Privacy Policy

Last updated: July 24, 2026

Overview

Big Thinkers is an educational platform used by children, families, teachers, and schools. Because some of our users are children under 13, this service is designed to comply with the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA) where we handle student education records, and applicable U.S. state student- and minor-privacy laws. This policy explains what we collect, why, who we share it with, how long we keep it, and the rights and choices available to you.

We treat every user as a child unless and until we can reliably determine otherwise through our age-screening process or an authenticated parent/teacher/administrator account.

How we determine age

Before we collect personal information for an account, we ask for the user's age or date of birth through a neutral age screen. We use this information solely to determine which privacy rules apply to the account and to route the user to the correct experience:

  • Under 13 — we require verifiable parental consent or school authorization before collecting personal information beyond the age screen.
  • 13–17 — we apply heightened minor-privacy protections and the highest-privacy defaults required by applicable state law.
  • 18 and over — parent, teacher, and administrator accounts.

We store an age-band status (not just the raw birth date) so that downstream features can apply the correct protections. Information collected to screen age is used only for that purpose and is not repurposed for marketing, profiling, or any unrelated use.

Information we collect

From children under 13 (after verifiable parental consent or school authorization):

  • Age-screening result (under 13 vs. 13+)
  • Account display name, login email, and password
  • Course progress, lesson activity, XP, and streak data
  • Family-plan membership and invitation status when the account joins a family plan
  • Optional lesson help-chat messages the learner types when asking Ren or Mira for help on an activity (processed ephemerally; see "AI help chat in lessons" below)
  • Optional problem reports the learner chooses to submit from a lesson: a short description of the issue and a screenshot of the lesson screen at that moment (see "Problem reports" below)
  • Persistent identifiers (such as authentication cookies and a first-party analytics identifier) used only to support internal operations
  • An approximate, coarse location (country, region, and city) that our analytics provider derives from the connection's IP address for security and internal-operations purposes; we retain only this coarse location and discard the IP address itself, and we never derive street-level or precise geolocation

From users 13–17: the same categories above, configured to the highest-privacy defaults, with no public profile and no behavioral advertising.

From parents, teachers, and administrators: name, email, password, account role, and the link between a parent/teacher and the child accounts they manage.

For paid plans: Stripe processes payment details on our behalf. We store the subscription owner, plan, billing status, renewal date, and family-seat membership needed to provide Premium access. A parent or guardian must authorize purchases made for a user under 13.

Mobile push notification tokens (13+ and parents only):if a user who is 13 or older—or a parent—installs our mobile app and chooses to turn on push notifications, we collect a device push token (a persistent identifier issued by the operating system and Expo) so we can send the reminders they opted into. We do not collect push tokens from a child's device; reminders relating to a child under 13 are sent to the parent instead (see below). Push tokens are collected only after the user grants the operating-system notification permission, and a user can turn push notifications off at any time in Settings or in their device settings.

Web push notification subscriptions (13+ and parents only):if a user who is 13 or older—or a parent—chooses to turn on browser notifications, we collect a web push subscription (a persistent identifier issued by the browser's push service, such as Apple, Google, or Mozilla) so we can send the reminders they opted into. Because this happens during signup, a subscription may be created before an account exists; when it is, we store only the push subscription itself (no name or email) and use it solely to help the person finish creating their account, and we automatically delete it if the account is never created. We do not collect web push subscriptions from a child under 13; browser notifications are offered only after a neutral age check confirms the user is 13 or older. A user can turn browser notifications off at any time in Settings or in their browser settings.

We practice data minimization: we do not require children to provide more personal information than is reasonably necessary to use a feature, and we do not collect "nice to have" data from child-facing forms.

What we do not collect

We do not knowingly collect biometric identifiers, street-level or precise geolocation, children's photos or videos, or audio recordings of children. Our analytics provider derives an approximate, coarse location (country, region, and city) from the connection's IP address when an event is received; we retain only this coarse location and do not store the device IP address itself in our analytics or error-monitoring tooling, and we do not use this location to build profiles of, or to contact, a child. We do not run session recording or autocapture for child or teen accounts. For adult parent, teacher, and administrator accounts only, we may use session recording (with form inputs masked) and autocapture to improve the service—see "Analytics (PostHog)" below. If we ever introduce recording for minors, we will update this policy and obtain any required consent first.

How we use information

  • Provide, secure, and operate the educational service and user accounts
  • Save and display learning progress, XP, and streaks
  • Authenticate users and protect against fraud and abuse
  • Send transactional and account-related email (for example, parental-consent and password-reset messages)
  • Send learning reminders and streak, milestone, and re-engagement notifications by email and—for users 13 and older or parents who have opted in—by mobile push notification. For accounts belonging to a child under 13, these reminders are sent to the parent, not to the child's device. We cap engagement notifications to roughly one message per day across all channels, and every recipient can turn them off.
  • Maintain and improve the service through first-party analytics and error monitoring (the COPPA "support for internal operations" exception)
  • Answer on-lesson help questions through a bounded AI tutor (Ren or Mira) when the learner chooses to use help chat
  • Investigate and fix issues a learner chooses to report from a lesson, using the description and lesson-screen screenshot they submit

We do not use any child's personal information to build profiles, to power behavioral or targeted advertising, or to train third-party AI/ML models.

AI help chat in lessons

During a lesson, a learner may open an optional help chat with their guide character (Ren or Mira) to ask questions about the current activity or lesson. When they send a message, we transmit that message—along with server-selected lesson context needed to answer (for example, the current screen prompt and high-level lesson structure)—to our AI provider, Anthropic, solely to generate a short educational reply. We do not send answer keys to the model for the purpose of revealing correct answers, and the tutor is instructed to stay on-lesson and not disclose grading secrets.

Help-chat messages are processed ephemerally to generate the reply. We do not store the chat transcript in our database. A copy may be held only in the learner's device/session while they remain in that activity, and it is discarded when they leave the lesson player or move to a different activity. Anthropic processes the request under our written agreement and may not use the content to train models for its own purposes. We do not use help-chat content for advertising or profiling.

Problem reports

During a lesson, a learner may choose to report a problem (for example, a broken activity or something that looks wrong). When they press the report button, we capture an image of the lesson screen as it appears in their browser at that moment, show it to them, and let them describe what happened before submitting. The screenshot is generated on the learner's device and shows only the lesson interface—we do not access the device camera, other tabs, or anything outside the lesson page.

Submitted reports (the description, the screenshot, and which lesson screen the report came from) are stored privately, are accessible only to our staff, and are used solely to investigate and fix the reported issue. They are never used for advertising, profiling, or model training, and they are automatically deleted 90 days after submission.

Analytics (PostHog)

We use PostHog for first-party product analytics to understand how the service is used and to improve it. Traffic to PostHog from the web app is routed through our own origin. Page-view URLs are stripped of tokens and other sensitive parameters, and the device IP address is discarded rather than stored. Before the IP is discarded, PostHog derives an approximate location (country, region, and city) from it; we retain only this coarse location—never street-level or precise geolocation—and use it solely for security and measuring product usage. We use PostHog only for internal operations (service improvement, security, and measuring product usage), never for advertising or behavioral profiling of children.

Children under 13 and users whose age band is unknown:we collect only anonymous, first-party product events (for example, which onboarding step or lesson was started or completed) under COPPA's "support for internal operations" exception. We never link a child account to a PostHog identity, we do not create person profiles for anonymous child sessions, and we do not enable autocapture or session recording for these users. Aside from the coarse, approximate location (country, region, and city) our analytics provider derives from the IP address for security and internal-operations purposes—which is never used to build profiles of, or to contact, a child—event properties are limited to non-identifying product metadata (such as course or lesson slugs, counts, and fixed onboarding preference enums like learning goal, interest categories, character choice, AI skill level, and time/schedule preferences)—not free-text content, emails, names, or exact age.

Users 13–17: we may associate product events with their account id so we can understand retention and feature use, with the highest-privacy defaults required by applicable state law. Autocapture and session recording remain off for teens.

Parents, teachers, and administrators: in addition to identified product events, we may enable autocapture and session recording to diagnose UX issues (for example, checkout friction). Session recordings mask password and email fields and other sensitive inputs. Recording is not used for advertising.

Error and performance monitoring (Sentry)

We use Sentry to detect, diagnose, and fix errors and performance issues. Sentry is configured to not send default personal information (such as IP addresses, user-agent strings, or request headers), and our integration strips user details from error events before they are sent. We do not attach a child's email or username to error reports. Sentry is used solely to keep the service reliable and secure.

Advertising measurement (Meta Pixel)

On selected public marketing pages (for example, the homepage, Premium, About, Educators, Blog, and public course catalog pages), we load the Meta (Facebook) Pixel so we can measure the effectiveness of our own advertising campaigns on Meta platforms and build audiences of people who visited those pages. The Pixel may set cookies or similar identifiers on the device and may receive the page URL, a browser/device identifier, and the IP address of the visit. Meta acts as an independent controller of the data it receives through the Pixel under Meta's own privacy policy.

What we do not do:we do not load the Meta Pixel on authenticated child-facing lesson or dashboard pages, and we do not fire Pixel conversion events for accounts identified as under 13 or whose age band is unknown. We do not use the Pixel to deliver targeted or behavioral advertising to children, and we do not sell children's personal information. Conversion events such as account registration and Premium purchase are fired only for adult (parent/teacher) and teen (13+) accounts.

If you arrived from a Meta ad, your visit to a public marketing page may be associated with that ad for campaign measurement. You can limit Meta's ad tracking through your Meta account ad preferences and your browser's cookie controls.

Cookies and similar technologies

We use a small number of first-party cookies, along with browser local and session storage, to sign users in, remember preferences, and measure product usage. On public marketing pages only, we also load the Meta Pixel (see "Advertising measurement (Meta Pixel)" above), which may set third-party cookies or similar identifiers for advertising measurement. We do not load advertising pixels or third-party ad networks on authenticated child-facing lesson or dashboard pages.

Strictly necessary — required for the service to work:

  • Supabase authentication cookies (names beginning with sb-) — keep a user signed in and protect the session. Without these, login does not work.
  • bt_age_attestation and bt_age_under13 — record the result of the neutral age screen and prevent an immediate retry with a different age. Both expire after one hour and cannot be read by page scripts.
  • bt_onboarding_character and bt_onboarding_personalization— carry a user's onboarding selections across a sign-in redirect so they are not lost. Both expire after one hour.
  • bt_consent_child_name and bt_consent_token— carry the parental-consent details for an under-13 signup across a sign-in redirect, so a child's name is never placed in a URL. Both expire after one hour and cannot be read by page scripts.

Preferences — remember a choice the user made:

  • btw-color-mode — stores the light or dark theme selection so the correct theme appears on the first paint of the next visit. Expires after one year.
  • Browser local storage — the sound-effects setting, whether a promotional banner was dismissed, and whether a streak celebration has already been shown. These stay on the device and are not sent to us.
  • Browser session storage — in-progress onboarding answers and signup context, so a partially completed form survives a page refresh. These are cleared when the browser tab is closed and on sign-out.

Analytics — first-party measurement only:

  • PostHog identifier (a first-party cookie whose name begins with ph_, plus a matching entry in browser storage) — distinguishes one visit from another so we can count usage. It is served from our own domain and is never shared with advertisers or used for cross-site tracking. For children under 13 and for users whose age band we cannot determine, analytics capture is turned off and no analytics profile is created; a small first-party flag may be stored to remember that opted-out state. See "Analytics (PostHog)" above for the full detail.

Third parties that may set their own storage:

  • Stripe— loaded only on the checkout page. Stripe sets its own cookies to detect payment fraud, governed by Stripe's privacy policy. Stripe is not loaded on child-facing lesson pages.
  • Meta (Facebook)— loaded only on public marketing pages and for adult/teen conversion events. Meta may set cookies or similar identifiers for advertising measurement, governed by Meta's privacy policy. The Meta Pixel is not loaded on child-facing lesson or dashboard pages.
  • YouTube and Vimeo — used only when a lesson includes a hosted video. We embed YouTube through its privacy-enhanced youtube-nocookie.com domain. A provider may set storage on the device when a video is played.

Mobile app:our iOS and Android apps do not use cookies. The signed-in session is held in the device's secure keychain, and preferences are stored in on-device app storage.

Your choices:most browsers let you block or delete cookies and clear site storage in their settings. Blocking the strictly necessary cookies above will prevent sign-in and the age screen from working. Analytics is already off by default for children and for any user whose age we cannot determine. We do not sell personal information. To limit Meta advertising measurement, use your Meta account ad preferences and your browser's cookie controls, or avoid public marketing pages while logged out of Meta.

Service providers we share data with

We share personal information only with the vendors needed to run the service, each under a written data-processing agreement (DPA) that restricts their use of the data to providing services to us. We do not sell personal information, and we do not disclose a child's personal information to third parties for their own purposes.

  • Supabase — authentication and database hosting (United States)
  • Vercel — application hosting and delivery
  • Resend — transactional and notification email delivery
  • Expo — mobile push notification delivery (13+ and parent devices only; no child-device tokens)
  • Browser push services (Apple, Google, Mozilla) — web push notification delivery (13+ and parents only; no child subscriptions)
  • Stripe — recurring subscription billing; purchases for users under 13 require parent or guardian authorization
  • Anthropic— AI model inference for optional lesson help chat and in-lesson AI interactive exercises (ephemeral processing; educational purpose only; not for advertising or model training for Anthropic's own purposes)
  • PostHog — first-party product analytics (no behavioral advertising; child sessions anonymous; session recording only for adult parent/teacher/admin accounts with inputs masked)
  • Sentry — error and performance monitoring (no default PII)
  • Meta Platforms (Facebook)— advertising measurement via the Meta Pixel on public marketing pages and for adult/teen conversion events only (not loaded for under-13 accounts or on child-facing lesson/dashboard pages; Meta is an independent controller of Pixel data under Meta's privacy policy)

Verifiable parental consent

For users under 13, we provide parents with direct notice and obtain verifiable parental consent before collecting, using, or disclosing the child's personal information beyond the age screen. Consent to collect a child's information is separate from any consent that would be required to disclose it to a third party for that party's own purposes (which we do not do). Parents may review their child's information, refuse to permit further collection or use, revoke consent, and request deletion at any time by contacting us at support@bigthinkers.ai. A child's own account settings also include self-service data export and account deletion.

Schools and student records (FERPA)

When a school deploys Big Thinkers, the school may provide authorization in place of individual parental consent, but only for the school-authorized educational purpose. Student data received in this context is used solely to provide the educational service the school engaged us for—never for marketing, advertising, profiling, or sale. We act as a "school official" with a legitimate educational interest. Self-serve classroom tools are currently paused; schools interested in deployment should contact educators@bigthinkers.ai. Parents and eligible students may access, review, and request correction or deletion of education records by contacting us at support@bigthinkers.ai, and we return or delete a school's student data when the school relationship ends.

State privacy and minor-protection laws

For users in states with student- and minor-privacy laws (such as California, Illinois, New York, and others), we honor the following baseline regardless of age band: no sale of personal information, no targeted advertising based on data obtained through the service, no profiling except for school-authorized educational purposes, highest-privacy defaults for minors, and no use of dark patterns to weaken privacy choices. Deletion is available on request, including on a district's request for student data.

Data retention

  • Incomplete, unconfirmed, completed, or revoked parental-consent requests are deleted after 90 days (or sooner when the related account is deleted).
  • Daily learning-activity records are retained for 24 months.
  • Lesson and activity progress records are retained while the account is active and for up to 24 months after last activity, then automatically deleted. Inactive accounts with no learning activity for 24 months are scheduled for deletion after notice where required.
  • Notification delivery logs are retained for 12 months and then automatically deleted.
  • Lesson help-chat transcripts are not retained in our database; they exist only in the learner's session while the activity is open.
  • Mobile push notification tokens are retained while the device is active and are automatically deleted after a period of inactivity, when the operating system reports the token is no longer valid, or when the user turns off push notifications or deletes their account.
  • Web push notification subscriptions are retained while active and are automatically deleted after a period of inactivity, when the browser's push service reports them as expired, or when the user turns off browser notifications or deletes their account. A web push subscription created during signup that is never linked to an account is automatically deleted after 30 days.
  • Problem reports, including their lesson-screen screenshots, are deleted 90 days after submission.
  • Pending family-plan invitations expire after seven days. Family membership is retained while the seat or subscription remains active and is removed when the member leaves, the owner removes the seat, or the subscription ends.
  • Account data is retained while the account is active and deleted when a user, authorized parent, or school requests deletion.
  • Analytics and error-monitoring data are retained only as long as needed for the internal-operations purpose and within our providers' configured retention windows.

We delete personal information once the purpose for which it was collected has been fulfilled, subject to legal retention requirements.

Security

We maintain a written information-security program with safeguards appropriate to the sensitivity of the data we handle, including row-level security on databases holding child data, encryption in transit and at rest, least-privilege access to service credentials, and a policy against placing child personal information in logs, analytics events, or error reports. We require written assurances (DPAs) from the vendors that process personal information on our behalf.

Your rights and choices

Users may export their data or delete their account from Settings after any active subscription has ended. Parents may review, download, or delete their child's data and revoke consent by contacting support. Schools may request access to, correction of, or deletion of student records. To exercise any of these rights, or if you have questions about this policy, contact us at support@bigthinkers.ai.

Where your data is processed

Big Thinkers is operated from the United States, and our core service providers process data in the United States. PostHog analytics is hosted on PostHog's U.S. cloud, and Sentry error monitoring is processed in Sentry's U.S. region. If you access the service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your location. Where required for international transfers, we rely on appropriate safeguards (such as standard contractual clauses) in our agreements with service providers.

Changes to this policy

If we make a material change to what we collect, how we use it, or the third parties we share it with, we will update this policy and, where required, obtain renewed parental or school consent before the change takes effect for affected users.

Contact us

Big Thinkers — Privacy. Email support@bigthinkers.ai for any privacy, COPPA, or FERPA request, including parental review, consent revocation, and deletion.