Privacy Policy
Kids AI Smart Learning ("we", "us", "our") respects your privacy and your child's privacy. This policy explains what we collect, why, how we protect it, and the choices you have.
1. Data We Collect
From the parent (you)
- Account information: name, email address, phone number (if provided), encrypted password, profile avatar
- Subscription data: plan, billing status, payment identifiers from Razorpay (we do not store your card number)
- Communications: WhatsApp delivery status of notifications we send you, email correspondence
From the child (with parental consent)
- Profile: first name, age, class, language preference, avatar choice
- Voice recordings: short audio clips of the child answering lesson questions (temporarily stored for STT processing, then discarded within 7 days)
- Learning data: questions attempted, correct/incorrect counts, response times, session lengths, badges earned
- Uploaded images: textbook pages the parent scans, stored under the parent's account
Automatic
- Technical data: IP address, browser/device type, page views, error logs
- Cookies: a single authentication cookie (httpOnly, secure). We do not use advertising or tracking cookies
2. How We Use Data
Strictly to deliver the Service:
- Run voice lessons (voice → text → AI → reply → audio)
- Track progress and generate reports
- Send WhatsApp daily summaries and weekly reports (opt-out available)
- Process payments through Razorpay
- Detect fraud and abuse
- Respond to support requests
We do not use your or your child's data for advertising or sell it to third parties.
3. Third Parties We Share Data With
| Service | Purpose | Data shared |
|---|---|---|
| Razorpay | Payment processing | Name, email, payment details |
| Sarvam AI | Speech-to-text + text-to-speech | Short voice clips, text |
| Google Gemini | AI lesson generation | Lesson questions, scanned text, no child identifiers |
| WhatsApp Business (via Chatwoot) | Parent notifications | Parent's phone + message content |
All providers have their own privacy policies and are contractually required to handle data securely.
4. Children's Privacy
We do not knowingly collect information from children without verifiable parental consent, which is established through the parent creating the account and explicitly adding the child. Children cannot sign up directly. Parents can:
- View all data we have on their child from the /home dashboard
- Delete a child profile at any time — this removes all associated learning data within 30 days
- Request a full data export via email
5. Data Retention
- Voice recordings: 7 days (processed and then deleted)
- Learning data (question attempts, sessions): 18 months, then anonymized
- Account data: as long as the account is active; 90 days after deletion
- Payment records: 7 years (legal requirement under Indian tax law)
- Uploaded textbook images: 90 days, then deleted
6. Security
- All traffic served over HTTPS (TLS)
- Passwords stored as bcrypt hashes (salted, slow-hashed — never plaintext)
- Database hosted on a private Indian VPS with restricted access
- Authentication via JWT in httpOnly + SameSite cookies
- Regular backups; incident response process documented
7. Your Rights
You have the right to:
- Access: request a copy of your data
- Correct: fix inaccuracies from the /profile page
- Delete: close your account from /account (deletes all associated data within 90 days)
- Opt out: disable daily/weekly WhatsApp from /profile
- Portability: export your data by emailing marinersapp@gmail.com
8. Cookies
We use one essential cookie: bubo_token — a JWT for authentication. It's httpOnly (JavaScript cannot read it), secure (HTTPS-only), SameSite=Lax, and expires after 7 days. We do not use any advertising, analytics, or cross-site tracking cookies.
9. Cross-Border Transfers
Data is primarily stored in India. Some AI providers (Google Gemini, Sarvam AI) may process small amounts of data outside India during lesson generation. All transfers use encrypted connections.
10. Changes to This Policy
Material changes will be announced via email and in-app banner at least 14 days before taking effect. We will always keep an archive of prior versions on request.
11. Contact
Questions? Data requests? Email marinersapp@gmail.com — we respond within 5 working days.