Safety and trust
Privacy
What SchoolQuest AI collects, why, which AI service receives what, how long it is kept, and how a parent reads, exports or deletes it.
Who is responsible
SchoolQuest AI is operated by Binoron, LLC, 1111B S Governors Ave # 47095, Dover, DE 19904, United States, as part of the Little AI Minds Universe. Most families using it are worldschooling and homeschooling households living outside the European Union, including EU citizens living abroad, so this page is written to be read by a parent anywhere rather than to fit one country's template. Where the law of a family's country makes us the controller of the personal data described here, that is Binoron, LLC. Questions reach us through the in-app feedback page or at hello@littleaiminds.com.
What we collect and why
A parent creates the account; children work inside the profiles the parent sets up. We collect what the app needs to keep a learning record and adapt the next step, and nothing that only exists to profile a family.
- Parent account: the email address and the sign-in method used (an emailed sign-in link, Google or Apple). It signs you in, secures the account, and lets us write to you about it.
- Child learning profiles: the display name the parent chooses, birth year, grade level, interests, strengths, growth edges, sensory preferences (noise, movement breaks, visual density), focus window, preferred tone, learning language, Hebrew address form, and the onboarding answers about country, schooling model and goals. All of it is entered by the parent.
- Learning sessions and answers: the subject and skill worked on, the answer the child typed, whether it was correct, how long it took, hints and retries, an optional self-reported feeling, the diagnostic result and the mastery update. This is what makes progress and the learning record real.
- Tutor messages: the tutor's turns and the child's turns inside a session, so a parent can read back what was said.
- Literacy analyses: the derived practice metrics described below plus the parent-facing text the AI returns, kept for the retention window the parent chooses.
- Portfolio artefacts: title, description, tags, evidence date, and any file a parent uploads (image, PDF or text) into a private storage area.
- Parent notes and recommendations, so the weekly picture stays in one place.
- AI usage records: provider, model, purpose, token counts and a one-way hash of the request. They exist for daily budgets and cost control. The prompt text itself is not stored in them.
- Public forms: the feedback form and the starter-guide signup store what you type there — name where asked, email, country, languages, your message — together with the IP address the request came from, for spam control.
Which AI service receives what
One outside AI provider is called today: OpenAI. There are two paths to it, and each sends only what the feature needs. Both set the provider's store flag to false, which asks OpenAI not to retain the request. If the tutor call fails, the app falls back to its own deterministic tutor logic rather than sending the same request to a second provider.
- The AI tutor sends: subject and skill title, the exercise text, the diagnostic signal, the explanation style, session mode, age, emotional state, preferred tone, focus window, sensory profile, mastery state and confidence, interests, strengths, growth edges, known misconception risks and the response language.
- The AI tutor does not send the child's name. The name is stripped in one single place before the request leaves the app, and the tutor function's own contract has no name field at all, so a future caller cannot reintroduce it by accident. Your email address, the account id and the child profile id are not sent either.
- The optional literacy cloud analysis sends derived numbers only: reading accuracy, expected and heard word counts, omitted and changed words, a pace band and transcript length; stroke and point counts, guide fit, baseline touch, width and height coverage, pressure samples, rhythm and travel; and for a worksheet photo only its width, height, brightness and contrast. Plus the lesson title and target, the practice language and the interface language.
- The literacy path sends no audio recording, no photo, no handwriting stroke file and no child name. The database enforces the same boundary: a stored analysis row is rejected unless it records that no raw media was kept.
- The literacy analysis stays switched off until a parent turns it on and confirms consent for that session, and it can be deleted immediately afterwards.
What stays on the device, and the browser speech caveat
The literacy practice tools run in the browser and stay switched off until a parent enables them for that browser session. Handwriting strokes and worksheet photos are analysed on the device: the image and the stroke file never leave it and never reach us.
- Speech-to-text is done by the browser's own speech service, not by us. In some browsers — Chrome for example — the recording is sent to the browser maker to be turned into text. That is the browser's processing, never ours: we receive no audio at any point.
- Only the resulting text stays in the app, where it is compared with the tiny reading target on the device.
- Reading the target aloud uses the browser's own speech synthesis, again without sending anything to us.
- If the parent has switched the optional cloud analysis on, the derived numbers listed above are what leave the device — not the audio, the photo or the strokes.
Who helps us run the service, and payments
A small number of providers help run SchoolQuest AI. Each receives only what its job requires.
- Supabase — database, sign-in and private file storage for everything described above.
- Vercel — hosting and delivery of the app. Serving a page necessarily means Vercel handles the request, but no page-analytics product is running: nothing counts your visits, sets a cookie, follows you to other websites or builds a profile of a child.
- OpenAI — the tutor and the optional literacy analysis, exactly as described above.
- Resend — transactional email such as the sign-in link and subscription confirmations, where email is configured.
- Stripe — payments, once paid plans are switched on. Stripe receives the parent's email address, an internal account identifier and the plan chosen. The price is set on our server, so a checkout amount cannot be changed from the browser. We never receive or store card numbers.
How we protect data
Family learning data is treated as child learning data throughout. These are the concrete measures, not aspirations.
- Encryption: traffic runs over HTTPS/TLS, the site is served with a strict transport-security header, and stored data is encrypted at rest by the database provider.
- Row-level security scopes every family table — parent profile, child profiles, sessions, answers, tutor messages, mastery, recommendations, parent notes, portfolio artefacts, literacy progress, literacy analyses, reviewer share links and entitlements — so a signed-in parent can read or change only their own family's rows.
- Creating a child profile is gated in the database, not only in the app: the students table accepts a new row only from an account that carries a recorded, current, non-withdrawn guardian consent. Correcting, exporting and deleting an existing child record are never gated — those are your rights, and a consent switch must not stand in front of them.
- The public Data API is closed to anonymous callers: all privileges on tables in the public schema are revoked from the anonymous role, and default privileges are revoked too, so the key that ships in the browser reads nothing on its own.
- Uploaded portfolio files live in a private storage bucket whose paths are checked against both the parent account and the child profile on every read, write and delete.
- The tutor endpoint fails closed: it rejects anonymous callers, and when its daily usage check cannot be evaluated it refuses the request rather than letting it through.
- Service keys stay on the server and never reach the browser; access to production systems is limited to the operator.
- Browser hardening: content-type sniffing is off, the site refuses to be framed, referrers are trimmed, camera and microphone are restricted to this site and geolocation is switched off entirely.
- SchoolQuest AI has no parent PIN. The parent's own sign-in is what separates the parent area from the child's learning area, so the device should stay with the adult when parent pages are open.
- No online service can promise perfect security. If we ever learn of a breach affecting your family's data, we will notify you and the relevant authorities as required by law.
How long we keep data
The learning record itself is kept until a parent deletes it, because a record only works if it survives the term. The raw material underneath it — sessions, answers, tutor conversations — ages out on the fixed windows below. Those deletions are real deletions run by a daily job, not a filter that hides an expired row while it stays in the database. Your own deletion is still a step you take: ending a subscription does not delete anything on its own.
- Account, child profiles, mastery, daily missions, portfolio artefacts and parent notes: kept until deleted. This is the record a homeschooling family may have to show years later. Deleting a child profile removes its learning records with it; deleting the account removes everything linked to it.
- Learning sessions and the answers inside them: deleted 36 months after they were recorded, together with the recommendations attached to them. The mastery summary derived from them stays.
- Tutor messages: deleted 12 months after they were written. They are a child's own words in a conversation with an AI, so they get the shortest window of the learning data.
- Literacy cloud analyses: the parent picks a retention window when consenting — 14 days by default — and the database refuses any window longer than 30 days. The daily job deletes the analysis once that window has passed, and a parent can delete any analysis immediately.
- Reviewer share links: they carry an expiry date the parent sets and can be revoked earlier. Only a one-way hash of the link token is stored, never the token itself.
- Rate-limit counters: held in server memory only, never written to the database, and gone when the process restarts.
- Public form entries — feedback, starter-guide signup — including the IP address recorded with them: kept until you ask us to remove them.
- Encrypted provider backups may still hold data for a limited period after deletion, until they roll over.
Your rights and how to use them
Reading, exporting and deleting your family's data never depends on paying for anything and never depends on a consent switch. Those controls stay open for as long as the account exists. We do not charge for a request and never treat you worse for making one; we aim to answer within the time your law allows — one month where the GDPR applies.
- Access — everything we hold about your family is visible in the parent dashboard once you are signed in.
- Correct — edit the child profile, the notes and the portfolio entries directly in the app.
- Export — download everything this account holds as one file from the parent area: your account details, every child profile, sessions, answers, mastery, missions, tutor conversations, literacy progress and analyses, portfolio entries, parent notes, consent records and billing records. Uploaded files are not inside the file; each portfolio entry carries a download link that works for one hour. You can also download a learning record as a PDF for any date range you choose.
- Delete — remove a single portfolio artefact, a single literacy analysis or a reviewer share link; delete a whole child profile after typing its name to confirm, which also removes its sessions, answers, tutor messages, mastery, recommendations, notes, artefacts, literacy progress and AI usage records; or delete the entire account from the parent area after retyping your email address, which removes every child profile, your uploaded files, your consent record and your entitlement rows along with the sign-in itself. Account deletion is permanent and cannot be undone, so export first if you want to keep the learning record. A paid subscription is billed by Stripe and is not cancelled by deleting the account — cancel it in the billing portal first.
- Object, restrict or withdraw consent — withdraw the recorded guardian consent in the parent area, switch the optional literacy cloud analysis off, or ask us to stop a specific processing. Withdrawing guardian consent stops new child profiles being created; it never touches the data already held, which stays readable, correctable and deletable.
Where data is processed
Binoron, LLC is a United States company, and the providers listed above process data in the United States and may process it in other regions. Families using SchoolQuest AI are spread across many countries, so data will normally cross a border on its way to us. Where European or United Kingdom data-protection law applies to a family, transfers outside the EU and EEA rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or, where a provider takes part in it, the EU-US Data Privacy Framework. We use our providers' business interfaces rather than consumer accounts.
Children's data and the parent's role
SchoolQuest AI is built for a child to use inside an account an adult owns and supervises. That framing is not decoration: it decides who can enter data, who can see it and who can remove it.
- Only an adult creates the account. Children never register, never give us an email address and never get their own login.
- Everything about a child is either entered by the parent or typed by the child inside a session the parent set up.
- The AI tutor never learns the child's name, so the profile it works from stays anonymous pedagogy rather than an identified psychological profile.
- The optional literacy cloud analysis stays off until the parent switches it on for that browser session, and it sends derived numbers only.
- There are no public child profiles, no friend lists, no messaging with strangers and no advertising to children. We do not sell anyone's data.
- The parent stays responsible for supervising sessions and for reviewing what the AI says. The app supports learning; it does not replace an adult's judgement.
- If you believe a child's data reached us that should not have, write to us and we will remove it.
Questions and complaints
Start with us: use the feedback page inside the app or write to hello@littleaiminds.com. Please keep sensitive child details out of a public form and send only the context needed to look into the question. If we do not resolve it, you can go to a supervisory authority: residents of the EU and EEA to their national data protection authority, residents of the United Kingdom to the ICO, residents of Israel to the Privacy Protection Authority, and residents of the United States may have rights under their state law. Families in other countries can approach their national authority where one exists.
Changes and last update
This page describes how SchoolQuest AI works today, not how we hope it will work. If something meaningful changes, we update the date here and tell account holders by email or an in-app notice before the change takes effect. Last updated: 2026-07-26.
