Legal

Privacy Policy

Last updated: July 15, 2026

1. Overview

This Privacy Policy explains how Ugdio (“we”, “us”) collects, uses, and shares information when you use our website and application (the “Service”).

Ugdio is built for extracurricular organizations. Organizations that use the Service are typically the data controllers for student and member data they upload. We act as a processor for that organization data, and as a controller for account and product analytics data.

2. Information we collect

Account information

  • Name, email address, and authentication details
  • Organization name and membership role

Organization content

  • Group names and schedules
  • Student names, emails, and group memberships
  • Attendance records and related operational data you enter
  • Files you upload for import (for example spreadsheets)

Usage and technical data

  • IP address, browser type, device information
  • Pages visited, approximate timestamps, and diagnostic logs
  • Cookies or similar technologies needed for authentication and preferences

3. How we use information

  • Provide, maintain, and secure the Service
  • Authenticate users and manage organization workspaces
  • Process imports, attendance, and other features you request
  • Communicate about product updates, security notices, and support
  • Monitor abuse, troubleshoot issues, and improve reliability
  • Comply with legal obligations

4. Legal bases

Where GDPR or similar laws apply, we process personal data under one or more of these bases: performance of a contract, legitimate interests (such as securing and improving the Service), consent where required, and legal obligation.

5. Sharing

We do not sell personal data. We may share information with:

  • Service providers that help us host, authenticate, email, or operate the Service
  • Organization admins and members you invite into a workspace
  • Authorities when required by law or to protect rights and safety
  • Successor entities in a merger, acquisition, or asset transfer

Our current infrastructure may include providers such as Supabase for authentication and database hosting. Those providers process data under their own terms and safeguards.

6. International transfers

Data may be processed in countries other than yours. Where required, we use appropriate safeguards for cross-border transfers.

7. Retention

We retain account and organization data for as long as your workspace remains active and as needed to provide the Service. We may keep limited records after deletion for security, dispute resolution, backups, or legal compliance, then delete or anonymize them when no longer needed.

8. Security

We use industry-standard measures appropriate to the nature of the Service, including encryption in transit, access controls, and organization-scoped data isolation. No method of transmission or storage is completely secure.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing. Organization admins should handle most student-data requests for data they control. You can also contact us at the email below.

10. Children

The Service is intended for organizations and adult administrators. Organizations may store information about minors as part of running extracurricular programs. Those organizations are responsible for ensuring they have authority and any required parental or guardian consent to process that information.

11. Cookies

We use essential cookies and similar technologies for authentication, session management, and remembering preferences (for example the active organization). We do not use advertising trackers on the core application.

12. Changes

We may update this Privacy Policy from time to time. We will change the “Last updated” date and, when changes are material, provide additional notice when appropriate.

13. Contact

Privacy questions: privacy@ugdio.com