logs are kept only as long as needed for security and reliability.
- To request deletion or deactivation of a staff account, contact us at the email below. Academy operational records may be retained as required for legitimate academy or legal purposes.
7. Your Rights
- Request access, correction, or deletion of your personal staff data.
- Opt out of push notifications in your device settings.
- Contact us at morsi5038@gmail.com.
8. International Transfers
Data may be processed on servers outside your country (including Firebase infrastructure) with appropriate safeguards provided by those services.
9. Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do.
10. Contact
MS Academy — Privacy requests: morsi5038@gmail.com