Privacy Policy
Last updated: June 24, 2026
This Privacy Notice for Locked on Learning ("we," "us," or "our") describes how and why we collect, store, use, and share ("process") your information when you use our service ("Service") — including our parent dashboard at app.lockedonlearning.app (a Progressive Web App) and the Locked on Learning child app installed on a child's device. We built Locked on Learning to be private by design: children sign in with a Family Code and a PIN — never an email, last name, photo, or other personal contact information.
Summary of key points
- We collect a parent's email address and password (stored only as a cryptographic hash by our authentication provider) when you create an account, plus your name and an optional family name.
- For each child, a parent enters a first name, a grade level, learning-gate settings, and (optionally) emergency contact phone numbers. Children do not provide an email, last name, age, photo, or location.
- From the child's device we collect learning-gate activity — quiz attempts (subject and whether the answer was correct), lock/unlock events, screen-time, and device check-ins — to run the gate and show parents progress.
- We use OpenAI only to generate the quiz questions in a shared question bank, organized by grade and subject. We never send a child's name, identifier, scores, or any personal information to OpenAI.
- If you choose to subscribe to a paid plan, we will use Stripe to process payments — your card details are handled entirely by Stripe and we never see or store your full card number. Paid subscriptions are not yet available, so no payment information is collected today.
- We use Supabase for our database, authentication, storage, real-time sync, and serverless functions, and Resend to deliver safety-alert emails to parents (for example, when a child's gated device stops checking in).
- We do not use cookies, third-party analytics, advertising SDKs, or tracking pixels, and we do not sell personal information — ever.
- We automatically delete a child's detailed activity logs after 90 days and daily learning summaries after 12 months, and you can delete everything immediately at any time.
- Child profiles are created and controlled by a parent/guardian. We comply with COPPA; adding a child requires affirmative parental consent, and parents can review, export, and delete all of a child's data at any time. See Section 9.
1. Information We Collect
Information you provide
| Category | Data collected |
|---|---|
| Account credentials | Parent email address and password. Passwords are stored only as a cryptographic hash by our authentication provider (Supabase Auth); we never store or see your plaintext password. |
| Parent profile | Your name (as you enter it), an optional family/household name, and an auto-generated Family Code used to pair children's devices and invite additional guardians. |
| Child profile | Each child's first name and grade level (K–9), plus the settings you choose: daily and per-session time limits, subject mix (reading, math, science), device platform, and lock state. We do not collect a child's last name, age, date of birth, or photo. |
| Child device login | To let a child sign in on their own device, the parent sets a numeric PIN. The PIN is stored only as a cryptographic hash. Each child is assigned a non-deliverable internal identifier used solely to authenticate them — it is not a working email address and cannot receive mail. |
| Emergency contacts | If you choose to add them, the labels and phone numbers of the people a child can call during a lock (e.g., "Mom," "Dad"). These are entered by the parent and used to power the always-available emergency screen on the child's device. |
| Payment information | If you subscribe to a paid plan, payments are processed by Stripe. Your full card number and billing details are handled exclusively by Stripe; we never receive or store your full card number, and your email address is shared with Stripe only to create a customer profile. Paid subscriptions are not yet available, so no payment information is collected today. |
Usage and product analytics (parent dashboard)
When you use the parent dashboard, we keep a small, first-party log of a few product-usage events so we can understand adoption and retention and improve the Service — for example, an account being created, the app being opened (including returns), a child being added, and a device being locked. We also keep first-party crash and error diagnostics from the dashboard. These records:
- are stored only on our own servers — they are not sent to any third-party analytics, advertising, or tracking service;
- are keyed to the parent account and carry only low-detail, non-identifying context (such as a device platform or a count) — never a child's name, identifier, or any child data;
- are used only to measure adoption and retention and to keep the Service reliable, and are permanently deleted when you delete your account.
Information collected from the child's device
To run the learning gate and show parents progress, the child app reports limited, non-identifying activity:
| Category | Data collected |
|---|---|
| Learning-gate events | Quiz attempts (subject and whether the answer was correct), lock and unlock events, and screen-time intervals — each with a timestamp and the device platform (iOS or Android). We also store daily totals (quizzes attempted/correct, time locked/unlocked) so parents can see trends. |
| Device check-ins (presence) | A periodic "heartbeat" timestamp and a status (online, silent, or unknown) so a parent can tell whether a gated device is still reporting in. We do not collect the device's location, IP-based location, model, serial number, advertising ID, or other device fingerprints. |
| Diagnostic information | Limited error and reliability information needed to keep the Service working. This is used only for debugging and to keep the Service reliable; it is never sold or shared with advertisers and is not used to build a cross-site or advertising profile of you or your child. |
Information we do not collect
To be clear about what we do not collect:
- A child's last name, age, or date of birth
- Photos, video, or audio
- Precise geolocation (GPS) or IP-based location
- Device identifiers such as IMEI, serial number, Android ID, or advertising ID (IDFA/AAID)
- Browsing history or app-usage history beyond the learning-gate events described above
- Phone numbers, other than the emergency-contact numbers a parent chooses to enter
- Your full payment card number or other financial details (these are handled entirely by Stripe)
2. How We Process Your Information
We process information for the following purposes:
- To operate the learning-gate cycle — gating device access behind grade-adaptive quizzes, unlocking earned time, and enforcing the lock through the native child app.
- To enable device management — letting parents lock, release, or grant free time from any browser, and surfacing tamper and presence alerts.
- To show parents progress — displaying quiz performance, mastery, and screen-time analytics in the dashboard.
- To generate quiz content — creating a shared bank of grade- and subject-appropriate questions (see Section 6).
- To support multi-guardian families — sharing management of a family's children among the parents/guardians you invite.
- To process payments and provide support — managing your subscription and answering your questions.
- To keep the Service reliable and secure — diagnosing errors and enforcing access controls so a family can only reach its own data.
3. Legal Bases for Processing (EU/UK)
If you are located in the EU or UK, we process your personal information on the following grounds:
- Performance of a contract — to provide the Service, manage your subscription, and enable family management under our Terms of Service.
- Consent — where you have given permission, such as a parent's consent to collect their child's learning data, or adding emergency contacts.
- Legitimate interests — to diagnose errors, keep the Service reliable, and prevent fraud, provided these interests are not overridden by your rights.
- Legal obligation — to comply with applicable laws.
4. When and With Whom We Share Information
Within your family
The children, settings, and learning data in a family are shared among the guardians of that family — the owner plus any guardians invited with the Family Code. No data is ever shared between different families.
Service providers (sub-processors)
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, storage, real-time sync, and serverless functions | All data described in Section 1 is stored on Supabase's infrastructure. |
| OpenAI | Generating quiz questions for the shared question bank | Only a grade level, a subject, and a generation seed. No child or family identifiers, names, scores, or personal information are ever sent to OpenAI. |
| Stripe (planned) | Subscription payments and billing, once paid plans are available | If you subscribe, your email address, a customer ID, and payment method details (handled directly by Stripe). No data is shared with Stripe today, as paid subscriptions are not yet active. |
| Resend | Delivering safety-alert emails to parents | A parent's email address and the contents of the message — for example, a presence alert noting a child's first name and that their device stopped checking in. No quiz scores or other child data are included. |
We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes.
5. Cookies and Tracking Technologies
We do not use cookies. We do not use third-party analytics, advertising networks, tracking pixels, or fingerprinting technologies.
The dashboard uses your browser's localStorage only for strictly functional purposes, such as keeping you signed in. The child app stores a small amount of data on the device (its sign-in session, a cached set of quiz questions, and counters waiting to sync) so the gate keeps working when the device is briefly offline. None of this tracks you across websites or is shared with third parties.
6. Quiz Generation and AI
Locked on Learning uses OpenAI's API to write the quiz questions in our question bank. When more questions are needed for a grade and subject, we send OpenAI only a grade level, a subject, and a generation seed. We never send a child's name, identifier, grade-by-name, quiz history, scores, or any other personal information.
The generated questions are stored in a shared bank reused across all families — they are organized only by grade and subject and are never personalized to an individual child. If OpenAI is unavailable or the feature is disabled, the app falls back to built-in question templates so a child is never left without content. The OpenAI API key is stored on our servers and is never exposed to any device.
Important: automatically generated quiz content may occasionally contain errors and is not a substitute for a formal curriculum or professional educational advice.
7. How Long We Keep Your Information
- Account data — retained while your account is active. You can delete your account yourself at any time using the self-service "Delete my account" control in Settings, which starts a 30-day grace period before your data is permanently removed; you can also contact us to request deletion.
- Children's learning data — to limit how long we keep a child's activity, we automatically delete detailed device activity logs after 90 days and daily learning summaries after 12 months. (The daily summaries power the dashboard's progress trends; the detailed event logs they are derived from are no longer needed once summarized.) Regardless of these windows, when you remove a child's profile all of that child's associated data is permanently and immediately deleted, and deleting your account deletes the data for all of your children.
- Diagnostic information — retained only as long as needed to debug and maintain the Service.
- Payment records — retained as required by applicable financial regulations and by Stripe's own retention policies.
You can export or delete a child's data at any time from the dashboard; you do not have to wait for any retention period to elapse.
8. How We Keep Your Information Safe
We use organizational and technical measures to protect your information:
- Row Level Security (RLS) — every database table enforces policies so a family can only ever access its own data.
- Hashed credentials — parent passwords and child PINs are cryptographically hashed by our authentication provider; we never see them in plaintext.
- Server-side secrets — third-party API keys (such as OpenAI and Resend, and Stripe once paid plans launch) and other secrets are stored on our servers and are never exposed to a browser or device.
- Scoped device credential — the native enforcer on a child's device uses a separate, hashed, single-purpose token to read the current lock state; it cannot read account credentials or other profile data.
- Encrypted transport — all data in transit is encrypted via HTTPS/TLS.
No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Information About Children (COPPA Compliance)
Locked on Learning complies with the Children's Online Privacy Protection Act ("COPPA") as enforced by the U.S. Federal Trade Commission. Our Service is designed for families and is used by children under 13 under the supervision of a parent or guardian. Only adults (18 or older) may create an account.
How children's information is collected
Child profiles are created and managed exclusively from a parent/guardian's authenticated account. Children never independently create accounts. When you add a child, you must affirmatively acknowledge a consent notice stating that you are the child's parent or legal guardian and that you consent to Locked on Learning collecting educational usage data (such as quiz responses and screen time) for your child, and confirming that you can export or delete that data at any time. We record this consent in a permanent, immutable audit trail, which is included in your child's data export. No child data is collected through any path that bypasses parental consent.
What we collect about children
We collect only the minimum needed for the Service to function:
- First name and grade level, entered by the parent
- Learning-gate settings the parent chooses (time limits, subject mix)
- Emergency contacts (labels and phone numbers) the parent chooses to add
- Learning-gate activity generated through use — quiz attempts, lock/unlock events, screen-time, and device check-ins
We do not collect a child's last name, age, date of birth, photo, precise location, or device identifiers, and we do not ask a child for any contact information.
How we use children's information
Children's information is used solely to operate the learning gate and device management and to show the parent their child's progress. We never use children's information for advertising, marketing, or profiling, and we never sell it.
Third parties and children's data
- Supabase stores and processes children's data as our infrastructure provider.
- OpenAI receives no children's data — quiz generation uses only a grade and subject (see Section 6).
- Resend may deliver a safety email to the parent that includes the child's first name (for example, a presence alert).
Parental rights under COPPA
- Right to review — view all of your child's data in the dashboard, and download a complete export from Settings.
- Right to refuse further collection — disable your child's device login or restrict their access at any time.
- Right to delete — remove your child's profile, which permanently and immediately deletes all associated data (profile, learning-gate events, analytics, and the child's device login). This action is irreversible.
- Right to revoke consent — revoke at any time by removing the child's profile, which triggers the deletion above.
Data retention for children
To minimize how long children's data is kept, we automatically delete a child's detailed device activity logs after 90 days and daily learning summaries after 12 months (see Section 7). All of a child's data is also deleted immediately when you remove their profile.
If you believe we have collected information about your child without your consent, contact us immediately at [email protected] and we will promptly delete it.
10. Your Privacy Rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access — request a copy of the information we hold about you.
- Rectification — update your name, family name, and child settings directly in the app at any time.
- Deletion — delete a child's data from the dashboard at any time, or delete your own account yourself using the self-service "Delete my account" control in Settings (30-day grace period, then permanent). If you are unable to access Settings, you may instead request account deletion by contacting us.
- Restriction — choose not to add emergency contacts or limit how you use the Service.
- Portability — export your child's data from Settings.
- Withdraw consent — where processing is based on consent, withdraw it by discontinuing the relevant feature or removing the child's profile.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
11. Do-Not-Track
Because there is no uniform standard for Do-Not-Track ("DNT") signals, we do not respond to them. However, since we use no cross-site tracking technologies, third-party analytics services, or advertising networks, your activity is not tracked across other sites or shared with third parties regardless of your DNT setting. (We do keep the small, first-party, parent-only usage log described in Section 1, which never leaves our servers.)
12. United States Privacy Rights
If you are a resident of a U.S. state with a comprehensive privacy law (such as California, Colorado, Connecticut, Texas, Virginia, and others), you may have rights to know what personal information we collect, to request its deletion, to correct it, and to not be discriminated against for exercising these rights. We do not sell personal information and do not process it for targeted advertising. To exercise your rights, contact us at [email protected].
13. Updates to This Notice
We may update this Privacy Notice from time to time. The updated version will be indicated by a revised "Last updated" date at the top of this page. If we make material changes, we will post a prominent notice within the Service.
14. How to Contact Us
If you have questions about this Privacy Notice or our data practices, contact us by email:
- Privacy inquiries: [email protected]
- General support: [email protected]