Policy
Privacy Policy
Effective 25 September 2026 · Teachbricks Private Limited
lib/legal/config.ts and reviewed by a qualified Indian lawyer before launch. Onboarding asks members to accept it.This notice explains what personal data Parentz collects, why, and what you can do about it. It is issued under the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1.Who is responsible
Teachbricks Private Limited, registered office Plot No. 177, GRR Domain, TNGO’s Colony, Gachibowli, Hyderabad 500032, Telangana, India, is the Data Fiduciary for personal data processed through Parentz. You are the Data Principal.
2.What we collect, and why
- Your Google account email and name, when you sign in. Purpose: to create and authenticate your account. Your email is never shown publicly.
- Username, display name and bio, which you choose. Purpose: to attribute what you post. These are public.
- What you post — discussions, comments, votes. Purpose: to operate the community. Discussions and comments are public and indexed by search engines.
- Private messages you send to other members, and whether you accept messages. Purpose: to deliver them to the person you wrote to. A message is visible to the two people in the conversation, and to a moderator only if one of them reports it. Message text is never sent to an analytics or email provider — a notification email says only who wrote to you.
- Verification requests, if you ask to be a verified parent: the statement you write and, optionally, one image or PDF you attach as evidence, such as a school ID card. Purpose: for a moderator to decide the request. Only moderators can open the file, it is never shown to other members, and it is deleted the moment the request is decided. The statement and the decision, with its reason, are kept with your account.
- Technical logs — request metadata and error reports. Purpose: to keep the service working and secure.
- Usage analytics — which pages you view, which searches you run (the number of characters and results, never the words), and which actions you take such as posting, commenting or voting. Purpose: to understand how the community is used and what to improve. We do not record the text of your searches or the content of your posts into any analytics system.
We do not collect financial information, government identifiers, biometric data, or health records. Please do not put them in a post.
3.Our lawful basis
We process your data on the basis of the consent you give when you create an account and accept these policies, and for the legitimate uses permitted by section 7 of the DPDP Act — including complying with a legal obligation and responding to a lawful order.
You may withdraw consent at any time by deleting your account. Withdrawal does not affect processing already carried out, and section 6 below explains what happens to content you posted.
4.Children
Parentz is for adults aged 18 and over. We do not knowingly collect the personal data of a child as defined by the DPDP Act, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has created an account, tell our Grievance Officer and we will delete it.
5.Who we share it with
We do not sell your personal data. We share it only with:
- Supabase — database, authentication and storage.
- Vercel — application hosting and delivery.
- Google — only to authenticate your sign-in.
- PostHog — product analytics. Receives the events described in section 2 against a pseudonymous identifier, never your email address or your content.
- Sentry — error monitoring. Receives technical error reports. Cookies, authorisation headers, request bodies and query values are removed before they are sent.
- Resend — email delivery. Receives your email address and the text of a notification (who replied, and the title of the discussion) only when we email you about a reply or a moderation decision. You can turn these emails off in Settings or with the one-click link in every email; nothing else we send goes through it.
- A court or government agency, where we are lawfully required to.
These providers process data on our instructions. Some of them operate infrastructure outside India; we rely on their contractual and technical safeguards, and on the transfer provisions of section 16 of the DPDP Act.
6.How long we keep it
- Your account data, including private messages: for as long as the account exists.
- After you delete your account: registration information is retained for 180 days, as Rule 3(1)(g) of the IT Rules, 2021 requires, then deleted.
- Content you posted: discussions and comments remain published. Your name stays on them for as long as the account can still be restored, and is removed when the account is erased at the end of that period. Deleting an individual discussion works differently and is explained in section 5 of the Terms of Use — read it before posting anything sensitive in a discussion body.
- Evidence attached to a verification request: until the request is decided, then deleted at once. The request itself and its outcome stay with your account.
- Logs: retained for a limited operational period and then discarded.
7.Your rights
Under the DPDP Act you have the right to:
- obtain a summary of the personal data we process about you, and of our processing activities;
- have inaccurate or incomplete data corrected, completed or updated;
- have your personal data erased, subject to the retention periods above and to any legal requirement to keep it;
- nominate another individual to exercise these rights on your behalf in the event of your death or incapacity;
- a readily available means of grievance redressal.
To exercise any of these, write to support@turtil.co.
8.Security
Access to data is enforced in the database itself through row-level security, not only in the application, so a member can read and change only their own records. Passwords are never stored — sign-in is delegated to Google. Traffic is encrypted in transit. No system is perfectly secure, and we will notify you and the Data Protection Board of a personal data breach as section 8(6) of the DPDP Act requires.
9.Cookies
We use a session cookie to keep you signed in. It is required for the service to function. We also store an analytics identifier — in a cookie and in your browser’s local storage — so that repeat visits can be counted as one person rather than many; it holds a random value, not your name or email. We do not use advertising or cross-site tracking cookies, and we do not share this identifier with advertisers. Public pages are readable without signing in.
10.Grievances
Concerns or complaints about your data go to Support Team, Grievance Officer, support@turtil.co. We acknowledge within 24 hours and respond within 15 days.
If you are not satisfied, you may complain to the Data Protection Board of India under the DPDP Act, 2023.