Privacy, consent & family data
OWNER-REVIEW DRAFT · 29 September 2026. Proposed operator: MyeKids. Confirm the operating legal entity, address, privacy lead and response contacts before launch.
What we collect and why
We use guardian name, email and contact number to operate the account, enrollment and support. Children use an alias, age and optional interests. We keep enrollment, quiz attempts, creations, revisions, teacher feedback and attendance to support learning. School/daycare applications add authorized pickup contacts, arrival/departure records, activities, meals and rest notes. Do not submit passwords, identity-document scans, diagnoses or unnecessary personal details in free-text fields.
Who can see records
A guardian sees their own family's records. Assigned teaching/care staff access records needed for their group. Authorized administrators and safeguarding staff have role-specific responsibilities. Child portfolios are private. Public teacher profiles are adult-only; fictional demo profiles are labelled. There is no public child directory, behavioral advertising or open adult–child direct messaging.
Consent and child choice
The guardian must have authority to enroll the child and authorize participation. Staff explain activities in child-friendly language and respect a child's wish to pause or stop. Learning consent and care participation are separate choices. New consent events record the policy version; earlier decisions remain in history. Withdrawing learning consent pauses course access and teacher portfolio access. Care withdrawal blocks new attendance/learning entries while allowing an already-present child to be handed over safely. Historical care records may remain available to authorized staff pending retention review. Public child sharing and general AI chat are disabled; they must not be introduced under this general consent.
Services and transfers
SSLCommerz receives guardian billing information for hosted payment; the application does not collect card details. Hosting, email, meeting providers and backup locations must be named and reviewed before live use. External learning resources open only when a guardian/teacher chooses them; their accounts, cookies and terms are separate. No third-party analytics is enabled in this release.
Your controls
Edit profile details in Account, download a JSON family-record export, and download attachments from the private portfolio. Submit correction/deletion requests in Account → Privacy or contact support. Staff verify the requester and review retained financial, safety or disputed records before acting. Export does not grant another family access. Deletion is a staff workflow, not an immediate automatic operation.
Proposed retention schedule — owner/legal review required
Unconverted inquiries: review after 90 days. Ordinary transient care notes: review after 90 days. Learning portfolios: review 12 months after last active enrollment and give the family an export opportunity. Routine access/monitoring logs: proposed 30 days. Backups: proposed rolling 30-day rotation. Payment, consent and safeguarding evidence: the owner and qualified advisers must set lawful periods before launch; legal holds override routine deletion. These are proposed review dates, not claims that automated deletion already exists.
Security and incidents
We restrict private media access, use signed-in roles and record key changes. Production operators must configure HTTPS, backups, staff account protection and scanning. Report suspected exposure through the concern/support route. The designated privacy and safeguarding leads assess incidents and any notification duties. This draft does not certify compliance with any particular law.
