Privacy Policy
Last updated: July 21, 2026
1. Introduction / Who We Are
The Warden ("we", "us", "our") is a hostel management app built and operated by Inspirante Technologies. This policy explains what data the Warden mobile app (Android and iOS) collects, how it's used, and who it's shared with.
Inspirante Technologies owns and operates this application and its underlying infrastructure. We collect and store user data solely to provide the hostel management service to the institution that this app is built for.
2. Who Uses This App (Users & Accounts)
The Warden is used by three kinds of people at this institution: students, parents, and hostel staff/wardens.
User accounts are created and managed by the institution's administration. Users cannot self-register within the app. Your account is provisioned by your hostel's administration (or, for parents, linked to your child's student record) as part of onboarding to the hostel this app is run by. There is no public sign-up.
Data isolation - Your data can only be accessed by your hostel's authorized staff, based on their role and permissions. It cannot be accessed by any other institution or organization.
3. Information We Collect
Account & profile information - name, email address, phone number, gender, role (student, parent, or staff), and, for students, academic details (branch, degree, year of study, admission batch) and room assignment. This is created by the hostel administration when your account is provisioned and can be updated by you or by staff.
Profile photo - students are asked to upload a profile photo (a picture of themselves), either chosen from their device's photo library or taken directly with the device's camera. It is used to identify residents within the hostel - for example, so staff can match a face to a room and student record. Each photo is reviewed and approved (or rejected) by your hostel's authorized staff before it is used, and can be replaced or removed by you or by staff. The image is resized and stored on our file storage; we do not run facial-recognition or biometric matching on it. Camera access is only used at the moment you choose to take a photo, and photo-library access is only used to let you pick an existing image - we do not browse or read your photo library otherwise.
Saving images to your device - where the app lets you download an image (for example, a notification attachment), you can choose to save it directly to your device's photo library. This uses a save-only permission - we can add photos to your library at your request, but cannot read or browse your existing photos through it.
Password - stored only as a one-way cryptographic hash. We cannot read or recover your actual password.
Family relationship data - a parent account is linked to their child's student record so that parents can view the same leave, attendance, and maintenance information as the student.
Requests you submit - content of leave applications and maintenance requests (description, category, dates, status, and any files you attach, such as a supporting document or photo picked from your device's file/document picker).
Attendance records - Attendance punch timestamps recorded by physical biometric scanners installed at the hostel premises. These scanners capture a fingerprint template on dedicated hardware operated by the hostel; the app only ever displays the resulting attendance timestamps and status to you - it does not capture, upload, or process fingerprint data itself.
On-device app lock (Face ID / fingerprint / passcode) - if you turn on biometric app-lock, your device's operating system verifies your face or fingerprint locally to unlock the app. This biometric data is processed entirely by your phone's operating system (Apple/Google), never leaves your device, and is never seen by us. We only store the encrypted login session on your device (in the OS-provided secure keychain/keystore) so it can be unlocked this way.
Push notification token - if you allow notifications, we store a device push token (issued by Apple/Google's push services) so we can send you alerts about your leave/maintenance status, attendance, and app updates. We do not use this token for advertising.
We do not collect your precise location, browse or read your photo library beyond a profile photo, attachment, or download you explicitly choose, contacts, or microphone/audio data.
4. How We Use Your Information
- Operate core features: leave requests, maintenance requests, attendance, room and profile information.
- Authenticate you and keep your session secure.
- Let staff/wardens review and act on student requests, as part of the hostel's normal administrative workflow.
- Let a linked parent view their child's leave, attendance, and maintenance status.
- Send notifications (in-app push, and email/SMS where applicable) about status changes on your own requests, and attendance.
- Enforce the hostel's rules and comply with legal or institutional recordkeeping obligations.
We do not use your data for advertising, and we do not build advertising or marketing profiles from it.
5. Data Storage and Security
All data is encrypted in transit using industry-standard HTTPS/TLS. Passwords are hashed (bcrypt) and never stored in plain text. Sessions use short-lived signed tokens; on mobile these tokens are stored using your device's secure keychain/keystore (Android Keystore / iOS Keychain), not in plain storage.
We apply role-based access controls so that only authorized staff can view student records, and only to the extent their role requires - for example, a warden in one block may not have the same visibility as an administrator.
6. Service Providers and Third Parties
We use third-party infrastructure and communication vendors solely to operate the app on our behalf, including database/hosting providers, file storage (for attachments and profile photos), and push-notification delivery (Apple Push Notification service / Firebase Cloud Messaging).
We use third-party SMS and email service providers solely to deliver notifications on our behalf. These providers process phone numbers and email addresses only to send messages you receive through the app, and are contractually/technically prohibited from using this data for their own purposes.
These providers only process data to the extent necessary to provide their service to us - they do not have independent rights to use your data.
8. Data Retention
We retain account and request data for as long as your account is active with your hostel, and for a reasonable period afterward to satisfy the institution's administrative and legal recordkeeping needs (for example, academic-year attendance records). When your hostel administration removes your account, associated personal data is deleted or anonymized within a reasonable period, except where retention is required by law.
9. Your Rights and Data Deletion
- Access or correction: contact your hostel administration, or email us, to review or correct your profile information.
- Notifications: you can disable push notifications at any time from your device's system settings.
- App lock: biometric app-lock is optional and can be turned off in the app's settings at any time.
As accounts are managed by the institution, users may request deletion of their account and data by contacting their hostel administration, who will process the request with us. Alternatively, to request deletion directly:
- ask your hostel's warden/administrator to remove your account from the system, or
- email inspirantech@gmail.com from the email address associated with your account, stating your name, role (student/parent/staff), and hostel, and we will forward the request to your institution and process deletion once confirmed.
Some records (e.g. attendance history required for academic or regulatory recordkeeping) may be retained by the institution as required by law even after your account is deleted, but will no longer be accessible to you or linked to an active app account.
10. Children's / Minors' Privacy
The Warden is provisioned by the hostel institution for its residents and, where relevant, their parents - it is not a consumer app aimed at children and has no public sign-up. Where a student user is a minor, their account is created and managed by the institution with parental/guardian involvement (via the parent account), consistent with the institution's own enrollment and consent processes. If you believe a child's data has been collected outside of this context, contact us using the details in Section 9 and we will address it.
11. Changes to This Policy
We may update this policy as the app changes. If we make material changes, we'll update the "Last updated" date above and, where appropriate, notify users in the app. Continued use of the app after an update means you accept the revised policy.
12. Contact Us
Questions about this policy or how your data is handled can be sent to inspirantech@gmail.com (Inspirante Technologies).