Privacy Policy
Last updated: 3 June 2026 · Draft pending legal review.
This is a plain-English draft we publish for transparency. The practices
below are what we actually do today. We will replace this with a
counsel-reviewed policy before CogniKiddo opens beyond the
family-and-friends pilot. If anything here is unclear, email
safety@cognikiddo.com.
1. Who we are & what this covers
CogniKiddo ("we", "us") is a voice-first learning app for children aged
6–10. This policy explains what information we collect through the app and
this website, how we use it, and the choices you have. CogniKiddo is built
for parents and guardians — children do not create
accounts or provide information directly to us.
2. Children & parental consent
- Only a parent or legal guardian may create an account and add a child profile.
-
By adding a child, you confirm you are their parent/guardian and you
consent to our collecting and processing that child's information as
described here.
-
We design for data minimisation: we collect only what's needed to teach
and to show you what your child is learning.
-
We do not knowingly let children sign up on their own, and we never
market to children.
3. Information we collect
- Parent account: name, email, password hash, and the timestamp / IP / device user-agent recorded when you consent.
- Child profile: display name, date of birth (used only to pick a grade band — never shown back to the child or shared), grade, and preferences (world theme, tutor voice, daily time limit).
- Learning activity: activity attempts (correct/incorrect), per-skill mastery, quiz and game results, tutor exchanges, and timing.
- Voice recordings: audio of your child speaking to the tutor during voice activities (see §7).
- Technical & usage data: session counts, error reports, and AI-usage cost. The child's identifier is hashed before it appears in any log line.
4. How we use information
- To run lessons, quizzes, Explore, and games, and to adapt difficulty to your child's level.
- To produce your daily parent digest, weekly trends, and session transcripts.
- To screen every exchange through our safety filter (see our Safety page).
- To keep the service secure, debug problems, and understand aggregate usage and cost.
- To contact you about your account, the pilot, or a safety matter.
5. What we never do
- We do not sell or rent your or your child's data, ever.
- We do not use your child's voice or text to train AI models — ours or anyone else's. We do not opt into any provider's "data may be used for training" tier.
- We do not show advertising or build advertising profiles.
- We do not share data with third parties except the service providers in §8, who process it only on our instructions.
6. Legal bases
We process children's data on the basis of parental consent,
which you can withdraw at any time by deleting the child profile or the
account (§9). We rely on legitimate interests only for security, fraud
prevention, and keeping the service running.
7. Voice recordings & retention
- Voice clips are stored in encrypted object storage for 30 days so you can replay any moment from the transcripts screen.
- After 30 days an automated lifecycle rule permanently deletes the clip — we have no mechanism to keep it longer.
- Transcribed text may persist with the session record so the digest stays meaningful; you can delete it with the account (§9).
8. Service providers (subprocessors)
Running a voice-first product means relying on a few vendors. We list them all so you can audit the chain:
- Anthropic — Claude models for tutor responses, the daily digest, and the safety classifier.
- OpenAI — Whisper for speech-to-text and a text-to-speech voice.
- Fly.io — application hosting.
- Neon — PostgreSQL database (runs on AWS).
- Upstash — Redis for transient state such as sign-in tokens (runs on AWS).
- Cloudflare — DNS, R2 object storage (voice clips & assets), Pages (this site), and Email Routing (inbound mail).
- Resend — outbound transactional email (sign-in links, account notices); messages are delivered over Amazon SES infrastructure.
- Expo (EAS) — mobile app builds and over-the-air updates.
9. Your rights & choices
- Access & export: email us and we'll send a machine-readable copy of everything tied to your account.
- Correct: edit profile details in the app, or ask us.
- Pause: log out from Settings to suspend access on a device.
- Delete: ask us and we will delete every record tied to your account within 7 days, confirmed by email. Voice clips older than 30 days are already gone.
- Withdraw consent: deleting a child profile or the account withdraws consent for that data.
To exercise any of these, email safety@cognikiddo.com or support@cognikiddo.com.
10. Where your data is stored
Data is processed on servers in the Asia-Pacific (Singapore) region and by
the providers listed above, some of which operate in other countries.
Where data crosses borders, we rely on our providers' standard safeguards.
We are evaluating data-residency options as we prepare for public launch.
11. Security
Data is encrypted in transit (TLS) and at rest. Passwords are stored only
as salted hashes. Access to production systems is limited and logged. No
system is perfectly secure, but we treat children's data as the highest
bar and design accordingly.
12. Data retention
We keep account and learning data while your account is active and for a
short period after, then delete or anonymise it. Voice clips: 30 days
(§7). Account deletion on request: within 7 days (§9).
13. Changes to this policy
We'll update the "last updated" date above when this changes, and notify
account holders by email for material changes.
14. Contact
Privacy or data questions: safety@cognikiddo.com.
General help: support@cognikiddo.com.
See also our Safety and Terms pages.