Privacy

Privacy Policy

Last updated: 9 July 2026 · We are committed to protecting your family's privacy

Our Privacy Promise

We never sell your personal data. We never show ads to children. We collect only what is strictly necessary to provide and improve the educational service.

1

Who This Policy Applies To

This Privacy Policy applies to all users of the GenAI Kids platform — parents, guardians, and the children learning on the platform. It covers data collected through our website, mobile applications, and any associated services.

We comply with: the Australian Privacy Act 1988 (including the Australian Privacy Principles), COPPA (Children's Online Privacy Protection Act, US), and GDPR where applicable to EU/UK users.

2

Data We Collect

Account & Identity Data (Parent/Guardian):

  • Full name and email address (required for account creation)
  • Password (stored hashed — we never see it in plain text)
  • Subscription and billing status (plan type, renewal date)

Child Profile Data:

  • Display name (first name or nickname only — no last name required)
  • Age group (6–8, 9–12, 13–16)
  • Avatar selection
  • Learning track and preferences

Learning Activity Data:

  • Lessons completed, quiz scores, XP earned, badges unlocked
  • Session duration and activity timestamps
  • AI chat message history (stored for safety moderation and continuity)

Technical Data:

  • IP address, browser type, operating system, device type
  • Device identifiers and session tokens (used to maintain your session and authenticate requests — see our Cookie Policy)
  • Cookies and similar technologies (see our Cookie Policy)
  • Error logs and performance diagnostics

Payment Data: iOS app purchases are handled by Apple In-App Purchase, and web purchases are handled by Stripe. We receive only non-sensitive billing metadata such as plan, status, and renewal date. We never store card numbers or CVVs.

3

How We Use Your Data

  • To create and manage your account and child profiles
  • To deliver, personalise, and improve the learning experience
  • To generate adaptive AI content tailored to each child's age and level
  • To send transactional emails (account confirmation, subscription receipts)
  • To provide parent reports on learning progress
  • To moderate AI interactions and ensure child safety
  • To diagnose technical issues and improve platform performance
  • To comply with legal obligations

We will only send marketing emails if you have explicitly opted in. You can unsubscribe at any time.

4

Children's Privacy (COPPA Compliance)

We treat children's data with the highest level of care.

  • All child accounts are created and managed by a verified parent or guardian.
  • We collect only the minimum data necessary to provide the educational service.
  • We do not serve personalised advertising to children.
  • We do not share children's data with any third-party advertisers or data brokers.
  • AI conversations involving children are filtered and moderated.
  • Parents may access, correct, or delete their child's data at any time.

Parental Rights

To review, correct, or delete your child's personal information, email privacy-genaikids@cyberdeux.com with the subject line "Parental Data Request". We will respond within 30 days.

5

Data Sharing & Third Parties

We do not sell your data. We share data only with the following trusted service providers, under strict data processing agreements:

  • Apple — in-app purchase processing for iOS subscriptions
  • Stripe — web payment processing (PCI-DSS Level 1 certified)
  • Base44 — our underlying platform infrastructure (data stored in secure cloud)
  • AI model providers — AI model inference (prompts processed; not used to train public models)
  • Law enforcement — only when legally required and with appropriate process

If we are involved in a merger or acquisition, we will notify users before any personal data is transferred.

6

Data Retention

  • Account data is retained while your account is active.
  • Upon account deletion, personal data is permanently purged within 30 days.
  • Anonymised, aggregated analytics data may be retained indefinitely.
  • We may retain data longer if required by law (e.g. tax records for up to 7 years).
7

Data Security

We implement industry-standard security measures including:

  • All data encrypted in transit (TLS 1.2+)
  • Data encrypted at rest using AES-256
  • Access to production systems restricted to authorised personnel only
  • Regular security reviews and penetration testing
  • Immediate breach notification procedures per applicable law

However, no system is perfectly secure. If you suspect a security issue, contact support-genaikids@cyberdeux.com immediately.

8

Your Privacy Rights

Depending on your location, you may have the following rights:

  • Right of Access — obtain a copy of your personal data
  • Right to Rectification — correct inaccurate data
  • Right to Erasure — request deletion of your data ("right to be forgotten")
  • Right to Restriction — limit how we process your data
  • Right to Data Portability — receive your data in a machine-readable format
  • Right to Object — object to certain types of processing
  • Right to Withdraw Consent — where processing is consent-based

To exercise any right, email privacy-genaikids@cyberdeux.com. We will respond within 30 days.

9

International Data Transfers

Our platform infrastructure may process data in Australia and the United States. Where data is transferred outside Australia, we ensure appropriate safeguards are in place in accordance with the Australian Privacy Act and applicable international frameworks.

10

Cookies

We use cookies and similar technologies. See our full Cookie Policy for details on what we use and how to manage your preferences.

11

Changes to This Policy

We may update this policy periodically. For material changes, we will notify you by email and in-app notification at least 14 days in advance. The "last updated" date at the top reflects the most recent revision.

12

Contact & Complaints

For privacy enquiries: privacy-genaikids@cyberdeux.com

If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au after first attempting to resolve the matter with us.

Open Contact Form →