Kurious

Privacy Policy

Last updated: June 2026

Kurious is a learning product for children ages 6–12, available on the web at kurious.me and as an Android app published under the Google Play "Designed for Families" program. We treat children's information with the highest care and only collect what is necessary to deliver the product. This page explains what we collect, who processes it, how long we keep it, and how parents can exercise their rights.

Who can sign up (COPPA verifiable parental consent)

Only a parent or legal guardian can create a Kurious account. We do not sell directly to children, and a child cannot create an account on their own. By signing up you confirm you are at least 18, you are the parent or legal guardian of any child profile you create, and you consent to the data collection described below on that child's behalf. We record the timestamp and version of your consent. You can withdraw consent at any time by deleting your account from the parent dashboard, which deletes all associated child data within 30 days.

What we collect

From parents

  • Email address (used for sign-in, password reset, and account-critical updates).
  • Account creation timestamp and the COPPA consent record (timestamp + policy version).
  • Optional payment information for subscriptions, handled directly by our payment processor — we never see card numbers.

From children

  • Display name or nickname (no last name; no school; no contact info).
  • Birth year (used only to set the curriculum level — we do not store full date of birth).
  • Optional interest tag (e.g. "animals", "space") to personalise prompts.
  • Conversations with Kurious — text messages and voice utterances captured during a session.
  • Voice audio while the microphone is active (push-to-talk or conversation mode). Sent to our text-to-speech / speech-to-text provider for real-time processing.
  • Projects the child builds: code, canvas snapshots, named assets.
  • Learning telemetry: which concepts were attempted, mastered, and re-encountered (used to adapt the curriculum and to power the parent dashboard).

What we do not collect

  • No advertising IDs. No third-party ad SDKs. No interest-based or behavioural advertising of any kind.
  • No persistent device identifiers tied to children (e.g. AAID, IDFA).
  • No third-party product analytics for child sessions. PostHog, Sentry, and similar tools are loaded only for parent-facing screens and are disabled inside the Android child shell.
  • No precise location data. We may infer approximate region from the request IP for routing only; we do not store it.
  • No photos, videos, or media library access.
  • No contacts, calendar, SMS, or device data beyond what the child explicitly produces in-app.

Third-party processors

We use the following vendors strictly to operate Kurious. Each processes data only on our instructions under a data processing agreement (DPA). None receives data for their own marketing, advertising, or model-training purposes.

  • Google (Sign in with Google) — parent sign-in only. When a parent chooses to sign in, Google shares their name, email address, and a Google account identifier with us. We never receive the parent's Google password. Parent sessions are then issued and held by Kurious itself.
  • Anthropic (Claude API) — the language model that powers the conversation. Receives the child's text or transcribed voice messages and the conversation context for the current session. Anthropic does not use Kurious data to train its models.
  • ElevenLabs — text-to-speech and (in voice mode) speech-to-text + Conversational AI. Receives child voice audio while the mic is active and the text Kurious speaks back. Audio is processed in transit; cached audio is purged within 7 days. ElevenLabs has signed our DPA for children's data processing before voice mode is enabled in production.
  • Cloudflare R2 — encrypted object storage for canvas snapshots and short-lived audio cache.
  • Vercel — hosting for the web application and API. Receives request metadata (IP, user-agent) for routing and abuse prevention. Logs are retained for 30 days.
  • Neon (managed Postgres) — primary database. Encrypted at rest and in transit. Currently hosted in the United States (AWS us-east-1).
  • Upstash Redis — short-lived chat stream buffer and rate-limit counters. No long-term storage of child content.
  • PostHog and Sentry — product analytics and crash reporting, parents only. Not loaded for child sessions; disabled inside the Kurious Android shell.

How long we keep it

  • Voice audio: deleted within 7 days from any cache; not persisted in our primary database.
  • Conversation transcripts and projects: kept while the account is active so the child can resume and the parent can review progress.
  • Learning telemetry: kept while the account is active to power the parent dashboard.
  • Account data after deletion request: removed from production systems within 30 days; from backups within 90 days.

Your rights as a parent

From the parent dashboard you can, at any time:

  • Review your child's projects and learning history (full conversation transcripts are included in the data export).
  • Export all of your child's data as JSON.
  • Delete an individual child's account, which removes all of their data.
  • Delete your entire account, which removes all data for you and all of your children.
  • Disable voice mode at any time by revoking the microphone permission on your child's device — text chat keeps working (see "Mobile app permissions" below).

You can also email us at privacy@kurious.me to make a request. We honor verified parental requests within 30 days.

Mobile app permissions

  • Microphone — required for voice mode only. Requested the first time you tap the mic. Audio is sent to ElevenLabs in real time and not stored beyond a short cache.
  • Notifications — optional. Used only for parent-facing learning summaries; never marketing.
  • Storage — optional. Used only when a parent or child exports a project image.

You can revoke any permission from your Android system settings at any time. Revoking microphone disables voice but keeps text chat working.

Security

All traffic is over TLS. Database and object storage are encrypted at rest. Access to production data is restricted to a small set of named employees and audited. We do not knowingly store children's full names, addresses, school information, or other directly identifying attributes.

International transfers

Kurious is operated from infrastructure in the United States and European Union. By using Kurious you consent to your data being processed in those regions under standard contractual clauses where applicable.

For users in India — DPDP Act notice

If you are in India, this section supplements the rest of this policy and is provided under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Data Fiduciary

Kurious (contact: privacy@kurious.me) is the Data Fiduciary for the personal data described in this policy. The third-party processors listed above act as Data Processors on our documented instructions.

Basis of processing and children's data

We process personal data on the basis of consent. Because every learner on Kurious is a child, we obtain verifiable consent from the parent or legal guardian before processing any child's data, as required by Section 9 of the DPDP Act. In line with Section 9, Kurious does not perform tracking or behavioural monitoring of children for advertising, and does not serve targeted advertising to children — there are no ads in Kurious at all.

Your rights under the DPDP Act

  • Access — request a summary of the personal data we process and the processing activities (the parent dashboard export provides this as JSON).
  • Correction and erasure — correct inaccurate data or erase data that is no longer necessary; deleting a child profile or your account from the parent dashboard does this immediately.
  • Grievance redressal — raise a complaint with us using the contact below; we respond within 7 days and resolve verified requests within 30 days.
  • Nomination — nominate another individual to exercise these rights on your behalf in case of death or incapacity (email us to record a nominee).
  • Withdrawal of consent — withdraw consent at any time with the same ease you gave it; withdrawing consent stops further processing and triggers deletion as described in "How long we keep it".

Where your data is processed

Our primary database and AI processors are currently located in the United States (listed per-vendor above). The DPDP Act permits transfer of personal data outside India except to countries restricted by the Central Government; we will not transfer your data to any restricted country. Each processor is bound by a data processing agreement limiting use to our instructions.

Data retention

We retain personal data only as long as needed for the purpose it was collected: voice audio is purged within 7 days, conversation and project data is kept while the account is active, and deleted accounts are removed from production within 30 days and from backups within 90 days.

Grievance Officer

For DPDP Act grievances, contact our Grievance Officer at grievance@kurious.me with the subject line "DPDP Grievance". If you are not satisfied with our response, you may complain to the Data Protection Board of India.

Changes to this policy

We may update this policy as Kurious evolves. Material changes will be announced with a notice in the parent dashboard before they take effect.

Contact

Privacy questions: privacy@kurious.me