Effective: June 27, 2026 · Version: 1.3 · Owner: James Kang, Founder (hello@nudgelearn.app)
Published pursuant to the Children's Online Privacy Protection Act (16 CFR Part 312) as amended effective April 22, 2026. This policy is binding on NudgeLearn and is referenced from our public Privacy Policy.
NudgeLearn collects personal information from parents (account holders) and minors (the children being tutored, and students whose work is graded) to operate a push-based AI tutoring service and a photo-based homework grader. This policy specifies, for each category of personal information we collect: (a) the purpose of collection, (b) the specific business need that justifies continued retention, and (c) the timeline after which the information is deleted or anonymized.
No personal information is retained indefinitely. No personal information is retained longer than reasonably necessary to fulfill the purpose for which it was collected.
| Category | Purpose | Business need | Timeline |
|---|---|---|---|
| Parent email, Stripe customer ID, subscription status, consent version & timestamp | Account management, billing, VPC proof | Required to service the subscription and produce a VPC record if audited | Active subscription + 7 years after cancellation |
| Child first name, grade, math track, channel identifier (phone number), delivery-time preference | Personalize daily tutoring messages and route inbound answers | Required every day the child is enrolled | Deleted within 30 days of account deletion or subscription cancellation |
| Raw inbound answer text | Evaluator scoring, hint chain context | Only needed for the active session and short-term adaptive difficulty calibration | Nulled 30 days after message timestamp (automated) |
| Structured response record (correctness, error type, difficulty, question ID, timestamp) | Adaptive difficulty, weekly parent report, aggregate quality metrics | Supports 12 months of longitudinal reporting and model improvement | Row deleted 12 months after message timestamp (automated) |
| Daily cost ledger (aggregate) | Per-student cost monitoring | Operational cost control | 24 months, then aggregated to monthly rollups |
| Consent events — VPC proof | Regulatory evidence that VPC was obtained before any collection | Required by COPPA enforcement | 7 years after consent revocation or account deletion |
| Webhook delivery logs, error logs | Operational debugging, abuse investigation | Short-term reliability | 30 days |
| Resend email delivery metadata (parent weekly report) | Deliverability monitoring | Operational | 90 days |
| Grader — uploaded image of student work + grading results (transcribed problems, the student’s answers, correct answers, score) | Grade the work and let the account holder review past grades | Available while the account is active for the account holder to revisit | Free plan: each graded paper is automatically deleted 90 days after upload, and only the 50 most recent are retained. Pro / Organization plans: retained while the account is active. Any graded paper can be deleted on demand from grading history, and all grader data is permanently deleted when the account is deleted. |
| Grader — teacher-entered roster (student names, optional notes, class/assignment labels) | Organize a teacher’s grades by student and class | Needed to group grades for class analytics | Retained while the account is active; permanently deleted when the account is deleted |
Any category not listed above is not retained.
From children enrolled in the messaging (SMS / WhatsApp / Telegram) tutoring service, we do not collect: email addresses, geolocation, photos, audio, video, biometric identifiers, government IDs, or persistent identifiers used for cross-site tracking. The Grader, a separate feature, does process a photo of a student's written work that a parent or teacher uploads — see the schedule above. We do not sell or license any child data, we do not use child data for behavioral advertising, and we do not load advertising trackers on pages that display student work.
Parents may, at any time, via email to hello@nudgelearn.app:
This policy is reviewed at least annually and whenever (a) data practices materially change, (b) a new regulation takes effect, or (c) a new collection category is introduced. The Founder approves revisions in writing.