Privacy Policy — newworld.education
**Effective Date:** [DATE TO BE INSERTED AT LAUNCH]
**Last Updated:** [DATE]
**Operated by:** Khurram Badar, sole proprietor, operating the newworld.education brand
**Planned entity (within 6 months of launch):** [To be updated once RAKEZ FZE activity is amended or new entity formed]
**Contact:** privacy@newworld.education
---
A Plain-English Summary (read this first)
Before the legal language, here is what this policy says in plain English:
1. **We collect as little as possible.** We don't need your child's real name, date of birth, address, or photo to help them learn. We don't ask for any of it.
2. **We separate identity data from learning data.** Your child's login information lives in one place. Their learning progress lives in another, tagged with a random code that doesn't identify them.
3. **We don't track you across the internet.** No Google Analytics. No Facebook Pixel. No ad networks. No third-party trackers of any kind.
4. **We don't sell data. To anyone. Ever.** Not to advertisers, not to data brokers, not to other platforms. Not even if someone offered us money for it.
5. **You can delete everything, anytime.** One click from your account settings. We honour deletion requests within 30 days.
6. **Starky doesn't remember forever.** Your child's conversations with Starky are automatically deleted after 90 days unless flagged for safety reasons.
7. **We do not use your child's data to train AI models.** Your child's conversations and work are used only to serve them — never used to improve our AI, and never sent to anyone else to improve theirs.
If any of the above is not true at any point in the future, we will tell you before we change it, not after.
The rest of this document is the detailed legal version of the same commitments.
---
1. Who This Policy Applies To
This Privacy Policy applies to everyone who uses newworld.education, including:
- Parents and guardians who create accounts
- Students (learners) whose accounts are managed by a parent or guardian
- Teachers and school administrators (if using school features)
- Visitors to our website who are not logged in
By using newworld.education, you agree to this Privacy Policy. If you do not agree, please do not use the platform.
---
2. What We Collect
We follow a principle called **data minimisation**. We collect only what the platform needs to function. Nothing more.
2.1 Account Information (Parent/Guardian)
When a parent creates an account, we collect:
- An email address (used for login, password recovery, and weekly summaries)
- A password (stored hashed, never visible to us or anyone else)
- Country of residence (to localise curriculum and content)
We do NOT collect: full name, phone number, home address, date of birth, photo, or any other identifying information about the parent.
2.2 Learner Profile (Child)
When a parent adds a child to their account, we collect:
- A display nickname, chosen by the parent (e.g., "Yusuf," "Champ," or any name the parent prefers — does not need to be the child's real name)
- An age band (e.g., "Year 4" or "age 9–10"), not a date of birth
- Curriculum selection (e.g., Cambridge IGCSE, Edexcel, FBISE)
- Country (for curriculum localisation only)
We do NOT collect from or about the child: real full name, date of birth, home address, phone number, photo, school name, geolocation beyond country, biometric data, or any information about the family, religion, ethnicity, health, or personal circumstances.
2.3 Learning Activity (Usage Data)
As the child uses the platform, we generate and store:
- Answers to questions and Brain Games puzzles
- Scores, mastery levels, and progress
- Time spent on lessons and modules
- Which curriculum topics are strong or weak
- Conversations with Starky (see retention below)
This data is tagged with an internal random identifier (a pseudonymous ID), not a name. Even our own engineers cannot tell which child in the usage database corresponds to which account, without explicitly cross-referencing the separate profile database.
2.4 Technical Data
When any browser connects to our platform, our servers automatically receive technical data that every website receives:
- IP address (used for security, rate-limiting, and fraud prevention; retained for 30 days then deleted)
- Browser type and operating system (for compatibility)
- Device type (for responsive design)
We do NOT use this data for tracking, profiling, or advertising.
2.5 Payment Information
When a parent subscribes, payment is processed by **Stripe**, a PCI-compliant payment provider. We do not see, store, or have access to credit card numbers, CVV codes, or bank details. Stripe provides us only with a payment confirmation and a token to process future renewals.
2.6 Voluntary Information
If a parent contacts support, we receive whatever they send us (email content, attachments). This is retained for 12 months then deleted, unless the issue is ongoing.
---
3. What We Do NOT Collect
To be explicit — because this is as important as what we do collect — we do NOT collect, and we have no technical ability to collect:
- The child's real full name
- The child's date of birth (age band only)
- The child's photo, voice recording, or any biometric data
- The child's home address or phone number
- The child's school name (unless the school is a formal partner, in which case parents are notified explicitly)
- Precise location (GPS, Wi-Fi, or beacon data)
- Social media profiles or links
- Contacts, calendar, or any device data beyond what a standard browser sends
- Information about the child's family, religion, ethnicity, sexuality, health, or disability
- Fingerprint, facial recognition, voice print, or any biometric identifier
- Any information from any third-party source (we never purchase, rent, or acquire data about users from anyone)
If any future feature would require collecting any of the above, we will not add it silently. We will announce it, explain why, and ask for opt-in consent — separately from the initial account setup.
---
4. How We Use What We Collect
We use the data we collect ONLY for these purposes:
4.1 Providing the Service
4.2 Safety and Security
4.3 Service Improvement (Aggregated and Anonymised Only)
We do NOT use your data for:
- Advertising (we show no ads)
- Training or improving AI models outside of the platform
- Selling, renting, or trading to any third party
- Profiling for commercial purposes
- Any form of behavioural targeting
---
5. The Separation Architecture (How We Protect Your Data)
This section is unusual — most privacy policies don't explain technical architecture. We think parents deserve to know.
newworld.education uses a **data separation architecture**:
- **Profile Database** — Contains account information: email, nickname, age band, curriculum. Encrypted at rest. Accessed only for account operations.
- **Usage Database** — Contains learning progress, answers, and activity. Tagged with a random identifier (UUID), not a name. Contains no identifying information.
- **The bridge** — The random UUID is the only link between the two databases. The Usage Database on its own cannot be traced back to any individual child.
**What this means in practice:** If our Usage Database were ever breached or leaked, the attacker would see a list of random codes and learning scores. They would not know which child is which. This is the strongest protection architecturally possible for a functional learning platform.
---
6. How Long We Keep Data
We keep data only as long as necessary.
| Data Type | Retention Period |
|---|---|
| Account information (while active) | Until account deletion |
| Starky conversations | **90 days** after each conversation, then auto-deleted |
| Learning progress (scores, mastery) | Duration of active account, plus 90 days after deletion |
| IP addresses | 30 days |
| Payment records | 7 years (legal tax requirement) |
| Safety-flagged events | 2 years, access restricted |
| Support emails | 12 months |
| Backups | 30 days, rolling |
When an account is deleted (see Section 10), we delete data within 30 days from our active systems, and within 60 days from all backups.
---
7. Who We Share Data With
We share personal data only with:
7.1 Essential Service Providers
These are third parties that make the platform work. We share only what's necessary.
| Provider | What We Share | Why |
|---|---|---|
| **Vercel** (hosting) | Technical data, encrypted application data | Serves the platform |
| **Supabase** (database) | Account and usage data | Stores our data |
| **Anthropic** (AI — Claude) | Starky conversation content | Powers Starky |
| **Stripe** (payments) | Parent email, country, subscription tier | Processes payments |
| **Resend** or similar (email) | Parent email, message content | Sends emails |
Each of these providers is contractually required to use our data only to provide their service to us. None of them are permitted to use our data for their own purposes, including AI training, advertising, or analytics.
**Important note on Anthropic:** When the student talks to Starky, the message is sent to Anthropic's API for processing. Anthropic's commercial API terms state that API inputs and outputs are NOT used to train their models. You can review Anthropic's commercial terms at anthropic.com.
7.2 Legal Requirements
We may disclose data if legally required — for example, a court order. When we can, we will notify you before disclosing unless prohibited by law.
7.3 Safety Concerns
If we detect that a child may be in immediate danger (see Section 9), we will notify the parent on the account. We may also contact local emergency services if we believe there is risk of serious harm and parent contact fails, though our capability to do this is limited.
7.4 What We Never Do
We do NOT:
- Sell data to anyone, for any price
- Rent or licence data to advertisers, data brokers, or research firms
- Share data with social media platforms
- Share data with other educational platforms
- Share data with employers, insurers, or government agencies beyond legal obligations
- Allow third parties to track users on our platform
---
8. Cookies and Tracking
8.1 What We Use
We use a minimum of cookies, limited to:
- A session cookie (to keep you logged in)
- A preferences cookie (to remember your language and display settings)
- A CSRF protection cookie (for security)
8.2 What We Do NOT Use
We do NOT use:
- Google Analytics
- Facebook Pixel
- Hotjar, Mixpanel, Segment, or any behavioural analytics
- Advertising cookies or retargeting pixels
- Third-party trackers of any kind
No banner is necessary because we do not use non-essential cookies. We mention this to be transparent about what is and isn't happening on your browser.
---
9. Safety Monitoring and Crisis Response
We take seriously our duty of care to children using the platform.
9.1 What We Monitor
Starky conversations are automatically scanned for signals that a child may be in emotional distress, at risk of self-harm, or experiencing harm from another person. This scanning is done by automated systems — no human reads conversations routinely.
9.2 What Happens If Distress Is Detected
If the system detects such a signal, the following happens:
1. **Starky responds with care** — acknowledging the child's feelings, expressing concern, and suggesting they talk to a trusted adult
2. **Crisis resources are shown** — region-appropriate helplines are surfaced in the interface
3. **The parent is notified** via email, push notification, and (if enabled) WhatsApp, within 1 hour
4. **A safety event is logged** internally, accessible only to designated safety reviewers
5. **The conversation continues** — the child is not cut off, blocked, or logged out
9.3 Limitations
- Automated detection is imperfect. It may miss genuine distress and may flag messages that turn out to be harmless.
- We cannot guarantee intervention in any specific situation.
- We are not a crisis response service. Parents remain primarily responsible for their child's wellbeing.
---
10. Your Rights
Under applicable law (including GDPR for users in the UK and EU, UAE Federal Decree-Law No. 45 of 2021, and similar protections elsewhere), you have the following rights over your data and your child's data.
10.1 Right to Access
10.2 Right to Correction
10.3 Right to Deletion
10.4 Right to Portability
10.5 Right to Object
10.6 Right to Withdraw Consent
10.7 Right to Complain
10.8 How to Exercise Your Rights
Email **privacy@newworld.education** or use the tools in your account settings. We will not charge a fee for reasonable requests. We may ask for verification that you are who you claim to be — this protects the child's data from unauthorised access.
---
11. Children's Privacy (Extra Protections)
Children using newworld.education receive additional protections:
11.1 Parent-Managed Accounts
11.2 No Direct Marketing to Children
11.3 No Social Features
11.4 No Profile Enrichment
11.5 Parental Access
Parents cannot view:
- The raw content of Starky conversations (except when a safety event is flagged)
- The child's journaling or personal notes (if such features exist in future)
This balance respects the child's space for honest expression while maintaining parental oversight of safety-critical events.
11.6 Under COPPA (if applicable to US users)
---
12. International Data Transfers
The platform is operated from the UAE. Your data may be processed in data centres in the UAE, EU, US, or other regions, depending on the service provider. Where data is transferred out of the UAE, EU, or UK, appropriate safeguards are in place (standard contractual clauses or equivalent).
---
13. Security
We take security seriously. Technical measures include:
- Encryption of all data in transit (TLS/HTTPS)
- Encryption of data at rest
- Hashed passwords (never stored in plain text)
- Row-level security on database tables
- Regular security updates
- Rate limiting and fraud detection
- Minimal access for developers (principle of least privilege)
We cannot guarantee absolute security — no system can — but we apply modern standards appropriate to a platform handling children's data.
If a data breach occurs that affects your data, we will notify you and relevant authorities as required by applicable law, typically within 72 hours of discovery.
---
14. Changes to This Policy
We may update this Privacy Policy from time to time.
**For material changes** (any change that expands what we collect, how we use it, or who we share it with), we will:
- Notify you by email at least 30 days in advance
- Show a notice on the platform at next login
- Allow you to review and accept, or delete your account if you do not agree
**For non-material changes** (typos, formatting, clarifications that don't change practice), we will update the "Last Updated" date.
We will not make a material change retroactive to data already collected without explicit new consent.
---
15. Contact
For any privacy question, concern, or rights request:
**Email:** privacy@newworld.education
**Response time:** Within 5 business days for questions; within 30 days for rights requests
For general questions: hello@newworld.education
For legal matters: legal@newworld.education
---
16. Our Honest Commitment
We are a small team building newworld.education because we believe children deserve better learning tools. We chose to collect less data, not more, because we think that's what's right — not because a regulation forced us to.
If you ever think we've fallen short of the commitments in this policy, tell us. We will either fix it, explain why we cannot, or, if neither is possible, help you delete your account cleanly.
— Khurram Badar, founder
---
**Last reviewed:** [DATE]
**Next scheduled review:** [DATE + 12 months]
**IMPORTANT NOTICE:** This document is a draft. It has not been reviewed by a lawyer. For a production launch, a one-time review by a data-protection specialist is strongly recommended but has been deferred by the operator at this time. The operator has acknowledged this decision and its associated risks.