Your data, and what MarkWise does with it
Last updated: September 9, 2026
MarkWise is an attendance-management service used by educational institutions to record and verify student attendance for in-person and online classes. This policy explains what information the MarkWise web and mobile applications collect, why, and what control you have over it. MarkWise is provided to you through your institution — your institution controls your enrollment and account, and remains responsible for how attendance records are used academically.
1. Information we collect
Account and profile information: name, institutional email, admission number (students) or staff number (lecturers), course and institution affiliation, and a password (stored only as a salted hash, never in plain text).
Attendance records: which sessions you attended, the method used (Bluetooth Low Energy, QR code, PIN, online passkey check-in, or manual marking by a lecturer), and the timestamp. For in-person sessions, a per-device identifier and, where supported, a cryptographic signature are recorded solely to detect duplicate or proxy (“buddy”) check-ins on the same session.
Device permissions on the mobile app: Bluetooth (to broadcast or detect in-person attendance signals) and, on Android versions where the operating system requires it as a prerequisite for Bluetooth scanning, Location permission — MarkWise does not read, store, or transmit your GPS location; the permission is requested only because some Android versions tie it to Bluetooth scanning. Camera access is used solely to scan a QR code on screen and is never used to capture or store photos.
Biometric check-in (passkeys): Online attendance can be verified using your device's own biometric or screen-lock authentication (Face ID, Touch ID, Windows Hello, fingerprint) via the WebAuthn/passkey standard. Your fingerprint or face data is processed entirely on your own device by its operating system — MarkWise and its servers never receive, see, or store this biometric data. We only receive a cryptographic signature proving the check succeeded on your device.
Push notification tokens: if you enable notifications, we register a device token with Google Firebase Cloud Messaging to deliver attendance and course-related alerts.
Technical data: basic request metadata (IP address, timestamps) generated by normal use of the service, used for security and abuse prevention.
Crash and diagnostic data: if the mobile app encounters an error or crashes, technical details — device type and OS version, app version, and a stack trace of what the app was doing at the time — are sent to our crash-reporting provider, Sentry, so we can identify and fix the problem. This is used solely to keep the app stable and working correctly, never for advertising or profiling.
2. How we use this information
- To record, verify, and report attendance to your institution and lecturers.
- To detect and prevent duplicate, proxy, or fraudulent attendance marking.
- To authenticate your account and secure it against unauthorized access.
- To send attendance, delegation, and course-related notifications you've opted into.
- To maintain, troubleshoot, and improve the reliability of the service.
We do not sell your personal data, and we do not use it for advertising.
3. Who can see your data
Your attendance records and profile are visible to lecturers teaching your enrolled units and to your institution's administrators, within the scope of their own institution only — MarkWise is multi-tenant, and data is isolated between institutions. We share data with third parties only as needed to operate the service itself: our hosting infrastructure (Google Cloud for the backend service, and Neon for our database), Google Firebase Cloud Messaging if you enable push notifications, and Sentry for crash and error diagnostics from the mobile app. We do not otherwise share your data with third parties, and we never sell it.
4. Data retention and deletion
We retain attendance and account records for as long as your institution keeps you enrolled, and as needed to satisfy academic record-keeping requirements. You can permanently delete your account and associated personal data at any time from within the mobile app (Settings → Delete Account) or by contacting us using the details below. Some attendance records may be retained by your institution independently of your MarkWise account, as they form part of your academic record.
5. Security
Data is encrypted in transit (HTTPS/TLS). Passwords are stored as salted hashes, never in plain text. Attendance sessions use cryptographic signing to detect tampering, and sensitive values cached on your device (such as a PIN used for offline attendance marking) are encrypted at rest. No system is perfectly secure, but we design MarkWise to minimize what it collects and to protect what it does collect.
6. Children's privacy
MarkWise is intended for use by students and staff of post-secondary educational institutions and is not directed at children under 13. If you believe a child has provided us with personal data, please contact us and we will remove it.
7. Changes to this policy
We may update this policy as the service changes. Material changes will be reflected by updating the date above, and where appropriate, we'll notify you in-app.
8. Contact us
Questions about this policy or your data can be sent via our Contact page, or to your institution's MarkWise administrator, who can escalate to us on your behalf.
This policy describes MarkWise's data practices as implemented in the product. It is not a substitute for legal advice — institutions should have it reviewed against their own regulatory obligations (e.g. local data protection law) before relying on it.