Cyfamod-SMS Apps Privacy Policy
Cyfamod-SMS Apps Privacy Policy
Last updated: 1 August 2026
This policy applies only to the Cyfamod-SMS Staff and Cyfamod-SMS Student mobile apps (together, the “SMS Apps”). It does not describe the data practices of Cyfamod’s other products or the general Cyfamod website.
1. What the mobile apps do
Cyfamod-SMS Staff helps authorised school staff access school, class, student and results information. Cyfamod-SMS Student lets a learner sign in with school-provided credentials to view their school information, complete permitted bio-data, view results and download a result slip. The SMS Apps do not offer public account registration: accounts and learner admission details are created and managed by the relevant school.
2. Information used by Cyfamod-SMS Staff
Cyfamod-SMS Staff uses staff account and profile information, including name, email address, phone number, role, address and, where held by the school, gender, qualifications and employment information. It also gives authorised staff access to student and guardian information needed for school administration, including names, contact details, admission number, class details, profile photographs, attendance, academic results, skill or behaviour ratings, and teacher comments.
Where a school has recorded it, authorised staff may also see student blood-group or medical-information fields. This information is used only for the school-management functions available to authorised users.
3. Information used by Cyfamod-SMS Student
Cyfamod-SMS Student uses the learner’s admission number and password to sign in. It displays and, where permitted, sends updates to profile and bio-data, including name, address, profile photograph, date of birth, gender, nationality, state or local-government-area of origin, and blood group. It may display linked parent or guardian names, phone numbers and email addresses, as well as school, class, subject, session, term and academic-result information.
4. How information is used and shared
We use this information to authenticate users, provide the requested school-management features, maintain authorised school records, display results and result slips, and support the security and operation of the SMS Apps. Information is available to the relevant school and authorised users according to their roles and permissions. We do not sell this information or use it for advertising, and the SMS Apps do not contain advertising.
5. What the apps do not currently use
The current SMS Apps do not use precise or approximate location, contacts, microphone, SMS or call-log data, payment information, advertising identifiers or advertising SDKs.
6. Crash reports and diagnostic data
To keep the SMS Apps stable and to fix faults quickly, released versions send automated crash reports and error diagnostics to our diagnostics provider. This applies only to published preview and production builds; it is switched off during development, and the information is used solely to identify and correct faults.
A diagnostic report may include the error message and its type, the technical stack trace showing where in the app the fault occurred, the screen in use at the time, the device model, the operating system version, the app version and build number, which of the two apps reported the fault, and a short trail of the screens opened and controls tapped immediately beforehand. Record identifiers — such as admission numbers or internal record references — are removed on the device before a report is sent, so a report shows which kind of screen or request failed without identifying the learner involved.
A sample of app sessions, together with sessions in which an error occurs, also record a masked reconstruction of the screens involved so that a fault can be understood in context. All text and all images are masked on the device before a recording is sent, so passwords, PINs, names, results and any other on-screen content are replaced with placeholder blocks and only the layout remains visible.
We do not attach IP addresses, request contents, names, email addresses or passwords to diagnostic reports, and diagnostic data is never used for advertising, profiling or tracking across other apps or websites. Ordinary connectivity problems — for example a device losing its internet connection — are shown to the user in the app and are not reported to us.
Diagnostic data is processed on our behalf by Sentry (Functional Software, Inc.) and is stored on infrastructure located in the European Union. Sentry’s privacy notice is available at sentry.io/privacy.
7. Security and retention
Access is controlled through school-provided credentials and role-based permissions. The SMS Apps store the access token in secure device storage. School records are retained according to the relevant school’s instructions and any applicable operational, legal, security or record-keeping requirements. Crash reports and diagnostic data are retained only for as long as they remain useful for diagnosing faults, subject to our diagnostics provider’s retention limits, after which they are deleted.
8. Schools, learners and privacy questions
Schools are responsible for the information they enter, the people they authorise to use the SMS Apps, and any permissions required for learner information. If you need a school record corrected, accessed or removed, please contact the relevant school first. The current SMS Apps do not provide self-service account deletion.
For questions about this policy, email privacy@cyfamod.com. Please include the school or service involved and enough detail for us to understand your question. We may need to verify identity and work with the relevant school before responding to school-record requests.
9. Changes to this policy
We may update this policy when the SMS Apps or their data practices change. The updated policy will be published at this address with a revised “Last updated” date.

