Legal
DRAFT — pending counsel review (G3), not yet legally operative. This document is an internal draft prepared by the product team to describe current data practices. It has not been reviewed by legal counsel, is not a legal notice, and does not yet bind anyone. Bracketed placeholders (e.g.
[ENTITY],[MAILING ADDRESS]) are for counsel to complete.
Privacy Policy
Service: Quiz Karts (quizkarts.com)
Operator: [ENTITY]
Effective date: [EFFECTIVE DATE]
Contact: [PRIVACY CONTACT EMAIL] · [MAILING ADDRESS]
Quiz Karts is a learning game for children that a parent or guardian sets up and controls. This policy describes what information we collect, how we use it, who we share it with, and the choices and rights available to parents. Because the Service is directed to children under 13, this policy is written to serve as the direct notice a parent receives at the point of collection; the standalone version is at coppa-notice.md.
This is a description of our practices. It is not a certification of compliance with any law.
1. Who has an account
Only a parent or guardian holds an account. A parent registers with an email address and password, or signs in with Google.
Children never log in and never create their own accounts. A child plays only after the signed-in parent selects a child profile the parent created.
2. Information we collect from the parent
- Email address — used to sign in, secure the account, and send service email.
- Password — stored only as a salted PBKDF2-SHA256 hash; we never store or log the plaintext password.
- Google account details (only if the parent chooses Google Sign-In) — the parent's Google account identifier (
sub), email address, and display name, obtained from a Google-issued token our server verifies. - Session tokens — an opaque bearer token is issued at sign-in and expires after 30 days.
- Login-attempt records — the email and timestamp of recent sign-in attempts, kept briefly to rate-limit and protect the account, then automatically purged.
- Subscription and billing records (paid plans) — when a parent subscribes, our payment processor handles the card transaction; we retain the processor's customer and subscription identifiers, plan, and status. We do not store full card numbers.
- Marketing contact (optional) — an email address a visitor submits to request updates about a school or district.
- Product events — first-party usage events recorded in our own database to understand and improve the Service.
3. Information related to a child
A parent creates a child profile. The profile holds:
- A display name — free text the parent enters (up to 24 characters). The parent chooses what to put here; it may be a first name, a nickname, or any label the parent prefers. The child does not create this profile or type this in.
- A grade level (0–8) and an avatar (one of two presets, "girl" or "boy").
- Learning activity — for each question the child answers: the question, whether the answer was correct, the game mode, how long the answer took, and a timestamp. This drives the practice ladder and the parent's report card.
- Game progress and cosmetics — points, race and dash results, high scores, and the child's collected/equipped in-game items and treehouse decorations.
- Transient "park" presence — while a child is in the shared family park screen, the profile's name, avatar, and current outfit are held so siblings can see each other; this record auto-expires within about 45 seconds of the child leaving.
We do not ask the child for a home address, phone number, photograph, precise location, or other contact information, and the Service provides no field for a child to enter such information.
4. How a child interacts with others
- No chat or free text between children. In head-to-head duels the only messages a child can send are a small set of preset emoji cheers; any other input is discarded by the server.
- Family-only visibility. The park roster and duels are limited to profiles under the same parent account (siblings). A child never sees, is matched with, or can contact another family's child.
5. How we use information
We use the information above to: run the game and save progress; adapt question difficulty to the child; show parents a report card; operate accounts and sign-in; secure accounts and prevent abuse; process subscriptions; respond to support requests; and improve the Service.
We do not use children's information to serve behavioral advertising or to build advertising profiles.
6. Sharing and third parties
- We do not sell personal information, and we do not share it for targeted advertising.
- No third-party advertising or analytics trackers. The web app loads no ad SDK and no third-party analytics/tracking script; product analytics are recorded first-party in our own database.
- Service providers we rely on:
- Google Sign-In — if a parent uses it, Google authenticates the parent and returns a verified token to us. The Sign-In component is loaded from Google.
- Payment processor — processes subscription card payments on paid plans. [Processor to be named by counsel; Stripe planned.]
- Hosting/infrastructure provider — runs the servers and database that store the data described here. [Provider details for counsel.]
We may also disclose information if required by law or to protect the Service and its users.
7. Data retention and deletion
- Session tokens expire 30 days after issue.
- Login-attempt records are purged automatically (kept only for a short rate-limit window).
- Park-presence records auto-expire within seconds of a child leaving the park.
- Account, profile, and learning-activity records persist until the account is closed or the parent requests deletion (see §8). [Full retention schedule with concrete deletion deadlines to be set with counsel per the written data-retention obligation in research/plan_business.md §7.1.]
8. Parent rights and choices
A signed-in parent can, within the app, view their children's profiles, progress, and report-card analytics, and edit a child's profile.
A parent may also:
- Review the personal information we hold about their child;
- Delete their child's information and/or close the account;
- Refuse further collection or use of their child's information (this may end the child's ability to use the Service).
There is currently no self-service "delete account" button in the app; to exercise the rights above, contact us at [PRIVACY CONTACT EMAIL] and we will verify the request and act on it.
9. Security
We protect account credentials and data with measures including: salted PBKDF2-SHA256 password hashing; per-request ownership checks so a parent can reach only their own family's data; sign-in rate limiting; expiring session tokens; default-deny cross-origin access; and baseline security response headers including HSTS.
[Written information-security program to be documented with counsel per research/plan_business.md §7.1.]
10. Changes to this policy
We may update this policy. Material changes affecting information already collected from children will be handled consistent with the parental-notice practices described here. [Mechanism to be finalized with counsel.]
11. Contact
[ENTITY] [MAILING ADDRESS] [PRIVACY CONTACT EMAIL]