MathCompass Kids Privacy Policy
Version: 1.0 Effective date: 20 August 2026 Last updated: 20 August 2026
In brief — also for children
MathCompass Kids helps children practise maths. An adult creates the account, and the child uses a profile created by a parent or guardian.
- We ask only for the child's nickname or first name, without a surname.
- We do not display advertising or use external product analytics tools.
- We do not sell data or use it for behavioural advertising.
- We send a worksheet photo to an AI provider only to read the exercises. Once processing is complete, we do not store the photo in our database.
- A parent can view and delete the child's profile data.
- An educator in a private group sees the child's data only after the parent joins the child to that group. The educator can send only a preset message selected from a list. The app has no open chat or free-text messages from an educator to a child.
If anything is unclear, a child should ask a trusted adult for help. Privacy questions can be sent to privacy@happy-bits.eu.
1. Data controller
The data controller is Marcin Bojar-Ślusarczyk, a self-employed individual operating in Spain under the trade name Happy Bits.
Address: C. Tarongers, 38, 46171 Casinos, Valencia, Spain.
Email for privacy matters and the exercise of rights: privacy@happy-bits.eu.
2. Scope of this Policy
This Policy applies to the MathCompass Kids mobile app, its API, and related services.
The first release is offered to people in the European Union and European Economic Area. We do not make the app available for download in the official stores in the United States or the United Kingdom. This page is public and may also be opened by someone outside the EEA — that does not mean that the Service is sold there. Before entering those markets, we will implement the required local child-protection measures and update this Policy.
MathCompass Kids is a service intended directly for families and educators acting privately. It is not a school system or a service commissioned by a school. Users must not place student rosters or official school records in the app.
3. Users of the Service
An adult may create an account as a parent, guardian, or privately acting educator. A child does not create an account independently. A parent or guardian creates and controls the child's profile and the devices that may use it.
The “teacher” role is the name of a function for an adult account. We do not verify professional qualifications, employment by a school, or authority to represent an institution.
4. Data we process
4.1 Adult account data
- email address, nickname or display name, and account role;
- language, time zone, and app settings;
- secured cryptographic password hash, email-verification status, sessions, tokens, parent PIN, pairing codes, and security records;
- the version of the documents presented, their language, and the time and method of acceptance;
- support correspondence and rights requests.
We do not store the password in plain text.
4.2 Child profile and learning
- a random profile identifier and a nickname or first name without a surname;
- a drawn avatar selected from the app's catalogue and its colour; the app does not allow a child's photograph to be set as the avatar;
- profile settings;
- exercises, answers, visible working, checking results, number of attempts, hints used, progress, rewards, and completion status;
- for plans that include learning-time measurement: the start and last activity of a session and aggregated active time; we do not record a stream of individual taps;
- identifiers of paired devices and tokens needed for access and notifications.
We do not ask for a date of birth, surname, home address, telephone number, school name, or student identifier.
4.3 Worksheets and AI features
When an authorised user scans a worksheet, generates exercises, or requests a hint, we process:
- the worksheet photo while it is uploaded and analysed;
- recognised text, numbers, exercise layout, and user corrections;
- exercise context and visible working needed to provide a hint;
- the model response, checking result, and basic technical data about the call.
We do not store the original photo in the MathCompass Kids database after the request is complete. We store the structured exercises obtained from the scan so that the user can use them.
We do not include the adult's email address, the child's profile name, or our account or profile identifiers in an ordinary AI request. The photo may, however, contain information written on the paper, so it should be cropped or covered before it is sent.
If a user reports a problem with AI content, we store the selected reason, an optional description, and a protected copy of the context needed to investigate the report.
4.4 Private groups and feedback
After a parent joins a child to a private group, the educator can see the child's nickname or first name, assigned exercises, submitted solutions, and progress. Feedback for the child is one of the preset messages selected from a list. There is no open message field or chat between the educator and the child.
4.5 Purchases
Only an adult makes purchases. We process the product and transaction identifier, store, subscription status, entitlements, credits, refunds, and purchase restoration.
RevenueCat receives the adult account identifier and the app, device, and purchase data needed to manage entitlements. We do not send RevenueCat a child profile name or identifier, the child's answers, progress, or worksheet content. We do not receive the full payment-card number.
4.6 Technical data
The server and infrastructure providers may process the IP address, device information, operating system and app version, language, timestamps, installation identifiers, technical request data, and error and security information.
We do not use external product analytics tools, advertising identifiers, or precise location.
5. Purposes and legal bases for processing
In the EEA, we process data on the basis of:
- performance of a contract with the adult (Article 6(1)(b) GDPR) — to operate the account, authenticate users, provide selected features, handle purchases, and provide support;
- legitimate interests (Article 6(1)(f) GDPR) — to provide educational features, protect the Service, prevent abuse, and improve its reliability; in this assessment, the child's interests and rights take priority;
- legal obligation (Article 6(1)(c) GDPR) — in particular, to meet tax, accounting, and data-subject-rights obligations;
- consent (Article 6(1)(a) GDPR) — only when we request it for an optional feature or device permission.
AI features are initiated at the request of an authorised user. We do not use data for marketing, behavioural advertising, or commercial profiling of a child.
6. Providers and recipients of data
We use the services of the following providers:
- Railway — API hosting;
- Supabase — database hosting;
- OpenAI and Anthropic — reading worksheets, generating exercises, and creating hints, depending on the feature and model route;
- RevenueCat — handling adult purchases and entitlements;
- Apple App Store and Google Play — payments, subscriptions, refunds, and purchase restoration;
- Expo, Apple APNs, and Google FCM — delivery of optional push notifications;
- Resend — delivery of account and security messages.
Data may be provided to advisers or public authorities where required by law or necessary to establish, exercise, or defend legal claims.
We do not sell personal data. We do not disclose it to data brokers, advertising networks, or for targeted advertising.
7. Data processed by AI providers
OpenAI may generally retain the content of requests and responses in security logs for up to 30 days. Anthropic deletes commercial API inputs and outputs from its backend within 30 days. Exceptionally, content may be retained for longer where required by law or needed to enforce usage policies, prevent abuse, or protect services and people from harm. Data submitted by Happy Bits through the APIs is not used to train their models.
We limit the information sent to these providers and do not intentionally include information identifying the child.
8. Transfers outside the EEA
Some providers may process data outside the EEA, particularly in the United States. In such cases, data is transferred using mechanisms provided for by the GDPR, such as a European Commission adequacy decision or Standard Contractual Clauses.
Information about the mechanism used by a particular provider can be obtained by writing to privacy@happy-bits.eu.
9. How long we keep data
- We keep the account, child profiles, exercises, answers, and progress while the Service is used, until the user deletes them or the purpose of processing ends.
- We delete an unverified account after 14 days. Local data needed to resume verification expires after 15 days.
- We delete data related to email verification and password reset no later than 30 days after it is used or expires.
- We do not store the original worksheet photo in our database after handling the request. OpenAI or Anthropic normally retains a copy for no longer than 30 days, subject to the exceptions described in section 7.
- We keep the content of an AI problem report for up to 90 days; we may keep a content-free statistical record for up to 12 months.
- We keep completed technical notification events for up to 30 days and completed billing events for up to 90 days.
- We may keep data required for tax and accounting, refunds, fraud prevention, or the defence of legal claims for the period required by law, normally no longer than six years.
- We keep security logs for the time needed to protect the Service and investigate an incident. Backups are overwritten in their normal cycle.
When the purpose ends, we delete or irreversibly anonymise data unless the law requires further restricted retention.
10. Account and data deletion
An adult can delete the account in the app settings or send a request to privacy@happy-bits.eu. Instructions are also available on the public account-deletion page.
Account deletion covers the adult account, the child profiles belonging to it, exercises, answers, progress, paired devices, and data held by providers where further retention is not required. We also request deletion of the RevenueCat customer associated with the adult account identifier.
Deleting the account does not cancel a subscription in the Apple App Store or Google Play. The subscription must be cancelled separately in the relevant store settings.
Before fulfilling a request submitted by email, we may ask for proportionate confirmation of control over the account. We do not require an identity document if the account can be sufficiently verified in another way.
11. Device permissions
The app may request access to the camera or photo library to select a worksheet, and permission for notifications to deliver enabled reminders and work-related messages. Permissions can be disabled in the device settings.
We do not request access to contacts, the microphone, or precise location.
12. Security
We use safeguards appropriate to the risk, including encryption in transit, password hashing, role-based access control, short-lived sessions, secret management, rate limiting, data minimisation, backups, and security-event logging. AI-content reports are stored in encrypted form.
No method provides absolute security. If an incident occurs, we investigate it, limit its effects, and make any notifications required by law.
13. The user's and child's rights
Depending on the circumstances, a person may request access to data, receive a copy, request correction, deletion, restriction of processing, or data portability, and object to processing based on legitimate interests. Consent may be withdrawn at any time.
Rights relating to a child's data belong to the child. A parent or guardian may exercise them on the child's behalf where authorised and acting in the child's best interests.
Requests should be sent to privacy@happy-bits.eu. We will respond without undue delay, normally within one month.
A complaint may be submitted to the Spanish data-protection authority — the Agencia Española de Protección de Datos — or to the competent data-protection authority in the person's EEA country of residence.
14. Automated checking and AI
Maths answers are checked using deterministic rules. AI helps to read worksheets, create exercises, and formulate hints, but it may be wrong.
MathCompass Kids does not make solely automated decisions that produce legal or similarly significant effects for a child. Results are not official school grades or a basis for admission, classification, or any other official decision.
15. Advertising, analytics, and sale of data
MathCompass Kids has no advertising or external product analytics. We do not sell data, disclose it for targeted advertising, track users across apps, or create an advertising profile of a child.
16. Changes to this Policy
We may update this Policy when the Service, the law, or the way we process data changes. With each update, we will provide a new date and version number. We will notify users of material changes in the app or by email. Where required by law, we will ask for new consent.
17. Contact
Happy Bits — Marcin Bojar-Ślusarczyk
C. Tarongers, 38
46171 Casinos, Valencia
Spain