Legal
Privacy Policy
Last updated: July 15, 2026
1. Overview
This Privacy Policy explains how Ugdio (“we”, “us”) collects, uses, and shares information when you use our website and application (the “Service”).
Ugdio is built for extracurricular organizations. Organizations that use the Service are typically the data controllers for student and member data they upload. We act as a processor for that organization data, and as a controller for account and product analytics data.
2. Information we collect
Account information
- Name, email address, and authentication details
- Organization name and membership role
Organization content
- Group names and schedules
- Student names, emails, and group memberships
- Attendance records and related operational data you enter
- Files you upload for import (for example spreadsheets)
Usage and technical data
- IP address, browser type, device information
- Pages visited, approximate timestamps, and diagnostic logs
- Cookies or similar technologies needed for authentication and preferences
3. How we use information
- Provide, maintain, and secure the Service
- Authenticate users and manage organization workspaces
- Process imports, attendance, and other features you request
- Communicate about product updates, security notices, and support
- Monitor abuse, troubleshoot issues, and improve reliability
- Comply with legal obligations
4. Legal bases
Where GDPR or similar laws apply, we process personal data under one or more of these bases: performance of a contract, legitimate interests (such as securing and improving the Service), consent where required, and legal obligation.
5. Sharing
We do not sell personal data. We may share information with:
- Service providers that help us host, authenticate, email, or operate the Service
- Organization admins and members you invite into a workspace
- Authorities when required by law or to protect rights and safety
- Successor entities in a merger, acquisition, or asset transfer
Our current infrastructure may include providers such as Supabase for authentication and database hosting. Those providers process data under their own terms and safeguards.
6. International transfers
Data may be processed in countries other than yours. Where required, we use appropriate safeguards for cross-border transfers.
7. Retention
We retain account and organization data for as long as your workspace remains active and as needed to provide the Service. We may keep limited records after deletion for security, dispute resolution, backups, or legal compliance, then delete or anonymize them when no longer needed.
8. Security
We use industry-standard measures appropriate to the nature of the Service, including encryption in transit, access controls, and organization-scoped data isolation. No method of transmission or storage is completely secure.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing. Organization admins should handle most student-data requests for data they control. You can also contact us at the email below.
10. Children
The Service is intended for organizations and adult administrators. Organizations may store information about minors as part of running extracurricular programs. Those organizations are responsible for ensuring they have authority and any required parental or guardian consent to process that information.
11. Cookies
We use essential cookies and similar technologies for authentication, session management, and remembering preferences (for example the active organization). We do not use advertising trackers on the core application.
12. Changes
We may update this Privacy Policy from time to time. We will change the “Last updated” date and, when changes are material, provide additional notice when appropriate.
13. Contact
Privacy questions: privacy@ugdio.com