Legal

Acceptable Use Policy

Version 1.0 ·Updated 2026-08-31

Next reviewed by 2027-02-28.

Written for everyone with a Kestrel account, and the school that gave them one.

Who this is for

This policy is for everyone who signs in to Kestrel. Every Kestrel account belongs to a member of staff at a school, so if you have an account, this is written to you.

Your school gave you the account and your school sets what your role lets you do. This policy sits underneath that: it is the floor, and your school's own rules can sit above it but never below. It is published as part of the Terms of Service between your school and Seraco Pty Ltd.

The rule everything else follows from

Open a student's record because your work requires it, and for no other reason. Being able to reach a record is not a reason to read it.

A school information system holds the enrolment, the family circumstances, the health notes and sometimes the child-protection history of children. Most of the harm ever done with one was done by somebody who was allowed to be in the system and had no business in that particular file. Access is not permission.

What you must not do

Opening a record you have no work reason to open
A neighbour's child, a colleague's child, a family in the news, your own child's classmate. Curiosity is the most common misuse of a student record and the easiest to talk yourself into. The record does not become yours to read because you can reach it.
Sharing your account, or signing in for somebody else
Register a passkey on a device only you use. Do not hand your account to a relief teacher, an administrator or a contractor, and do not stay signed in on a machine you are walking away from.
Taking records out for a purpose the school has not authorised
Copying, screenshotting, printing or pasting a student's information into another system, a personal device, a personal email account or a message to somebody outside the school. The school decides what may leave and where it may go.
Trying to reach another school's records
Each school's records are in their own database schema and PostgreSQL refuses the crossing, so an attempt fails. Making the attempt is still a breach of this policy, and every attempt is recorded.
Probing, scanning or attacking the service
Automated scanning, load testing, attempts to bypass the sign-in, attempts to reach the database, or anything designed to degrade the service for other schools. Reporting a vulnerability you found is a different thing, and the section below says how.
Using the record to harass, intimidate or profile anyone
Including a colleague, a parent, a student or a former student. A student information system is a register of children, and it is not a tool for settling anything.

Screens other people can see

A school office screen faces a counter, and a staffroom machine is shared. Lock the screen before you leave it and sign out at the end of the day. If you are showing something on a projector or sharing a screen in a meeting, open only the record the meeting is about.

Sign-in is by passkey, so the credential is on your device and there is no password for anyone to look over your shoulder and read. A signed-in session left open on a shared machine gets around all of that.

Telling somebody when something is wrong

If you see a record you should not be able to see, tell your school first. The school holds the relationship with that family and is the organisation that has to act. Do not keep looking to work out how far the problem goes.

If you have found a security flaw in Kestrel itself, write to security@seraco.io with enough detail to reproduce it. Reporting a flaw in good faith is not a breach of this policy, and we will not treat it as one. Confirming a flaw is real by reading somebody's records is a breach, so stop at the point you know.

What happens if this policy is broken

Your school decides what happens to you. It is your employer, it holds the relationship with the families on the record, and the consequence for a member of staff is its call rather than ours.

What we do is narrower. We can suspend an account, and we tell the school the same day and say why. We do that where an account is being used in a way this policy forbids, or where an account looks to be in somebody else's hands. The Terms of Service sets out how a suspension works.

Some misuse of a student record is also a criminal offence or a notifiable data breach. In that case the school has obligations to the family and to a regulator, and we give the school what it needs to meet them.

Changes to this policy

The version and the date at the top of this page tell you which edition you are reading. We write to every school before a change to this policy takes effect, and the letter tells them what changed, so a school can pass it on to its people.

How to reach us

Start with your school, which can answer most questions about what your role lets you do. For anything about this policy itself, write to hello@seraco.io. For personal information held about you, see the Privacy Policy.