Privacy policy

Your data, in plain words.

This tells you what RetailFlow and EduPort record, where those records are kept, which other services touch them, and what you can ask us to do about it. We wrote it for a shop owner and a school bursar, not for a lawyer.

Last updated: 7 October 2026.

Who runs this

Chikwo — business tools that grow with you.

Chikwo is run by one founder, Marist. There is no data team and no ad business. The same person builds the apps and runs the servers, so this policy describes real operations rather than a legal template.

Where

Lagos, Nigeria (West Africa Time).

This policy covers the Chikwo website, the RetailFlow and EduPort desktop apps, and the hosted portal you sign in to at app.chikwo.com. It does not cover what your own school or shop does with the records you hold.

The most important fact

The day-to-day database lives on your own machine.

Chikwo does not hold your shop’s sales or your school’s registers as the master copy. Both desktop apps keep their operational database on the computer you install them on.

RetailFlow

Database
C:\ProgramData\RetailFlow\pos.db
Encryption key
C:\ProgramData\RetailFlow\pos.db.key
Backups
C:\ProgramData\RetailFlow\backups\

EduPort

Database
%APPDATA%\SchoolPortal\school_portal.db
Photo media
%APPDATA%\SchoolPortal\media
Backups
%APPDATA%\SchoolPortal\backups

What this means for a school’s students. The names, results, fees and photographs of your students are, first and foremost, on your own computer and under your control. They are not sitting in a Chikwo database waiting to be read. When records do reach our cloud, that is a deliberate sync you can turn off or decline — explained below.

Personal data in Chikwo’s systems

What our own systems actually see.

Not everything is on your machine. These are the categories that genuinely pass through Chikwo’s servers, described exactly as the software does it.

1. Account and registration data

To create a school on the hosted portal, we collect: the school name, a chosen address (subdomain), and the administrator’s first name, last name, email and password. The password is stored only as a hash (bcrypt in EduPort, PBKDF2 in RetailFlow), never as plain text. There is a hidden field on the form that exists purely to catch bots.

Registration always happens against the hosted service, because that database is the only place that can decide whether an address like greenfield.chikwo.com is still free. So the school’s identity and its owner’s admin account exist on our cloud from sign-up, on every plan.

2. Marketing contact form

When someone uses the enquiry form on this site, we store their name, email, optional phone, the product they asked about, an optional organisation, the message itself, a one-word category, and a truncated hash of their IP address (not the raw IP). The form is protected by Cloudflare Turnstile, a robot check. No advertising trackers are involved.

3. Cloud sync of school records

When EduPort is online and sync is running, it uploads the tenant’s records to the cloud database and pulls down what changed elsewhere. The records that move are the tables the app keeps: the school profile and its media (including student photos), users and their Staff, Parent and Student accounts, guardian links, student profiles and medical fields, attendance, results and reports, fee types, invoices, payments, receipts and credits, exam questions and attempts, e-learning materials, notifications and circulars. The one table a device never uploads is its own billing row, so a school cannot edit its own invoice.

Sync is two-way whenever it runs: edits you make locally go up, and changes made on the hosted portal come down. It is not restricted to one direction on any plan; the difference between plans is which features are unlocked and the number of students you may keep, not whether records can reach the cloud. Read the EduPort page for the plan limits.

When the same record was changed in two places, the app resolves it by timestamp: a copy with no pending local edit simply takes the newer cloud version, and where both sides edited it, the version whose edit is strictly newer wins. Ties go to the cloud. This is a last-write-wins merge, so two people editing one record at once is a case to avoid.

4. Diagnostics and audit logs

EduPort keeps an append-only activity log. Every sign-in writes a LOGIN event that records the user’s email and role, the tenant, the time, and the client IP taken from the request header. Changes to records write the old and new values so a school can see who changed what. Viewing that log is a paid feature, but the events themselves are always recorded.

For billing, our systems keep the Paystack identifiers that let an event find the right tenant — customer code, subscription code and email token — and a ledger of billing events with the outcome. RetailFlow’s hosted service stores device records: a stable machine identifier you supply, the store it belongs to, a label, a last-seen time, and a hashed device token.

5. Support conversations

If you write to us or message on WhatsApp, we keep that conversation so we can help you. That is ordinary correspondence, not a product feature.

6. Billing

Chikwo holds your plan, billing cycle, whether you are in trial, grace or frozen, and your Paystack codes. We do not hold your card number. Card and bank details are entered on Paystack’s own checkout page and go straight to Paystack.

Student records

Children’s data: the school decides, we process.

EduPort exists to hold student records. This is the part that matters most, so it is set out plainly.

Your school is the data controller for its students. Chikwo processes those records on the school’s instructions. The school chooses what to record, who sees it, and whether to sync at all. The school must have its own lawful basis for the data it enters and its own notice to parents and guardians. Chikwo does not tell you which students to enrol or what to publish to a parent.

Because a child’s records are sensitive, the school should keep sign-in details private, use strong passwords, and only sync to the cloud where that is appropriate for its pupils.

Fields EduPort can hold for a student

  • Full name, preferred name, admission number, gender and date of birth.
  • State of origin, local government area, nationality and home address.
  • Guardian phone, emergency contact name, relationship and phone.
  • House, boarding status, hostel and transport means.
  • Medical notes where the school records them: blood group, genotype, allergies and conditions, disability notes, religion.
  • Class placement, attendance, results, terminal and annual reports, and assessment attempts.
  • Fee invoices, payments, receipts and credit balances.
  • A photograph, if the school uploads one; it is stored as a compressed image on the school’s own machine unless cloud media is switched on.

If you are a parent or student and a question about your records arises, the fastest route is usually your school, because your school controls the account. You may also write to us at contact@chikwo.com and we will help where the data is on our side.

Who else touches your data

Our processors, and what each one sees.

These are the only third parties in the request path. Each row names a service we actually call, what it handles, and why.

Third-party processors used by Chikwo
Who What they see Why
Cloudflare Website traffic to chikwo.com and the school portals; the Turnstile robot check; enquiry rows and site logs; the mirrored installer files in R2; media served through media.chikwo.com. Hosts the site and the *.chikwo.com routing, DNS, storage and HTTPS.
Render Runs the hosted EduPort portal and the RetailFlow owner dashboard, including their server-side sessions. Where the online portal and owner dashboard execute.
Supabase (Postgres) The cloud copy of a school’s synced records and subscriptions for EduPort; the billing, device and session tables for RetailFlow. The hosted database behind the portal.
Paystack Your card or bank details at checkout, the payment itself, and the subscription we bill you on. Prices you see are read live from Paystack. Takes payment. Card details go to Paystack, never to Chikwo.
GitHub The installer binaries themselves, which are published as release files and served to you when a download redirects to GitHub’s asset host. Where the Windows installers are stored and delivered from.
Resend The one acknowledgement email sent back to a website enquiry, with the sender’s name and email address, when our email sending is configured. Delivers the contact-form confirmation.

Two things we deliberately do not do. We do not name an image host we no longer use, and we do not send you marketing from a third-party list. If a service is not in the table above, it is not part of the path your data travels.

Cookies and sessions

Session cookies only, never advertising.

The hosted portal and the desktop apps set a single session cookie so that you stay signed in while you work. In EduPort it is named school_portal_session. On the hosted portal it is marked secure and sent only over HTTPS. It carries authentication and tenant context — nothing about your browsing elsewhere.

There are no advertising, analytics-fingerprinting or cross-site tracking cookies on these pages. Our web enquiry form uses a Cloudflare Turnstile widget for the robot check and nothing that profiles you for ads.

On the portal
Session data is stored server-side on Postgres through Flask-Session, not inside the cookie itself.
On the desktop app
The EduPort cookie is signed by the app and expires after 4 hours of inactivity; RetailFlow’s remembered sign-in lasts up to 30 days.
Same-site scope
The cookie is tied to one host, which is why opening the app by a different address looks like a fresh login.

Security

The protections that are really switched on.

Encrypted local database

Both apps store their database with SQLCipher, so the file on your disk is not readable as plain text.

Encrypted, numbered backups

EduPort protects backups with AES-256-GCM and derives the key with Argon2id (a PBKDF2 fallback is used where Argon2 is unavailable), and keeps the five most recent automatic backups.

HTTPS on the hosted site

The public site, the portal and the owner dashboard are served over HTTPS with strict transport security through Cloudflare.

Tenant isolation by host

The portal resolves which school you are looking at from the address you used, and refuses a host that maps to no tenant, so one school’s session cannot reach another’s records.

Signed entitlement tokens

RetailFlow tills trust a plan because it is signed with an Ed25519 key held by our service, not because a device claims it. A till cannot talk itself into a better plan.

Secrets kept off the app

Payment secret keys and signing keys are held by the hosted service and are deliberately not compiled into the desktop installers.

Be honest with yourself about two limits. Neither installer is code-signed yet, which is exactly why Windows shows a warning when you run it. And on your own network both apps serve plain HTTP, so traffic between a phone or a second laptop and the app on the local machine is not encrypted in transit. Use them on a private network you control, not on open or shared Wi-Fi.

How long, and who can delete

Retention, category by category.

Your local records
Kept until you delete them. You control the files; deleting the database, media and backup folders removes them from your machine.
Cloud copy and sync history
Kept until you ask us to remove it. Once a school syncs, a cloud copy and its sync log exist on our side; deleting those needs a written request to us.
Site logs
The website’s own request logs are purged older than 90 days automatically.
Enquiry submissions
Kept in our contact database until we delete them, which we do on request.
Billing records
Kept as long as we must, for the transaction and the subscription state.

There is no self-service button that wipes a school’s cloud copy. Because Chikwo is one person, removal is done by hand, carefully, by the person who knows what each table holds.

To ask for a deletion of a cloud copy, a sync history, or an enquiry you filed, write to contact@chikwo.com. A school deleting its own records only needs to delete the files on its machine; a school that has synced must also ask us, because that copy is ours to remove.

Deleting operational data does not erase entries the law or the payment provider requires us to keep about a transaction.

Your rights

Under the Nigeria Data Protection Act 2023.

Nigeria’s NDPA 2023 gives people rights over their personal data. Here is how to use them with Chikwo — and who can answer, since the data you see here is held on your own machine first.

Access

Ask what personal data of yours is on our systems. For your own shop or school records, the app itself shows them; for what we hold, we will tell you.

Rectification

Have wrong data corrected. A school edits its own records directly in EduPort or RetailFlow.

Erasure

Ask us to delete data we hold, subject to records we must lawfully keep.

Objection

Object to processing that relies on our legitimate use, such as keeping records in the cloud.

Portability

Take your data with you. Both apps export an encrypted backup you can hand to another system.

Complaint

Complain to us first, and if you are not satisfied, to Nigeria’s data protection authority.

To exercise any right, write to contact@chikwo.com and say which product and which data you mean. Chikwo is a one-person operation and does not have a dedicated Data Protection Officer; requests come to the founder directly. We have deliberately not invented a registration number or a compliance certificate we do not hold.

International transfers

Where the servers sit.

The EduPort hosted portal runs on Render in its Frankfurt (Germany) region, and the cloud database it reads from is Supabase. That means a school’s synced records, including student records, may be processed and stored outside Nigeria. The website itself and the routing for school addresses run on Cloudflare’s global network. Chikwo is Nigerian-operated, but the infrastructure is not all inside Nigeria, and we are telling you that rather than hiding it.

Marketing email

There is no newsletter.

The software does not send you marketing blasts, and we do not run an opt-in newsletter that could spam you. The only automatic email in the code is a single acknowledgement back to someone who submits the enquiry form on this website, to confirm we received it. Product and policy announcements go on this site; if we change this policy materially we also write to registered school owners (see below).

When this changes

How you will hear about an update.

This page carries a Last updated date at the top (currently 7 October 2026). The version you are reading is the current one; if that date moves, the policy changed.

Material changes are announced on the site, and we will email registered school owners when a change affects how their students’ data is handled. The honest position is that this is a commitment we keep by hand, not an automated feed — which is why the dated line and your own bookmark are the reliable signals.

Related: our Terms of Service set out the licence, the plan limits and who is responsible for what.

A question about your data? Ask a person.

WhatsApp and email, answered within 24 business hours by the founder who builds these apps. We are in Lagos, WAT.