Privacy Policy
Last Updated: February 2026
1. About SmartKidz & Our Commitment to Children's Privacy
SmartKidz (“we,” “us,” or “our”) operates an AI-powered educational platform designed for children in Years 1–6. We take the privacy of children extremely seriously and comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as well as the Children's Online Privacy Protection Act (COPPA) and the EU General Data Protection Regulation (GDPR).
- › We do not serve advertisements to children.
- › We do not sell children's data.
- › We do not use identifiable children's data to train general AI models.
2. Who This Policy Applies To
This policy applies to all users of SmartKidz, with special provisions for users under the age of 13 (“children”). Children under 13 may only use SmartKidz under a parent or guardian account with verifiable parental consent.
3. Information We Collect
From Parents / Guardians (Account Holders)
- › Email address: Used for account authentication and communications.
- › Password: Stored encrypted; we never see your password in plain text.
- › Subscription / Billing Information: Processed securely by Stripe; we do not store card details.
From Children (With Parental Consent)
- › First name only: Used to personalise the learning experience.
- › Age / Grade level: Used to match educational content to the child's level.
- › Learning activity data: Quiz answers, game scores, XP points, and progress tracking.
- › Session timestamps: Recorded when the child last used the platform.
Voice Data Notice
SmartKidz offers an optional AI Voice Tutor feature. If enabled, voice audio is processed in real-time by our provider (OpenAI) to provide educational assistance and is not stored, recorded, or retained by SmartKidz after the session ends.
Automatically Collected Technical Data
- › IP address: Used for security and fraud prevention only.
- › Device Metadata: Browser and device type to ensure platform compatibility.
- › Cookies: We use essential session cookies only. We do not use advertising or tracking cookies.
Data Residency Disclosure
Our data is stored on secure servers. By using the Service, you acknowledge that your information may be transferred to and processed in locations including Australia and the United States. We ensure all providers meet appropriate data protection standards.
4. How We Use Information & Automated Decision-Making
We use information solely to deliver the educational service, maintain security, and process payments.
- › Delivering the educational service to your child
- › Personalising learning content and difficulty to your child's progress
- › Displaying progress reports and insights to parents
- › Maintaining account security and processing payments
Automated Decision-Making (ADM)
SmartKidz uses automated systems to analyse your child's learning activity (e.g., quiz scores) to tailor lesson difficulty and track progress toward ACARA v9.0 curriculum markers. Parents have the right to request a manual review of any significant automated educational decision by contacting us.
We never use personal information or learning data for direct marketing, profiling, or AI model training.
5. Third-Party Service Providers
We share limited data with providers solely for operation. These providers are not permitted to use your data for any other purpose:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & Authentication | Email, first name, progress data |
| OpenAI | AI Tutor (Riley) processing | Chat messages only — no personal identifiers sent where possible |
| Stripe | Payment processing for parents | Parent billing info only — never child data |
6. Data Retention
- › Active accounts: Data is retained for the duration of the subscription.
- › Inactive accounts: Data is deleted after 12 months of inactivity.
- › Upon account deletion: All personal data is permanently deleted within 30 days.
7. Parental Rights
As a parent or guardian, you have the right to review, delete, or correct your child's information, and to withdraw consent at any time. To exercise these rights, email [email protected].
8. Data Security
- › TLS 1.3 encryption for all data in transit
- › AES-256 encryption for data at rest
- › Regular security reviews
In the event of a data breach affecting personal information, we will notify affected parents within 72 hours.
9. International Users (GDPR)
For EEA/UK users, our lawful bases for processing are contract performance, legitimate interests (security), and consent (optional features).
10. Contact Us & Complaints
For privacy questions or to exercise your rights:
- ›Email: [email protected]
Australian Complaints
If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
11. Cookie Policy
SmartKidz uses “cookies” (small text files placed on your device) strictly for essential platform functionality.
Essential Cookies
We use session cookies to authenticate your account, keep you logged in securely, and save your child's progress during an active session.
No Tracking
We do not use third-party advertising cookies, cross-site tracking cookies, or commercial analytics cookies that profile our users.
By using SmartKidz, you consent to the use of these essential functional cookies.