Privacy Policy
Last Updated: December 1, 2025
At Curious Kelly, we believe privacy is a fundamental right. This Privacy Policy explains how we collect, use, protect, and share information when you use our educational platform.
TL;DR: We collect only what we need to provide personalized learning. We never sell your data. Parents have full control over children's accounts. You can delete your data anytime.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Name and email address
- Age (to personalize lesson content)
- Authentication data (OAuth tokens from Google, Apple, or GitHub)
- Subscription and payment information (processed securely by Stripe)
1.2 Learning Data
To provide personalized education, we track:
- Lessons completed and progress
- Quiz answers and performance metrics
- Time spent in lessons
- Preferred learning pace and difficulty
- Streak and achievement data
1.3 Technical Data
We automatically collect:
- Device type, operating system, and browser
- IP address and general location (city/country level)
- Session duration and interaction patterns
- Error logs and performance metrics
1.4 Voice and Avatar Interactions
When using Kelly's voice features:
- Voice inputs are processed by OpenAI Realtime API and ElevenLabs
- Audio is not stored permanently unless you explicitly save it
- Transcripts may be retained to improve lesson quality
2. COPPA Compliance (Children Under 13)
Important: Curious Kelly is designed for learners ages 2-102. For children under 13, we comply with the Children's Online Privacy Protection Act (COPPA).
2.1 Parental Consent
Before a child under 13 can use Curious Kelly:
- A parent or guardian must create the account
- Parents provide consent through a verified email process
- Parents can review, modify, or delete their child's data at any time
2.2 Limited Data Collection for Children
For users under 13, we collect only:
- First name (no last name required)
- Age range (not exact birthdate)
- Learning progress (to maintain continuity)
We do NOT collect from children under 13:
- Email addresses
- Phone numbers
- Photos or videos
- Precise geolocation
- Social media profiles
2.3 Parental Rights
Parents can:
- Review all data collected about their child
- Request deletion of their child's account and data
- Refuse further collection of data
- Contact us at privacy@curiouskelly.com
3. How We Use Your Information
We use collected data to:
- Personalize Learning: Adapt lesson difficulty and pacing to your age and progress
- Provide Service: Deliver daily lessons, track streaks, and sync across devices
- Improve Quality: Analyze usage patterns to enhance content and fix bugs
- Communicate: Send lesson reminders, progress reports, and important updates
- Process Payments: Handle subscriptions and refunds
- Ensure Safety: Detect fraud, abuse, and technical issues
4. Third-Party Integrations
We partner with trusted services to deliver Curious Kelly:
4.1 Voice and AI Services
- OpenAI: Powers Kelly's conversational AI (subject to OpenAI's privacy policy)
- ElevenLabs: Generates Kelly's voice (audio processed securely)
4.2 Avatar Rendering
- Unity Technologies: Renders Kelly's 3D avatar in your browser
- NVIDIA Audio2Face: Synchronizes lip movements (processed locally when possible)
4.3 Infrastructure
- Cloudflare: Content delivery and DDoS protection
- AWS/Render: Hosting and data storage (encrypted at rest)
- Stripe: Payment processing (we never see full credit card numbers)
4.4 Analytics
- Mixpanel/Amplitude: Product analytics (anonymized where possible)
- Sentry: Error tracking (no personal data in logs)
5. Cookies and Tracking
We use cookies and similar technologies for:
- Essential Cookies: Authentication, session management (required)
- Analytics Cookies: Understanding how you use Curious Kelly (optional)
- Preference Cookies: Remembering your settings (optional)
You can control cookies through your browser settings. Disabling essential cookies may prevent login.
6. Data Sharing and Disclosure
We never sell your personal data.
We may share data only in these limited circumstances:
- With Your Consent: When you explicitly authorize sharing
- Service Providers: Third parties who help operate Curious Kelly (under strict contracts)
- Legal Requirements: If required by law, court order, or to protect safety
- Business Transfers: In the event of a merger or acquisition (with notice to you)
7. Data Security
We protect your data with:
- Encryption in transit (TLS/SSL) and at rest (AES-256)
- Regular security audits and penetration testing
- Access controls (employees see only what they need)
- Secure authentication (OAuth 2.0, no plain-text passwords)
- Automated backups and disaster recovery
However, no system is 100% secure. We cannot guarantee absolute security.
8. Your Rights and Choices
8.1 Access and Portability
You can:
- View all your data in your account settings
- Export your learning history and progress
- Request a complete data archive
8.2 Correction and Deletion
You can:
- Update your profile information anytime
- Delete your account (and all associated data) instantly
- Request specific data deletion via privacy@curiouskelly.com
8.3 Marketing and Communications
You can:
- Opt out of promotional emails (unsubscribe link in every email)
- Control push notifications in your device settings
- Adjust reminder frequency in account settings
8.4 Do Not Track
We respect browser "Do Not Track" signals for non-essential analytics.
9. Data Retention
We retain data only as long as necessary:
- Active Accounts: Data retained while your subscription is active
- Canceled Accounts: Data deleted 90 days after cancellation (unless you request sooner)
- Legal Requirements: Some data (e.g., payment records) kept for tax/legal compliance (7 years)
- Anonymized Analytics: Aggregated, non-personal data may be retained indefinitely
10. International Data Transfers
Curious Kelly is based in California, USA. If you access our service from outside the United States, your data may be transferred to and processed in the US. We ensure appropriate safeguards are in place for international transfers.
11. Changes to This Policy
We may update this Privacy Policy as our service evolves. Material changes will be announced via:
- Email notification to all users
- Prominent notice on our website
- In-app notification
Continued use after changes constitutes acceptance of the updated policy.
12. Contact Us
Questions, concerns, or requests about your privacy?
Email: privacy@curiouskelly.com
Mail: Curious Kelly PBC, Privacy Team, [Address TBD]
Response Time: We aim to respond within 48 hours
13. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed (we don't sell data)
- Right to delete personal information
- Right to opt-out of sale (not applicable, as we don't sell data)
- Right to non-discrimination for exercising your rights
To exercise these rights, contact privacy@curiouskelly.com.
14. European Privacy Rights (GDPR)
If you are in the European Economic Area, you have rights under GDPR:
- Right to access your personal data
- Right to rectification (correction)
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
Our legal basis for processing is typically consent or contractual necessity.