NetCyberAI

Data Ownership & Security

NetCyberAI is designed so each school’s data stays isolated from every other school, enforced at the database level, and a school can export a full copy of its own records instead of being locked into the platform. As of Phase 0 no live database exists yet, so these are locked design commitments for the first release, not features running today.

Current status: Phase 0

Today, NetCyberAI operates only this public website. No school, student, or parent data is collected, stored, or processed by us yet — there is no live database, no login, and no messaging integration. The commitments below describe how the platform is designed to work once a school is actually onboarded, and each one is marked as such.

Consent, before anything else (DPDP)

Planned, Phase 1 design already locked in the schema: every student record is created in a quarantined pending_consent state, including bulk CSV imports of hundreds of students at once. No outbound message and no recognition scoring reaches a student until consent is recorded. Daily Pulse, Weekly Brief, and Recognition are each a separately consentable purpose, defaulting to off, independently withdrawable at any time — turning one off does not require turning the others off.

WhatsApp privacy

Permanent policy, not a configurable setting: every parent message is sent 1-on-1. WhatsApp Groups are never used for parent communication, because a group would expose every parent’s phone number to every other parent in that group — a privacy problem with no consent basis, and one we refuse to build regardless of how a school asks for it.

No third-party tracking on your data

No third-party analytics script, advertising pixel, or session-replay tool runs on any authenticated page where school or student data would be visible — this is a standing rule, not a Phase 1 promise. It already applies to this Phase 0 site: this website itself sets no third-party tracking cookies and loads no ad or analytics pixels.

Where your data lives

Planned commitment for Phase 1: the school database will be provisioned on Supabase in its Mumbai, India region (AWS ap-south-1), so operational school data is stored in India by default. Supabase’s own platform guarantees that all customer data is encrypted at rest with AES-256 and encrypted in transit via TLS — this is a default of the underlying infrastructure we would be provisioning, not a feature we would build ourselves, and it applies automatically once that project exists.

Source: Supabase’s security page. Checked 16 September 2026.

Every query scoped to your school

Locked architectural decision, already reflected in the schema design: every operational table carries a school identifier, and access is restricted using Postgres Row-Level Security — enforced by the database itself, not only by application code that a future bug could bypass. No table is exempt from this rule.

Exporting your data

Planned for Phase 1: a school will be able to request a full export of its own records in standard formats (CSV / SQL), not a proprietary format that locks you into the platform. This does not exist yet because there is no live database yet — we are not claiming an export button exists today.

If you leave

Planned for Phase 1: on offboarding, a school receives a full export of its data before deletion, and we intend to publish a specific retention and deletion timeline once that operational process actually exists, rather than promise a number now that nothing has tested.

Frequently asked questions

Can a school export all of its own data?

This is planned for Phase 1, not live today. Once a school’s data exists, it is intended to be exportable in standard formats — CSV or SQL — rather than a proprietary format, so a school is never locked into the platform.

Where is school data stored?

The Phase 1 database is planned to be provisioned on Supabase in its Mumbai, India region (AWS ap-south-1), so operational school data would be stored in India by default. No live database exists yet in Phase 0.

How is children’s data handled under the DPDP Act?

No student record becomes active without a verifiable consent record from a parent or guardian. A bulk import creates records in a pending-consent state rather than an active one, and each communication type — Daily Pulse, recognition, Weekly Brief — is separately consentable and defaults to off until specifically granted.

What happens to our data if we leave?

This is planned for Phase 1: on offboarding, a school is intended to receive a full export of its data before deletion, with a specific retention and deletion timeline published once that operational process actually exists and has been tested.

Does NetCyberAI use third-party analytics?

No third-party analytics script, advertising pixel, or session-replay tool runs on any authenticated page where school or student data would be visible. This Phase 0 public website itself also sets no third-party tracking cookies.

Have a specific question?

Ask us directly on WhatsApp, or write to admin@netcyberai.com.