Privacy Policy for AI Safety Adventures
Effective Date: January 31, 2026
Last Updated: September 1, 2026 (this update corrects how we describe consent for classroom use: COPPA contains no "school consent" exception and we no longer claim one — see "How Consent Works for Classroom Use"; we also removed the FERPA "school official" label, which did not fit us, corrected the failed sign-in disclosure to say exactly what is and is not kept, and completed the description of what our sign-in rate limits count. The August 28, 2026 update before it: one product change and several accuracy corrections. The product change: we removed every place a student could type a free-text answer — worksheet written questions are now answered in handwriting on the printed worksheet, and Investigator reflection prompts are discussed rather than typed. The corrections: a daily job now deletes the error records in our own database at 30 days; we stopped calling student identifiers "anonymous", because they are pseudonymous and a persistent identifier counts as personal information under COPPA; we corrected the age range the Service serves; and we corrected what our rate-limit provider receives — since August 24, 2026 it gets only scrambled digests, never the raw IP address, while the separate usage record we switched off on August 8, 2026 still holds its old entries; see Processor Inventory for the full technical list)
COPPA Compliance: Updated for COPPA 2025 requirements
Introduction
AI Safety Adventures ("we," "our," or "us") operates game.ethis.ai (the "Service"). This Privacy Policy explains how we collect, use, and protect information when you use our educational platform. We are committed to complying with the Children's Online Privacy Protection Act (COPPA) and protecting the privacy of children under 13.
COPPA NOTICE: Our Service is designed for use in educational settings under teacher supervision. We collect minimal information from children. Students sign in with a machine-generated identifier instead of a real name. That identifier is pseudonymous, not anonymous: under COPPA a persistent identifier counts as personal information, so we use it only to run the Service. The "Kid-Created Accounts" section below explains this in full.
Information We Collect
Teacher Accounts
When teachers create accounts, we collect:
- Email address
- Name
- Google account information (if using Google Sign-In)
- Classroom and student management data
- Payment information (processed securely by Stripe; we do not store credit card numbers)
Student Information
We prioritize student privacy and collect minimal information:
- Machine-generated identifiers, not real names - Students are identified by a randomly generated token or username. This is pseudonymous, not anonymous: a persistent identifier is personal information under COPPA, and we use it only to run the Service.
- Progress data and quiz responses linked to that identifier
- We do not ask a student for their name, home address, birthdate, phone number, photo, or precise location.
- No typed written answers. We removed every place a student could type a written answer. Worksheet questions that call for one are completed in handwriting on the printed worksheet, which stays in the classroom — the Service never sees that paper. Reflection prompts in the Investigator edition are for thinking and class discussion, and have no typing box. The answers we do store are the choices a student picks on multiple-choice and true/false questions — the letter of the choice, nothing more; the Service refuses any other value — and their teacher can see those. One honest carve-out: security and error records can still capture short pieces of typed text. When a sign-in fails, we keep what was typed in the username box only if it matches the shape of the usernames we hand out — two words from our word lists plus two digits. A username like that is personal information under COPPA, the same as the identifier described above, and we keep it for one reason: to see which account someone was trying to open. Anything else that was typed does not go into that security record — it holds only the fact that the text was not one of our usernames, and how many characters it had. An error report from a page that breaks can still include what a form held when it broke. Those records exist to keep accounts safe and to fix bugs, are not shown on any teacher or student screen, and age out on the schedules in the Data Retention section below. Earlier versions of the Service had typing boxes for the worksheet and reflection activities. We removed them on August 28, 2026, and we checked our records first: no student had ever used them.
- Two exceptions we want to be plain about. A student aged 13 or over who makes their own account can give us an email address, which we use to verify the account and to help them sign back in. Children under 13 never give us an email. Separately, if a teacher turns on the optional Google Classroom or Microsoft roster sync, the school sends us its own roster, which may contain real student names. That comes from the school, not from the child.
Automatic Information
We may collect:
- Usage data through Vercel Analytics and Speed Insights. These load only on a short list of adult pages that we name in our code. The list is the home page, our marketing and information pages, the adult sign-in pages, the teacher dashboard, and the admin console. Every page not on that list is off by default. That includes all of the kids' play pages.
- Device information, browser type, and IP addresses. Your browser user-agent is the line of text your browser sends naming itself and your device. It does not name a person. Here is where each of these goes:
- Children's sign-in records. When a child signs in or makes an account, we keep a security record. It holds the IP address and the user-agent, each as a SHA-256 digest. A digest is a scrambled fingerprint of the text it was made from. It keeps the plain address out of the record. But a digest is not the same as anonymous data. An IP address digest can be turned back into the address, so we treat it as personal data.
- Server logs. Raw IP addresses and user-agents sit in our server logs for 30 days.
- Anti-abuse limits. Our rate limits count requests by a SHA-256 digest of the IP address — a scrambled fingerprint, like the sign-in records above. Sign-in limits fold what was typed into the digest, so tries at different accounts are counted separately: the username for a child's own account, and the class code and student number for a school sign-in. Adult sign-in limits are counted by a digest of the email address alone. Since August 24, 2026 the raw address itself does not leave our servers for this purpose; before that date most limits did send the raw address, and those short-lived counter entries have since expired on their own. A digest is not the same as anonymous data: an IP address digest can be turned back into the address, so we treat it as personal data. The counts themselves expire within 24 hours. Until August 8, 2026 our rate-limit provider also built a second, separate usage record that included the raw address. We switched that off, so nothing new is added to it. The entries made before that date are still held by the provider, they have no expiry date, and no job deletes them yet.
- Parent sign-ins and adult account events. These records keep the raw IP address and user-agent. Account events are things like teacher and parent sign-up, password reset, and email checks.
- Error reports. These keep the raw user-agent, including reports sent from the kids' pages. Again, that names a browser and a device, not a person.
- Cookies for signing in and staying signed in. Analytics cookies only on the adult pages in the list above.
How We Use Your Information
We use collected information to:
- Provide and maintain the Service
- Enable teacher accounts and classroom management
- Track student progress through machine-generated identifiers
- Improve our educational content and user experience
- Analyze usage patterns through analytics tools
- Communicate with teachers about their accounts
Data Retention
We follow strict data retention policies in compliance with COPPA 2025 requirements:
Student Data
- Active classroom lifetime + 30-90 days after classroom deletion
- Automatic deletion when classroom is removed by teacher
- Parent/guardian request: Deleted within 5 business days
Teacher Data
- Account lifetime + 30 days after account deletion
- Billing data: 7 years (legal requirement for tax purposes)
- Teachers may request account deletion at any time: privacy@ethis.ai
System Logs
- Server logs: a rolling 30-day window. Older entries drop off the end.
- Error reports we send to Sentry: 90 days. Sentry then deletes them.
- Error records in our own database: 30 days. A job clears them every day.
- Audit logs: 1 year. A job clears them every day.
- Adult account events — teacher and parent sign-up, email verification, password reset and password change — sit in a second log. Our target is 1 year. No job clears it yet.
Full details: See our complete Data Retention Policy
Children's Privacy (COPPA Compliance)
Our Service is designed for students in grades 3-12, which is roughly ages 8 to 18. For the children under 13 among them, we comply with the Children's Online Privacy Protection Act (COPPA) as updated in 2025. We take children's privacy seriously and follow strict data protection practices.
What Information We Collect from Children
We use a minimal data collection approach:
- A machine-generated identifier - Students are identified by a cryptographically random token or username rather than by their real name. It is pseudonymous, not anonymous: a persistent identifier is personal information under 16 CFR §312.2(7). A teacher can match it to a student in their own classroom, which is how they see who needs help.
- Learning progress data - Lessons completed, quiz scores, achievement badges (linked to that identifier only)
- Display names (optional) - If enabled by the teacher; pseudonymous only
- No other personal information - Beyond a first-party persistent identifier used solely for internal operations (see "Kid-Created Accounts" below), we do not collect names, photos, precise locations, or other PII from students. The two exceptions are named under "Student Information" above: an email address from students aged 13 and over who make their own account, and school-supplied roster data if a teacher turns on roster sync.
Kid-Created Accounts (Explorer Edition): Persistent Identifier for Internal Operations
In the Explorer Edition (grades 3-8), a child can create their own account and start playing without a parent email and without a verifiable-parental-consent gate. This section is the online notice required by the COPPA Rule at 16 CFR §312.4(d)(3) for operators that rely on the internal-operations exception at 16 CFR §312.5(c)(7). Both requirements come from the 2025 COPPA Rule, 90 FR 16977 (Apr. 22, 2025), whose compliance deadline was April 22, 2026.
A child-created Explorer account stores only a machine-generated username (for example, "brave-robot-42"), a hashed PIN or emoji passcode the child chooses, an avatar selection, and the child's own in-game progress and scores. We do not ask for, and the child does not provide, a real name, email address, phone number, birthdate, photo, voice recording, location, or any free text about themselves. The generated username is not an email or contact handle and cannot be used to reach the child.
This is not a "collect-nothing" account. A machine-generated username is a first-party persistent identifier, which is personal information under 16 CFR §312.2(7). Stated precisely: we collect no personal information from the child other than a first-party persistent identifier that we use solely to support the internal operations of the Service. That is exactly what the §312.5(c)(7) exception permits, and this notice is what §312.4(d)(3) requires in return.
The specific internal operations the identifier supports:
- Authenticate the child — sign them in, and sign them back into the same account when they return.
- Maintain state — keep the child's place in the current adventure or episode.
- Personalize the child's own content — remember the choices they made and the scores and progress they earned.
- Product analytics and security — measure and improve the Service, and guard against fraud and abuse. The analytics half uses only grouped or session-scoped data. It is not tied to a child's real name or address. The security half also uses the IP address of the request. Our anti-abuse service gets a scrambled digest of that address, not the address itself. See "Automatic Information" above.
Safeguards — what the identifier is never used for. We do not use the persistent identifier, or any account data, to contact or message the child, to build a behavioral profile of the child, or to serve targeted, behavioral, or interest-based advertising (we serve no advertising to children at all). We do not disclose the identifier or the child's account data to third parties for any of those purposes; any provider that hosts or processes this data acts only as our service provider under contract.
Data retention and deletion (16 CFR §312.10). We keep a child-created account and its persistent identifier only as long as reasonably necessary to provide the Service to that child — that is, while the account is in use. When the identifier is no longer needed for that purpose, we delete it. A parent or guardian may review or request deletion of their child's account at any time by contacting privacy@ethis.ai; we act on verified deletion requests within 5 business days.
Parental Rights
Parents and legal guardians have the following rights under COPPA:
- Review: Request to review the child's information via the teacher
- Delete: Request deletion of the child's data at any time
- Refuse collection: Refuse further collection or use of the child's information
- Consent: The school may act as the parent's agent in authorizing classroom use — see "How Consent Works for Classroom Use" below
To exercise these rights, contact: privacy@ethis.ai or contact your child's teacher
How Consent Works for Classroom Use
COPPA does not contain a school-consent exception; the FTC declined to codify one in its 2025 amendments. We follow the FTC's published guidance for ed tech, under which a school may act as the parent's agent in authorizing a service used solely for the school's educational purposes and for no commercial purpose. We give the school the same notice we would give a parent, and on request we will provide the categories of information collected, allow review and deletion, and stop further collection at any time. Responsibility for COPPA compliance rests with us as the operator, not with the school, the teacher, or any parent. We:
- Collect only information necessary for educational purposes
- Do not use student information for commercial purposes
- Do not share student information with third parties (except as required for Service operation)
- Notify schools of our data practices
Data Retention for Student Information
Student data is retained as follows (see our full Data Retention Policy):
- Active classroom: Data retained while student is enrolled
- After classroom deletion: 30-90 days (varies by data type)
- Parent request: Deleted within 5 business days
- Inactivity: Data reviewed after 365 days of no use
We Do NOT
- Sell or rent student information to anyone
- Use student information for targeted advertising
- Create profiles of students for non-educational purposes
- Share student information with data brokers
- Require children to provide more information than necessary to use the Service
Third-Party Services (Sub-Processors)
We use the following third-party services to operate our Service. We do NOT share student information with advertising or marketing services. For the complete technical inventory including data-deletion APIs and SLAs, see our Processor Inventory.
| Service | Purpose | Data Shared |
|---|---|---|
| Vercel | Hosting & CDN | Request paths, response status, and the client IP address (no request bodies). |
| Neon Postgres | Database storage | All application data (encrypted at rest by Neon; AES-256) |
| Stripe | Payment processing | Teacher billing only (no student data) |
| Resend | Transactional email (parents, teachers, admin) | Parent + teacher email addresses; email subject and body. Never sent: kid PIN, kid emoji, kid username, kid raw token |
| Sentry | Error tracking | Random user IDs (UUIDs) — pseudonymous, not anonymous, because the same ID follows the same student across reports — plus error stack traces. Sensitive keys (parent emails, kid PINs, passwords, raw session tokens) are redacted before send via a beforeSend filter. Request bodies are stripped. |
| Upstash Redis | Rate limiting (abuse and lockout protection) | Rate-limit counts only. Every key we send is a SHA-256 digest — of an IP address, an email, or an IP joined with an account identifier. We never send a raw email or a raw token, and since August 24, 2026 we do not send a raw IP address either. A digest is not the same as anonymous data. The counts themselves expire within 24 hours. A second, separate usage record that included the raw address was switched off on August 8, 2026; nothing new is added to it, but the entries made before that date are still held by the provider, have no expiry date, and are not deleted on a schedule yet. |
| Vercel Blob | Teacher community-resource file uploads | Teacher-uploaded file contents + uploader ID. Teacher-only feature; no student-initiated uploads. |
| Vercel Analytics + Speed Insights | Page-view metrics + page-load performance | Page path, page views, page-load speed, and country-level location. These load only on a short list of adult pages that we name in our code. The list is the home page, our marketing and information pages, the adult sign-in pages, the teacher dashboard, and the admin console. Every page not on that list is off by default. That includes all of the kids' play pages. |
| Google OAuth | Teacher authentication (optional) | Teacher email + name (only when teacher opts in to Google Sign-In) |
| Google Classroom | Teacher LMS roster sync (opt-in; teacher initiates) | Teacher OAuth scope + classroom roster data (only when teacher uses the integration). Roster contains student display-names as provided by the school SIS; we do not enrich or persist beyond the classroom record. |
| Microsoft Graph | Teacher LMS roster sync (opt-in; teacher initiates) | Teacher OAuth scope + classroom roster data (only when teacher uses the integration). Same scope as Google Classroom row. |
We do NOT use:
- Google Analytics or any advertising/marketing analytics
- Any analytics on the kids' play and sign-up pages (those pages are tracking-free)
- Advertising networks
- Social media tracking pixels
- Data brokers or third-party marketing services
These services have their own privacy policies and we require all of them to comply with COPPA and maintain appropriate security measures. A Data Processing Agreement (DPA) is on file with each processor that handles parent or kid-linked data.
Data Security
We implement industry-standard technical and organizational measures to protect your information:
- Encryption in transit: HTTPS/TLS 1.3
- Encryption at rest: AES-256 for all databases
- Secure authentication: NextAuth.js with bcrypt password hashing
- Rate limiting: Protection against brute force attacks
- Security headers: CSP, HSTS, X-Frame-Options
- Dependency scanning: Automated vulnerability detection (Dependabot)
- Regular security assessments: Quarterly security reviews
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
Data Breach Notification
In the unlikely event of a data breach affecting student information, we will:
- Notify the FTC: Within 10 business days (as required by COPPA 2025)
- Notify schools: Within 48 hours of discovery
- Notify parents: Via schools within 72 hours (if PII was exposed)
- Notify affected individuals: Via email for teacher accounts
- Provide details: Nature of breach, data affected, remediation steps
We maintain an Incident Response Runbook for rapid response to security incidents.
Your Rights
Depending on your location, you may have rights including:
- Access to your personal information
- Correction of inaccurate information
- Deletion of your account and associated data
- Objection to certain data processing
- Data portability
To exercise these rights, contact us at mike@ethis.ai.
International Users
If you are accessing our Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending email notifications to registered teachers for material changes
COPPA Compliance & Enforcement
We are committed to full compliance with COPPA as enforced by the Federal Trade Commission (FTC). Key commitments:
- FTC Registration: We have provided required operator information to the FTC
- Consent for classroom use: The school acts as the parent's agent under the FTC's published ed-tech guidance — see "How Consent Works for Classroom Use" above. Responsibility for COPPA compliance stays with us as the operator
- Data Minimization: We collect only information necessary for educational purposes
- Transparency: This policy clearly explains our data practices in plain language
- Reasonable Security: We maintain appropriate safeguards for children's information
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Privacy & COPPA Inquiries: privacy@ethis.ai
General Questions: mike@ethis.ai
Data Deletion Requests: privacy@ethis.ai
Security Concerns: security@ethis.ai
Website: https://game.ethis.ai
Response Time: We respond to privacy inquiries within 5 business days.
Cookie Policy
We use cookies and similar tracking technologies to:
- Maintain user sessions
- Remember user preferences
- Collect analytics data
- Improve Service functionality
You can control cookies through your browser settings, though some features may not function properly if cookies are disabled.
Data Processing Legal Basis (GDPR)
For users in the European Economic Area (EEA), our legal basis for processing personal information includes:
- Consent: When you provide explicit consent (e.g., creating an account)
- Legitimate Interests: To operate and improve our Service
- Legal Obligations: To comply with applicable laws
California Privacy Rights
CCPA (California Consumer Privacy Act)
California residents have additional rights under the CCPA:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
SOPIPA (Student Online Personal Information Protection Act)
For California students, we comply with SOPIPA by:
- Not using student information for targeted advertising
- Not creating profiles for non-educational purposes
- Not selling student information
- Maintaining reasonable security procedures
- Deleting student information upon request
To exercise these rights, contact privacy@ethis.ai.
FERPA (Educational Records)
The Family Educational Rights and Privacy Act (FERPA) applies to schools that receive federal education funding — it binds the school, not us directly, and many private schools are not subject to it at all. Where a school that is subject to FERPA uses the Service, we support that school's compliance. We:
- Use student information only for authorized educational purposes
- Do not share student information with unauthorized third parties
- Maintain security standards consistent with FERPA requirements
- Cooperate with schools' FERPA compliance obligations
State Student Privacy Laws
We comply with state student privacy laws including:
- California: SOPIPA, AB 1584 (privacy policy requirements)
- New York: Education Law 2-d (data security and privacy)
- Texas: Student Data Privacy Act
- Connecticut: Student Data Privacy Act (PA 16-189)
Schools may request a Data Processing Agreement (DPA) for additional contractual protections.
AI Safety Adventures is operated by Ethis.AI
© 2026 Ethis.AI. All rights reserved.