Privacy Policy
Athowl (the “Service”) · Beta · Last updated: [date]
This policy explains what personal information we collect, why, where it is kept, and your choices. We built the Service for children, so we hold ourselves to a simple standard: collect as little as possible, never sell it, never advertise with it.
1. What we collect
- Parent account: your email address and sign-in credentials (managed by Clerk, our sign-in provider).
- Child profile: a first name or nickname and grade level, provided by the parent. We do not ask children for personal details, and the AI coach is instructed never to ask about a child’s personal life.
- Learning activity: problems served, answers, hints used, timing, progress and skill estimates, and in-app rewards — the data that makes the coaching adaptive.
- Technical basics: logs and error reports needed to keep the Service working.
Your child’s chats with the AI coach are not stored. Each message passes through an automatic filter that removes personal information (names, contact details, and similar) before the AI generates a reply, and the conversation is not saved to our database.
We do not collect your child’s email, birthdate, school, address, phone number, photo, precise location, contacts, or advertising identifiers — and there are no ads in the Service.
2. What we use it for
Only to run and improve the Service: adapting difficulty to your child, powering the AI coach, showing progress to you, fixing bugs, and (during beta) understanding how testers use the product. We do not sell personal information, and we do not use it for advertising or profiling unrelated to learning.
3. Where your data lives
Learning data and child profiles are stored in Canada (our database runs in the AWS Canada-Central region, operated by Supabase). Some processing happens on trusted providers’ infrastructure in the United States, as listed below. This is the honest picture: stored in Canada, with some processing on US infrastructure.
4. Service providers we rely on
- Supabase (database hosting, Canada — AWS ca-central-1): stores learning data and profiles.
- Vercel (application hosting, US): runs the app that serves pages and problems.
- Clerk (sign-in, US): stores the parent email and handles authentication.
- Anthropic (AI provider, US): receives the child’s PII-filtered math messages to generate the coach’s replies. We do not permit our data to be used to train their models under our API terms.
- [If enabled during beta: PostHog (product analytics) and Sentry (error reporting).]
Each provider processes data only to provide its service to us, under its own security and privacy commitments.
5. Children’s privacy
Accounts are created and controlled by a parent or legal guardian; children use the Service with that consent. We orient our practices to Canada’s PIPEDA. The AI coach operates under strict rules: math only, never asking about a child’s personal life, family, or feelings, and an automatic personal-information filter runs before any child text reaches the AI provider.
6. Retention and deletion
We keep data while the account is active and as needed for the beta. A parent can delete a child’s profile and all associated learning data at any time from the in-app Account page (this is permanent), or by emailing [contact email]; email requests are honoured within 30 days. When the beta ends, we will either delete test data or ask your permission to keep it.
7. Security
Data is encrypted in transit; database access is restricted and credentialed; secrets are stored in managed, encrypted configuration. No system is perfectly secure, but we design for a child-data-first standard: minimal collection, minimal access.
8. Your rights
You may request access to, correction of, or deletion of your personal information, and withdraw consent for your child’s use of the Service, by contacting [contact email]. You may also complain to the Office of the Privacy Commissioner of Canada.
9. Changes
We may update this policy during the beta. Material changes will be communicated (for example, by email or an in-app notice) before they take effect.
10. Contact
Privacy questions or requests: [contact email] · [legal entity name], [city, province].