Privacy Policy

What we collect, why, who we share it with, and how a parent gets it deleted.

Version 2026-07-29. We keep a record of which version you agreed to when you signed up.

Draft — pending legal review. Not yet a binding notice.

This text was drafted from what the software actually does, not by a lawyer, and it has not been reviewed by one. It describes our real data practices accurately to the best of our knowledge, but it must be reviewed and approved by qualified counsel — against COPPA, GDPR / UK GDPR, and any state privacy laws that apply — before this service accepts a sign-up from a child.

Outstanding: the operating entity and the contact address for parental access and deletion requests are still unset (LEGAL_OPERATOR / LEGAL_CONTACT_EMAIL in src/lib/legal.ts). COPPA requires both to be published.

Who we are

CosmicoLab is a STEM learning service for children, operated by [OPERATOR NAME — NOT SET]. Questions about this policy, or requests to see or delete a child's data, go to [CONTACT EMAIL — NOT SET].

What we collect

We collect only what the service needs to work:

  • Account details — name, email address and a password (stored only as a salted hash, never in readable form), plus the emoji avatar and the role you chose (parent, teacher, school administrator or student).
  • A learner's birth year — the year only, never a full date of birth. We use it to match content to the right age band and to apply the under-13 protections described below. It is deliberately coarse so that we hold less about a child than a full birthday would reveal.
  • Learning progress — which quests were started and completed, scores, XP and coins earned.
  • Time spent — daily play time, so parents can set and enforce time limits.
  • Family, class and school links — which parent a child belongs to, or which class and school a student is enrolled in.
  • Parental control settings — the limits a parent sets, and a hashed PIN for the parent dashboard.
  • Subscription status — which plan an account is on. Card details are handled entirely by Stripe; we never see or store a card number.

We do not ask children for a photograph, a home address, a phone number, a precise location, or a school year group.

Children under 13 (COPPA)

A child under 13 cannot create their own account. If someone tells us at sign-up that they are under 13, we stop and ask a parent or guardian to create the account instead. This is deliberate: consent for a child's data has to come from an adult, and a child ticking a box is not that.

A parent creates the account, confirms they are the child's parent or legal guardian, and consents to the collection described above. A school or teacher may instead create student accounts under the school's own authority, where the school acts as the parent's agent for classroom use.

We never condition a child's participation on disclosing more information than is reasonably necessary to take part.

Parents: you can review the personal information we hold about your child, have it deleted, and refuse any further collection — at any time, by writing to [CONTACT EMAIL — NOT SET]. Deleting a child's profile from your dashboard removes their profile, progress and usage records. Withdrawing consent means we close the child's account.

How we use it

To run the service and nothing else: to sign you in, to save and sync progress across devices, to unlock the right content for an age and a plan, to show a parent or teacher how their child or class is doing, to apply parental controls, and to manage billing.

What we never do

  • We do not sell or rent personal information. Ever, to anyone.
  • We do not show advertising, and we do not do behavioural or targeted advertising.
  • We do not run third-party analytics, advertising SDKs, or tracking pixels. The service loads no third-party tracking scripts at all.
  • We do not build advertising profiles of children.

Who we share it with

Only the service providers that make the product run. They process data on our instructions and may not use it for their own purposes:

  • Supabase — the database and sign-in system that stores accounts and progress.
  • Vercel — hosting; serves the site and processes the network requests needed to do so.
  • Stripe — payment processing for paid plans. Stripe receives the payment details a subscriber enters; we do not.
  • Google Fonts — the site loads its typefaces from Google's servers, which means your browser's IP address is visible to Google when a page loads. We do not send Google any account information.

We may also disclose information where the law requires it, or to protect the safety of a child or another person.

How long we keep it

For as long as the account is open. When an account or a child profile is deleted, we delete the profile and the progress, usage and enrolment records attached to it. Some records — for example billing records we are required to retain — may persist for as long as the law requires.

How it's protected

Data is held in an access-controlled database where every read and write is checked against the signed-in user by row-level security in the database itself, not just by the app. A parent can only see their own children; a teacher only their own classes. Passwords are stored hashed, and parent dashboard PINs are stored hashed. Traffic is encrypted in transit.

No service can promise perfect security, and we do not. If a breach affects your family's information, we will tell you.

Changes to this policy

If we change this policy in a way that affects how we treat information already collected from a child, we will obtain fresh parental consent before applying it. Each version is dated, and we record which version an account agreed to.

Contact

Write to [CONTACT EMAIL — NOT SET] for any privacy question, or to exercise any right described here.

See also: Privacy Policy · Terms of Service