This Privacy Policy explains how LiteracyLab AI ("we," "us") collects, uses, and protects information when a parent or legal guardian ("Account Holder", "you") creates an account and sets up a profile for their child or student ("Child User") on our website and workspace (the "Service").
The Service is built around parental control by design. A parent or legal guardian creates the account, provides billing information, and creates and manages every Child User profile linked to that account. Child Users do not register independently, do not provide their own contact information, and cannot change account-level settings such as billing, subscription plan, or profile deletion — only the Account Holder can do this.
Because many Child Users are under 13, we are designed around the US Children's Online Privacy Protection Act ("COPPA"): a Child User cannot register, provide their own contact details, or create a profile independently — only an adult Account Holder, using their own confirmed email address, can do so, on the Child User's behalf. We do not solicit any personal information directly from a Child User at any point. If we become aware that a Child User has obtained access other than through an Account Holder-created profile, we will promptly disable that access and delete any associated data.
We have not implemented a heightened identity- or age-verification step (such as a government ID check or a knowledge-based verification question) beyond confirmed-email account creation. Before this Service is offered commercially at scale, we intend to review whether COPPA's "verifiable parental consent" standard requires a stronger method for our specific data uses, with qualified counsel.
| Category | What we collect | From whom |
|---|---|---|
| Account information | Parent/guardian email address, password (hashed), subscription/billing status | Account Holder |
| Child profile | Student display name (a nickname or first name only is sufficient — a full legal name is never required), grade or year level, country curriculum, selected interest tags | Account Holder, on behalf of the Child User |
| Learning content | Story and essay submissions, reading-comprehension responses, associated word/character counts, generated feedback, and mastery/progress history | Child User, via the workspace |
| Technical data | Basic device and usage logs (e.g. timestamps, error logs) used only to operate and secure the Service | Automatically, from the browser/device |
We do not knowingly collect a Child User's precise geolocation, contact information (email, phone), government identifiers, or biometric data, and we do not require any of this to use the Service.
When a Child User submits a story, essay, or a set of reading-comprehension answers, that content is sent securely to a third-party large language model provider (for example, OpenAI's API) solely to generate real-time educational feedback — a Glow, a Grow, vocabulary suggestions, and a micro-mission. This processing happens through the provider's business/API terms, under which:
We do not use Child User writing submissions for behavioral advertising, and we do not build advertising profiles of Child Users.
We do not sell personal information, and we do not use Child User data for cross-context behavioral advertising, as those terms are used under applicable US state privacy laws.
At any time, an Account Holder may:
These dashboard controls are the primary way to exercise these rights and take effect immediately, without needing to wait on a support request. You can also email privacy@literacylabai.com for help, or for anything the dashboard controls don't cover; we will act on such requests without unreasonable delay, and in any case within the timeframe required by applicable law.
The parent dashboard shows how a Child User's mastery compares with other students in the exact same country curriculum and grade/year — an average score, a percentile, and a ranked "league ladder." This comparison is computed on our servers from aggregated data across accounts, but no Account Holder or Child User ever sees another family's raw data: every other entrant on the ladder is shown only as an anonymous rank and score (e.g. "Student 4 — 62%"), never a name or any other identifying detail. If fewer than five students share the exact same country and grade/year, the comparison is withheld entirely rather than shown against a small enough group that a specific other family's result could be inferred.
For users in the UK and EU, our lawful basis for processing a Child User's personal data is parental consent together with the performance of our contract with the Account Holder. In addition to the rights in Section 5, UK/EU Account Holders have the right to restrict or object to certain processing, and to lodge a complaint with their local data protection authority (in the UK, the Information Commissioner's Office).
In line with the UK Age Appropriate Design Code, the Service applies privacy-protective defaults for Child Users: profile visibility is private by default, no geolocation is collected, no "nudge" techniques are used to encourage additional data disclosure or extended usage beyond what a parent has configured, and no options that weaken a child's privacy are enabled by default.
For Australian users, we handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth) — collecting only what is reasonably necessary to provide the Service, not using or disclosing it for an unrelated secondary purpose, and giving an Account Holder access to and control over their Child User's information as set out in Section 5. Concerns can also be raised with the Office of the Australian Information Commissioner if they cannot be resolved with us directly.
For Canadian users, we handle personal information in line with the Personal Information Protection and Electronic Documents Act ("PIPEDA") — collecting it only with the Account Holder's knowledge and consent, for the purposes described in this Policy, and safeguarding it as described in Section 13. An Account Holder who is not satisfied with our response to a privacy concern may complain to the Office of the Privacy Commissioner of Canada.
For Singapore users, we handle personal data in line with the Personal Data Protection Act 2012 ("PDPA") — relying on the Account Holder's consent, collecting only what is reasonably required to provide the Service, and giving an Account Holder the access, correction, export, and deletion rights set out in Section 5. Concerns can also be raised with the Personal Data Protection Commission of Singapore.
For users in the UAE and other GCC markets we offer the Service to, we intend to handle personal data consistent with the UAE's Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") and equivalent regional frameworks — including a lawful basis for processing (parental consent), data-minimization, and the access/correction/export/deletion rights set out in Section 5. Given the number of distinct legal frameworks across GCC markets, this section is the least developed part of this Policy and should be prioritized for local counsel review before the Service accepts real users based in this region.
We retain account and Child User data for as long as the account remains active, plus a limited period afterward to allow for account recovery and to meet legal, accounting, or dispute-resolution obligations. A self-service account deletion (Section 5) deletes the underlying data immediately, other than any residual copy kept only as long as necessary in backups or as required by law.
We use industry-standard technical and organizational measures — including encryption in transit, access controls, and restricted internal access to Child User data — to protect information from unauthorized access, alteration, or disclosure. No system can be guaranteed 100% secure, and we will notify affected Account Holders in the event of a data breach as required by applicable law.
Because our infrastructure and AI-processing providers may operate in countries other than your own, personal data may be transferred internationally. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses for UK/EU transfers) to ensure data receives an equivalent level of protection wherever it is processed.
We may update this Privacy Policy from time to time. Material changes affecting how we handle Child User data will be communicated to Account Holders via the email on file before they take effect.
Questions, deletion requests, or export requests can be sent to privacy@literacylabai.com.