This section applies to users under the age of 13. Koydo complies with the Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. 6501-6506, and the Federal Trade Commission's implementing rule at 16 C.F.R. Part 312, including the Amended Rule effective April 22, 2026, which expands the definition of personal information to include biometric identifiers (such as voiceprints) and requires separate parental consent for third-party disclosure of children's personal information.
2.1 Parental Consent Is Required
We do not knowingly collect personal information from children under 13 without first obtaining verifiable parental consent. Before a child can use any feature of Koydo that involves the collection of personal information, a parent must:
- Create a parent account and add the child as a Student Profile.
- Provide the child's birth date (used solely to determine applicable age protections).
- Review a consent notice describing our data practices.
- Verify consent through our Verifiable Parental Consent (VPC) process, which involves an email confirmation sent to the parent's verified email address, containing a summary of data practices and a signed confirmation link.
A child's participation in Koydo is never conditioned on the disclosure of more personal information than is reasonably necessary to participate in the Service.
2.2 Information We Collect from Children (Default Mode)
When a parent provides consent, we collect the following information in default mode (without Koydo Intelligence enabled):
| Category | Specific Data | Purpose |
|---|---|---|
| Account information | Child's display name, age, grade level | To create and maintain the child's learning profile |
| Parent contact | Parent's email address (not the child's) | To communicate with the parent about the child's account and obtain consent |
| Learning progress | Lesson completion status, quiz and game scores, skill mastery levels | To track educational progress and present it to the parent and child |
| Content interaction events | Which lessons, activities, and games are started and completed | To recommend appropriate next content |
| Session information | Session start time, session duration, date of use | To generate progress reports for parents |
| Device information | Device type (e.g., tablet, phone), operating system version, screen size | To render the application correctly on the child's device |
| Gamification data | Experience points, levels, streaks, and in-app currency balances (no real money) | To provide motivational feedback and track progress |
| AI safety events | Records of content moderation actions | To ensure child safety and enforce content policies |
| Voice and audio data (biometric) | Audio recordings of pronunciation exercises, transmitted to our AI speech provider for real-time analysis. Audio is processed and immediately discarded — it is never stored on Koydo servers or the provider's servers. Under the COPPA Amended Rule (April 22, 2026), voice recordings constitute biometric identifiers and are personal information. | To evaluate pronunciation accuracy in language learning exercises. Requires separate parental consent for third-party AI disclosure (see Section 2.8). |
We do NOT collect the following from children under 13:
- Email addresses belonging to the child
- Precise geolocation
- Photographs or videos stored on our servers
- Persistent audio recordings (voice data for pronunciation exercises is transmitted, processed, and immediately discarded — never stored)
- Social media identifiers
- Advertising identifiers or persistent tracking identifiers
- Any data for behavioral advertising
2.3 Information Collected When Koydo Intelligence Is Enabled (Opt-In)
Koydo Intelligence ("KI") is an optional feature that parents may enable or disable at any time. When KI is enabled, we collect additional behavioral signals through our Koydo Intelligence system to provide an adaptive, personalized learning experience. These signals are described in full in Section 6 of this policy.
KI is off by default for children under 13. A parent must affirmatively opt in to KI, and the parent is presented with a separate, specific disclosure of what KI collects before enabling it. The parent may disable KI at any time from the Parent Dashboard, and upon disabling, all Koydo Intelligence signal data associated with the child is scheduled for deletion within 30 days.
2.4 How We Use Children's Information
We use information collected from children exclusively for the following purposes:
- Providing the educational service: Delivering lessons, quizzes, games, and learning activities appropriate to the child's age and skill level.
- Tracking learning progress: Generating progress reports visible to the child and parent.
- Adaptive learning (KI only): When KI is enabled, adjusting content difficulty, pacing, modality, and presentation based on the child's observed learning patterns.
- Safety and moderation: Monitoring AI-assisted interactions for safety and content policy compliance.
- Service improvement: Analyzing aggregated, de-identified usage patterns to improve our educational content and platform. No child's data is individually identifiable in these analyses.
We do NOT use children's information for:
- Behavioral advertising or targeted advertising of any kind
- Sale to third parties
- Creating public profiles or social networking features
- Any purpose unrelated to the educational service
2.5 Disclosure of Children's Information
We do not sell children's personal information. We do not disclose children's personal information to third parties except as follows:
- Service providers (with separate parental consent for AI disclosure): Certain features require transmitting children's data to the following specific third-party AI providers. Under the COPPA Amended Rule, we obtain separate parental consent before disclosing children's personal information to these third parties (see Section 2.8):
- OpenAI — AI tutoring conversations, content moderation checks, and pronunciation analysis (speech-to-text via Whisper API). Zero data retention (ZDR) enabled; data is processed and immediately discarded.
- Anthropic — Alternative AI tutoring model. Zero data retention enabled.
- Google (Gemini API) — Alternative AI tutoring model. Zero data retention enabled.
- ElevenLabs — Text-to-speech voice generation for read-aloud features. Only text prompts are sent (no child personal data).
- fal.ai — AI image generation for creative activities. Only text prompts are sent (no child personal data).
- Infrastructure providers (no separate consent required — essential to service operation):
- Supabase — Database hosting and authentication. Processes all account and learning data under DPA.
- Sentry — Error monitoring. Receives error logs with PII automatically scrubbed before transmission.
- Providers that do NOT receive child data:
- Stripe and RevenueCat — Payment processing for adult account holders only.
- Mixpanel — Product analytics, blocked for all users under 18.
- Vercel Analytics — Web performance metrics, blocked for all users under 15.
- Legal requirements: We may disclose information when required by law, subpoena, court order, or government request.
- Safety: We may disclose information when we believe in good faith that disclosure is necessary to protect the safety of a child.
2.6 Parent Rights Under COPPA
If you are the parent or legal guardian of a child under 13 using Koydo, you have the right to:
- Review your child's data: Access a complete summary of all personal information Koydo has collected from your child, available through the Parent Dashboard or by emailing privacy@koydo.app.
- Delete your child's data: Request deletion of all personal information collected from your child. You may do this through the Parent Dashboard ("Manage Child's Data" > "Delete All Data") or by emailing privacy@koydo.app. Deletion will be completed within 14 days of your confirmed request.
- Disable Koydo Intelligence: Turn off KI at any time from the Parent Dashboard. Upon disabling, Koydo Intelligence signal data will be deleted within 30 days.
- Export your child's data: Download a machine-readable (JSON) export of all data associated with your child's account from the Parent Dashboard.
- Revoke consent entirely: Withdraw your consent for Koydo to collect personal information from your child. Upon revocation, the child's account will be immediately deactivated. After a 14-day grace period (during which you may reverse your decision), all personal information will be permanently deleted.
- Consent to collection without consenting to disclosure: You may consent to Koydo's collection and use of your child's information without consenting to disclosure to third parties. Note that declining disclosure to essential service providers may limit the availability of certain features (such as AI-powered tutoring, which requires an AI model provider).
To exercise any of these rights, visit the Parent Dashboard or contact us at privacy@koydo.app. We will verify your identity as the child's parent before fulfilling any request.
2.7 What Children Can Access Without Parental Consent
Before a parent provides consent, a child may browse Koydo's course catalog and read course descriptions. These activities do not involve the collection of personal information. All features that involve data collection are locked until parental consent is verified.
2.8 Separate Consent for Third-Party AI Disclosure (COPPA Amended Rule)
Effective April 22, 2026, the COPPA Amended Rule requires operators to obtain separate, specific parental consent before disclosing a child's personal information to third parties, distinct from consent for the operator's own collection and use.
Koydo implements this requirement as follows:
- Two-part consent process: During the Verifiable Parental Consent flow, parents are presented with two distinct consent decisions:
- General consent: Consent for Koydo to collect and use the child's personal information as described in Sections 2.2 through 2.4 of this policy. This enables core platform features (lessons, quizzes, games, progress tracking) that do not involve third-party data disclosure.
- AI disclosure consent: Separate, specific consent for Koydo to transmit the child's personal information to the third-party AI providers named in Section 2.5 (OpenAI, Anthropic, Google Gemini) for the purpose of AI-powered tutoring, pronunciation analysis, and content moderation.
- Consent without disclosure: A parent may consent to Koydo's collection and use of the child's data (general consent) without consenting to third-party AI disclosure. In this case:
- The child can use all non-AI features: lessons, quizzes, games, flashcards, progress tracking, and all offline-capable learning content.
- AI-powered features (AI tutoring, pronunciation exercises, photo tutor, AI-generated content) will be unavailable.
- The parent may grant AI disclosure consent at any time from the Parent Dashboard.
- Revocation: A parent may revoke AI disclosure consent at any time from the Parent Dashboard without affecting general consent. Upon revocation, AI features are immediately disabled for the child, and a deletion request is sent to all AI providers.
- Named third parties: The specific third-party AI providers to which data may be disclosed are: OpenAI, Inc. (AI tutoring, pronunciation analysis via Whisper API, content moderation), AI assistance provider | Optional alternate tutoring assistance | United States | Yes, only as needed to provide the feature |
| Supabase | Database and authentication hosting | All account data, learning data, profiles | Yes | DPA signed |
| OpenAI | AI tutoring, content generation, moderation | AI conversation text, moderation checks | Yes (with parental consent; zero data retention enabled) | DPA signed 2026-03-19; COPPA-specific assurance requested, pending |
| Anthropic | AI tutoring (alternate model) | AI conversation text | Yes (with parental consent; zero data retention enabled) | DPA pending |
| Google (Gemini API) | AI tutoring (alternate model) | AI conversation text | Yes (with parental consent; zero data retention enabled) | DPA pending |
<!-- Removed: xAI/Grok — regulatory risk for child-serving platform. DO NOT RE-ENABLE. -->
| ElevenLabs | Audio asset pre-generation only (server-side text-to-speech, generating static audio files baked into Koydo content; not used for live, per-user AI traffic) | Koydo-authored scripts only; no User personal data is sent | No — content tooling, not a User-data processor | DPA pending (best-practice; not COPPA/GDPR-blocking because no User data flows) |
| fal.ai | AI image generation | Text prompts for image generation | Limited (text prompts only; no child personal data sent; requires AI disclosure consent for under-13) | DPA pending |
| Stripe | Payment processing | Payment card information, billing details | No (adults only) | DPA signed |
| RevenueCat | Subscription management (mobile) | Subscription status, purchase receipts | No (adults only) | DPA signed |
| Vercel | Web hosting and performance analytics | Web performance metrics, IP addresses (anonymized) | No (blocked for users under 18 via age-gated analytics) | DPA signed |
| Mixpanel | Product analytics | Usage events, feature interactions | No (blocked for users under 18) | DPA signed |
| Sentry | Error monitoring | Error logs, stack traces (PII auto-scrubbed) | Limited (error data only; PII scrubbed by policy) | DPA signed |
Important notes regarding child data and third-party processors:
- All AI model providers that process child data operate under zero data retention (ZDR) agreements or configurations. This means conversational data sent to these providers is processed and immediately discarded by the provider; it is not stored, logged, or used for model training.
- Mixpanel analytics are completely blocked for all users under 18. No analytics events, device identifiers, or behavioral data are sent to Mixpanel for minors.
- Stripe and RevenueCat process payment data only for adult account holders. Children do not have a direct payment relationship with Koydo.
- We are actively completing DPA execution with all providers listed as "DPA pending." Until each pending DPA is executed, the corresponding provider is gated to non-child traffic where the gate is operationally feasible, or otherwise restricted to data flows protected by adequate technical controls (such as zero data retention).
- ElevenLabs is used only to pre-generate static audio assets that ship with Koydo content (server-side rendering of Koydo-authored scripts). It does not receive User personal data, AI conversations, or live per-User traffic. It is listed in the table for completeness; it is not a User-data processor.
Sub-processors and change notifications. The processors listed above retain their own sub-processors (for example, Supabase uses AWS; Vercel uses Cloudflare and AWS). The current authoritative list of Koydo direct processors and their material sub-processors — together with a free email subscription to be notified of additions or replacements — is published at /legal/subprocessors. Where a User or Institutional customer reasonably objects to a new sub-processor within thirty (30) days of notice, Koydo will work in good faith to address the objection, including by offering an alternative arrangement or, where no reasonable alternative exists, terminating the affected service for that customer.