Privacy Policy
Distil EDU is a grading tool used by teaching staff. This page sets out what it stores about staff, students and parents, which other companies see that information, and how long it is kept.
In effect from 9 September 2026.
1. Who is responsible for your data
Distil EDU is operated by Youssef Mohamed Hamdy, based in Sheikh Zayed, Giza, Egypt.
The school, college or tutor using Distil EDU decides which students are entered and why, and is the data controller for that educational information. The operator processes it to provide the service on their instructions. The operator is separately responsible for the staff-account, security and operational processing it determines. These responsibilities depend on the actual relationship and applicable law; a school's separate data-processing agreement may set out further instructions and safeguards.
If you are a parent or a student and want to know what is held about you, ask the school or the teacher who marks your work first - they can see and change it directly. Questions about the platform itself go to privacy@distiledu.com.
2. What is stored about staff
An account is created by an administrator, or by a teacher for their own assistant. There is no public sign-up. It holds:
- the name and email address the account was created with, and an optional title such as “Dr”, used for teacher attribution on exported documents;
- a one-way hash of the password rather than a stored readable password; password-reset token hashes and expiry times;
- the roles held: administrator, teacher, both, or assistant; and, for an assistant, which teacher they work for;
- whether the account is active or paused, and which administrator paused it and when;
- interface preferences: the chosen colour theme, and which columns that person wants on an exported sheet.
- any short-lived messages sent to or from that account through the in-app staff messaging feature, including the text of the message and the sender’s name and email address. These delete themselves - see the retention section below.
If a member of staff connects a Google account, Distil EDU also stores that account's Google identifier and email address, the permissions granted, and the access tokens themselves encrypted. Those tokens are what allow the platform to read a class roster or return a mark on that person's behalf. Revoking Google access stops future authorised API use; removal of the stored connection is a separate request to the operator.
Activity records may include staff identifiers, email and roles, the action and time, record identifiers and labels, action details, and the request IP address and browser user-agent where available. These support security, troubleshooting and accountability.
3. What is stored about students and parents
Students do not have accounts and never sign in. Their records are created by their teacher, or imported from a linked Google Classroom course:
- the student's name, the name last reported by Google and whether staff corrected it, an internal reference code, and class membership;
- their Google Classroom identifier, where the class is linked to a course;
- marks, grades, absences, and whether each piece of work was handed in, handed in late, or not handed in;
- up to two parent or guardian contacts per student - a name and a phone number - and whether that family has been opted out of automated messages;
- a student email address, only where the teacher or Google Classroom supplied one.
The current forms do not collect parent email addresses.Messages home use WhatsApp or printed reports. Older installations may contain legacy fields until the operator removes them; removing a field from a form does not itself erase older records.
Submission records can include local staff notes, draft and assigned marks, return times, Google submission identifiers and states, hand-in timestamps and manual overrides. Local notes are not sent to Classroom or included in parent messages by the platform.
Class records include the subject, school and teacher attribution, optional crest, assessment instructions, components, deadlines, attachment references, grading boundaries and report settings. Student work can be fetched from Classroom and opened in Google Drive's preview. Files selected or uploaded through Google Picker are handled by Google; the platform uses their identifiers and links for attachments. The same student may have separate records in several classes.
A teacher may also save Google Meet or Zoom join links, a WhatsApp group invite link, and the next class title, time and duration. These details are available to the teacher and their assistants. Opening a link takes you to that provider. Copying an invitation or downloading a calendar event includes the meeting link; it does not automatically notify students. WhatsApp group members may see one another's phone numbers. Replacing a saved link here does not revoke the old invitation at its provider.
4. Messages to parents
Parent alerts require a staff action. The platform proposes a list, a member of staff reviews it on a confirmation screen and can remove anybody from it, and only then is anything sent.
There are two routes, and they differ in who handles the message:
- By hand. The platform opens a WhatsApp chat on the teacher's own device with the text prepared. The message travels through the teacher's own WhatsApp account, and Distil EDU sends nothing itself.
- Automatically. Where the school has configured it, the parent's phone number and the message are sent to Meta's WhatsApp Business service for delivery.
Alert records include the student and class, reasons and occurrence counts, recipient phone numbers, message body, sending staff member, time, route, and any provider message identifier or error. API acceptance and a staff-confirmed manual send are recorded differently; neither proves that a parent read the message. Failed attempts may also be recorded. Successful records help suppress repeated alerts about the same recorded circumstances.
A printable student report can also be shared as prepared WhatsApp text. This separate sharing route does not create the same alert-history record. When API messaging is unconfigured, a dry run sends nothing and may write the proposed phone number and message to server logs.
6. Google permissions and disconnecting
Google sign-in opens a pre-existing staff account. With the permissions you grant, the integration can discover or create courses, read rosters and student work, manage coursework, topics, announcements and materials, and return grades. Syncs can run when signing in, opening a class or exporting, as well as when you press a sync button.
The current connection requests full Google Drive access, not access limited to files created by this app. That permission can allow reading, creating, editing and deleting Drive files. The product uses Drive for attachment selection and upload, submission previews, and creating or replacing the live grade sheet. Google Picker receives a short-lived access token in your browser to perform its work.
Distil EDU's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google data is not used for advertising, sold, or used to train general-purpose AI models.
Revoke access through your Google account connections. The current app does not offer a disconnect-and-delete control in Settings. Contact the operator to request removal of stored credentials; deleting the staff account also removes its stored Google connection. Revoking access does not erase stored credentials or previously imported records, uploaded files, returned marks or existing Classroom posts.
7. The shared grade sheet, and what a class can see
Update Live Sheet can share class-wide results. It uploads the selected grade workbook to the teacher's Drive and, for a linked course with the required Google permissions, also creates or reuses a published Grades material in Classroom. Included student names, marks and hand-in information are then visible to the course. This is a class sheet, not a private result page for each student.
The sheet follows saved export choices and student exclusions, and later updates overwrite the contents at the same link. Without a linked course, the new sheet is created in the teacher's Drive without the Classroom post. Existing sharing permissions on a reused file still matter. A downloaded workbook or CSV can also contain a whole class; student reports contain one student's results and class comparisons.
Publishing to Classroom can happen within the sheet-update action, without a separate publication step. Staff must check the audience and have authority to disclose the included information. Removing the post alone should not be treated as revoking file access: review Drive sharing too. Unlinking or deleting the local class does not remove the external sheet or recall copies already downloaded or messages already received.
8. How long it is kept
- Class and student records have no automatic term-end expiry. Deleting a class removes its students, assessments, their marks, their hand-in records, and the record of any messages sent about them.
- The grade history - who changed which mark, and when, including saved score snapshots, absence flags, identifiers and staff email - has no automatic expiry and is retained after a student, assessment or class is deleted.
- Routine activity records, such as a sheet being exported or a roster synced, are scheduled to expire after 30 days. Database cleanup may occur shortly after that threshold.
- Security-relevant records - a password changed, an account created or paused, messages sent to parents - are kept without automatic expiry. These can retain staff email, record labels, action details and request information after the original record is removed.
- Staff messages sent through the in-app messaging feature are deleted automatically: 24 hours after the recipient first opens one, or 30 days after it was sent if it is never opened, whichever comes first. The recipient can also delete one immediately. Nothing about the message - not its text, not who sent it, not that it existed - is written to the activity record, so once it expires there is no copy of it in the platform. Messages can only be sent between staff who share a workspace, or to and from an administrator.
- Password reset links are stored only as a hash, expire automatically, and can be used once.
Deleting an individual student removes their active marks and submissions but does not itself delete their past parent-alert records. Class deletion removes those alert records. Removing a staff account removes its stored Google connection, but does not erase historical logs. Pausing an account preserves its data. Deleting local data does not delete Google or WhatsApp records, downloaded exports or printed reports.
The application has no self-service erasure control for retained audit records. Requests concerning those records require the operator's review under applicable law; the software's lack of expiry does not override legal rights or justify indefinite retention in every case. Provider logs and any backups follow their configured retention schedules; local deletion does not guarantee immediate removal from those systems.
9. How it is protected
- Passwords are hashed with bcrypt. Google tokens are encrypted with AES-256-GCM.
- A teacher can only load their own classes, and an assistant sees exactly the classes of the teacher they work for. That is enforced on the server for every request, rather than only hidden in the interface.
- Deleting or pausing an account takes effect on that person's next protected request. It cannot remove data already displayed, downloaded or shared outside the platform.
- Sign-in attempts and password-reset requests are rate limited, and the sign-in form gives the same answer for an unknown email as for a wrong password - so it cannot be used to find out who has an account.
- Grade-save and activity histories support accountability for changes.
No system is perfectly secure. If you believe an account has been misused, contact privacy@distiledu.com and ask an administrator to pause it. Pausing blocks further protected requests and is reversible.
10. Children’s information
Distil EDU holds information about school-age children, entered by their teachers. Children do not have accounts, are never asked for information directly, and are not advertised to.
The platform analyses marks and hand-in records to calculate T-scores, quartiles and grades, and to flag low attainment, missing work or absences against configured thresholds. These flags help staff decide what to review and whom to contact. They are not a diagnosis or an independent decision about a child: staff review results and authorise parent alerts. Students and parents can ask their teacher to explain or correct the underlying records and resulting assessment.
The lawful basis for holding a child's marks and a parent's phone number, and any consent needed before contacting a family, is the school's responsibility for its processing. The operator remains responsible for its own obligations. Applicable requirements for children's data and parental or guardian consent must be met before information is entered or shared. A student's alert opt-out stays set until staff change it; separate report sharing still requires staff to honour the family's communication preferences.
11. Your rights
Subject to applicable law, you can request access to or a copy of your information, correction or deletion, and object to or seek restrictions on processing. Where processing relies on consent, you may withdraw it for future processing. Rights and lawful retention exceptions depend on the circumstances; agreeing to the Terms does not waive these rights.
For educational records, contact the school or teacher first, or email privacy@distiledu.com so the request can be directed to the responsible party. Staff-account and platform requests go to that email directly. We may need proportionate identity or guardian-authority verification before releasing information. An ordinary grade export is not a complete copy of all personal data; retained logs and alert history can require the operator's assistance.
You may also raise a concern with Egypt's Personal Data Protection Center or another competent authority where applicable. Egypt's Personal Data Protection Law No. 151 of 2020 and its Executive Regulations No. 816 of 2025 provide the local data-protection framework.
13. Processing outside Egypt
The operator is based in Egypt. Hosting, database, email, Google and WhatsApp services may process information in other countries, depending on deployment settings and provider operations. This service does not promise that information remains in Egypt. Contact the operator for the locations and safeguards applicable to your deployment.
Any required transfer safeguards, permissions and consents must be in place before personal information is transferred. This notice is not evidence of a regulatory licence or transfer approval and does not replace a required agreement with a school.
14. Changes to this policy
If what Distil EDU stores, or who it is shared with, changes, this page changes with it and the date at the top is updated. Where a change materially affects students or parents, the schools using the platform will be told directly rather than left to notice.