What we collect about your child
Your child is under 13, so COPPA applies to everything below. You create the account, you supply every piece of information about your child, and your child can never sign themselves up.
What we ask for
- A display name. A nickname is fine, and we say so on the form.
- A birth month and year. Not the day. We need enough to keep readings age-appropriate, and the day adds nothing except a stronger way to identify your child.
- A grade, which you choose and can change.
- A four-digit PIN that you set, stored only as an Argon2id hash.
What we deliberately do not collect
- No last name.
- No photographs. Avatars come from a fixed set and there is no upload.
- No email address or phone number for your child.
- No free-text profile, biography, or anything else your child can write about themselves.
- No location, no contacts, no device identifiers beyond what a web session requires.
The one thing your child types
Children can type their own reading topic, capped at 80 characters. It is the only free text in the product. Every one is checked before anything is generated, recorded permanently, and shown to you — whether it was allowed or blocked. If we block one, you get an email containing exactly what your child typed and why, and that email cannot be switched off.
Advertising and tracking
There is none, anywhere your child can see. No advertising, no third-party analytics, no session replay, no tracking pixels, no social widgets.
Who else processes this
- OpenAI generates the readings, suggests topics, and checks typed topics. It receives the topic, your child's grade, their interests and recent reading topics, and their age in years for the topic check. Your child's nickname, birth month and year, and PIN are never sent.
- SendGrid delivers email to you. Your address only.
- Microsoft Azure hosts the database and the application.
Your controls
- Download everything we hold about your children, as JSON or CSV, at any time.
- Ask us to delete it and we will, within 30 days, including from our vendors where our contracts allow.
- Pause your child's access instantly from your dashboard.
- Every action you take that touches your child's data is written to an audit log.
How it is protected
- Encrypted in transit (TLS 1.2 or better) and at rest.
- PINs and birth data are treated as sensitive columns.
- A parent account can only ever reach its own children. That is enforced in the database query itself, not by a check somebody has to remember to write.