Data Privacy Agreement.

Our standard agreement with schools and districts. Plain language, ready to sign.

Last updated: August 27, 2026

This Data Privacy Agreement ("DPA") supplements our Terms of Service and Privacy Policy and governs how Kixmeta Labs LLC ("Provider", "we", "us") handles Student Data (as defined in Section 1) on behalf of a school or school district ("School") that uses GPTQuest (the "Service"). The School's Account Owner and any Teacher accounts are adult users: the Account Owner registers with a real email address and their school details (we do not collect the Account Owner's name), while Teacher accounts are provisioned by the Account Owner with school-issued credentials (no real email address is collected for them). Adult accounts are governed directly by our Privacy Policy and Terms of Service rather than by this DPA, though the data-minimization safeguards described in Sections 3 and 5 (no name, email address, or account identifier is attached to content sent to our AI providers) apply to any content an adult submits to those providers.

How to use this DPA

Schools and districts have three options:

  1. Accept this DPA as-is. Email connect@gptquest.ai with the details listed in Section 17. We will countersign and return a PDF within 5 business days.
  2. Sign the National Data Privacy Agreement (NDPA). We are willing to sign the Student Data Privacy Consortium's standard NDPA if your district uses it.
  3. Send us your district's own DPA. Email a draft to connect@gptquest.ai. We will review and respond within 10 business days.

1. Definitions

  • "Student Data" means personally identifiable information collected by the Service from or about a student through their use of the Service.
  • "Service" means the GPTQuest platform, websites, and related features operated by Provider.
  • "School" means the educational institution (a school, school district, or equivalent) that authorizes use of the Service for its students.
  • "Authorized Teacher" means an adult acting under the School's authority on the Service: the Account Owner (the adult, typically a teacher or school administrator, who registers the School's GPTQuest account and creates all Student and Teacher accounts), or a Teacher the Account Owner has placed in a classroom. A Teacher belongs to one classroom at a time and works only within it.

2. Ownership of Student Data

All Student Data is and remains the property of the School and the student/parent. Provider acts only as a processor of Student Data on the School's behalf. Provider does not acquire any ownership interest in Student Data.

3. Permitted Uses of Student Data

Provider will use Student Data only to:

  • Provide and maintain the Service for the School and its students
  • Provide customer support and respond to School/parent requests
  • Maintain the reliability, safety, and security of the Service
  • Enforce the Terms of Service and detect abuse
  • Comply with legal obligations

Provider will not:

  • Sell Student Data
  • Use Student Data for advertising, marketing, or behavioral profiling of students
  • Use Student Data to train AI models
  • Disclose Student Data except as permitted in Section 6
  • Contact students directly

Provider sends only the gameplay content needed to generate a result (such as a prompt or song lyrics) to its AI subprocessors, and does not transmit student names, email addresses, or account identifiers with it, so those inputs are not linked to an identified student. Before free-text is sent, an automated filter removes personal information a student may have typed. Provider's text provider (OpenAI), music subprocessor (ElevenLabs), and image subprocessor (Runware) do not use the content sent to them, or the results they generate, to train or improve their own models. Even so, because that content carries no student identity, it cannot be used to identify, contact, or profile a student. Provider sends the minimum content required and continues to review each subprocessor's data-use terms.

4. Data Collected from Students

Provider collects only the minimum data necessary:

  • A system-generated username, such as brave-mage-674, which the student types to sign in, and a synthetic email address built from it (not a real mailbox) used solely as a unique account identifier; students do not provide a real email and we do not contact students at this address
  • A Player Name, the name a student picks for their character the first time they sign in. It is the name their classmates see in the game World and the name used to identify them inside the app
  • An optional nickname for the student, entered by the Account Owner so adults can tell one account from another on the roster, visible only to the Account Owner and that student's Authorized Teacher, and never seen by the student. Provider asks Schools to use a nickname or initials rather than a student's real name. Where the School elects at onboarding not to use nicknames, the field does not exist for the School's accounts and rosters show the Player Name instead
  • Educational progress and gameplay data (Quest progress, XP, levels, streaks, in-game currency, narrative inputs), and the creations a student saves, being pictures, songs, and webpages, together with the title and any writing inside them
  • Device and connection data collected automatically from all users (browser type, operating system, IP address, and server-side request logs), used for security, operational reliability, and abuse prevention

Provider does not collect a date of birth, an age, or a grade level. Every Student account is treated as a child's account from the moment the School creates it.

The creations a student saves, together with their title and the writing inside them, can be reviewed and deleted by that student's Authorized Teacher and by the School's Account Owner in the Control Panel, as the School's own review of student work. No other school and no other student can see them.

A current and complete list of data categories is maintained in our Privacy Policy, Section 11.

5. Subprocessors

Provider uses the third-party service providers listed in Section 8 of our Privacy Policy to operate the Service, and will give the School at least 30 days' notice of any material change to its subprocessor list when the change affects Student Data. Provider's infrastructure subprocessors (such as Supabase, Vercel, Cloudflare, and Resend) are contractually required to handle Student Data only to deliver the service Provider has engaged them for, and not for their own purposes.

Student account records, progress, and game state are stored in the United States (Amazon Web Services, US-East region). Student-created media, such as saved songs and pictures, is stored with Vercel Blob, whose region is managed by that provider. Player-created avatar art is stored in Cloudflare R2 in its Eastern North America region, which spans the United States and Canada and carries no contractual United States residency commitment; those files are addressed by a hash of the outfit that produced them and carry no account identifier, so two students who choose the same outfit share one file. During multiplayer play, a student's Player Name (their in-game display name) and map position are relayed through Cloudflare PartyKit on a global edge network and held in that server's memory only; the provider stores no student records, and only the online status and last-seen time of connected players are written back to our database in the United States. Certain gameplay inputs a student submits during a Quest (for example, narrative text or song lyrics) are also transmitted to AI providers (OpenAI, Runware, and ElevenLabs) for real-time content generation. Image generation (Runware) is processed in the United States; some providers may process these inputs outside the United States. These inputs carry no student name, email address, or account identifier. As described in Section 3, our AI providers (OpenAI, ElevenLabs, and Runware) do not use these inputs, or the results they generate, to train or improve their own models.

6. Disclosure of Student Data

Provider may disclose Student Data only:

  • To subprocessors under written confidentiality and data-protection obligations
  • To the School itself, or to a parent/guardian making a verifiable request
  • To comply with a valid legal process (subpoena, court order), in which case Provider will give the School advance notice unless prohibited by law
  • In a merger, acquisition, or sale of assets, in which case the successor must assume the same obligations

7. Data Security

Provider maintains a written Information Security Program that includes:

  • Encryption of Student Data in transit (TLS) and at rest
  • Role-based access controls and least-privilege permissions for Provider personnel
  • Regular vendor risk reviews of all subprocessors
  • Privacy and data-handling training for every person with access to Student Data
  • An incident response plan covering detection, containment, investigation, and notification
  • Annual review and update of the program

A summary of the program appears in Section 9 of our Privacy Policy. The written Information Security Program itself is available to the School on request by emailing connect@gptquest.ai.

8. Data Breach Notification

If Provider becomes aware of a confirmed unauthorized acquisition of Student Data, Provider will:

  • Notify the School without undue delay and in any case within 24 hours of confirmation
  • Provide the School with a description of the incident, the categories and approximate number of students affected, the likely consequences, and the measures taken or proposed in response
  • Cooperate with the School's investigation and notification obligations to parents and regulators
  • Reimburse the School for the costs of any legally required breach notifications and related credit or identity monitoring services, for any incident not attributable to the School's own acts or omissions

9. Data Retention and Deletion

Provider retains Student Data only as long as needed to provide the Service, to give the School the 30-day window described below to renew or retrieve its Student Data after a term ends, or as required by law. Upon (a) termination of this DPA, (b) closure of a School account, (c) expiry of a paid, pilot, or trial term that the School has not renewed, or (d) the School's written request, Provider will delete or return all Student Data within 30 days, or by an extended deletion date agreed under the next paragraph, including from active systems. Backups containing Student Data will be deleted on the regular backup rotation, which does not exceed 90 days.

For an expiring term, Provider notifies the Account Owner by email at least 30 days before the term ends. The notice states the end date, the deletion date, and the School's options: renew, request a copy of its Student Data, or allow the term to expire. On the end date, access for the Account Owner and every Teacher and Student account under them ends; no Student Data is deleted on that date. The School may renew, in which case access is restored to every account, or request its Student Data in writing during the 30 days that follow. A copy requested before the deletion date is delivered before deletion. At the end of those 30 days, Provider deletes the School's Student Data as described above. Deletion is not reversible. Provider may, at the School's written request made before the deletion date, extend the window at its discretion; Provider answers a timely request in writing before the deletion date and does not delete while a timely request is unanswered.

10. Parent and Student Rights

Provider supports the following rights, exercisable through the School:

  • Access: Review the personal information held about a student
  • Correction: Correct inaccurate Student Data
  • Deletion: Request deletion of a student's data
  • Refusal: Stop further collection and use of a student's data by withdrawing that student from the Service, which closes their account and deletes their Student Data as described in Section 9

Provider will respond to verifiable requests routed through the School within 30 days.

11. Compliance with Laws

Provider designs the Service to comply with:

  • COPPA (Children's Online Privacy Protection Act, 16 CFR Part 312)
  • FERPA (Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g)
  • New York Education Law § 2-d and its implementing regulations (8 NYCRR Part 121), where the Service is used by New York schools and districts
  • Applicable state student-privacy laws, including California AB 1584 / SOPIPA, where the Service is used in those states

Provider operates under the COPPA school authorization exception when Student Data is collected from students under 13 through Authorized Teacher accounts.

For New York schools and districts, Provider will, on request, sign the district's Education Law § 2-d rider (including the district's Parents' Bill of Rights for Data Privacy and Security) and provide a supplemental Parents' Bill of Rights describing how Student Data is collected, stored, and protected. Request these by emailing connect@gptquest.ai.

12. Audit and Records

Upon reasonable written request (no more than once per year), Provider will provide the School with a written summary of its information security practices, subprocessor list, and any third-party security or privacy certifications then in effect.

13. Term and Termination

This DPA takes effect when the School begins using the Service or executes a signed copy, whichever is earlier. It remains in effect for as long as the School uses the Service. Either party may terminate this DPA upon 30 days' written notice. Termination of this DPA also ends the School's use of the Service on the termination date, unless a replacement data privacy agreement between the parties covers the Student Data, and the School's Student Data is then handled under Section 9 in the same way as an expired term. Sections 2, 3, 6, 7, 8, 9, and 10 survive termination for as long as Provider retains any Student Data, and Section 16 survives termination.

14. Modifications

Provider may update this DPA from time to time to reflect changes in law, the Service, or our practices. Provider will post any updated version here with a new "Last updated" date, whether or not the change is material, so a School can always tell which version it is reading.

A change is material if it expands or weakens how Student Data is handled: adding a category of Student Data we collect (Section 4), adding a purpose we use it for (Section 3), adding a subprocessor that receives Student Data or otherwise widening who it may be disclosed to (Sections 5 and 6), keeping Student Data longer (Section 9), weakening a security commitment (Section 7), or reducing the rights this DPA gives the School, its students, or their parents (Sections 2, 10, and 12). Provider will notify Account Owners by email at least 30 days before a material change takes effect. This is in addition to the subprocessor notice in Section 5.

A change that narrows or clarifies is not material and takes effect when it is posted. That includes removing a subprocessor, or replacing one without adding a new category of Student Data; collecting less; using Student Data for fewer purposes; deleting it sooner; corrections and clarifications to wording that describes practices we have not changed; and changes to the features, Quests, and content of the Service that do not affect any of the matters listed above.

15. Order of Precedence

If there is a conflict between this DPA and the Terms of Service or Privacy Policy with respect to Student Data, this DPA controls.

16. Governing Law

This DPA is governed by the laws of the state in which the School is located, without regard to its conflict-of-laws rules, and any action arising out of it will be brought in a court of competent jurisdiction in that state. Nothing in this DPA waives, limits, or requires the School to waive any immunity, defense, or protection available to it as a public entity.

17. Signatures

A countersigned PDF version of this DPA is available on request. To request one, email connect@gptquest.ai with:

  • Your school or district name
  • Name and title of the authorized signer
  • Mailing address
  • Approximate number of students who will use the Service

Provider will return a signed PDF within 5 business days.

Provider contact for this DPA:

Kixmeta Labs LLC
848 E Main Street, Suite 800 #1002
Ephrata, PA 17522, United States
Email: connect@gptquest.ai