Privacy Policy

Last Updated: August 10, 2026

Introduction

At Kaizly Learning, LLC ("we," "us," or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational Service. By accessing or using our platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please do not use the Service.

This Privacy Policy applies to information we collect:

  • On our website
  • Through email, text, and other electronic communications
  • When you interact with our advertising or integrations on third‑party sites

1. Information We Collect

1.1. Guardian Data. Name, email, billing and payment information, account credentials.

1.2. Child Data. Child's first name, grade level, school, city and state where the school resides, interests, performance metrics, engagement logs, and free‑text responses your child enters while completing learning activities (these are automatically screened and name‑redacted before storage or AI processing — see Section 9.3).

1.3. Usage Data. Pages visited, timestamps, device and browser information, IP address.

1.4. Activity Patterns. Which activities a child starts and completes, start/stop times, areas of the Service frequented, number of questions answered correctly or incorrectly.

2. How We Use Information

2.1. Service Delivery. Generate and schedule personalized learning plans; allow parents to view, monitor, and pre‑approve all content before child access.

2.2. Improvement & Analytics. Analyze aggregated usage and performance data to improve AI models, adjust difficulty levels, and refine content.

2.3. Communications. Send transactional emails (billing, account, and security alerts); send lifecycle and onboarding emails (such as setup reminders, first‑activity nudges, and trial reminders) by default, which you can opt out of at any time using the unsubscribe link in those emails; and send optional newsletters (with opt‑in).

2.4. Legal Compliance & Fraud Prevention. Verify identity, prevent fraud, and comply with legal obligations.

4. Data Sharing & Disclosure

4.1. Service Providers.

We share Personal Information with third‑party vendors who perform services on our behalf, including:

  • Payment processors (e.g., credit‑card companies)
  • Hosting and infrastructure (Google Firebase / Google Cloud Platform)
  • Email delivery (Resend – used to send account, lifecycle, and support emails to guardians)
  • Analytics (Google LLC – Google Analytics 4)
  • Advertising measurement (Meta Platforms, Inc. – Meta Pixel)
  • AI processing (OpenAI – used to generate and grade learning content; child inputs are filtered for personal information)
  • Analytics and research partners (e.g., to study educational impact)
  • Content‑filtering services (e.g., to scrub personal data from child inputs)

4.2. Affiliates & Business Partners.

We may share Personal Information and de‑identified usage data with our affiliates, subsidiaries, and business partners to:

  • Fulfill the purposes for which you provide the information (e.g., deliver content, process payments)
  • Screen performance, calibrate difficulty, and improve content recommendations
  • Conduct joint research or co‑marketing initiatives — guardian (adult) information only; we never share a child's personal information for research or co‑marketing purposes

4.3. Legal Requests.

We may disclose Personal Information in response to subpoenas, court orders, or as required by law, or to protect our rights, property, or safety, or those of our users or others.

4.4. Other Disclosures.

We may disclose Personal Information:

  • For any other purpose disclosed at the time of collection
  • With your consent

4.5. No Sale of Data.

We do not sell personal or child data to third parties.

On our public marketing pages, limited device and browsing data (such as pages visited, device type, and IP address) may be shared with advertising partners, including Meta Platforms, Inc., to measure and optimize our advertising as described in Sections 12 and 13, where permitted by applicable U.S. law. Additionally, when marketing cookies are enabled and you provide your email address during registration, we may share a one-way cryptographic hash (SHA-256) of your email address with Meta for advertising measurement purposes. We never share your actual email address, and this hashing is irreversible. We also share limited device data with analytics providers as described in Section 12. You may opt out of this sharing at any time through the cookie settings link in our footer, the notification bar shown on your first visit, or your browser settings, and we honor all opt-out choices.

5. Data Retention & Deletion

We retain personal and child data only as long as needed to provide the Service, and we do not retain children's personal information indefinitely. The defined limits below are our children's‑data retention policy, adopted August 10, 2026:

  • Active accounts. Personal and child data is retained for the life of your account.
  • Cancelled accounts. After cancellation, your family's data (including all child data) is retained for up to two years, after which it is flagged and deleted. You do not need to wait for that window — see "Deletion on request" below.
  • Operational logs. System logs used to operate and troubleshoot the Service — email‑delivery logs and AI generation/error logs — are retained for 90 to 180 days depending on log type, then deleted.
  • Support messages. Messages you send us through Contact Us are retained for 2 years.
  • Deletion on request. You may request deletion of your account and all associated child data at any time by emailing privacy@kaizly.com. We honor deletion requests within 30 days.

Deletion is irreversible once complete; our operational backups are retained for 7 days, which is the only window in which recently deleted data could be recovered.

Not covered by this section. Content Kaizly authors and publishes — lesson and activity templates, and published educational pages and PDFs — is not personal information about you or your child and is retained indefinitely as our work product.

Analytics event‑level data collected through Google Analytics 4 is retained for 14 months and then automatically deleted by Google.

6. Security Measures

  • Encryption. TLS for data in transit; AES‑256 at rest.
  • Access Controls. Role‑based permissions and regular audits.
  • Incident Response. Procedures to detect, contain, and notify you of any data breach without unreasonable delay, in accordance with U.S. law.

7. Parental Rights & Controls

7.1. Review & Remove Activity. Content and activities for each child are loaded to the platform up to five days ahead of their scheduled date. The parent dashboard includes a “Remove Activity” control that lets you review and withhold any activity from your child’s view before its scheduled date. If you take no action, the activity releases automatically to your child on that date.

7.2. Access & Correction. You may view and update your account information and child profiles at any time in your account settings.

7.3. Data Export. You may request an export of your child's data by contacting privacy@kaizly.com; we fulfill requests within 30 days.

7.4. Deletion & Refusal of Further Collection. To delete your account and all associated child data, email privacy@kaizly.com or use the "Contact Us" page; we honor requests within 30 days (see Section 5). You may also direct us to stop collecting any further personal information about a specific child at any time. Because the Service works by collecting a child's activity data to personalize instruction, refusing further collection for a child generally means we deactivate that child's profile — you do not need to close your entire family account to exercise this right for one child. We will comply unless prohibited by legal obligations.

8. International Data Transfers

All data is stored and processed in the United States. If we transfer data outside the U.S., we will implement appropriate safeguards (e.g., standard contractual clauses).

If you are located outside the United States and provide information to us, you consent to its transfer to and processing in the United States under this Privacy Policy.

9. Children's Privacy

9.1. No Collection Without Consent. We do not knowingly collect data from children under 13 without parental consent. If we learn that we have inadvertently collected such data without consent, we will delete it promptly.

9.2. Necessity. We collect no more of your child's personal information than is reasonably necessary to provide the Service — generating, scheduling, and grading personalized learning activities and reporting your child's progress to you. We do not collect a child's last name, birthdate, photo, or contact information.

9.3. How We Verify Parental Consent. We verify every adult account with a credit card at signup, one of the parental‑consent methods accepted under COPPA. We do not use government‑ID or facial‑recognition verification. Free‑text answers your child enters while completing an activity are automatically screened for their own first name (which is redacted before storage or AI processing) and passed through a content‑moderation filter; submissions the filter flags are rejected.

9.4. Your Right to Refuse or Delete. You may refuse to permit any further collection of your child's personal information, or request deletion of it, at any time by contacting privacy@kaizly.com. See Sections 5 and 7.4 for our retention windows and deletion process.

9.5. A Supervised Tool. Kaizly is built for parents and teachers, not as a standalone product for children. A child uses the Service only under parent or teacher supervision, on an account a verified adult created and consented to — children do not create their own accounts.

9.6. Who Receives Your Child's Data. The table below shows which of our service providers ever receive a child's personal information, and which never do.

Receives child dataAdult data only — never receives child data
OpenAI (generates and grades activities; processes but does not use API data to train its models)Stripe (billing and payment)
Firebase / Google Cloud Platform (hosting and storage)Meta Platforms, Inc. (advertising measurement)
Resend (transactional email, e.g., an activity reminder addressed to your child's first name)Google Analytics 4 (site analytics)

9.7. Teachers, Schools & Students. Kaizly's teacher tools are used by individual teachers, not schools, to generate printable worksheets and activities for their own classroom use. Students never create accounts and never submit any personal information through the teacher flow — a teacher may enter a lesson topic, standard, or brief description of the class, but no student names, accounts, answers, or other student data are collected by the Service in the teacher flow. Because no student data is collected, no school‑level consent is required or claimed; the COPPA consent described in Section 9.3 governs the teacher's own account.

10. Changes to This Policy

We will post updates here with a revised “Last Updated” date. For material changes—meaning any change that significantly affects what Personal Information we collect, how we use it, or your rights—we will provide notice via email or in‑app message at least 30 days before the change takes effect. Continued use of the Service after that 30‑day period constitutes acceptance.

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance and analyze your experience. Cookies are small data files stored on your device. In the United States, analytical cookies are active by default across the Service (our public marketing pages and the authenticated parent product) where permitted by law — but never on child‑directed activity pages, where we do not enable analytics at all. Advertising/measurement cookies are active by default only on our public marketing pages. You can opt out of analytical and advertising cookies at any time through the cookie settings link in our website footer, the notification bar on your first visit, or your browser settings. Types we use include:

  • Essential cookies: Necessary for core functionality
  • Analytical cookies: Help us understand usage patterns across the Service (public marketing pages and the authenticated parent product), but never on child‑directed activity pages (see Section 12)
  • Functional cookies: Remember your preferences
  • Advertising/measurement cookies: Used on our public marketing pages to measure the effectiveness of our advertising on platforms such as Meta (Facebook/Instagram). These cookies are active by default on those public marketing pages, may be disabled through your cookie preferences, and are never placed on child‑directed pages or enabled by default on authenticated/product routes (see Section 13)

You can manage analytical and advertising cookies through the cookie settings link in our footer, the notification bar shown on your first visit, or your browser settings. Essential cookies cannot be disabled as they are required for the site to function properly.

Client‑side storage. In addition to cookies, we use your browser’s sessionStorage (cleared when you close your browser) to hold marketing attribution parameters (e.g., UTM tags) during a single visit so they can be associated with your registration. We also use localStorage (persists until cleared) for small deduplication flags that prevent the same analytics event from being recorded more than once per user. These storage mechanisms do not contain personal information and are not shared with third parties.

12. Analytics

We use Google Analytics 4 to understand how visitors use our site. Google Analytics sets cookies and similar identifiers on your device and receives information such as device type, referring page, and pages visited. Google Analytics 4 does not log or store IP addresses. Google uses this information to provide aggregated reports to us. Google may also combine the data with information from other websites if you have allowed such processing in your Google account settings.

Conversion and engagement events. We record anonymized conversion events (such as registration steps completed, activities started, and subscription changes) to measure how effectively our Service guides users from sign‑up through active use. These events include non‑identifying metadata such as user role (parent or teacher), subscription plan type, and plan price, but never include names, email addresses, child names, or any data that could identify a specific individual or child. On authenticated pages, GA4 events contain only aggregated counts and categorical labels (e.g., subject, grade level) — no child‑specific answers, scores, or personally identifiable information are transmitted to Google.

Consent model. Google Analytics is configured with analytics storage enabled by default across the Service — our public marketing pages and the authenticated parent product (such as the dashboard and settings) — under a U.S. opt‑out model. We do not enable analytics, and set no analytics cookies, on child‑directed activity pages. When analytics is enabled, Google may set cookies on your device to help us understand how the Service is used. If you opt out of analytical cookies through our cookie preferences, analytics storage is disabled everywhere and Google processes data in a privacy‑safe, cookieless mode that does not store identifiers on your device.

  • Opt‑out: You can install the Google Analytics Opt‑out Browser Add‑on or disable analytical cookies through the cookie settings link in our footer or the notification bar shown on your first visit.
  • Legal basis: Legitimate interest for analytics on public marketing pages, with the ability to opt out at any time, where permitted by applicable U.S. law.
  • Data sharing: Google Analytics 4 does not log or store IP addresses, and we do not send any user‑identifiable or child‑specific data to Google.
  • Retention: Google Analytics event‑level data is retained for 14 months and then deleted automatically.

See How Google uses information from sites or apps that use our services for further details.

13. Advertising Measurement

We use the Meta Pixel (provided by Meta Platforms, Inc.) on our public marketing pages to measure and optimize the effectiveness of our advertising on Meta platforms (Facebook and Instagram). The Meta Pixel is a snippet of code that sets cookies and similar identifiers on your device when you visit our marketing pages.

In addition to the browser‑based Meta Pixel, we use Meta's Conversions API to send the same categories of data listed below directly from our servers. This server‑side transmission improves the reliability of our advertising measurement when browser‑based tracking is unavailable (for example, due to ad blockers or browser privacy features). The Conversions API transmits data only when marketing cookies are enabled, and we apply the same data limitations described below (no names, email addresses, or child data).

What data is collected. When enabled, the Meta Pixel and Conversions API receive:

  • Pages visited on our marketing site
  • Browser and device type
  • IP address
  • Referrer URL

Hashed email matching. When marketing cookies are enabled and you provide your email address (for example, during account registration), we may share a one-way cryptographic hash (SHA-256) of your email address with Meta to improve the accuracy of our advertising measurement. This process converts your email address into a fixed-length string of characters that cannot be reversed to reveal your actual email address. We never send your actual email address, name, phone number, or any other personal identifier in cleartext to Meta. No child data of any kind -- hashed or otherwise -- is transmitted to Meta.

Purpose. We use this data to:

  • Measure how many visitors arrive at our site from Meta ads
  • Understand which ads are effective so we can improve our outreach
  • Build audiences of site visitors for advertising on Meta platforms

Where it runs. The Meta Pixel is loaded only on public marketing pages. It is never loaded on child‑directed pages, the learning platform, or any authenticated area of the Service by default. The Conversions API follows the same public-marketing-page scope and is not enabled by default on authenticated/product routes.

Consent model. The Meta Pixel and Conversions API are active by default on public marketing pages to measure the effectiveness of our advertising. You may opt out of marketing cookies at any time through the cookie settings link in our website footer or the notification bar shown on your first visit. If you opt out, the pixel will not load, the Conversions API will not send data, and no information will be sent to Meta.

Opt‑out. You can opt out at any time by:

  • Managing your cookie preferences through the settings link in our footer or the notification bar shown on your first visit
  • Adjusting your ad preferences in your Meta ad settings

Legal basis. Legitimate interest for advertising measurement on public marketing pages, with the ability to opt out at any time, where permitted by applicable U.S. law.

See Meta's Privacy Policy for further details on how Meta processes data it receives.

14. California Privacy Rights (CCPA/CPRA)

We do not sell personal data. When marketing cookies are enabled on our public marketing pages, limited device and browsing data may be shared with Meta Platforms, Inc. for advertising measurement as described in Section 13; under CCPA/CPRA this may constitute “sharing” for cross-context behavioral advertising. You may opt out of this sharing at any time by managing your cookie preferences through the settings link in our footer or the notification bar shown on your first visit. California consumers have the following rights under the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”):

  • Right to Know. Request disclosure of the categories and specific pieces of Personal Information we have collected about you.
  • Right to Delete. Request that we delete Personal Information collected from you, subject to certain exemptions.
  • Right to Correct. Request correction of inaccurate Personal Information.
  • Right to Opt‑out of Sale/Sharing. Direct us to not sell or share Personal Information. We do not sell data. You may opt out of sharing for advertising measurement by managing your cookie preferences through the settings link in our footer or the notification bar shown on your first visit, or by submitting a request to privacy@kaizly.com.
  • Right to Non‑Discrimination. You will not receive discriminatory treatment for exercising any of your CCPA/CPRA rights.

How to Exercise Your Rights. Email us at privacy@kaizly.com or submit a request via our Contact Us page. We will verify your identity before fulfilling the request.

15. Third‑Party Links and Services

Our Service may contain links to third‑party websites or services that we do not own or control. We are not responsible for their content or privacy practices. Please review the privacy policies of any third‑party sites you visit.

16. Contact Us

If you have any questions or requests regarding this Privacy Policy, contact us at:

  • Email: privacy@kaizly.com
  • Mail: 539 W. Commerce St #3004, Dallas, TX 75208, United States

Disputes arising from this Policy are governed by the dispute‑resolution terms in our Terms of Service.