Privacy Policy.

How GPTQuest collects, uses, and safeguards information. Designed with COPPA, FERPA, and GDPR principles in mind.

Last updated: September 11, 2026

1. Introduction

GPTQuest, operated and owned by Kixmeta Labs LLC ("we", "us", "our"), respects your privacy and is committed to protecting your personal information. GPTQuest is an AI Literacy and educational platform designed for students in grades 3 to 8. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use the GPTQuest platform and services (the "Service"). The Service is built to meet the requirements of the Children's Online Privacy Protection Act (COPPA) and to help schools meet their obligations under the Family Educational Rights and Privacy Act (FERPA). By using this Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

We may collect the following categories of information:

a. Account Information

When you create an account, we collect only essential information:

  • Email address (Account Owners only, used for authentication and transactional communications; Student and Teacher accounts use a system-generated synthetic identifier instead, described below)
  • Display name (a user-created pseudonym for in-app identification; for a student, this is their Player Name, described in Section 11)
  • The Account Owner's name and their role at the school, together with their confirmation that the school or district authorizes them to create student accounts, the date, and the wording they agreed to (Account Owners only; not collected for Student or Teacher accounts, and not used to sign in)

During the current launch period, GPTQuest accounts are registered by adults only. The adult who registers the account (the "Account Owner", typically a teacher or a school administrator) provides their name, their role at the school, an email address, and their school name, district, and state, and agrees to this Privacy Policy and our Terms of Service, which govern their account and any content they create. We also record their confirmation that the school or district authorizes them to create student accounts on its behalf, together with the date and the exact wording they agreed to. The Account Owner's name and role are used only to identify who accepted that responsibility and to contact them about the account; they are never shown to students and are never sent to our AI providers.

The Account Owner creates and manages all other accounts through the Control Panel. They may create Teacher accounts for the adults who run their classrooms and place each Teacher in a classroom; a Teacher belongs to one classroom at a time and has access only to that classroom. Teacher accounts sign in with credentials issued by the Account Owner and, like Student accounts, use a system-generated synthetic email address (not a real mailbox) as their account identifier; we do not collect a real email address for them. The Account Owner may also record an optional nickname for a Teacher account so adults can tell accounts apart on the roster; it is visible only inside the Control Panel and is never sent to our AI providers. A school can ask us, before it creates its first accounts, to turn nicknames off entirely; for that school the field does not exist anywhere in the Control Panel, for Teacher and Student accounts alike, and rosters show each account's Player Name instead. Because Student and Teacher accounts have no real mailbox, they cannot recover a password by email, so a school can instead reprint a lost login card: the Account Owner can do this for a classroom they own, and a Teacher for the students in a classroom they teach. Account Owner passwords work the other way and are recoverable only through the password reset flow. Student accounts are likewise created by the Account Owner; for students under 13, accounts are created under the school's authority (see Section 11). Adults may also play Quests; when they do, they receive the same protections as students, and no name, email address, or account identifier is sent to our AI providers.

b. Usage and Interaction Data

We collect data about your use of the Service, including:

  • Quest progress, completions, and game state
  • Server-side request logs from our hosting provider, used for operational reliability and abuse prevention
  • A sign-in attempt log we keep ourselves, recording the sign-in address typed, the IP address, the browser, and whether the attempt succeeded, used to lock an account after repeated failures and to investigate suspicious activity

We do not currently run dedicated user-behavior analytics (no Google Analytics, Mixpanel, or similar). If we add analytics tooling in the future, we will update this Policy and request consent through the cookie banner before activating any non-essential tracking.

c. Device and Technical Data

We collect:

  • Browser type and version
  • Operating system
  • IP address
  • Server-side request logs

d. Gameplay Content

Narrative text, written responses, and choices you create during gameplay. Where a Quest saves a creation, such as a song, a webpage, or a creature, the text the student wrote is stored so that the student can return to their own work in their own account. The student's Teacher and their school's Account Owner can review the creations a student saved, being the pictures, songs, and webpages, including the title the student gave the work and the writing inside it such as song lyrics and the text on a webpage, and can delete a creation. This is the ordinary review of student work that a school would otherwise carry out itself. Elsewhere on the Teacher progress view, skill levels and counts are calculated on our servers and are shown as a level or a number, never as a quote of what the student wrote. Most are produced from observations of how the student played. Some are produced from the student's own writing: a count taken over a saved creation, for example how many dishes on a webpage carry a description, and the score our AI gave a written answer in a Quest that saves no creation. In each case the calculation happens on our servers and only the resulting level or number is shown. Chat between students is limited to a curated picker of emojis, stickers, and preset phrases (no free-text chat); these selections are relayed in real time within the classroom's private Instance and are not retained as chat logs.

e. Support and Communications

Messages you send us via the Contact Us page or email. When a Teacher or student uses the in-app report tool to flag generated content as inappropriate, the flagged content (the Quest conversation, or the image and the prompt that produced it), any comment the reporter typed, the reporting account's display name, and its account identifier are sent to our staff for safety review.

f. Cookies and Similar Technologies

We use only essential cookies needed for authentication and session continuity. Your choice on the cookie banner is remembered in your browser's local storage rather than in a cookie. We do not currently set analytics or marketing cookies.

3. How We Use Your Information

We use information to:

  • Provide, maintain, and improve the Service. We maintain and improve it using operational and device data. The text a student writes in a Quest is used to run that Quest, to save the student's own work so they can return to it, and to produce the progress indicators described in Section 2(d)
  • Personalize your experience
  • Track educational progression (XP, levels, streaks, and Quest completions)
  • Communicate updates and support messages
  • Protect against fraud and enforce policies
  • Comply with legal requirements

We do not sell your personal information.

4. Cookies and Tracking Technologies

What Are Cookies?

Cookies are small pieces of data stored on your device that let the Service recognize your sign-in session and remember your preferences.

Cookies We Currently Use

  • Essential authentication cookies set by our auth provider (Supabase) to keep you signed in
  • A cookie-consent preference, stored in your browser's local storage rather than in a cookie, that records your choice on the cookie banner

We do not currently set analytics, advertising, or third-party tracking cookies. The cookie-consent banner you see on the site is forward-looking: if we ever add non-essential cookies, the banner will gate them behind your consent before they are set.

Managing Cookies

You can control cookie preferences through your browser settings. Disabling essential cookies will prevent you from staying signed in.

5. Your Rights (Global)

Access & Correction

You may request a copy of the personal data we hold about you and correct inaccuracies.

Deletion

You may request deletion of your personal data, subject to legal requirements.

Data Portability

You may request your data in a structured, machine-readable format.

Objection & Restriction

You have the right to object to or request restrictions on certain processing activities.

To exercise these rights, visit our Contact Us page.

6. GDPR — European Union / EEA Residents

If you are located in the EU/EEA, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right to Access: Obtain confirmation whether your data is processed
  • Right to Rectification: Correct inaccurate personal data
  • Right to Erasure: Delete personal data (subject to limitations)
  • Right to Restrict Processing: Limit how your data is used
  • Right to Data Portability: Receive your data in a common format
  • Right to Object: Object to processing based on legitimate interest
  • Right to Withdraw Consent: When processing is based on consent

To exercise GDPR rights, visit our Contact Us page.

7. CCPA / CPRA — California Residents

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

Your Rights

  • Right to Know: What personal data we collect and how we use it
  • Right to Delete: Request deletion of personal data
  • Right to Opt-Out: Opt out of "sale" of personal data (we do not sell personal data)
  • Right to Non-Discrimination: We will not discriminate for exercising your rights

Shine the Light

You may request details about shared personal data with third parties for marketing.

To exercise California privacy rights, visit our Contact Us page.

8. Data Sharing and Disclosure

We may share your information with:

a. Service Providers (Subprocessors)

The vendors below process data on our behalf to operate the Service. Each is bound by their own terms and security commitments and processes data only for the purposes described. Student account and progress data are stored in the United States (Supabase, hosted on Amazon Web Services, US-East region). Some services run on global edge networks or process data outside the United States as noted below and in Section 13.

  • Supabase: Postgres database and authentication; stores Student account records, progress, and game state. Hosted in the United States (AWS US-East). supabase.com/privacy
  • Vercel: application hosting, edge compute, and platform logs; operational request logs, no student profiles. vercel.com/legal/privacy-notice
  • Vercel Blob: storage for user-generated audio and images (songs from Lyra the Songweaver and pictures generated in My Magical Animal). Region managed by Vercel and not independently pinned to the United States by us. vercel.com/legal/privacy-notice
  • Cloudflare R2: storage of game assets and player-created avatar images; contains no student names, emails, or other student identifiers. Stored in Cloudflare's Eastern North America region, which spans the United States and Canada. cloudflare.com/privacypolicy
  • Cloudflare / PartyKit: real-time multiplayer presence within a classroom Instance; transient Player Name (the display name classmates already see) and map position, no stored student records. Runs on a global edge network. cloudflare.com/privacypolicy
  • Cloudflare Turnstile: bot and abuse checks on our sign-in, sign-up, and password pages; receives your IP address and browser signals only, with no name, account identifier, or gameplay content. cloudflare.com/privacypolicy
  • Resend: transactional email delivery. We never email students; recipients are Account Owners, newsletter subscribers, and people who write to us. Safety reports filed with the in-app report tool are also delivered this way, and a report filed by a student carries that student's Player Name, their synthetic account identifier, and the Quest conversation they flagged. resend.com/legal/privacy-policy

b. AI and Content Partners

Text, image, and music inputs you submit during gameplay may be processed by third-party AI providers to generate Quest content:

We do not train any AI models on your inputs. We do not send any user's name, email address, or account identifier to these providers, whether the user is a student or a teacher; only the content needed to generate a result (such as a prompt or song lyrics) is transmitted, and it is not linked to anyone. Our text provider (OpenAI), our music provider (ElevenLabs), and our image provider (Runware) do not use the content we send, or the results they generate, to train or improve their AI models. Even so, because that content carries no user identity, it cannot be used to identify, contact, or profile a child or adult. Prompts and lyrics are free-form text typed by the user; before this text is sent to the provider, an automated filter removes personal information a user may have typed, and we also encourage teachers to review gameplay with students to help them avoid entering real names or sensitive details. We continue to review each provider's data-use terms. See our Responsible AI page for more on how AI is used in the Service.

c. Legal Authorities

When required by law or to protect our rights.

d. Affiliates and Business Transactions

In connection with a merger, acquisition, or sale of assets, in which case the successor must assume the same obligations set out in this Privacy Policy and in any Data Privacy Agreement with a school.

e. With Your Consent

When you explicitly agree to share data.

We do not sell your personal information.

9. Data Security

We maintain a written Information Security Program appropriate to the sensitivity of the data we handle. The program includes:

  • Encryption of personal data in transit (TLS) and at rest
  • Role-based access controls and least-privilege permissions for our team
  • Regular vendor risk reviews of all subprocessors listed in Section 8
  • Privacy and data-handling training for everyone with access to our systems, completed before access is granted and annually thereafter
  • An incident response process for suspected security events
  • Annual review and update of the program

In the event of a confirmed data breach involving student personal information, we will notify affected schools without undue delay and in any case within 24 hours of confirming the breach, and, where required by law, parents and regulators within the timeframes required by applicable law. Where a breach is not attributable to a school's own acts or omissions, we will reimburse the affected school or district for the costs of legally required breach notifications and any related credit or identity monitoring services it provides.

No method of transmission over the Internet is 100% secure, but we work continuously to protect your data.

10. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. A school account whose paid, pilot, or trial term ends without renewal expires on its end date: access ends for the Account Owner and every Teacher and Student account under it. Nothing is deleted on that date. Thirty days later the account and every account under it are deleted in the same way as a closed account, described below, and that deletion is not reversible. We email the Account Owner at least 30 days before the term ends, and during the 30 days after expiry the school may renew, which restores access, or request a copy of its records (see Section 11); a copy requested before the deletion date is delivered before the account is deleted. A school that needs more time must ask us in writing before the deletion date, and any extension is at our discretion.

When you close your account, your authentication record is deleted immediately and the deletion cascades through every per-user table in our database (profile, gem balance, gem transaction history, friendships, Quest sessions, World position, notifications, and similar). Closing an account also deletes the media files that account created in storage, such as saved songs and pictures. If an Account Owner closes a school's account, every Teacher and Student account under it is deleted first, each with its stored media, and then the Account Owner's own account. A small number of records deliberately survive the cascade. A deletion ledger entry for the account, and one for any saved creation an adult deleted earlier, each hold only system-generated identifiers, the action taken, and a timestamp, and carry no personal information; they are kept so a school can establish that an account or a piece of work was deleted, by whom, and when. Our sign-in attempt log, described in Section 2b, records the sign-in address typed rather than the account row, so it is also not cleared by the cascade; it is kept for security investigation. Any of these records can be removed by hand to satisfy a verified request to erase everything about an individual. Platform-level server logs (Vercel, Cloudflare) persist according to those providers' retention windows and are not tied to individual user accounts. Copies of personal data in encrypted backups are removed as backups rotate on our regular schedule, which does not exceed 90 days.

11. Children's Privacy & COPPA Compliance

GPTQuest is designed for students in grades 3 to 8 (approximately ages 8 to 14). We are committed to complying with the Children's Online Privacy Protection Act (COPPA) and take special care to protect the privacy of children under 13.

a. School-Authorized Access (Under 13)

GPTQuest operates under the COPPA "school authorization" exception. Under this exception, schools may consent to the collection of personal information from students under 13 on behalf of parents, provided the data is used for an educational purpose authorized by the school and not for any commercial purpose.

By creating Student accounts, the Account Owner confirms that they are authorized by their school or district to do so for educational purposes, and that the school has provided (or will provide) any required notice to parents.

Schools and districts that wish to enter into a formal Data Privacy Agreement (DPA) with us can read our standard Data Privacy Agreement and request a countersigned copy by emailing connect@gptquest.ai. A summary of our data practices for school administrators is available at /for-schools.

GPTQuest collects only the minimum data necessary to provide the Service to young learners.

b. Data We Collect from Students

We collect only the minimum data necessary to provide educational services:

  • A system-generated username, such as brave-mage-674, which the student types to sign in, and a synthetic email address built from it (not a real mailbox) used solely as a unique account identifier; students do not provide a real email and we do not contact students at this address
  • A Player Name, the name a student picks for their character the first time they sign in. It is the name their classmates see in the game World and the name used to identify them inside the app
  • An optional nickname for the student, entered by the Account Owner so adults can tell one account from another on the roster, and visible only to the Account Owner and that student's Teacher. Students never see it. It is never shown to other students and never sent to our AI providers. A school can choose not to use nicknames at all; for that school the field does not exist, and rosters show the Player Name instead
  • Educational progress and gameplay data (Quest progress and completions, XP and levels, streaks, in-game currency balances such as Gems and gold, friendships within the same school, World position, and notifications), including the text a student writes into a creation they save (such as a song, a webpage, or a creature), which is stored so the student can return to their own work. The creations a student saves, being pictures, songs, and webpages, together with the title and any writing inside them, can be reviewed and deleted by that student's Teacher and their school's Account Owner
  • Device and connection data collected automatically from all users (browser type, operating system, IP address, and server-side request logs), used for security, operational reliability, and abuse prevention, as described in Sections 2b and 2c

We do not collect a date of birth, an age, or a grade level. Every student account is treated as a child's account from the moment the school creates it.

We ask schools to use nicknames or initials rather than real names, both for the nickname an Account Owner records and for the Player Name a student picks. A school can also ask us, before it creates its first accounts, to turn nicknames off entirely; the field is then removed from the Control Panel for every account that school creates, and it cannot be switched on from inside the Control Panel.

c. How We Use Student Data

Student data is used exclusively for educational purposes:

  • Providing access to educational Quests and content
  • Tracking learning progress, skill levels, and Quest completions
  • Letting the student keep and return to the creations they save in Quests
  • Showing the student's Teacher skill levels, counts, and completion for each Quest, calculated on our servers from how the student played
  • Letting the student's Teacher, and their school's Account Owner, review the work that student saved, including the picture, song, or webpage itself and the title and writing the student produced for it, and remove a creation where the school considers that appropriate. Access is limited to the Teachers responsible for that student's classroom and to the school's Account Owner; no other school, and no other student, can see them. Every deletion by an adult is recorded so the school can establish who removed a student's work and when
  • Enabling collaborative multiplayer features within their Teacher's private Instance

We do not send emails to students. We do not use student data for advertising, marketing, or behavioral profiling. We do not run third-party analytics or behavioral tracking on Student accounts. We do not sell student data.

d. Parental Rights

Parents and legal guardians have the right to:

  • Review the personal information we have collected from their child
  • Request correction of inaccurate information about their child
  • Request deletion of their child's personal information
  • Refuse further collection or use of their child's information
  • Request that we stop sharing their child's information with third parties

To exercise these rights, contact us through our Contact Us page or contact your child's school.

If a parent's request relates to a Student account managed under the school authorization exception, we may direct the parent to the school or district that authorized the account, in line with FTC guidance. We will respond to verifiable parent requests within 30 days.

e. School Access to Student Data

The school or district owns its students' educational records. Teachers and Account Owners can review the creations their students saved, and the writing inside them, directly in the Control Panel. For student work that the Control Panel does not display, and for a copy of a student's records to answer a parent's request, to correct a record, or to retain it at the end of a term, a school may request it from us in writing at connect@gptquest.ai. We respond to a verified request from the Account Owner within 30 days.

f. Account Registration

During the current launch period, only adult Account Owners may register directly through the Service. Student and Teacher accounts (including students aged 13 and older, and students under 13) are created by the school's Account Owner through the Control Panel, subject to the terms of this Privacy Policy.

12. Third-Party Services

We use third-party services that process data on our behalf, including AI providers, hosting, authentication, and storage. The current list is detailed in Section 8. If we add other categories of providers in the future (such as analytics tooling), we will update this Policy. All providers we work with are contractually bound to protect your data and use it only for the purposes described.

13. International Transfers

Your data may be transferred to and processed in countries with different data protection laws, including the United States. By using GPTQuest, you consent to these transfers. We implement appropriate safeguards where required.

Where data is transferred from the EU/EEA, the United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Addendum where applicable), which are incorporated into our agreements with our subprocessors.

14. Changes to This Policy

We may update this Privacy Policy. We will post the updated version with a new "Last Updated" date at the top and may notify you via the Service. Continued use of the Service constitutes acceptance.

15. Contact Us

If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us:

Kixmeta Labs LLC
848 E Main Street, Suite 800 #1002
Ephrata, PA 17522, United States
Email: connect@gptquest.ai

You can also reach us through our Contact Us page.