Data protection assessment
How each duty is met
- M1, Consent record: consent row per student naming profiling and ai scope; teen consent 13-17
- M2, Data protection assessment: versioned assessment on file
- M3, Engagement features need consent: any kid-facing reward or streak feature has a consent row naming scope rewards; rewards pay for offline completion, never minutes in the app; day-ends rule enforced
- M4, No precise location: no lat/long fields for any student or family
- M5, No ads, sale or crossover: no reader outside this store
- M6, COPPA parental consent: verifiable parental consent before collection
- M7, AI content safety: safety pass and guardian release on every item
- M8, Children's privacy notice: direct notice to the parent and an online notice naming each third party by identity and category, with the retention policy published inside it
- M9, Written data retention policy: a written policy states each kind of child data, why it is kept, and when it is deleted
- M10, Written information security program: a written program covers safeguards, service provider selection, and yearly review
- M11, Separate consent for any disclosure: any sharing beyond running the service has its own consent row, apart from the service consent
- M12, Parent review and delete: a guardian can export and delete a child's data, and each request has a completion row
- M13, Child voice is personal information: no child voice is recorded unless the notice names it and consent covers it; read-aloud output is fine
- M14, Breach notice within 30 days: affected Colorado residents are notified within 30 days of determining a breach
- M15, Accessible pages: every Homeschooling page passes the onepager WCAG 2.1 AA run, every link clicked
- M16, Text consent: a guardian consent row names SMS before any text is sent; no texts to children
- M17, Keep only what is needed: every stored field for a child maps to a use in the curriculum, gates, or proof; unused fields are dropped
Version ed32ce517c1ea714.