Lekhaa — Privacy Policy

Last updated: 24 July 2026

Lekhaa is school management software. Schools use it to keep admission records, fee ledgers and staff records. Almost all the personal data in Lekhaa is entered by a school, about its own students, guardians and employees — we hold it on that school's behalf.

If you are a parent, student or teacher: your school decides what is recorded about you and how long it is kept. To see, correct or delete your records, contact your school first — they control the account. We act on their instructions.

1. Who we are

This app and service are operated by Akshay Basotra, trading as Lekhaa (“Lekhaa”, “we”, “us”), contactable at akshaybasotra@gmail.com.

In data-protection terms the school is the data fiduciary / controller and we are the data processor. We do not decide what a school records about a child; we provide the system that stores it.

2. What data is in Lekhaa

Data your school enters

AboutFields
Students Name, date of birth, gender, photo, phone, email, address, national/birth-certificate ID, religion, blood group, class and enrolment history, admission and registration numbers, previous school, notes, and uploaded documents (e.g. birth certificate, ID, marksheets).
Guardians Name, relationship, phone, national ID, occupation, education, profession, income, and whether they consented to WhatsApp messages.
Staff Name, date of birth, gender, photo, phone, email, address, father's/husband's name, designation, joining date, qualifications, experience, subjects and salary.
Money Fee structures, invoices, payments, receipts, concessions and the student ledger. We do not process card or bank payments — Lekhaa records payments a school has already collected.

Data we hold about app users

A login account for each staff member: name, email address, role, campus, and a password stored only as a one-way cryptographic hash. We never store passwords in a readable form.

Data the app stores on your device

Your sign-in tokens, your user profile and your selected campus, so you are not asked to log in on every launch. Signing out erases them. Uninstalling the app removes them.

3. What we do not do

4. Why we process this data

We do not use school data to train machine-learning models.

5. Where data is stored, and who else touches it

We use a small number of infrastructure providers, who process data only to run the service:

ProviderPurpose
NeonManaged PostgreSQL database — all records described above.
RenderHosts the application server.
Cloudflare (R2 & Pages)Stores uploaded photos and documents; serves the web app.
Google Play / Apple App StoreDistribute the mobile apps. Their own privacy policies apply to the store itself.

Our application server runs in Singapore. The managed database and file storage are operated by the providers above, who may process data in more than one region. In all cases, data may be stored or processed outside the country you are in.

6. WhatsApp messages

A school may connect its own WhatsApp Business account to send fee reminders and receipts. When it does, the guardian's phone number and the message content are sent to Meta through that school's account, and Meta's privacy terms apply to the delivery. We do not send messages from a Lekhaa-owned number, and no message goes out unless the school has enabled it and recorded the guardian's consent. The school's WhatsApp credentials are encrypted before we store them.

7. Children's data

Lekhaa holds records about children, but it is not a product for children — accounts belong to school staff, and children do not sign in. The school is responsible for having the lawful basis and, where required, verifiable parental consent for the records it enters. We do not knowingly create accounts for anyone under 18, and we do not track, profile or advertise to children.

8. Security

No system is perfectly secure. If a breach affects your data we will notify the school and the relevant authority as required by law.

9. How long we keep data

School records are kept for as long as the school's account is active, because a school needs historical admission and fee records for years. Deleted records are first marked as deleted and hidden from normal use, then removed. Financial ledger entries are never edited or deleted — a correction is recorded as a further entry, so the audit trail stays intact. If a school closes its account we will delete or return its data on request, allowing a reasonable period for backups to expire.

10. Your rights

Depending on where you live, you may have the right to access, correct, or erase your personal data, to withdraw consent, and to complain to a data-protection authority. In India, the Digital Personal Data Protection Act 2023 gives these rights and also the right to nominate someone to exercise them on your behalf.

Parents, students and staff: contact your school — they hold the account and can act immediately. Schools: contact us at akshaybasotra@gmail.com and we will help you fulfil a request, or act on your instructions, within the time the law allows.

Grievances may be addressed to Akshay Basotra at akshaybasotra@gmail.com, who is responsible for answering questions about how Lekhaa handles personal data.

11. Beta testing

While Lekhaa is in open/beta testing, please do not enter data you cannot afford to lose. Test environments may be reset, and features may change or be withdrawn without notice.

12. Changes to this policy

We will update this page when our practices change and revise the date at the top. Significant changes will be communicated to schools directly.