Privacy Policy
Effective Date: January 1, 2025
Last Updated: January 16, 2025
Table of Contents
1. Introduction
K-12Buddy ("we," "our," or "us") is committed to protecting the privacy and security of our users, especially children under 13 years of age. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational platform.
We comply with all applicable data protection laws including:
- COPPA - Children's Online Privacy Protection Act (USA)
- FERPA - Family Educational Rights and Privacy Act (USA)
- GDPR - General Data Protection Regulation (EU)
- PIPEDA - Personal Information Protection and Electronic Documents Act (Canada)
- CCPA - California Consumer Privacy Act
2. Information We Collect
Information You Provide
- Parent/Guardian information: Name, email, phone number
- Student information: First name, grade level, age (no last names for children under 13)
- Educational data: Subjects of interest, learning goals, quiz responses
- Account credentials: Username and encrypted password
- Payment information: Processed securely through Stripe (we don't store card details)
Information Collected Automatically
- Usage data: Pages visited, features used, time spent
- Device information: Browser type, operating system (no device IDs for children)
- IP address: For security and geographic customization (anonymized for children)
- Cookies: Essential cookies only for children under 13
Note for Children Under 13: We collect minimal information and always require parental consent. We never collect more than necessary for educational purposes.
3. How We Use Information
We use collected information solely for educational purposes:
- Provide personalized learning experiences
- Track educational progress and generate reports for parents
- Respond to questions and provide homework help
- Send important account and safety notifications
- Improve our educational content and platform
- Ensure platform safety and prevent misuse
- Comply with legal obligations
We Never: Sell student data, use data for advertising, create marketing profiles, or share data with third parties for non-educational purposes.
4. Data Sharing and Disclosure
We share information only in these limited circumstances:
- With Parents/Guardians: Full access to their child's account and data
- Service Providers: Trusted partners who help operate our platform (under strict contracts)
- Legal Requirements: When required by law or to protect safety
- Business Transfers: If K-12Buddy is acquired (with continued privacy protection)
- With Consent: Only with explicit parental consent for children
All third parties are required to maintain the confidentiality and security of student data and can only use it to provide services to K-12Buddy.
5. Data Security
We implement industry-standard security measures:
Encryption
256-bit SSL encryption for all data transfers and AES encryption for stored data
Secure Hosting
SOC 2 certified data centers with 24/7 monitoring
Access Controls
Role-based access with multi-factor authentication for staff
Regular Audits
Annual security audits and penetration testing
6. Children's Privacy (COPPA Compliance)
We take special precautions to protect children under 13:
- We require verifiable parental consent before collecting any information
- Parents can review, update, or delete their child's information at any time
- We collect only information necessary for educational purposes
- No behavioral advertising or tracking
- No social features that allow children to publicly share information
- Automatic deletion of unnecessary data
Parental Rights Include:
- • Access to all child's data
- • Correct inaccurate information
- • Delete child's account and data
- • Refuse further data collection
- • Receive notices of any data breaches
7. Your Rights
Depending on your location, you have the following rights:
All Users
- • Access your personal information
- • Correct inaccurate data
- • Delete your account
- • Export your data
- • Opt-out of non-essential processing
EU Residents (GDPR)
- • Right to be forgotten
- • Data portability
- • Restrict processing
- • Object to processing
- • Lodge complaints with supervisory authorities
California Residents (CCPA)
- • Know what personal information is collected
- • Know if information is sold or disclosed
- • Say no to the sale of personal information
- • Equal service and price regardless of privacy choices
To exercise any of these rights, contact us at privacy@k12buddy.com or use the controls in your account settings.
8. Data Retention
We retain data only as long as necessary:
Data Type | Retention Period |
---|---|
Active Account Data | Duration of account + 30 days |
Educational Records | As required by FERPA (typically 3 years) |
Deleted Account Data | 30 days (for recovery), then permanently deleted |
Backup Data | 90 days rolling backups |
Basic Plan Storage | 30 days for user-generated content |
Parents can request immediate deletion of their child's data at any time.
9. International Users
K-12Buddy operates globally and processes data in the United States. By using our service, you consent to the transfer of your information to the U.S.
For EU users, we use Standard Contractual Clauses approved by the European Commission for data transfers. We also participate in the EU-U.S. Data Privacy Framework.
Canadian users are protected under PIPEDA, and we ensure all data handling meets Canadian privacy standards.
10. Contact Information
For privacy-related questions or to exercise your rights:
Data Protection Officer
K-12Buddy Privacy Team
Email: privacy@k12buddy.com
Phone: 1-800-K12-BUDDY
Address: 123 Education Way, Learning City, CA 90210
We respond to all privacy requests within 30 days (or sooner if required by applicable law).
Updates to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending email notification to parents/guardians
- Requiring consent for material changes affecting children under 13