Skip to document
ClevaAI

Early-stage policy

Privacy Policy

This early-stage Privacy Policy explains what ClevaAI collects, why it is used, how long it is kept, and the choices available to learners and parents.

Last updated: August 20, 2026

1. Data we collect

We collect only the information needed to create accounts, provide learning activities, protect users, and improve the early-stage service.

  • Account information such as name, email address, username, and a securely hashed PIN.
  • Learner birth month and year, derived age band, and a parent or guardian email when the learner is under 13.
  • Profile choices such as persona, companion, and avatar.
  • Learning activity such as prompts, selected answers, generated outputs, progress, scores, feedback, and challenge history.
  • Authentication, device, cookie, and security information needed to operate and protect the service.

2. How we use and share data

We use information to provide accounts and learning activities, personalize age-appropriate experiences, calculate progress, maintain security, and respond to support or privacy requests.

  • We do not sell personal information or use children’s information for targeted advertising.
  • Limited information may be processed by service providers that support hosting, authentication, AI-generated learning responses, email delivery, security, and error monitoring.
  • We disclose information when required by law or when reasonably necessary to protect users and the service.

3. Retention periods

Our early-stage retention schedule is designed to keep information only for as long as it supports the purpose for which it was collected.

  • Account and profile information: while the account is active, then scheduled for deletion within 30 days of a verified deletion request or account closure.
  • Learning activity, prompts, outputs, progress, and scores: up to 12 months after the learner’s last activity, unless deleted earlier on a verified request.
  • Pending parent or guardian contact information: up to 30 days when a consent request is not completed.
  • Authentication and security logs: up to 90 days, unless a longer period is needed to investigate misuse or meet a legal obligation.
  • Backups: removed through the normal backup cycle within 90 days after deletion from active systems.
  • Consent and privacy-request records: up to 3 years after account closure or consent revocation to document the request and our response.

4. Your rights and parental rights

Parents and guardians may ask what personal information we hold about their child and may request corrections, a copy, deletion, or an end to further collection and use. Learners and adult users may make the same requests for their own information.

  • Request access to or a copy of personal information.
  • Correct inaccurate account or profile information.
  • Delete an account and associated personal information, subject to limited security or legal retention needs.
  • Withdraw an acknowledgement or parental consent and stop further collection where applicable.
  • Ask questions or raise a privacy concern by emailing the address below. We may verify identity and the parent-child relationship before fulfilling a request.

5. Changes to this policy

We may update this policy as the application develops. Material changes will be shown here with a new update date, and we will request a new acknowledgement or parental consent when required.