Privacy Policy

Last Updated: December 2024

OctoWhiz ("we," "us," or "our") is committed to protecting the privacy of children and their families. This Privacy Policy explains how we collect, use, and safeguard information when you use the OctoWhiz mobile application ("App").

OctoWhiz is designed for students in grades 1-10 (approximately ages 6-16) and their parents/guardians. We comply with the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation (GDPR), and other applicable privacy laws.

1. Information We Collect

1.1 Information Provided by Parents/Guardians

  • Parent email address (for verification and progress reports)
  • Child's first name or nickname
  • Child's grade level
  • Learning preferences and goals

1.2 Information Provided by Students

  • Study content uploads (photos of worksheets, PDFs, notes)
  • Quiz answers and flashcard responses
  • Chat conversations with the AI tutor
  • Study session data (time spent, topics studied)

1.3 Automatically Collected Information

  • Device type and operating system version
  • App usage patterns (screens visited, features used)
  • Performance data (quiz scores, flashcard progress)
  • Crash reports and error logs
  • Anonymized analytics data

1.4 Information We Do NOT Collect

  • Precise location data
  • Contact lists or address books
  • Photos from camera roll (only new photos taken for uploads)
  • Microphone or audio recordings
  • Biometric data
  • Social media accounts

2. How We Use Information

2.1 To Provide Educational Services

  • Generate personalized quizzes and flashcards from uploaded content
  • Track academic progress and identify areas needing improvement
  • Provide AI tutoring assistance through the Octo chat feature
  • Send weekly progress reports to parents

2.2 To Improve the App

  • Analyze usage patterns to improve features
  • Fix bugs and improve performance
  • Develop new educational content and features

2.3 We Do NOT Use Information For

  • Behavioral advertising or targeted ads
  • Selling or sharing with data brokers
  • Creating advertising profiles
  • Any purpose unrelated to educational services

3. AI Features and Data Processing

OctoWhiz uses artificial intelligence to:

  • Extract educational content from uploaded materials
  • Generate quiz questions and flashcards
  • Provide tutoring assistance through the Octo chat

3.1 How AI Processes Data

  • Uploaded content is processed by our AI service provider (Anthropic Claude API)
  • Chat conversations are processed to generate educational responses
  • AI does not retain student data after processing
  • AI is instructed to never provide direct homework answers

3.2 AI Safety Measures

  • All AI responses are filtered for age-appropriate content
  • AI cannot access internet or external content
  • AI operates only within educational context
  • For users under 13, additional chat restrictions may apply

4. Third-Party Services

We use the following third-party services:

4.1 Firebase (Google)

4.2 Anthropic Claude API

  • Purpose: AI content processing and chat responses
  • Data processed: Uploaded educational content, chat messages
  • Privacy policy: anthropic.com/privacy

4.3 SendGrid (Twilio)

  • Purpose: Sending weekly progress emails to parents
  • Data processed: Parent email address, progress summaries
  • Privacy policy: twilio.com/legal/privacy

4.4 PostHog

  • Purpose: Anonymous usage analytics
  • Data processed: Anonymized app usage events
  • Privacy policy: posthog.com/privacy

All third-party providers are contractually required to:

  • Process data only as instructed
  • Implement appropriate security measures
  • Not use data for their own purposes
  • Comply with applicable privacy laws

5. Data Retention and Deletion

5.1 Retention Periods

  • Account data: Retained while account is active
  • Study content: Retained until deleted by user or account deletion
  • Progress data: Retained for duration of account
  • Chat history: Retained for 30 days, then automatically deleted
  • Analytics data: Anonymized and retained for 2 years

5.2 Account Deletion

Users can delete their account at any time through:

Upon deletion, we will:

  • Delete all personal information within 30 days
  • Delete all uploaded content immediately
  • Remove from email lists immediately
  • Retain only anonymized, aggregated data

6. Parental Rights (COPPA Compliance)

Parents and guardians have the right to:

6.1 Review Information

  • View all data collected about their child
  • Request a copy of their child's data
  • Access through: Settings → Parent Dashboard → Data Export

6.2 Delete Information

  • Request deletion of their child's account and all associated data
  • Delete specific content uploads
  • Access through: Settings → Account → Delete Account

6.3 Refuse Further Collection

  • Revoke consent for data collection
  • This will result in account termination
  • Contact: [email protected]

6.4 Consent Mechanisms

  • Parent email verification required during signup
  • Parents receive email notification of account creation
  • Parents can manage account through parent dashboard

7. Data Security

We implement industry-standard security measures:

  • Encryption in transit (TLS 1.3)
  • Encryption at rest (AES-256)
  • Firebase App Check for API security
  • Regular security audits
  • Access controls and authentication
  • Secure data centers (Google Cloud Platform)

8. International Data Transfers

Data may be processed in the United States. For users in the European Economic Area (EEA), we rely on:

  • Standard Contractual Clauses with service providers
  • Firebase's Data Processing Terms
  • Anthropic's Data Processing Agreement

9. Children's Privacy

9.1 Age Restrictions

  • Children under 13 require verified parental consent
  • Parents must verify their email during signup
  • AI chat features may be restricted for users under 13

9.2 No Behavioral Advertising

  • We do not serve ads to children
  • We do not create advertising profiles
  • We do not share data with advertisers

9.3 Safe Communication

  • No direct messaging between users
  • No social features or friend lists
  • AI chat is one-way (student to AI only)
  • All content is moderated for safety

10. Your Rights

Depending on your location, you may have the right to:

  • Access your personal information
  • Correct inaccurate information
  • Delete your information
  • Object to processing
  • Data portability
  • Withdraw consent

To exercise these rights, contact: [email protected]

11. Changes to This Policy

We may update this Privacy Policy periodically. We will:

  • Post the updated policy in the App
  • Update the "Last Updated" date
  • Notify parents via email for material changes
  • Request new consent if required by law

12. Contact Us

For privacy questions or concerns:

For complaints, you may also contact:

  • US: Federal Trade Commission (ftc.gov)
  • EU: Your local Data Protection Authority