Legal

Privacy Policy

Effective date: March 1, 2025 · Last updated: March 26, 2026

COPPA Compliance Notice

Kluey is an educational service for children under 13 used under parental supervision. We comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information directly from children under 13. All accounts are created and controlled by parents or legal guardians.

1. Who We Are

Kluey ("Kluey," "we," "us," or "our") is an educational technology platform that provides AI-powered Socratic tutoring for children in grades K–6. Our service is accessed at kluey.ai. If you have privacy questions, contact us at privacy@kluey.ai.

2. Information We Collect

2.1 Information Provided by Parents (Account Holders)

  • Account registration: first name, last name, email address, and password (stored as a bcrypt hash, never plaintext).
  • Profile updates: optional phone number.
  • Payment information: managed entirely by Stripe. We store only Stripe customer IDs and subscription status — no raw card data is ever stored on our servers.
  • Children's profiles: first name, grade level, and avatar — all collected from the parent, not the child.

2.2 Information Generated Through Use

  • Session transcripts: the text messages exchanged between the child and the AI coach. These are stored to enable progress reporting, session history review by parents, and quality improvement.
  • Learning analytics: subject, topic, duration, XP earned, streak data, and struggle flags generated automatically during sessions.
  • Gamification data: XP points, levels, badges earned.

2.3 Technical Data Collected Automatically

  • Log data: IP address, browser type, operating system, referring URL, pages visited, and timestamps. Used for security, fraud prevention, and service monitoring.
  • Session cookies: strictly necessary session cookies to keep you logged in. We do not use third-party advertising trackers or analytics cookies.

3. How We Use Your Information

  • Provide and operate the tutoring service.
  • Send OTP verification codes, password-change notifications, and transactional emails.
  • Send weekly learning reports and struggle alerts (if enabled by the parent).
  • Process payments via Stripe and manage subscriptions.
  • Generate AI coaching sessions using OpenAI's API. Session content is sent to OpenAI subject to their Privacy Policy. We have opted out of data training use.
  • Analyse learning patterns to improve our Socratic prompting system.
  • Respond to support requests submitted through the contact form.
  • Comply with legal obligations and enforce our Terms of Service.

4. Children's Privacy (COPPA)

We take children's privacy seriously. We comply with COPPA requirements:

  • Accounts are created and owned by parents (age 18+). Children cannot independently create accounts.
  • We collect only the minimum data needed from children's profiles: first name, grade, and avatar (set by the parent).
  • Children's session data is visible only to the parent who owns the account.
  • We do not serve targeted advertising to children or share children's data with advertising networks.
  • Parents may review, correct, or delete their child's data at any time by contacting privacy@kluey.ai.
  • We do not retain children's data beyond what is necessary for the service or required by law.

5. Data Sharing & Third Parties

We do not sell personal information. We share data only with the following service providers under contract:

Provider Purpose Data Shared
OpenAIAI coaching responsesSession messages (no PII beyond chat context)
StripePayment processingEmail, payment details
SMTP providerTransactional emailEmail address, first name

We may disclose information when required by law, to prevent fraud, or to protect the safety of our users.

6. Data Security

We implement appropriate technical and organisational measures including bcrypt password hashing, CSRF protection, rate limiting, HTTPS-only connections, parameterised SQL queries, and strict session controls. No method is 100% secure; in the event of a data breach we will notify affected users as required by applicable law.

7. Data Retention

  • Account and profile data is retained while your account is active.
  • Upon account deletion, personal data and children's profiles are removed within 30 days, except where required for legal, fraud-prevention, or billing purposes.
  • Server logs are retained for 90 days and then deleted.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Delete your account and associated data.
  • Object to or restrict processing of your data.
  • Port your data in a machine-readable format.
  • Withdraw consent for non-essential communications.

To exercise any of these rights, email privacy@kluey.ai. We will respond within 30 days.

9. Cookies

We use only a single strictly-necessary session cookie to maintain your login state. We do not use advertising or analytics cookies. You can disable cookies in your browser settings, but doing so will prevent you from logging in.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email at least 14 days before the new policy takes effect. Continued use after the effective date constitutes acceptance.

11. Contact Us

For privacy-related questions or to exercise your rights:

Kluey

Email: privacy@kluey.ai

Contact form: https://kluey-ai.com/contact