Privacy Policy

Effective date: 15 September 2026 · Last updated: 21 September 2026
Prototype notice: LiteracyLab AI is currently an interactive product prototype. This document was drafted with AI assistance to reflect our intended data practices under COPPA, UK/EU GDPR (including the UK Age Appropriate Design Code, sometimes referred to as "GDPR-K"), Australia's Privacy Act 1988, Canada's PIPEDA, Singapore's PDPA, the UAE's PDPL, and general international data-protection standards — it was not drafted or reviewed by a qualified privacy lawyer in any jurisdiction, and an AI's drafting is not a substitute for one. It must be finalized by a licensed attorney — ideally one in each region the Service actually operates in — before the Service processes any real child's personal data.

This Privacy Policy explains how LiteracyLab AI ("we," "us") collects, uses, and protects information when a parent or legal guardian ("Account Holder", "you") creates an account and sets up a profile for their child or student ("Child User") on our website and workspace (the "Service").

1. Who manages the account

The Service is built around parental control by design. A parent or legal guardian creates the account, provides billing information, and creates and manages every Child User profile linked to that account. Child Users do not register independently, do not provide their own contact information, and cannot change account-level settings such as billing, subscription plan, or profile deletion — only the Account Holder can do this.

Because many Child Users are under 13, we are designed around the US Children's Online Privacy Protection Act ("COPPA"): a Child User cannot register, provide their own contact details, or create a profile independently — only an adult Account Holder, using their own confirmed email address, can do so, on the Child User's behalf. We do not solicit any personal information directly from a Child User at any point. If we become aware that a Child User has obtained access other than through an Account Holder-created profile, we will promptly disable that access and delete any associated data.

We have not implemented a heightened identity- or age-verification step (such as a government ID check or a knowledge-based verification question) beyond confirmed-email account creation. Before this Service is offered commercially at scale, we intend to review whether COPPA's "verifiable parental consent" standard requires a stronger method for our specific data uses, with qualified counsel.

2. Information we collect

CategoryWhat we collectFrom whom
Account informationParent/guardian email address, password (hashed), subscription/billing statusAccount Holder
Child profileStudent display name (a nickname or first name only is sufficient — a full legal name is never required), grade or year level, country curriculum, selected interest tagsAccount Holder, on behalf of the Child User
Learning contentStory and essay submissions, reading-comprehension responses, associated word/character counts, generated feedback, and mastery/progress historyChild User, via the workspace
Technical dataBasic device and usage logs (e.g. timestamps, error logs) used only to operate and secure the ServiceAutomatically, from the browser/device

We do not knowingly collect a Child User's precise geolocation, contact information (email, phone), government identifiers, or biometric data, and we do not require any of this to use the Service.

3. How submissions are processed by AI — in plain terms

When a Child User submits a story, essay, or a set of reading-comprehension answers, that content is sent securely to a third-party large language model provider (for example, OpenAI's API) solely to generate real-time educational feedback — a Glow, a Grow, vocabulary suggestions, and a micro-mission. This processing happens through the provider's business/API terms, under which:

We do not use Child User writing submissions for behavioral advertising, and we do not build advertising profiles of Child Users.

4. How we use information

We do not sell personal information, and we do not use Child User data for cross-context behavioral advertising, as those terms are used under applicable US state privacy laws.

5. Your rights as a parent or guardian

At any time, an Account Holder may:

These dashboard controls are the primary way to exercise these rights and take effect immediately, without needing to wait on a support request. You can also email privacy@literacylabai.com for help, or for anything the dashboard controls don't cover; we will act on such requests without unreasonable delay, and in any case within the timeframe required by applicable law.

6. Anonymous comparison with other students

The parent dashboard shows how a Child User's mastery compares with other students in the exact same country curriculum and grade/year — an average score, a percentile, and a ranked "league ladder." This comparison is computed on our servers from aggregated data across accounts, but no Account Holder or Child User ever sees another family's raw data: every other entrant on the ladder is shown only as an anonymous rank and score (e.g. "Student 4 — 62%"), never a name or any other identifying detail. If fewer than five students share the exact same country and grade/year, the comparison is withheld entirely rather than shown against a small enough group that a specific other family's result could be inferred.

7. UK and EU users (GDPR and the Children's Code)

For users in the UK and EU, our lawful basis for processing a Child User's personal data is parental consent together with the performance of our contract with the Account Holder. In addition to the rights in Section 5, UK/EU Account Holders have the right to restrict or object to certain processing, and to lodge a complaint with their local data protection authority (in the UK, the Information Commissioner's Office).

In line with the UK Age Appropriate Design Code, the Service applies privacy-protective defaults for Child Users: profile visibility is private by default, no geolocation is collected, no "nudge" techniques are used to encourage additional data disclosure or extended usage beyond what a parent has configured, and no options that weaken a child's privacy are enabled by default.

8. Australia

For Australian users, we handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth) — collecting only what is reasonably necessary to provide the Service, not using or disclosing it for an unrelated secondary purpose, and giving an Account Holder access to and control over their Child User's information as set out in Section 5. Concerns can also be raised with the Office of the Australian Information Commissioner if they cannot be resolved with us directly.

9. Canada

For Canadian users, we handle personal information in line with the Personal Information Protection and Electronic Documents Act ("PIPEDA") — collecting it only with the Account Holder's knowledge and consent, for the purposes described in this Policy, and safeguarding it as described in Section 13. An Account Holder who is not satisfied with our response to a privacy concern may complain to the Office of the Privacy Commissioner of Canada.

10. Singapore

For Singapore users, we handle personal data in line with the Personal Data Protection Act 2012 ("PDPA") — relying on the Account Holder's consent, collecting only what is reasonably required to provide the Service, and giving an Account Holder the access, correction, export, and deletion rights set out in Section 5. Concerns can also be raised with the Personal Data Protection Commission of Singapore.

11. UAE and GCC hubs

For users in the UAE and other GCC markets we offer the Service to, we intend to handle personal data consistent with the UAE's Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") and equivalent regional frameworks — including a lawful basis for processing (parental consent), data-minimization, and the access/correction/export/deletion rights set out in Section 5. Given the number of distinct legal frameworks across GCC markets, this section is the least developed part of this Policy and should be prioritized for local counsel review before the Service accepts real users based in this region.

12. Data retention

We retain account and Child User data for as long as the account remains active, plus a limited period afterward to allow for account recovery and to meet legal, accounting, or dispute-resolution obligations. A self-service account deletion (Section 5) deletes the underlying data immediately, other than any residual copy kept only as long as necessary in backups or as required by law.

13. Data security

We use industry-standard technical and organizational measures — including encryption in transit, access controls, and restricted internal access to Child User data — to protect information from unauthorized access, alteration, or disclosure. No system can be guaranteed 100% secure, and we will notify affected Account Holders in the event of a data breach as required by applicable law.

14. International data transfers

Because our infrastructure and AI-processing providers may operate in countries other than your own, personal data may be transferred internationally. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses for UK/EU transfers) to ensure data receives an equivalent level of protection wherever it is processed.

15. Changes to this policy

We may update this Privacy Policy from time to time. Material changes affecting how we handle Child User data will be communicated to Account Holders via the email on file before they take effect.

16. Contact us

Questions, deletion requests, or export requests can be sent to privacy@literacylabai.com.