Plain-Language Summary (1-page)
> The full policy below is the authoritative document; this summary is provided in plain language for accessibility.
What we collect. Account info (display name, age, grade), learning progress (lesson completion, scores, skill mastery), how you interact with activities (signals like time spent, retries, content choices), and — only with your explicit opt-in — additional behavioral signals used by our adaptive learning engine Koydo Intelligence to personalize the learning experience. When pronunciation features are available, short voice clips may be sent to an approved provider for real-time analysis. Koydo does not keep the source recording after processing.
What we do NOT do.
- We do not run advertising. Ever.
- We do not sell or share your personal information for cross-context behavioral advertising.
- We do not use your child's work or conversations to train AI models.
- We do not profile your child for non-educational purposes.
- We do not keep voice recordings.
Your rights. You can access, correct, export (machine-readable JSON), and delete your data anytime. Parents of children under 13 can review the child's information, delete it, export it, disable Koydo Intelligence, and revoke consent. California residents have additional CPRA rights (limit use of sensitive personal information, opt out of profiling/automated decisions, learn about automated decision-making logic). EEA, UK, and Swiss users have full GDPR rights including access, rectification, erasure, portability, restriction, and objection.
How to delete your stuff. Adults: Account Settings → Delete Account. Teens (13–17): Account Settings → Delete Account. Parents: Parent Dashboard → Manage Child's Data → Delete All Data. Schools: contact privacy@koydo.app — we delete within 30 days. Koydo deletes its own records and requests or performs provider-side deletion where the provider stores an addressable record.
Who decides what we do with data. Koydo's Privacy Officer at privacy@koydo.app. EEA and UK users may also contact our Article 27 representatives listed at the international transfer notice.
For more detail on any of the above, the full policy follows.
KOYDO LLC ("Koydo," "we," "us," or "our") operates the Koydo educational platform, including the Koydo website, Koydo mobile applications (Koydo Jr., Koydo Kids, Koydo Learn, Koydo Academy), and the Koydo Distill notes application (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our Service.
We take the privacy of all users seriously, and we take the privacy of children extremely seriously. This policy is written in plain language so that parents, students, teachers, and all users can understand our data practices.
If you have questions about this policy, contact us at privacy@koydo.app.
Plain-language summary
1. Definitions
- Child or Children: Users under the age of 13.
- Teen: Users between the ages of 13 and 17, inclusive.
- Adult: Users 18 years of age or older.
- Parent: A parent or legal guardian of a Child or Teen user.
- Koydo Intelligence or KI: Our optional adaptive learning system that uses behavioral signals to personalize the learning experience. KI is powered by the Koydo Intelligence system described in Section 6.
- Koydo Intelligence: Prismatic Learning Intelligence Signal Model, our behavioral signal analysis system that observes how a learner interacts with the platform in order to adapt content difficulty, pacing, and presentation style.
- Student Profile: A profile created by a Parent for a Child or Teen user.
Plain-language summary
2. Children Under 13 (COPPA)
This section applies to users under the age of 13. Koydo complies with the Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. 6501-6506, and the Federal Trade Commission's implementing rule at 16 C.F.R. Part 312, including amendments effective June 23, 2025, with a general compliance date of April 22, 2026. Those amendments expand the definition of personal information to include biometric identifiers that can recognize an individual and add protections concerning disclosure, security, retention, and deletion.
2.1 Parental Consent Is Required
We do not knowingly collect personal information from children under 13 without first obtaining verifiable parental consent. Before a child can use any feature of Koydo that involves the collection of personal information, a parent must:
- Create a parent account and add the child as a Student Profile.
- Provide the child's birth date (used solely to determine applicable age protections).
- Review a consent notice describing our data practices.
- Verify consent through our Verifiable Parental Consent (VPC) process, which involves an email confirmation sent to the parent's verified email address, containing a summary of data practices and a signed confirmation link.
A child's participation in Koydo is never conditioned on the disclosure of more personal information than is reasonably necessary to participate in the Service.
2.2 Information We Collect from Children (Default Mode)
When a parent provides consent, we collect the following information in default mode (without Koydo Intelligence enabled):
| Category | Specific Data | Purpose |
|---|---|---|
| Account information | Child's display name, age, grade level | To create and maintain the child's learning profile |
| Parent contact | Parent's email address (not the child's) | To communicate with the parent about the child's account and obtain consent |
| Learning progress | Lesson completion status, quiz and game scores, skill mastery levels | To track educational progress and present it to the parent and child |
| Content interaction events | Which lessons, activities, and games are started and completed | To recommend appropriate next content |
| Session information | Session start time, session duration, date of use | To generate progress reports for parents |
| Device information | Device type (e.g., tablet, phone), operating system version, screen size | To render the application correctly on the child's device |
| Gamification data | Experience points, levels, streaks, and in-app currency balances (no real money) | To provide motivational feedback and track progress |
| AI safety events | Records of content moderation actions | To ensure child safety and enforce content policies |
| Voice and audio data (biometric) | Audio recordings of pronunciation exercises may be transmitted to an approved speech provider for real-time analysis. Koydo does not keep the source recording after processing. Provider-side handling depends on the approved service and verified account settings. A voice recording is personal information when it is a biometric identifier that can be used for automated or semi-automated recognition of an individual. | To evaluate pronunciation accuracy in language learning exercises. Requires separate parental consent and a current provider evidence gate for children under 13 (see Section 2.8). |
We do NOT collect the following from children under 13:
- Email addresses belonging to the child
- Precise geolocation
- Photographs or videos stored on our servers
- Persistent source audio recordings on Koydo servers after voice processing is complete
- Social media identifiers
- Advertising identifiers or persistent tracking identifiers
- Any data for behavioral advertising
2.3 Information Collected When Koydo Intelligence Is Enabled (Opt-In)
Koydo Intelligence ("KI") is an optional feature that parents may enable or disable at any time. When KI is enabled, we collect additional behavioral signals through our Koydo Intelligence system to provide an adaptive, personalized learning experience. These signals are described in full in Section 6 of this policy.
KI is off by default for children under 13. A parent must affirmatively opt in to KI, and the parent is presented with a separate, specific disclosure of what KI collects before enabling it. The parent may disable KI at any time from the Parent Dashboard, and upon disabling, all Koydo Intelligence signal data associated with the child is scheduled for deletion within 30 days.
2.4 How We Use Children's Information
We use information collected from children exclusively for the following purposes:
- Providing the educational service: Delivering lessons, quizzes, games, and learning activities appropriate to the child's age and skill level.
- Tracking learning progress: Generating progress reports visible to the child and parent.
- Adaptive learning (KI only): When KI is enabled, adjusting content difficulty, pacing, modality, and presentation based on the child's observed learning patterns.
- Safety and moderation: Monitoring AI-assisted interactions for safety and content policy compliance.
- Service improvement: Analyzing aggregated, de-identified usage patterns to improve our educational content and platform. No child's data is individually identifiable in these analyses.
We do NOT use children's information for:
- Behavioral advertising or targeted advertising of any kind
- Sale to third parties
- Creating public profiles or social networking features
- Any purpose unrelated to the educational service
2.5 Disclosure of Children's Information
We do not sell children's personal information. We do not disclose children's personal information to third parties except as follows:
- Service providers (with separate parental consent for AI disclosure): Certain AI features may use OpenAI, Anthropic, or Google Gemini. Separate parental consent is necessary but not sufficient: Koydo's child-safe router also requires current private evidence of contract coverage, provider data-use terms, retention controls, and matching account settings. If no provider passes that review, the child-facing AI feature is unavailable rather than routed to an unverified provider.
- Content-generation providers that do not receive child personal data: ElevenLabs may render approved Koydo-authored lesson narration, and fal.ai may generate staff-authored creative assets. These flows do not include a child's account data, conversation, uploaded audio, or other child personal information.
- Infrastructure providers (no separate consent required — essential to service operation):
- Supabase — Database hosting and authentication. Processes account and learning data as essential infrastructure under applicable data-processing terms.
- Sentry — Error monitoring. Receives minimized crash metadata only. Koydo removes user identity, request data, learner content, breadcrumbs, custom context, and attachments before transmission for every user; automatic session tracking, session replay, and performance traces are disabled.
- Providers that do NOT receive child data:
- Stripe and RevenueCat — Payment processing for adult account holders only.
- Mixpanel — Optional product analytics integration, disabled in the current linked web configuration. If enabled later, it requires a known adult active profile and analytics consent.
- Vercel Analytics — Optional web analytics are blocked for active profiles known to be under 18. Anonymous visitors have no verified account age and must select adult mode and consent before the analytics scripts load.
- Legal requirements: We may disclose information when required by law, subpoena, court order, or government request.
- Safety: We may disclose information when we believe in good faith that disclosure is necessary to protect the safety of a child.
2.6 Parent Rights Under COPPA
If you are the parent or legal guardian of a child under 13 using Koydo, you have the right to:
- Review your child's data: Access a complete summary of all personal information Koydo has collected from your child, available through the Parent Dashboard or by emailing privacy@koydo.app.
- Delete your child's data: Request deletion of all personal information collected from your child. You may do this through the Parent Dashboard ("Manage Child's Data" > "Delete All Data") or by emailing privacy@koydo.app. The live account purge is scheduled within 14 days of your confirmed request. Restricted rotating backups and security logs expire on their provider schedules and are not returned to ordinary use.
- Disable Koydo Intelligence: Turn off KI at any time from the Parent Dashboard. Upon disabling, Koydo Intelligence signal data will be deleted within 30 days.
- Export your child's data: Download a machine-readable (JSON) export of all data associated with your child's account from the Parent Dashboard.
- Revoke consent entirely: Withdraw your consent for Koydo to collect personal information from your child. Koydo revokes refresh sessions and stops new collection; an already-issued access token can remain valid for up to one hour before it expires. After a 14-day grace period (during which you may reverse your decision), Koydo purges the live account. Restricted rotating backups and security logs then age out on their provider schedules.
- Consent to collection without consenting to disclosure: You may consent to Koydo's collection and use of your child's information without consenting to disclosure to third parties. Note that declining disclosure to essential service providers may limit the availability of certain features (such as AI-powered tutoring, which requires an AI model provider).
To exercise any of these rights, visit the Parent Dashboard or contact us at privacy@koydo.app. We will verify your identity as the child's parent before fulfilling any request.
2.7 What Children Can Access Without Parental Consent
Before a parent provides consent, a child may browse Koydo's course catalog and read course descriptions. These activities do not involve the collection of personal information. All features that involve data collection are locked until parental consent is verified.
2.8 Separate Consent for Third-Party AI Disclosure (COPPA Amended Rule)
Under the amended COPPA Rule, whose general compliance date was April 22, 2026, operators must obtain separate, specific parental consent before disclosing a child's personal information to third parties unless the disclosure is integral to the website or online service. This consent is distinct from consent for the operator's own collection and use.
Koydo implements this requirement as follows:
- Two-part consent process: During the Verifiable Parental Consent flow, parents are presented with two distinct consent decisions:
- General consent: Consent for Koydo to collect and use the child's personal information as described in Sections 2.2 through 2.4 of this policy. This enables core platform features (lessons, quizzes, games, progress tracking) that do not involve third-party data disclosure.
- AI disclosure consent: Separate, specific consent for Koydo to transmit the child's personal information to an AI provider named in Section 2.5 for the purpose described at consent time. A provider must also pass Koydo's private evidence gate before the feature can send child personal data.
- Consent without disclosure: A parent may consent to Koydo's collection and use of the child's data (general consent) without consenting to third-party AI disclosure. In this case:
- The child can use all non-AI features: lessons, quizzes, games, flashcards, progress tracking, and all offline-capable learning content.
- AI-powered features (AI tutoring, pronunciation exercises, photo tutor, AI-generated content) will be unavailable.
- The parent may grant AI disclosure consent at any time from the Parent Dashboard.
- Revocation: A parent may revoke AI disclosure consent at any time from the Parent Dashboard without affecting general consent. Upon revocation, AI features are immediately disabled for the child. Koydo deletes its own associated records and submits provider-side deletion where a provider stored an addressable record.
- Named third parties: The providers eligible for private review are AI assistance provider | Optional tutoring and safety assistance | United States | Yes, only as needed to provide the feature |
| Supabase | Database and authentication hosting | Account data, learning data, profiles | Essential infrastructure; child data is protected by access controls and row-level security |
| OpenAI | AI tutoring, content generation, moderation, and some voice services | API inputs and outputs for enabled features | Child personal data is fail-closed behind separate consent and a private evidence gate; DPA executed March 19, 2026 |
| Anthropic | Alternate AI model | API inputs and outputs for enabled features | Child personal data is disabled unless private contract and configuration evidence is current |
| Google (Gemini and Google Cloud AI services) | Alternate AI and voice services | API inputs and outputs for enabled features | Child personal data is disabled unless private contract, paid-service, and configuration evidence is current |
<!-- Removed: xAI/Grok — regulatory risk for child-serving platform. DO NOT RE-ENABLE. -->
| ElevenLabs | Text-to-speech and approved narration rendering | Text submitted for an enabled narration flow; no audio input | Child personal data is blocked; approved Koydo-authored narration may be rendered |
| fal.ai | Staff-operated image generation | Staff-authored image prompts | Admin-only route; no child personal data |
| Stripe | Payment processing | Payment card information, billing details | Adult account holders only |
| RevenueCat | Mobile subscription management | Subscription status, purchase receipts | Adult purchase relationship only |
| Vercel | Web hosting and optional performance measurement | Essential network data for hosting; aggregated analytics for eligible users | Optional analytics are blocked for active profiles known to be under 18; anonymous visitors must select adult mode and consent |
| Mixpanel | Optional product analytics, currently disabled | Usage events and feature interactions if enabled | Requires a known adult active profile and consent; minors, anonymous visitors, unresolved profiles, and opt-outs are blocked |
| Sentry | Error monitoring | Minimized crash metadata and stack locations | User identity, request data, learner content, breadcrumbs, custom context, attachments, automatic session tracking, session replay, and performance traces are blocked at the source for every user |
Important notes regarding child data and third-party processors:
- Koydo does not opt API content into provider model training. Provider retention is service-specific: standard commercial API terms may permit limited retention for safety or service operation, while enhanced retention controls require separate eligibility, configuration, or agreement. Koydo claims zero retention only when current evidence covers the exact service and account.
- Child-safe AI routing is fail-closed. A provider cannot receive child personal data merely because it is available as an adult-route fallback.
- Mixpanel analytics are disabled in the current linked web configuration. The guarded integration blocks minors, anonymous visitors, unresolved profile ages, consent withdrawal, and opt-out transitions before wrapper events can send.
- Stripe and RevenueCat process payment data only for adult account holders. Children do not have a direct payment relationship with Koydo.
- ElevenLabs may receive text for live narration on eligible non-child routes and may render approved Koydo-authored narration. Koydo does not send it a user's audio recording through these flows.
Sub-processors and change notifications. The processors listed above retain their own sub-processors (for example, Supabase uses AWS; Vercel uses Cloudflare and AWS). The current authoritative list of Koydo direct processors and their material sub-processors — together with a free email subscription to be notified of additions or replacements — is published at /legal/subprocessors. Where a User or Institutional customer reasonably objects to a new sub-processor within thirty (30) days of notice, Koydo will work in good faith to address the objection, including by offering an alternative arrangement or, where no reasonable alternative exists, terminating the affected service for that customer.
Plain-language summary
8. Data Retention
We retain different categories of data for different periods, based on the purpose of collection and applicable legal requirements.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account information (email, display name, birth date, grade) | Lifetime of account | Necessary to provide the service |
| Learning progress (lesson completion, skill mastery, quiz scores) | Lifetime of account | Core educational record |
| Gamification data (XP, levels, streaks, currency) | Lifetime of account | Part of the learning experience |
| AI tutor conversations — under 13 (Children) | 30 days from creation | COPPA data-minimization (16 C.F.R. § 312.7); shortest period sufficient for safety, abuse detection, and dispute resolution |
| AI tutor conversations — 13–17 (Teens) | 90 days from creation | Sufficient for safety review and pedagogical continuity |
| AI tutor conversations — 18+ (Adults) | 12 months from creation | Sufficient for context continuity and dispute resolution |
| Koydo Intelligence raw signal events | 1 year from creation | Necessary for longitudinal adaptive learning analysis |
| Koydo Intelligence session snapshots | 90 days from creation | Short-term adaptive decision-making |
| Koydo Intelligence learner profiles (aggregated composites) | Lifetime of account (deleted upon request or account deletion) | Long-term personalization |
| Koydo Intelligence interventions (pedagogical actions) | 1 year from creation | Evaluating effectiveness of learning adaptations |
| Session records (study sessions) | 1 year from creation | Progress reporting and analytics |
| AI safety and moderation events | 1 year from creation | Safety audit trail and regulatory compliance |
| Direct messages | Lifetime of account | User communication record |
| Payment and financial records | 7 years from transaction | Tax and financial regulatory compliance |
| Legal evidence (consent records, policy acceptances, IP at consent) | Indefinite | Legal compliance and audit trail |
| Deletion audit logs (anonymized, no PII) | Indefinite | Verification that deletion was executed |
| Device login information | Until consumed or expired | Temporary; used only for device login flow |
| Koydo Distill voice recordings | Not retained | Process-and-discard; no server storage |
| Pronunciation exercise audio | Not retained by Koydo after processing | External processing is enabled only under the consent and provider-evidence controls described in Section 2.8; provider-side retention is service-specific |
| Koydo Distill transcripts and notes | Lifetime of account | User-created content |
Upon account deletion:
- Adult and teen self-service requests use a cancellable 30-day grace period. Parent-confirmed child requests use a 14-day grace period. Verified GDPR erasure requests are queued without a grace period, and institutional requests are processed within 30 days.
- After the live account is purged, restricted rotating database backups and provider security logs may retain copies or request metadata until their scheduled expiry. They are not returned to ordinary use. If a backup is restored for disaster recovery, deletion requests must be reapplied before restored data can return to ordinary use.
- Supabase Storage objects are deleted separately through the Storage API and are not included in Supabase database backups.
- Financial records are anonymized (user identifiers removed) and retained for the legally required period.
- Deletion audit records are retained in anonymized form (no personal identifiers) to verify that deletion was properly executed.
- Koydo submits provider-side deletion for addressable records created through a provider API. For stateless API calls without a user-keyed provider record, retention follows the provider's applicable terms and verified account settings; Koydo records cleanup successes, failures, and documented skips.
Legal hold exception. The retention periods above may be extended only for specific User accounts subject to a documented written legal hold (active dispute, regulatory inquiry, court order, subpoena, or formal claim). Legal holds are issued through a documented internal process; they apply only to the specific account(s) implicated; they auto-expire when the trigger event closes; and they do not justify general retention beyond the periods stated above for any other User. The "dispute resolution" rationale alone does not authorize indefinite retention.
Plain-language summary
9. Data Security
We implement technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Koydo maintains a formal Written Information Security Program as required by COPPA 16 C.F.R. § 312.8. A summary of our security measures follows; the full program document is available upon request to privacy@koydo.app.
9.1 Encryption
- In transit: All data transmitted between your device and Koydo's servers is encrypted using TLS 1.2 or higher.
- At rest: All data stored in our databases is encrypted at rest using AES-256 encryption.
- Payment data: All payment processing is handled by Stripe, which is PCI DSS Level 1 certified. Koydo never stores, processes, or transmits raw payment card data on its own servers.
9.2 Access Controls
- Access to user data is restricted to authorized personnel on a need-to-know basis.
- Administrative access to production systems requires multi-factor authentication.
- All access to child data is logged and auditable.
9.3 AI Safety Architecture
- All AI interactions involving children pass through a multi-layer safety system including content moderation, persona safety constraints, and fail-closed circuit breakers.
- If the moderation system is unavailable, AI features are automatically disabled (fail-closed design).
- AI safety events are logged for audit and review.
9.4 SOC 2 Compliance
Koydo is pursuing SOC 2 Type II certification. Our infrastructure provider (Supabase/AWS) maintains SOC 2 Type II certification. We will update this policy when Koydo's own SOC 2 certification is achieved.
9.5 Breach Notification
In the event of a data breach affecting personal information:
- We will notify affected users (or parents, in the case of children) without undue delay and in any event within 72 hours of becoming aware of the breach.
- We will notify the Federal Trade Commission and any applicable state attorneys general as required by law.
- For EU users, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33.
- Notification will include: the nature of the breach, the categories of data affected, likely consequences, and measures taken to address the breach.
Plain-language summary
10. Your Rights
10.1 All Users
Regardless of age or location, all Koydo users (or their parents, for children) have the right to:
- Access: Request a copy of all personal information we hold about you.
- Correction: Request correction of inaccurate personal information.
- Deletion: Request deletion of your account and associated personal information.
- Export: Download your data in a machine-readable format (JSON).
- Opt out of analytics: Disable optional analytics collection at any time.
10.2 Parents of Children Under 13 (COPPA Rights)
See Section 2.6 for a complete description of parental rights, including the right to review, delete, export, disable KI, and revoke consent.
10.3 California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"):
CCPA core rights:
- Right to know. Request a copy of the personal information we have collected about you, the categories of sources, the purposes of collection, and the categories of third parties with whom we share it.
- Right to correct. Request correction of inaccurate personal information.
- Right to delete. Request deletion of your personal information, subject to limited statutory exceptions.
- Right to opt out of sale or share. Koydo does not sell or share personal information for cross-context behavioral advertising. We nevertheless honor "Do Not Sell or Share My Personal Information" requests at /legal/do-not-sell.
- Right to non-discrimination. We will not deny service, charge a different price, or provide a different level of service because you exercised any of these rights.
CPRA additional rights (effective for all Koydo California Users):
- Right to limit use and disclosure of Sensitive Personal Information. California recognizes certain categories of personal information as "sensitive" — including precise geolocation, biometric identifiers used for unique identification, health information, racial or ethnic origin, religious beliefs, contents of mail or messages, financial-account credentials, sex life or sexual orientation, and the fact that an individual is a minor. You may direct Koydo to use Sensitive Personal Information only for the purposes that are reasonably necessary to provide the Service and for the additional purposes permitted by Cal. Civ. Code § 1798.121(b). To exercise this right, visit /legal/limit-sensitive-pi.
- Right to opt out of profiling and automated decision-making with significant effect. Where Koydo uses automated processing — for example, the Koydo Intelligence behavioral signal system that informs adaptive learning decisions described in Section 6 — you may opt out of having that processing applied to your account. When you opt out, Koydo serves a non-personalized version of the adaptive learning experience. You can opt out at any time in Account Settings.
- Right to information about automated decision-making logic. You may request meaningful information about the logic involved in any automated decision, the significance of the processing, and the envisioned consequences. Koydo's authoritative disclosure of its automated decision-making logic — the Koydo Intelligence signal taxonomy, derived indices, and how the indices are used — is published at /legal/automated-decisions.
To exercise any of these rights, contact us at privacy@koydo.app or use the controls in your account settings. We respond within forty-five (45) calendar days, with one forty-five-day extension where reasonably necessary, in line with CCPA § 1798.130.
10.4 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following additional rights, in each case as recognized by the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the United Kingdom General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR"), and the Swiss Federal Act on Data Protection (revised effective 1 September 2023, "FADP"):
- Right of access (Art. 15) — request a copy of your personal data.
- Right to rectification (Art. 16) — correct inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17) — request deletion in the circumstances specified by law.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format (we provide JSON).
- Right to object (Art. 21) — object to processing based on legitimate interest, including profiling.
- Right not to be subject to a decision based solely on automated processing (Art. 22) where the decision produces legal or similarly significant effects.
- Right to withdraw consent at any time for processing based on consent (Art. 7(3)).
- Right to lodge a complaint with your local supervisory authority. EEA Users may identify their authority at edpb.europa.eu; UK Users may contact the Information Commissioner's Office at ico.org.uk; Swiss Users may contact the Federal Data Protection and Information Commissioner at edoeb.admin.ch.
Legal bases for processing. Koydo processes personal data under the following lawful bases identified by Art. 6 GDPR and corresponding provisions of UK GDPR and FADP: contract performance (delivering the Service you signed up for); legitimate interest (adaptive learning, platform security, service improvement, fraud prevention, debugging); consent (Koydo Intelligence opt-in, optional analytics, marketing-showcase use of co-created content per TOS § 8.4(c)); and legal obligation (child safety, financial recordkeeping, regulator response). For each processing activity, the applicable legal basis is recorded in our internal Article 30 record of processing activities, available to supervisory authorities on request.
Privacy Team. Koydo's Privacy Team is the single point of contact for data-protection inquiries and is reachable at privacy@koydo.app. Koydo does not currently designate a named individual as Data Protection Officer; if Koydo becomes required to maintain a formal DPO under GDPR Article 37, the appointment will be reflected in this Section.
EU / UK Article 27 Representatives — pending. Koydo has not yet appointed representatives under GDPR Article 27 or UK GDPR Article 27. The status of these appointments is published at the international transfer notice and will be updated when appointments are made. Pending appointment, EEA and UK data subjects may contact Koydo's Privacy Team directly at privacy@koydo.app. EEA data subjects retain the right to lodge a complaint with the supervisory authority of their habitual residence; UK data subjects retain the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.
Cross-border transfers. Your personal data is transferred to and processed in the United States. Koydo relies on the following transfer mechanisms, each documented and available for inspection at the international transfer notice:
- EU SCCs — the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, Modules 2 (Controller-to-Processor) and 3 (Processor-to-Processor), as appropriate to the processing relationship;
- UK Addendum to the EU SCCs — the International Data Transfer Addendum issued by the UK Information Commissioner's Office (version B1.0, in force 21 March 2022), which incorporates the EU SCCs into UK law for transfers from the United Kingdom; and
- Swiss FADP addendum — the supplementary clauses recognized by the Swiss Federal Data Protection and Information Commissioner for transfers from Switzerland.
Koydo has performed transfer impact assessments addressing FISA Section 702, Executive Order 12333, and the EU-U.S. Data Privacy Framework. Koydo's certification status under the Data Privacy Framework, where applicable, is published at the international transfer notice.
Member-state age thresholds. For Users in EU member states where the GDPR parental-consent age threshold is higher than 13 (Art. 8 GDPR and member-state implementations), Koydo applies the stricter threshold. Examples: Germany and the Netherlands require parental consent up to age 16; France up to age 15. Users in the United Kingdom are governed by the UK GDPR's age 13 threshold and the UK Age Appropriate Design Code (Children's Code) standards.
Plain-language summary
11. International Users and Cross-Border Transfers
Koydo is based in the United States. If you access the Service from outside the United States, your data will be transferred to, stored in, and processed in the United States and any other country where Koydo or its processors operate.
- EEA Users: Where a transfer requires a Chapter V safeguard, Koydo relies on the EU Standard Contractual Clauses (Decision 2021/914) or another lawful mechanism applicable to the specific service. Provider-level status is maintained in Koydo's private contract register and described at the international transfer notice.
- UK Users: Transfers from the United Kingdom to the United States are made pursuant to the UK Addendum to the EU SCCs (B1.0, 21 March 2022), adopted by the Information Commissioner's Office, executed alongside the EU SCCs above. Alternatively, where executed separately with a processor, Koydo relies on the UK International Data Transfer Agreement (IDTA).
- Swiss Users: Transfers from Switzerland to the United States rely on the EU SCCs as supplemented by the FADP-specific addendum recognized by the Swiss Federal Data Protection and Information Commissioner.
- Sub-processor transfers: Koydo requires applicable flow-down data-protection obligations before a provider processes Customer Personal Data. The current sub-processor list is at /legal/subprocessors.
- AI model providers: Commercial API terms generally prohibit training on customer API content unless the customer opts in. Retention and transfer safeguards vary by product and account configuration; child personal data remains blocked unless evidence for the exact provider flow is current.
If you would like a copy of the executed transfer mechanism for a specific data flow, contact privacy@koydo.app — Koydo will provide the document or a redacted summary within thirty (30) days.
Plain-language summary
12. Changes to This Policy
12.1 What Counts as a "Material Change"
A change to this Privacy Policy is material if it touches any of the following:
- Categories of personal data Koydo collects;
- Identity of Koydo's processors or sub-processors;
- Data retention periods;
- User rights or how to exercise them;
- Any provision specifically governing Children, Teens, or Parents;
- Security commitments or breach-notification timelines;
- International transfer mechanisms; or
- Lawful bases for processing.
Non-material changes — typographical fixes, formatting, restructuring, and clarifying language that does not alter rights or obligations — may be published without advance notice. The version and effective date at the top of this policy will be updated.
12.2 Notice Process for Material Changes
For material changes affecting adults (18+) and teens (13–17), Koydo provides at least thirty (30) days' advance notice via:
- Email to the address associated with your account; and
- In-app notification displayed prominently within the Service; and
- A one-click "review changes" page summarizing what changed and why.
Continued use after the effective date constitutes acceptance. You may decline by closing your account before the effective date.
12.3 Children Under 13 — Re-Verifiable-Parental-Consent
For material changes affecting any provision governing Children under 13 — including changes to data categories, processors, retention periods, or children-specific rights — Koydo will, consistent with 16 C.F.R. § 312.5, re-obtain Verifiable Parental Consent before the change applies to existing Child Profiles. Until re-consent is obtained from a Parent, the previously-consented practices remain in effect for that Child Profile. If a Parent does not respond, the affected Child Profile remains on the previously-consented practices; Koydo will not silently default to the new practices.
12.4 Legally-Required Changes
Changes required by law, regulation, court order, or regulator directive may be implemented with shorter notice or with immediate effect. The reason and effective date will be described in this policy or the accompanying notice.
Plain-language summary
13. How to Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, you may contact us at:
KOYDO LLC
940 W. FM 544 #332
Wylie, Texas 75098-5157
United States
Telephone: +1 (214) 218-6693
Email: privacy@koydo.app
| Inquiry type | Email | Subject line | Response window |
|---|---|---|---|
| General privacy inquiry | privacy@koydo.app | Privacy Inquiry | 30 days |
| COPPA parental request (under 13) | privacy@koydo.app | COPPA Parent Request | 14 days |
| GDPR / UK GDPR / FADP request | privacy@koydo.app | GDPR Data Request | 30 days (extendable by 60 per Art. 12(3)) |
| CCPA / CPRA request | privacy@koydo.app | CCPA Request | 45 days (extendable by 45) |
| FERPA / school request | privacy@koydo.app | School Data Request | 30 days |
| Data breach concern | privacy@koydo.app | Security Incident | Without undue delay |
Privacy Team. Koydo's Privacy Team is the single point of contact for data-protection matters and is reachable at privacy@koydo.app. Koydo does not currently designate a named individual as Data Protection Officer in this Privacy Policy; if Koydo is required to maintain a formal DPO under GDPR Article 37, the appointment will be reflected in this Section.
EU / UK Article 27 Representatives — pending appointment. EEA and UK data subjects may contact the Privacy Team directly at privacy@koydo.app while these appointments are pending. The current status is at the international transfer notice.
Koydo Privacy Policy v2026-07-11 — Effective July 11, 2026 — supersedes v2026-05-09
Plain-language summary