Security & Privacy Overview
Effective September 6, 2026
This page is written for center owners, not for engineers. It describes, in plain English, how SamayIQ protects your center's information — and what it does not claim.
Your center's information stays with your center
Every student, guardian, schedule, attendance record, book loan, staff record, and setting in SamayIQ belongs to one specific center. Every request the application handles is checked against the signed-in account and limited to that account's own center, on the server, before any record is read or written — not merely hidden in the interface. Other centers cannot access your center's records through SamayIQ, and you cannot access theirs.
Controlled staff access
Access requires a real account and a current sign-in session. The owner invites staff and assigns each one a role, and roles carry permissions — so a staff account only reaches the parts of SamayIQ your center has allowed it to reach. When someone leaves, the owner deactivates their account and their access ends. On the kiosk, student check-in is open by design, while the staff-only and books modes are protected by a PIN your center sets.
Passwords and sign-in
Passwords are stored only as one-way hashes (bcrypt), never as readable text, so nobody — including us — can read a center's password out of the database. Sign-in attempts are rate-limited, password-reset and email-verification links are single-use and expire, and sessions are carried in cookies that browser scripts cannot read.
Encrypted connections
SamayIQ is served over HTTPS, and its connections to the database, the file storage, the email service, and the payment processor are encrypted in transit. The application also sends standard browser security headers on every response.
Private storage for sensitive files
Guardian ID photos are uploaded into private storage that is not publicly reachable — there is no shareable public URL for them. When an authorized staff member at your center views one, SamayIQ generates a short-lived access link that expires. Guessing a file's location is not enough to open it.
Audit records for sensitive actions
SamayIQ records security-relevant events — sign-in successes and failures, password resets, staff role changes, invitations, and staff deactivation — with the account involved and the originating IP address, so an unexpected change can be traced back.
Payments
Subscription payments are handled by Stripe. Card details are entered on Stripe's own pages and are processed by Stripe; SamayIQ never receives or stores card numbers. Messages Stripe sends back to SamayIQ are cryptographically verified before they are acted on.
Hosting and backups
Your center's records are stored in a PostgreSQL database hosted on Supabase, and the application runs on Vercel. We rely on those providers' managed infrastructure, including their database backups, rather than operating our own servers. Uploaded files live in Supabase's private storage.
What we do not do with your data
- We do not sell personal information.
- We do not use student, guardian, or attendance information for advertising.
- We do not share your center's records with other centers.
Like any software operator, we have the technical ability to access data on our servers when it is needed to run, maintain, and support SamayIQ — for example, to investigate a problem you report. That access exists to operate the service, nothing more. Our Privacy Policy covers what is collected and how to have it removed.
What we do not claim
No system can guarantee against every risk, and we will not pretend otherwise. SamayIQ holds no security certifications — we are not SOC 2 certified, and we make no HIPAA, FERPA, or COPPA certification claim. We have not published a third-party penetration test. The protections above describe how the software is actually built today; they are not a promise that nothing can ever go wrong.
If you believe you have found a security problem in SamayIQ, please email support.samayiq@gmail.com and describe it. We would much rather hear about it.
Technical security details are available upon request.
If your center needs more specifics before signing up — how center separation is enforced, how uploads are handled, which providers touch which data — email support.samayiq@gmail.com and we will walk through it.