Skip to content

Privacy Policy

Last updated: 2026-07-19

This Privacy Policy explains how K12 Times ("we", "us") collects, uses, stores, shares, and protects your personal data. This notice is issued under the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") and the Information Technology Rules, 2011 as amended.

1. Who we are

K12 Times is a K-12 education news and school-publishing platform operated by an Indian individual founder (the operating legal entity will be updated here once incorporated). For data-protection enquiries, see our Grievance Officer page.

2. Data we collect

  • Account data (all users): name, email address, password (stored only as a cryptographic hash), city, and role (school staff, parent/guardian, or student).
  • Student accounts — deliberately minimal:the student's name, class/standard, school name, and the guardian details below. We do notcollect a student's date of birth, mobile number, or home address at signup.
  • Parent / guardian data (for a student account):the guardian's name and email address(a phone number is not accepted for this purpose), the exact consent statement agreed to, and the date. Guardian consent is confirmed by a one-time code sent to the guardian's email — see section 3.
  • School and relationship records: which school an organisation represents, its verification status, staff memberships and roles, student–school enrolment records, and guardian–student relationship records (including which guardian is the primary decision-maker). Alongside internal account identifiers we store irreversible pseudonymous references so that our audit history stays meaningful even after an account is erased — these references cannot be turned back into a person.
  • Content: news drafts, event listings, student creative work (writing, art, photographs and similar), and the review history attached to each item.
  • Permission records: every guardian permission request and decision, kept as an append-only history (see section 4).
  • Usage data: page views, likes, IP address (logged briefly for rate-limiting and abuse prevention), device user-agent.
  • Cookies: a session cookie for authentication plus essential security cookies. Our usage analytics are cookieless. We do not use advertising or cross-site tracking cookies.

3. Children's data

K12 Times serves K-12 students, who are generally under 18 and are treated as "children" under Section 9 of the DPDP Act 2023. Our model is guardian-controlled by design:

  • No open student self-registration. Student accounts are created through the school and guardian onboarding path, and this is enforced on our servers — not just in the page design.
  • Verifiable guardian consent at collection.A student account cannot be created without a guardian's name, email, and explicit consent to an unticked-by-default statement. We record the exact statement and date.
  • Guardian confirmation by one-time code.Guardian relationships are confirmed by a short-lived one-time code sent to the guardian's email. A student account whose guardian never completes verification is automatically deleted after 7 days, together with its pending records.
  • Structured relationships, not a one-time declaration. We keep an explicit relationship record between each guardian and student (a child may have more than one linked guardian, with one primary decision-maker), and between each student and their school. Schools can only initiate a guardian link for students actually enrolled with them.
  • Item-specific permission, not blanket consent.Account-level consent never publishes anything. Each public use of a child's work requires a separate permission request that the guardian decides — see section 4.
  • No behavioural tracking of children. In line with Section 9(3), we do not carry out behavioural monitoring or targeted advertising directed at children. Our analytics are cookieless and aggregate.

A parent or guardian may write to our Grievance Officer at any time to access, correct, or delete a child's data, or to withdraw consent.

4. How publication works — and how it is undone

Content on K12 Times moves through independent safeguards before it can appear publicly, and every safeguard can also take it back down:

  • Private by default.A student's submitted work is a private record. It is visible only to the student's school reviewers until every gate below is satisfied.
  • School approval. An authorised school reviewer must approve the item.
  • Guardian permission (children's work). The primary guardian receives a request showing exactly what would be published. The guardian separately chooses which identity details may appear (for example, first name only rather than full name, or omitting the class). The narrowest choice always wins, and no decision means no publication. Every request and decision is kept as an append-only history — decisions are superseded, never overwritten.
  • Safety review. Content is additionally screened by an automated safety check (see section 5) and/or a human moderator before public visibility. If the safety systems are unavailable, content waits — unavailability can never approve anything.
  • Withdrawal, propagated.A guardian can withdraw permission at any time. Withdrawal immediately unpublishes the item and triggers removal of the public copies — feeds, sitemaps, caches and search-engine notifications — through a tracked queue that retries until done. The student's private work and private portfolio record are preserved; only the public publication disappears.
  • Private portfolio. School-approved work is also recorded privately for the student. This record is not public and survives any public withdrawal.

5. Automated and human review

  • AI safety screening. We use Google Gemini to screen content for child-appropriateness before public visibility. The AI can only mark content safe or hold it — publication additionally requires the human approvals in section 4. AI decisions are recorded with their reasons.
  • Human moderation.Our moderators can review any item, record a safety ruling with a reason, and take content down. Moderation actions are logged with the reviewer's identity.
  • Uploaded images are cleaned. Uploaded images are verified for file type, re-encoded, and stripped of hidden metadata — including any embedded location (GPS) data — before they can be served. Files that fail these checks are quarantined and removed.
  • Public reporting. Anyone — without an account — can report any public content. Reports create reference-numbered grievance tickets with response deadlines (see the Grievance page).

6. Purposes and legal basis

Under the DPDP Act 2023, we process personal data on the basis of consent (§6) or, in limited cases, the specified legitimate uses in §7 (such as voluntary provision for a specified purpose, or compliance with law). We do not rely on any general "legitimate interest" ground.

PurposeData usedBasisRetentionPublicly visible?
Account creation & loginName, email, hashed password, role, cityConsent at signup (§6); guardian consent for children (§9)Until account deletion; unverified child accounts auto-delete after 7 daysNo
School verification & staff administrationSchool identity, staff emails, roles, membership recordsConsent of the staff member; performance of the service the school requestedWhile the organisation is active; membership history retained for auditSchool name and verification status only
Guardian relationships & permission decisionsGuardian–student relationship records, permission requests and decisionsGuardian consent (§9); the record itself evidences that consentAppend-only history retained while the child's account existsNo
Reviewing & moderating contentContent, attached media, review and safety-ruling recordsConsent; platform-safety processing needed to operate the serviceReview history kept while the content existsNo
Publishing an approved itemThe work plus ONLY the identity fields the guardian permittedItem-specific guardian permission (children); author consent (adults)Until withdrawn by the guardian/author, or removed by moderationYes — within the permitted fields
Event registrationsRegistration record; contact details shared with the host school only if you tick an optional, unticked-by-default boxConsent at registrationUntil the registration is cancelled or the event record is removedNo (attendance counts only)
Transactional emailEmail addressNecessary to provide the service you signed up forUntil account deletionNo
Aggregate, cookieless analyticsPage views and a small set of product events; no identifiersData minimised and aggregated; not used to profile youShort-term, aggregate onlyNo
Abuse, fraud & security preventionIP address (short-lived logs), user-agent, security eventsNecessary to keep the service safe and lawfulUp to 90 days unless needed for an investigationNo
Grievance & legal-request handlingReporter contact (optional for public reports) and ticket recordsCompliance with law (§7)For the statutory record-keeping periodNo

7. Sharing and service providers

We do not sell personal data. We share data only with:

  • Service providers: Cloudflare (hosting/CDN and cookieless Web Analytics), Cloudflare R2 (media storage), Amazon SES (email delivery), and Google Gemini (automated content-safety screening). Content is sent to the AI provider for safety screening only.
  • The host school, for an event registration — only if you explicitly ticked the optional consent box when registering.
  • Law enforcement, when legally compelled by an Indian court order or statute.

8. Retention

  • Account data: until you delete your account.
  • Unverified child accounts: automatically deleted after 7 days (section 3).
  • Published content: until withdrawn or removed; withdrawal also removes the public copies (section 4).
  • Permission and audit history: retained as records of consent and accountability.
  • Security logs and IP addresses: up to 90 days unless needed for an investigation.
  • Grievance records: for the statutory record-keeping period.

Account deletion is different from publication withdrawal.Withdrawing permission for one item takes that item down and leaves the account intact. Deleting an account erases the account, unpublishes the person's published items, and triggers the same public-copy removal — while preserving the pseudonymous audit records that cannot identify anyone.

9. Your rights (DPDP Act §11–§14)

  • Access: request a summary of your (or your child's) personal data and how it is processed.
  • Correction, completion & updating: ask us to fix inaccurate or incomplete data.
  • Erasure: delete your account and its data, including a child's account.
  • Withdraw consent: at any time without penalty — per item (withdrawal) or entirely (deletion).
  • Nomination: nominate a person to exercise your rights in case of death or incapacity.
  • Grievance redressal: contact our Grievance Officer.

To exercise these rights, write to our Grievance Officer. Sensitive actions (such as account erasure) are confirmed with a one-time code so nobody else can trigger them for you. We acknowledge within 24 hours and respond within the timelines published on the Grievance page.

10. Security

We use TLS in transit, hashed passwords, time-bound access tokens, role-based access controls with deny-by-default authorisation, single-use time-limited codes for sensitive actions, and audit logging of administrative decisions. No system is perfectly secure; please use a strong unique password and report any suspected compromise to our Grievance Officer.

11. International transfers

Personal data is primarily stored in Mumbai, India. Some service providers (Cloudflare, Amazon, Google) may process data outside India under standard contractual safeguards.

12. Changes

We will publish material changes on this page and update the "Last updated" date. If we materially change the purposes of processing, we will request fresh consent — and for children's data, fresh guardian consent.