What the app needs in order to work at all
Everything else — after-school care, religion and ethics, pickup
authorizations, the health statement, image consent — is a statement you
file when you choose to. The app does not need any of it to work, and does not
collect it for itself. See
Consents and statements.
The PIN: four digits of a PESEL
What it is, and what it is not
The PIN is not a password. It does not protect your account, you cannot sign in with it, and nobody asks for it at login. It is a shared secret: a number you know and that the school already holds in its own records. The app says so right next to the field: “PIN = last 4 digits of child’s PESEL. The teacher will verify identity.”Why a shared secret at all
Because without one, anyone could enrol as any child’s parent. A class code circulates in messenger groups, reaches siblings’ parents, grandparents, and sometimes further. The code alone tells the teacher nothing about who used it. If a first and last name were enough to enrol a child, the best case would be a mess — two records for the same child, a mix-up between similar surnames. The worst case is considerably more serious: a stranger with a view into your child’s class and the ability to file statements in your name, pickup authorizations included. Four digits are the smallest thing both sides already know and a passer-by does not. The teacher compares them against the register, and approves or rejects the request.Why four digits and not the whole PESEL
Because a fragment is enough to check against the school’s records, and a fragment is worth far less than the whole thing.- We do not ask for the full number and we do not hold it. The form has room for four digits; the database has a field for four digits. The full PESEL never reaches us — it cannot be stolen from us, because it is not there.
- Four trailing digits do not identify a child on their own. They carry no date of birth, and the number cannot be reconstructed from them. Outside the context of one specific class they say nothing.
- They are entirely sufficient for the job. The teacher has to confirm the request came from somebody who knows the child. Four digits do that as well as eleven.
Why not a scanned document
Because a scanned birth certificate or ID would solve the same problem at the cost of a far larger pile of data: the full PESEL, an address, sometimes both parents’ details — and all of it as a file somebody would have to store, show to somebody, and eventually delete. Zebrania does not accept attachments for identity verification, and does not plan to. The same principle recurs elsewhere in the product: a fragment of somebody’s identity earns its place only when it actually does verification work. That is why the authorized person’s document number disappeared from pickup authorizations — it confirmed nothing, since a different document can be produced at the door anyway. The PIN stays, because it does its job.Who sees the PIN
How long it is kept
The PIN lives in two places, exactly like the child’s name — because Zebrania keeps two separate records for the same person:- In the child record on your list. It is yours; you correct it, and it goes when the child does.
- In the student record on the school’s side. That is a copy taken at the moment of enrolment. The school manages it.
What the PIN replaces
The case for this design is clearest next to what it replaces. Verification has to happen somehow; the only question is who pays for it.
Four digits move a small amount of work to the parent, who is sitting at
the form anyway and knows their own child’s PESEL. They take it off the
teacher, who would otherwise have to fill the class on everybody’s behalf.
Why it works this way, and not through an agreement with the school
This is the most important reason, and it is worth stating plainly, because it explains the shape of the whole product. In Zebrania the data originates with you and stays yours. When you enrol a child, you hand your own data to a specific teacher you chose. The school as an institution is not a party to that arrangement — there is no data-processing agreement, no institutional onboarding, and no data-protection officer’s sign-off gating any form. Privacy covers this at length. That is not an oversight but a deliberate choice, and it has a concrete payoff on the other side:- A school can start the same day. A teacher creates an account, creates a class, and hands out the code. Nobody waits for the head teacher to read, sign and return a contract.
- The service can be free. The agreement route means selling top-down: reaching the director, negotiating, clearing it with a data-protection officer. That raises the cost of running the service to the point where it could not be offered free of charge.
This page explains why the product is built the way it is. It is not legal
advice. The binding documents are the
privacy policy and the
terms, and they take precedence if
anything written here appears to conflict with them.
What the PIN does not do
The limits are worth knowing, because a field that looks like an identity check without being one would be worse than no field at all.- It does not protect your account. Signing in does that.
- It does not verify identity at pickup. Authorized pickup persons have their own list, and the check at the door rests on a name — see Consents and statements.
- It does not replace the teacher’s decision. A matching PIN is evidence, not automatic approval. A person always approves an enrolment.
- It is not required when you join through a guardian invitation. If the other parent has already enrolled the child, you join the existing record — see Inviting a guardian.
The documents
What next
- Who sees what, and how to delete your account? Privacy.
- Where exactly do you type the PIN? Children and contact details.
- What else do you file, and how do you take it back? Consents and statements.
- Enrolment rejected? Troubleshooting.