Draft. This describes how the product actually behaves today, but it has not been reviewed by a lawyer. Anything marked like this still needs to be filled in. Don't rely on it as a final statement until that review has happened.
COPPA
Children's privacy · Last updated September 22, 2026
The short version
The product is built so that there is nothing to collect from a child. Students never create accounts. A student joins a class through a link a teacher shares and picks a nickname, and that nickname is the whole record. We do not ask a child for a name, an email address, a birthday, a photograph or a location, and there is nowhere in the product to put one.
What a student's record contains
- A nickname, and an address-bar version of it.
- The school and class it belongs to.
- A token that lets the same browser be recognised as the same nickname next time.
- A recovery code, so a teacher can restore that nickname on a new device.
- The apps made under that nickname, and the descriptions written to make them.
No persistent identifier is used for anything except keeping the student's own work together. There is no advertising, no analytics vendor, no tracking across sites, and no profile built from what a student does.
Consent
Students use the product at a school's direction, for the school's educational purpose. We rely on the school to decide which students use it and to supervise that use, and we collect nothing beyond what that use requires. [Confirm with counsel that we rely on the school to authorise use on parents' behalf, as the FTC permits for educational services used at a school's direction, and state the conditions - notice to parents, no commercial use - that this rests on. If the product is ever offered to children outside a school, that basis does not carry over.]
When a child types something personal
The one place a student writes free text is the description of the app they want. Before a description made through the guided builder reaches the AI model, it is screened for personal information — full names, addresses, phone numbers, anything that identifies a specific real person. If any is found, the build stops and asks for a reword. The explanation shown never repeats the personal information back, and the check fails closed: an unclear result blocks rather than passes.
[The screen does not currently run on the join-link flow a student uses from a class code. Either close that gap or say so plainly here before publishing.]
If you believe a child has entered personal information into the product anyway, tell us at [privacy contact address] and we will remove it.
Parents
A parent can see everything the product holds about their child by asking the school, which knows which nickname is which child — the product does not. The school can request a copy or a deletion from us, and a parent can refuse further use by telling the school, which can remove the student.
Individual workspaces
A tutor or parent using the product on their own account can also run a class. Apps made in that workspace — including by students who join one of its classes — are shared to the public library by default, attributed to the workspace and never to a student. The join page says so before a student types anything, and any app can be made private afterwards.
Who else sees a student's data
The description a student writes is sent to Anthropic's API to build the app; a student's nickname is not part of what is sent, and content sent through the API is not used to train models. Our hosting provider runs the machines. Nobody else. We do not sell, rent or share children's information with anyone for their own purposes.
See also: Privacy Policy · FERPA · State privacy laws · Questions: [privacy contact address]