Security & privacy, plainly explained

This page describes what the system actually does — no invented certifications, just the real mechanisms behind how student data is handled.

Encrypted QR and NFC payloads

Every QR code and NFC tag carries an AES-256-CBC encrypted payload, not a plain student ID — reading one requires the app’s own decryption, not a generic QR reader.

Tags are checked, not just trusted

A tag read is validated against the physical hardware serial number registered to that student, not just the encrypted data stored on it — copying a tag’s payload onto a blank tag doesn’t pass the check.

Role-based, least-privilege access

Every action — starting a session, exporting a catalog, associating a tag — is gated by a specific permission on the logged-in account, so student data is visible only to staff who actually need it.

Anonymized exports

Attendance and roster exports can replace names with school-assigned student codes and shuffle the rows, for accounts granted that permission — so data can be shared without exposing identities.

Optional biometric app lock (native app)

On iOS and Android, the app can require Face ID, Touch ID, or a device fingerprint to reopen — useful if a phone is shared or left unattended. There’s no browser equivalent for the web app.

Marks are saved locally, then synced

Attendance is written to the device as you scan and only leaves it when you sync — a dropped connection can’t lose a class’s worth of marks.

Traffic goes through a secured API

Every scan and every sync goes over a secured connection to the backend API — the app never talks directly to a database.

Ready to simplify attendance?

Free to download, built for teachers, ready in minutes.

Or use the web app in your browser

Know a teacher who’d love this? Share it:

We use Google Analytics to understand how visitors use this site. We only turn it on if you agree. Learn more