BeeSync

Privacy Policy

Effective 26 August 2026 · Applies to the BeeSync mobile app and the BeeSync school portal.

BeeSync is school software. Almost everything in it — a child's grades, their attendance, a message to a teacher — belongs to the school that entered it, not to us. This page explains what the software stores, who can see it, and what happens when you want it gone.

Who we are

BeeSync is operated by Adnan Fares, a sole trader based in Lebanon. For anything on this page, write to support@beesync.app.

Who controls the data

Each school decides what to record about its students and staff, who may see it, and how long to keep it. In data-protection terms the school is the controller and BeeSync is the processor: we hold and transmit the data on the school's instructions and do not decide what goes in.

This matters for you as a parent or teacher: if you want a record corrected or removed, your school can usually do it immediately, and it is the faster route. We will always act on a request sent to us, but for content the school entered we may need to confirm with them first.

What BeeSync stores

Set out honestly, because a vague version of this table would not be worth reading.

CategoryWhat it includesWhere it comes from
Account Name, email address or BeeSync username, role at each school, language preference, profile photo, account status. Passwords are stored only as salted hashes and are never visible to us or to your school. Created by a school administrator; you can edit your own name, photo and language.
Student record Name, date of birth, gender, home address, home language, number of siblings, school start date, class, photo, weekly schedule, and guardian contact details. Entered by school staff.
Health and dietary information Allergies, intolerances, dietary requirements, illnesses, general health notes, and a doctor's name and contact number. Entered by school staff, usually from what a parent tells the school at enrolment.
Attendance Daily present/absent records, absence reports filed by parents, and planned early checkouts. Staff record attendance; parents file absences and checkout plans.
Academic Grades, term grades, generated report cards, homework, and class materials. Entered by teachers and administrators.
Communication Direct messages between parents and staff, school news posts, notices, survey responses, and short daily notes parents send to the class team. Written by whoever sends them.
Payments Records of school fees due and paid, and who recorded each payment. BeeSync does not process payments and never sees a card or bank number. Entered by school administrators.
Technical A push-notification token per device and whether it is iOS or Android, so alerts reach the right phone. Plus ordinary server logs (timestamps, error records) kept for a short period to keep the service running. Generated automatically.

BeeSync contains no advertising, no analytics SDKs and no third-party trackers. We do not build advertising profiles, we do not sell data, and we do not share it with anyone except the service providers listed below.

Children's information

BeeSync is used by adults — parents, teachers and school administrators. Children do not have their own accounts and are not asked to provide anything directly.

Information about a child is entered by their school under the school's own enrolment agreement with the family. If you are a parent and want to know exactly what your child's school has recorded, ask the school; every field is visible to them, and most of it is visible to you in the app.

Health and dietary information is treated as the most sensitive category in the system. It is visible only to staff at the child's own school and to that child's linked guardians. It is never used for anything but the care of that child.

Who can see what

Access is enforced by the database itself, on every single request, rather than by the app screens. In practice:

We do not browse school data. A small number of operational actions — restoring a backup, diagnosing a fault a school has reported — require technical access to the database, and we limit those to what the task needs.

Service providers

BeeSync runs on infrastructure we do not own. These providers process data strictly on our instructions:

ProviderWhat it doesWhat it sees
SupabaseDatabase, file storage, sign-inAll stored data, encrypted at rest and in transit
CloudflareServes this website and the school portalOrdinary web request data
ExpoDelivers push notifications to phonesThe notification's title and short body, and the device token
Apple, GoogleDistribute the mobile app; deliver notifications to the deviceStandard app-store and push-delivery data
Email providerSends password resets and notification emailsRecipient address and message content

Data may be stored on servers outside Lebanon, because these providers operate globally.

How long data is kept

If a school closes its account, its data is deleted on the timetable set out in the Terms.

Your rights

Lebanon has no single comprehensive data-protection statute, so we have written these commitments into the product rather than relying on one. Whoever you are, you may:

Write to support@beesync.app. We aim to reply within 30 days. Where the request concerns records a school entered, we will coordinate with the school and tell you that we have.

Security

Data is encrypted in transit and at rest. Access rules are enforced in the database on every request, not in the app, so a bug in a screen cannot expose another school's records. Accounts are protected by passwords that we never see in readable form. Backups are taken daily.

No system is perfect. If we discover a breach affecting your data, we will notify the affected schools promptly and tell them what happened, what was affected, and what we are doing about it.

Changes to this policy

If we change something that materially affects how data is handled, we will update the date at the top of this page and notify schools through the portal before the change takes effect.

Contact

Write to support@beesync.app for anything on this page — privacy requests, corrections, or deletion.