Khurram Badar / Archive / Courses / Privacy Policy — newworld.education

Privacy Policy — newworld.education

guide · 2026-04-19 · 2953 words · Khurram Badar · for institutions, professionals · intro

Plain-English privacy policy for educational platform emphasizing minimal data collection, child safety, and transparent practices.

privacy · education · legal · policy

Privacy Policy — newworld.education

**Effective Date:** [DATE TO BE INSERTED AT LAUNCH]
**Last Updated:** [DATE]
**Operated by:** Khurram Badar, sole proprietor, operating the newworld.education brand
**Planned entity (within 6 months of launch):** [To be updated once RAKEZ FZE activity is amended or new entity formed]
**Contact:** privacy@newworld.education

---

A Plain-English Summary (read this first)

Before the legal language, here is what this policy says in plain English:

1. **We collect as little as possible.** We don't need your child's real name, date of birth, address, or photo to help them learn. We don't ask for any of it.

2. **We separate identity data from learning data.** Your child's login information lives in one place. Their learning progress lives in another, tagged with a random code that doesn't identify them.

3. **We don't track you across the internet.** No Google Analytics. No Facebook Pixel. No ad networks. No third-party trackers of any kind.

4. **We don't sell data. To anyone. Ever.** Not to advertisers, not to data brokers, not to other platforms. Not even if someone offered us money for it.

5. **You can delete everything, anytime.** One click from your account settings. We honour deletion requests within 30 days.

6. **Starky doesn't remember forever.** Your child's conversations with Starky are automatically deleted after 90 days unless flagged for safety reasons.

7. **We do not use your child's data to train AI models.** Your child's conversations and work are used only to serve them — never used to improve our AI, and never sent to anyone else to improve theirs.

If any of the above is not true at any point in the future, we will tell you before we change it, not after.

The rest of this document is the detailed legal version of the same commitments.

---

1. Who This Policy Applies To

This Privacy Policy applies to everyone who uses newworld.education, including:

By using newworld.education, you agree to this Privacy Policy. If you do not agree, please do not use the platform.

---

2. What We Collect

We follow a principle called **data minimisation**. We collect only what the platform needs to function. Nothing more.

2.1 Account Information (Parent/Guardian)

When a parent creates an account, we collect:
- An email address (used for login, password recovery, and weekly summaries)
- A password (stored hashed, never visible to us or anyone else)
- Country of residence (to localise curriculum and content)

We do NOT collect: full name, phone number, home address, date of birth, photo, or any other identifying information about the parent.

2.2 Learner Profile (Child)

When a parent adds a child to their account, we collect:
- A display nickname, chosen by the parent (e.g., "Yusuf," "Champ," or any name the parent prefers — does not need to be the child's real name)
- An age band (e.g., "Year 4" or "age 9–10"), not a date of birth
- Curriculum selection (e.g., Cambridge IGCSE, Edexcel, FBISE)
- Country (for curriculum localisation only)

We do NOT collect from or about the child: real full name, date of birth, home address, phone number, photo, school name, geolocation beyond country, biometric data, or any information about the family, religion, ethnicity, health, or personal circumstances.

2.3 Learning Activity (Usage Data)

As the child uses the platform, we generate and store:
- Answers to questions and Brain Games puzzles
- Scores, mastery levels, and progress
- Time spent on lessons and modules
- Which curriculum topics are strong or weak
- Conversations with Starky (see retention below)

This data is tagged with an internal random identifier (a pseudonymous ID), not a name. Even our own engineers cannot tell which child in the usage database corresponds to which account, without explicitly cross-referencing the separate profile database.

2.4 Technical Data

When any browser connects to our platform, our servers automatically receive technical data that every website receives:
- IP address (used for security, rate-limiting, and fraud prevention; retained for 30 days then deleted)
- Browser type and operating system (for compatibility)
- Device type (for responsive design)

We do NOT use this data for tracking, profiling, or advertising.

2.5 Payment Information

When a parent subscribes, payment is processed by **Stripe**, a PCI-compliant payment provider. We do not see, store, or have access to credit card numbers, CVV codes, or bank details. Stripe provides us only with a payment confirmation and a token to process future renewals.

2.6 Voluntary Information

If a parent contacts support, we receive whatever they send us (email content, attachments). This is retained for 12 months then deleted, unless the issue is ongoing.

---

3. What We Do NOT Collect

To be explicit — because this is as important as what we do collect — we do NOT collect, and we have no technical ability to collect:

If any future feature would require collecting any of the above, we will not add it silently. We will announce it, explain why, and ask for opt-in consent — separately from the initial account setup.

---

4. How We Use What We Collect

We use the data we collect ONLY for these purposes:

4.1 Providing the Service

4.2 Safety and Security

4.3 Service Improvement (Aggregated and Anonymised Only)

We do NOT use your data for:
- Advertising (we show no ads)
- Training or improving AI models outside of the platform
- Selling, renting, or trading to any third party
- Profiling for commercial purposes
- Any form of behavioural targeting

---

5. The Separation Architecture (How We Protect Your Data)

This section is unusual — most privacy policies don't explain technical architecture. We think parents deserve to know.

newworld.education uses a **data separation architecture**:

**What this means in practice:** If our Usage Database were ever breached or leaked, the attacker would see a list of random codes and learning scores. They would not know which child is which. This is the strongest protection architecturally possible for a functional learning platform.

---

6. How Long We Keep Data

We keep data only as long as necessary.

| Data Type | Retention Period |
|---|---|
| Account information (while active) | Until account deletion |
| Starky conversations | **90 days** after each conversation, then auto-deleted |
| Learning progress (scores, mastery) | Duration of active account, plus 90 days after deletion |
| IP addresses | 30 days |
| Payment records | 7 years (legal tax requirement) |
| Safety-flagged events | 2 years, access restricted |
| Support emails | 12 months |
| Backups | 30 days, rolling |

When an account is deleted (see Section 10), we delete data within 30 days from our active systems, and within 60 days from all backups.

---

7. Who We Share Data With

We share personal data only with:

7.1 Essential Service Providers

These are third parties that make the platform work. We share only what's necessary.

| Provider | What We Share | Why |
|---|---|---|
| **Vercel** (hosting) | Technical data, encrypted application data | Serves the platform |
| **Supabase** (database) | Account and usage data | Stores our data |
| **Anthropic** (AI — Claude) | Starky conversation content | Powers Starky |
| **Stripe** (payments) | Parent email, country, subscription tier | Processes payments |
| **Resend** or similar (email) | Parent email, message content | Sends emails |

Each of these providers is contractually required to use our data only to provide their service to us. None of them are permitted to use our data for their own purposes, including AI training, advertising, or analytics.

**Important note on Anthropic:** When the student talks to Starky, the message is sent to Anthropic's API for processing. Anthropic's commercial API terms state that API inputs and outputs are NOT used to train their models. You can review Anthropic's commercial terms at anthropic.com.

7.2 Legal Requirements

We may disclose data if legally required — for example, a court order. When we can, we will notify you before disclosing unless prohibited by law.

7.3 Safety Concerns

If we detect that a child may be in immediate danger (see Section 9), we will notify the parent on the account. We may also contact local emergency services if we believe there is risk of serious harm and parent contact fails, though our capability to do this is limited.

7.4 What We Never Do

We do NOT:
- Sell data to anyone, for any price
- Rent or licence data to advertisers, data brokers, or research firms
- Share data with social media platforms
- Share data with other educational platforms
- Share data with employers, insurers, or government agencies beyond legal obligations
- Allow third parties to track users on our platform

---

8. Cookies and Tracking

8.1 What We Use

We use a minimum of cookies, limited to:
- A session cookie (to keep you logged in)
- A preferences cookie (to remember your language and display settings)
- A CSRF protection cookie (for security)

8.2 What We Do NOT Use

We do NOT use:
- Google Analytics
- Facebook Pixel
- Hotjar, Mixpanel, Segment, or any behavioural analytics
- Advertising cookies or retargeting pixels
- Third-party trackers of any kind

No banner is necessary because we do not use non-essential cookies. We mention this to be transparent about what is and isn't happening on your browser.

---

9. Safety Monitoring and Crisis Response

We take seriously our duty of care to children using the platform.

9.1 What We Monitor

Starky conversations are automatically scanned for signals that a child may be in emotional distress, at risk of self-harm, or experiencing harm from another person. This scanning is done by automated systems — no human reads conversations routinely.

9.2 What Happens If Distress Is Detected

If the system detects such a signal, the following happens:

1. **Starky responds with care** — acknowledging the child's feelings, expressing concern, and suggesting they talk to a trusted adult
2. **Crisis resources are shown** — region-appropriate helplines are surfaced in the interface
3. **The parent is notified** via email, push notification, and (if enabled) WhatsApp, within 1 hour
4. **A safety event is logged** internally, accessible only to designated safety reviewers
5. **The conversation continues** — the child is not cut off, blocked, or logged out

9.3 Limitations

---

10. Your Rights

Under applicable law (including GDPR for users in the UK and EU, UAE Federal Decree-Law No. 45 of 2021, and similar protections elsewhere), you have the following rights over your data and your child's data.

10.1 Right to Access

10.2 Right to Correction

10.3 Right to Deletion

10.4 Right to Portability

10.5 Right to Object

10.6 Right to Withdraw Consent

10.7 Right to Complain

10.8 How to Exercise Your Rights

Email **privacy@newworld.education** or use the tools in your account settings. We will not charge a fee for reasonable requests. We may ask for verification that you are who you claim to be — this protects the child's data from unauthorised access.

---

11. Children's Privacy (Extra Protections)

Children using newworld.education receive additional protections:

11.1 Parent-Managed Accounts

11.2 No Direct Marketing to Children

11.3 No Social Features

11.4 No Profile Enrichment

11.5 Parental Access

Parents cannot view:
- The raw content of Starky conversations (except when a safety event is flagged)
- The child's journaling or personal notes (if such features exist in future)

This balance respects the child's space for honest expression while maintaining parental oversight of safety-critical events.

11.6 Under COPPA (if applicable to US users)

---

12. International Data Transfers

The platform is operated from the UAE. Your data may be processed in data centres in the UAE, EU, US, or other regions, depending on the service provider. Where data is transferred out of the UAE, EU, or UK, appropriate safeguards are in place (standard contractual clauses or equivalent).

---

13. Security

We take security seriously. Technical measures include:
- Encryption of all data in transit (TLS/HTTPS)
- Encryption of data at rest
- Hashed passwords (never stored in plain text)
- Row-level security on database tables
- Regular security updates
- Rate limiting and fraud detection
- Minimal access for developers (principle of least privilege)

We cannot guarantee absolute security — no system can — but we apply modern standards appropriate to a platform handling children's data.

If a data breach occurs that affects your data, we will notify you and relevant authorities as required by applicable law, typically within 72 hours of discovery.

---

14. Changes to This Policy

We may update this Privacy Policy from time to time.

**For material changes** (any change that expands what we collect, how we use it, or who we share it with), we will:
- Notify you by email at least 30 days in advance
- Show a notice on the platform at next login
- Allow you to review and accept, or delete your account if you do not agree

**For non-material changes** (typos, formatting, clarifications that don't change practice), we will update the "Last Updated" date.

We will not make a material change retroactive to data already collected without explicit new consent.

---

15. Contact

For any privacy question, concern, or rights request:

**Email:** privacy@newworld.education
**Response time:** Within 5 business days for questions; within 30 days for rights requests

For general questions: hello@newworld.education
For legal matters: legal@newworld.education

---

16. Our Honest Commitment

We are a small team building newworld.education because we believe children deserve better learning tools. We chose to collect less data, not more, because we think that's what's right — not because a regulation forced us to.

If you ever think we've fallen short of the commitments in this policy, tell us. We will either fix it, explain why we cannot, or, if neither is possible, help you delete your account cleanly.

— Khurram Badar, founder

---

**Last reviewed:** [DATE]
**Next scheduled review:** [DATE + 12 months]

**IMPORTANT NOTICE:** This document is a draft. It has not been reviewed by a lawyer. For a production launch, a one-time review by a data-protection specialist is strongly recommended but has been deferred by the operator at this time. The operator has acknowledged this decision and its associated risks.

← UAE Curriculum Subject Map & Collection Checklist2050Planet: Sustainability Platform Architecture →
Two years of working thought, indexed.
Ask me to present it in your conference room — WhatsApp +971 55 623 9111
Book Session →