DRAFT — pending legal review. This beta version is provided for testing purposes.

Privacy Policy

Athowl (the “Service”) · Beta · Last updated: [date]

This policy explains what personal information we collect, why, where it is kept, and your choices. We built the Service for children, so we hold ourselves to a simple standard: collect as little as possible, never sell it, never advertise with it.

1. What we collect

Your child’s chats with the AI coach are not stored. Each message passes through an automatic filter that removes personal information (names, contact details, and similar) before the AI generates a reply, and the conversation is not saved to our database.

We do not collect your child’s email, birthdate, school, address, phone number, photo, precise location, contacts, or advertising identifiers — and there are no ads in the Service.

2. What we use it for

Only to run and improve the Service: adapting difficulty to your child, powering the AI coach, showing progress to you, fixing bugs, and (during beta) understanding how testers use the product. We do not sell personal information, and we do not use it for advertising or profiling unrelated to learning.

3. Where your data lives

Learning data and child profiles are stored in Canada (our database runs in the AWS Canada-Central region, operated by Supabase). Some processing happens on trusted providers’ infrastructure in the United States, as listed below. This is the honest picture: stored in Canada, with some processing on US infrastructure.

4. Service providers we rely on

Each provider processes data only to provide its service to us, under its own security and privacy commitments.

5. Children’s privacy

Accounts are created and controlled by a parent or legal guardian; children use the Service with that consent. We orient our practices to Canada’s PIPEDA. The AI coach operates under strict rules: math only, never asking about a child’s personal life, family, or feelings, and an automatic personal-information filter runs before any child text reaches the AI provider.

6. Retention and deletion

We keep data while the account is active and as needed for the beta. A parent can delete a child’s profile and all associated learning data at any time from the in-app Account page (this is permanent), or by emailing [contact email]; email requests are honoured within 30 days. When the beta ends, we will either delete test data or ask your permission to keep it.

7. Security

Data is encrypted in transit; database access is restricted and credentialed; secrets are stored in managed, encrypted configuration. No system is perfectly secure, but we design for a child-data-first standard: minimal collection, minimal access.

8. Your rights

You may request access to, correction of, or deletion of your personal information, and withdraw consent for your child’s use of the Service, by contacting [contact email]. You may also complain to the Office of the Privacy Commissioner of Canada.

9. Changes

We may update this policy during the beta. Material changes will be communicated (for example, by email or an in-app notice) before they take effect.

10. Contact

Privacy questions or requests: [contact email] · [legal entity name], [city, province].