Privacy Policy
Last updated 29 July 2026
Who we are
NGALMS is a learning management system supplied to educational institutions. Each institution has its own isolated space on the platform, reached at its own web address.
Your college decides what data is held about you and why; NGALMS processes that data on the college's instructions. If you are a student or a member of staff, please contact your institution first about anything relating to your records.
What we collect
- Account details — your name, role, and the email address or phone number used to sign in. These are supplied by your institution when your account is created.
- Institutional profile details — where your institution chooses to record them, a student or staff profile may also hold a date of birth, gender, postal address, admission number and date, blood group, category or quota, professional qualifications, and parent, guardian or emergency contact names and phone numbers. These fields are optional, are entered by your institution rather than by you, and exist because colleges need them for enrolment, examinations and emergencies. Blood group is health information, and category or quota can reveal ethnic or community background — both are treated as sensitive, are visible only to your own institution's staff, and are never used for anything beyond the administrative purpose your institution collected them for.
- Academic records — enrolments, attendance, assignments and submissions, grades, quiz attempts, timetable entries and any notes or documents your institution stores about your studies.
- Messages and things you write — announcements and notifications sent to you, notifications staff send to students, complaints and their responses, and teacher notes. Anonymous complaints never store your identity in the first place.
- Files you upload — assignment submissions, profile pictures and course materials.
- A device identifier for notifications — if you use the Android app and allow notifications, we store the push token issued to that device so we can deliver alerts about assignments, grades and announcements. It is tied to your account and deleted when you sign out or turn notifications off.
- Operational records — sign-in events and an audit log of administrative actions, kept so institutions can investigate mistakes and misuse.
We do not collect location data, contacts, photos beyond what you deliberately upload, or advertising identifiers. There is no advertising in NGALMS, and we do not sell personal data or share it with data brokers.
How we use it
Solely to run the service for your institution: showing you your courses, recording attendance and grades, delivering announcements and notifications, keeping accounts secure, and diagnosing faults. We do not profile you for marketing.
Notifications
Push notifications are optional. Android asks for your permission before any are sent, and you can withdraw it at any time in your device settings — no other part of the app is affected. Institutions can also switch notifications off entirely.
Who else sees it
Staff at your own institution, according to their role. Data is never shared between institutions — every record is isolated to the college it belongs to, and that separation is enforced by the database itself.
We use a small number of service providers to operate the platform: cloud hosting and a managed database, object storage for uploaded files, an email delivery provider, and Google Firebase Cloud Messaging to deliver push notifications. They process data only to provide those services to us.
How long we keep it
Academic records — enrolments, attendance, assignments, grades — for as long as your institution maintains its account with us, in line with its own record-retention obligations. Institutions can correct or delete these at any time.
Operational logs are deleted automatically on a schedule. Sign-in records, which include the IP address a sign-in came from, are kept for 180 days. Administrative action logs are kept for 2 years. AI-generated student reports are kept for one academic year, and can be regenerated at any time.
Uploaded files are deleted from our storage when the record they belong to is deleted. Push notification tokens are removed as soon as you sign out.
Security
Passwords are hashed and never stored in readable form. Traffic is encrypted in transit. Access is restricted by role, and each institution's data is separated at the database level so one college can never read another's.
Your choices
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Because your institution controls its own records, please raise these requests with your college administrator, who can act on them directly or ask us to help.
For deletion specifically, the full process — what you can remove yourself, what to send us, what is erased and what has to be kept — is set out on Account & Data Deletion.
Children
NGALMS is supplied to institutions for their enrolled students and staff. It is not directed at children, and accounts are created by institutions rather than through public sign-up.
Changes
If this policy changes materially we will update the date above and, where the change affects how data is used, tell institutions directly.
Contact
Questions about this policy can be sent to privacy@ngalms.com. If you are a student or member of staff, your institution's administrator is usually the fastest route.