For School Administrators.

A clear summary of what we collect, what we don't, and how we keep students safe, for the people approving GPTQuest at your school.

Last updated: August 27, 2026

This page is a plain-language summary for school and district administrators evaluating GPTQuest. The full legal terms live in our Privacy Policy and Terms of Service.

What GPTQuest is

GPTQuest is an AI-literacy platform for grades 3 to 8. Students play short, authored fantasy quests where they read, write, and learn to communicate with AI. An adult Account Owner (typically a teacher or school administrator) creates and manages all Student and Teacher accounts; students do not sign up themselves. Between quests, students explore a shared game World as customizable avatars, where they can meet classmates and start quests; each classroom plays in a private World Instance, closed to students outside the class.

What we collect from students

Only the minimum needed to run the Service:

  • A username we generate for the student, such as brave-mage-674, which is what they type to sign in, and a synthetic email built from it that serves only as a unique account identifier (not a real mailbox; we never email students)
  • A Player Name, the name a student picks for their character the first time they sign in. It is the name their classmates see in the game World, and we ask schools to have students pick something that is not their own name
  • An optional nickname, entered by the Account Owner so adults can tell one account from another on the roster. Students never see it. It is visible to the Account Owner and to that student's Teacher, is never shown to other students, and is never sent to our AI providers. We ask schools to use a nickname or initials here rather than a student's real name. A school that prefers not to use nicknames at all can tell us before it creates its first accounts; the field is then absent from the Control Panel and rosters show the Player Name instead
  • Educational progress and gameplay data (quest progress, XP, levels, streaks, in-game currency, narrative inputs), including the title and the writing a student produces for a creation they save in a quest, such as a song, a picture, or a webpage, stored so the student can return to their own work
  • Device and connection data (browser type, operating system, IP address, request logs) collected automatically from all users for security and operational reliability

What we do NOT do

  • We do not sell student data
  • We do not show students any advertising
  • We do not run behavioral profiling on students
  • We do not train AI models on student inputs. We send our AI providers only the content needed to generate a result, with no student names, email addresses, or account identifiers attached. Our text provider (OpenAI), music provider (ElevenLabs), and image provider (Runware) do not use that content to train or improve their own models; it carries no student identity in any case and cannot be used to identify, contact, or profile a student. Details in Section 8 of our Privacy Policy
  • We do not collect a date of birth, an age, or a grade level. Every account a school creates is treated as a child's account from the start
  • We do not contact students directly
  • We do not offer free-text chat between students; in-game chat uses curated emojis, stickers, and preset phrases

What school staff can see

A student's Teacher and the school's Account Owner can review the creations that student saved in a quest, being the picture, song, or webpage together with the title and the writing inside it, and can delete a creation. Access is limited to the Teacher of that student's classroom and to the school's Account Owner; no other school and no other student can see them. This is the ordinary review of student work a school would otherwise carry out itself. The other progress indicators a Teacher sees, such as skill levels, counts, and completion, are calculated on our servers and are shown as a level or a number, never as a quote. Some of them are worked out from what a student wrote, for example the score the AI gave a written answer or how many dishes on a webpage carry a real description; the writing itself is not reproduced in them.

Legal framework

  • COPPA: We operate under the school authorization exception. Schools consent on behalf of parents for educational use.
  • FERPA: Student records are treated as school-controlled education records.
  • New York Education Law §2-d: For New York schools and districts, we design the Service to comply with §2-d and 8 NYCRR Part 121, and will sign your district's §2-d rider (including the Parents' Bill of Rights) on request. See Section 11 of our Data Privacy Agreement.
  • Other state laws: We design the Service to support compliance with applicable state student-privacy laws, including California AB 1584 / SOPIPA, and our Data Privacy Agreement covers them where the Service is used in those states. If your district uses its own agreement, send it to connect@gptquest.ai and we will review it.

Subprocessors

A current list of every third party that processes data on our behalf is in Section 8 of our Privacy Policy.

Security

We maintain a written Information Security Program covering encryption, access control, vendor review, training, and incident response. If we confirm a breach involving student data, we notify affected schools within 24 hours. A summary is in Section 9 of our Privacy Policy, and the full program document is available to district reviewers on request.

One design choice is worth knowing before you print login cards. The Student and Teacher accounts an Account Owner creates have no real mailbox, so they cannot recover a password by email. Instead, the Account Owner can reprint the login cards for any classroom they own, and a Teacher can reprint the cards for the students in a classroom they teach; a Teacher never sees another Teacher's password. Account Owner passwords work the other way: they are recoverable only through the password reset flow.

Retention and deletion

We keep Student Data only as long as needed to provide the Service or as required by law. When an Account Owner closes the account, every Teacher and Student account beneath it is deleted first, each with the songs, pictures, and pages that account created, and then the Account Owner's own account. On a school's written request, or when a Data Privacy Agreement ends, we delete or return Student Data from active systems within 30 days. Copies in encrypted backups are removed as backups rotate, which does not exceed 90 days.

When a paid, pilot, or trial term ends without renewal, we email the Account Owner at least 30 days before the end date. Access ends on that date and nothing is deleted then. The school has the following 30 days to renew, which restores access to every account, or to request a copy of its records; a copy requested before the deletion date is delivered before anything is deleted. At the end of those 30 days the account and every account under it are deleted, and that deletion is not reversible. A school that needs more time must ask us in writing before the deletion date. Full details in Section 10 of our Privacy Policy and Section 9 of our Data Privacy Agreement.

Data Privacy Agreements (DPA)

Read our standard Data Privacy Agreement in full. Schools can accept it as-is, sign the SDPC's NDPA, or send us their district's own. To request a countersigned PDF, email connect@gptquest.ai. We countersign our standard DPA within 5 business days and respond to a district's own DPA within 10 business days.

Parent rights

Parents may review, request deletion of, or refuse further collection of their child's data. Requests come through the school first, then to us if needed. Full details in Section 11 of our Privacy Policy.

Contact for school administrators

Kixmeta Labs LLC
848 E Main Street, Suite 800 #1002
Ephrata, PA 17522, United States
Email: connect@gptquest.ai