Privacy Policy
Effective date · July 28, 2026
Alumno AI is a school management platform that helps educational institutions run admissions, academics, billing and family communication in one place. This Privacy Policy explains what personal information we handle, why, and the choices and rights you have. We have written it in plain language because we want you to actually understand it.
A note on our two roles. Alumno AI serves two different groups of people, and our privacy responsibilities differ for each. For the school staff who hold an Alumno AI account, we are the data controller. For a school's own community, the students, parents, guardians and applicants whose information a school manages through Alumno AI, the school is the data controller and we act only as a processor on the school's behalf. Because a school's records include information about children and adolescents, we treat this distinction with particular care and explain it in Sections 2, 5 and 13.
1. Introduction & Who We Are
Alumno AI is a software-as-a-service platform for school management. Through the Alumno AI web application at alumno.ai (and, where available, the Alumno AI mobile app), a school's authorized staff can manage their institution's workspace and, as modules become available, admissions and enrollment, academic records, billing, and communication with families. Alumno AI is a multi-tenant platform: each school is an organization, and a person can belong to one or more organizations with a role of owner, admin, or member. The service is provided in Spanish and English.
Alumno AI is operated by Braintu Inc., located at 251 Little Falls Drive, Wilmington, Delaware 19808, USA ("Alumno AI", "we", "us", or "our"). Throughout this policy we refer to the schools and staff members who hold an Alumno AI account as "you".
Scope. This policy primarily governs the personal information we handle as a controller: chiefly the account and organization information of the people who use Alumno AI. It also explains, for transparency, the categories of personal information we process on a school's behalf when the school uses Alumno AI to manage its student and family records. For that processor activity, the school's own privacy notices and the processor terms in our Terms & Conditions govern how the data is used, and an individual's rights run through the school. We say more about this in Sections 2, 5 and 13.
2. Who This Policy Covers
Alumno AI touches the personal information of two distinct groups of people, and our responsibilities are different for each. Please find the group that applies to you.
Account Users (a school's owners, admins, and members)
Account Users are the people who register for and use the Alumno AI dashboard: a school's directors, administrators, teachers and other authorized staff. For the personal information that relates to your Alumno AI account and your use of the service, Alumno AI is the data controller: we decide how and why that information is processed, and the rights described in Section 12 apply directly between you and us.
Students & Families (the school's own community)
Students & Families are the members of a school's own community: students (including children and adolescents), their parents and guardians, and applicants for admission, whose information the school records and manages through Alumno AI. For this information, the school is the data controller and Alumno AI acts only as a processor, handling the data on the school's behalf and under its documented instructions.
If you are a student, parent or guardian and want to exercise your privacy rights (to access, correct, or delete information held about you or your child, for example) please contact the school. For Students & Families, the school is the controller and must respond to those requests; Alumno AI will support the school but will not respond to the individual directly without the school's instruction, because the data belongs to that school and is isolated to its workspace. See Section 13 for more.
3. Information We Collect
The information below reflects what Alumno AI actually collects and stores. Almost all of it lives in our primary backend (Supabase). We do not collect more than we describe here; in particular, we use no advertising trackers. We do run first-party product analytics for Account Users (never for Students & Families), described under Technical & Usage Data below.
Account Information
When you create or use an Alumno AI account, we collect your full name, email address, your phone number (if you sign in by phone), your role within each organization you belong to, and (optionally) an avatar. Sign-in is passwordless: you sign in with your email address and a one-time code we send to it, with your phone number and a one-time SMS code (delivered through Twilio Verify, where enabled for the service), or with "Sign in with Google" or "Sign in with Microsoft." If you sign in with Google or Microsoft, we receive basic OAuth profile data from that provider (such as your name, email address, and profile image). Alumno AI accounts have no password: there is nothing for us to store, and authentication (including the one-time codes) is managed by Supabase Auth. See Section 6 for more on third-party sign-in.
Organization Data
For each school, we store configuration such as the school's name, its slug / URL, workspace settings, and the membership and role information that controls who can access the workspace. When an owner or admin invites a colleague, we store the invitee's email address and the invitation's status so the invitation can be delivered and redeemed.
Student & Family Records
As the school-management modules roll out, a school will record and manage personal information about its own community through Alumno AI. Depending on the modules the school uses, this can include student records (identification and contact details, enrollment and admissions information, academic information such as grades and attendance), family records (parents' and guardians' names and contact details), billing records (tuition and payment status), and the content of communications the school exchanges with families through the platform, including attachments shared in those conversations (such as photos, documents, and voice notes).
Important: this is third-party personal data that the school chooses to collect and manage, and much of it concerns minors. For this data the school is the controller and Alumno AI is the processor, and we process it only on the school's instructions to provide the service (see Sections 4 and 5). The school is responsible for having a lawful basis (including any parental or guardian authorizations its jurisdiction requires) to collect and store this information and for giving the notices its community is owed.
Cookies & Session Data
When you sign in, we process your authentication and session information through the essential cookies described in Section 8. We do not use non-essential or tracking cookies.
Technical & Usage Data
Like any web service, your device's IP address and similar connection information are necessarily handled by our hosting and backend providers (Vercel and Supabase) to deliver and secure the application. Alumno AI itself does not run geolocation or build advertising profiles, and it does not store IP addresses, device fingerprints, or browser strings about Students & Families at the application layer. We do not use advertising pixels or cross-site tracking.
Mobile App Permissions
If you use the Alumno AI mobile app, it asks for access to your camera, photo library, and microphone only when you choose to attach a photo or record a voice note in a conversation. The app does not access these in the background, and declining a permission only disables that attachment feature.
Product Analytics, Session Replay & Error Reports (PostHog)
To understand where Account Users get stuck and what errors they hit, we run product analytics through PostHog (one analytics project per product, hosted in PostHog's US cloud). For Account Users only, this collects: usage events (screens opened and actions taken), device and connection metadata, client-side error reports, and session replays: recordings of what your screen showed during a session. Replays capture screen content as you saw it, including text you type; passwords are always masked. Once you sign in, this data is linked to your account id and email so we can see a real session behind a real problem.
Scope and limits. Analytics covers Account Users only: Students & Families are never instrumented. On the web, analytics events are sent through our own domain (first-party); marketing pages set no analytics identifiers until you sign in. We use analytics to improve the product, never for advertising, and we never sell it.
4. How We Use Information
We use Account Users' information to provide and operate the service: creating and securing your account, delivering one-time sign-in codes and transactional email, running your school's workspace, and providing support. We also use it to protect the service (preventing abuse, enforcing our terms, and meeting our legal obligations).
We do not sell personal information, we do not share it with third parties for their own marketing, and we do not use the contents of a school's records to build advertising profiles. Where Alumno AI includes AI-assisted features, they operate on the school's data as part of the service, on the school's instructions, and never to train third-party models on your data without your agreement.
5. Student & Family Data: Our Role as Processor
For the records a school manages through Alumno AI, the school decides what is collected and why; Alumno AI executes the school's instructions: storing the data, displaying it to the school's authorized staff, sending the communications the school initiates, and deleting the data when the school asks. Each school's data is isolated to its own workspace, and access within the workspace is controlled by the roles the school assigns.
Children's data. School records naturally include the personal information of children and adolescents. Alumno AI processes that information exclusively on the school's behalf, under this processor role. Children do not create Alumno AI accounts, and we do not knowingly collect personal information directly from children outside the school relationship. Obtaining any required parental or guardian authorization for the school's processing, and honoring the special protections that apply to minors' data (in Colombia, under Ley 1581 de 2012 and its implementing decrees), is the school's responsibility as controller; we support schools in meeting it.
6. Sign-in with Google or Microsoft
If you choose to sign in with Google or Microsoft, the provider shares basic profile data with us (name, email address, profile image) so we can create and match your account. We use this data only for authentication and your account profile. We do not receive your contacts, files, calendar, or any other data from these providers, and we cannot post or act on your behalf. Alumno AI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7. Legal Bases & Colombian Data Protection
Where a legal basis is required, we process Account Users' information because it is necessary to perform our contract with you (providing the service), because of our legitimate interests in securing and improving the service, to comply with legal obligations, or with your consent where we ask for it.
Alumno AI serves schools in Colombia first, and we honor the Colombian data protection framework: Ley 1581 de 2012, its implementing decrees, and the constitutional right of habeas data. Data subjects in Colombia have the right to know, update, rectify and delete their personal data and to revoke consent, as described in Section 13. Where the data is a school's student and family records, those rights are exercised through the school, which is the controller under that framework.
8. Cookies
Alumno AI uses essential cookies: the authentication and session cookies our backend (Supabase Auth) needs to keep you signed in securely, and a cookie that remembers your language preference: plus, after you sign in, a first-party identifier for the product analytics described in Section 3, kept in your browser's storage on our own domain. We set no advertising or cross-site tracking cookies, and marketing pages set no analytics identifiers, so no consent banner is required under the applicable rules.
9. Sub-processors & Service Providers
We use a small number of service providers to run Alumno AI. Each processes personal information only to provide its service to us and under contractual data protection commitments:
- Supabase (database, authentication, and file storage): the primary backend where account data and each school's records are stored.
- Vercel (hosting and content delivery): serves the web application.
- Resend (transactional email): delivers one-time sign-in codes, invitations, and service email from alumno.ai addresses.
- Google and Microsoft (optional sign-in): authenticate you when you choose "Sign in with Google" or "Sign in with Microsoft."
- Stripe (payments): processes subscription payments for schools when billing features are enabled; Alumno AI never stores full card numbers.
- Twilio (SMS sign-in codes): delivers the one-time SMS codes when you sign in by phone (Twilio Verify), where enabled for the service.
- PostHog (product analytics): product analytics, session replay, and error reporting for Account Users (one analytics project per product, hosted in PostHog's US cloud). See Technical & Usage Data in Section 3.
We will update this list as the service evolves; material changes will be reflected in this policy.
10. International Transfers
Alumno AI is operated from the United States, and the service providers listed above store data primarily in the United States. If you use Alumno AI from Colombia or elsewhere, your information (and the records a school manages) will be transferred to and processed in the United States. We take the safeguards described in this policy and in our contracts with providers wherever the data is processed, and schools remain able to meet their local-law duties (including Colombia's international transfer rules) through our processor commitments.
11. Data Retention & Deletion
We keep Account Users' information for as long as the account is active. A school's records are kept for as long as the school's workspace exists and are handled on the school's instructions: when a school deletes a record, or deletes its organization, the corresponding data is removed from the live systems, with residual copies in encrypted backups expiring on a rolling basis. Schools should retain their own copies of records that local education regulations require them to preserve.
12. Security
We protect personal information with encryption in transit (TLS) and at rest, tenant isolation enforced at the database layer (each school's workspace is segregated with row-level security), role-based access inside each workspace, and passwordless authentication that eliminates stored passwords entirely. No system is perfectly secure, but we design so that the blast radius of any failure is as small as possible, and we will notify affected schools without undue delay if a security incident involves their data.
13. Your Rights
Account Users can access and update their name and avatar in the dashboard, and can ask us to access, correct, delete, or export the personal information we hold about them, or to restrict or object to its processing, by writing to the address in the contact block below. Where processing rests on consent, you can revoke it at any time. If you believe we have not honored your rights, you can complain to your local data protection authority (in Colombia, the Superintendencia de Industria y Comercio).
Students, parents and guardians exercise their rights (including habeas data rights in Colombia) through their school, which as controller must respond to requests to know, update, rectify or delete the information it manages. We support schools in fulfilling those requests promptly.
14. Children's Privacy
Alumno AI accounts are for adults only (18 years or older). We do not knowingly allow children to create accounts, and we do not knowingly collect personal information directly from children. Children's information enters Alumno AI only as part of a school's records, where the school is the controller, the processing serves the school's educational purposes, and the special protections for minors' data described in Section 5 apply. If you believe a child has created an account or that children's data is being processed outside these bounds, please contact us and we will act promptly.
15. Changes to This Policy
We may update this policy as Alumno AI evolves. When we make material changes, we will update the effective date above and notify Account Users through the service or by email. Continued use of Alumno AI after a change takes effect means the updated policy applies.
Questions about privacy at Alumno AI, or a request about your personal information? Write to us and we will get back to you promptly:
privacy@alumno.ai