Draft — not yet in force. Generation 3 Academy is not yet incorporated, so the operator, its registered address and its governing law are shown below as bracketed placeholders. This document has not been reviewed by a lawyer.
Until those brackets are filled in and a lawyer has read it, treat this as a statement of intent rather than a binding policy — and do not take money from families against it. Every open question is listed in the last section.
Privacy Policy
What we record about your child, who can see it, how long we keep it, and how to have it removed. Written to be read by a parent, not by a lawyer.
Who we are
Generation 3 Academy operates gen3academy.org and the learning platform called The Vessels, an Islamic Studies course for students in grades 6–12. This policy explains what the site and the platform record about the people who use them.
The operator is [LEGAL ENTITY NAME], a [ENTITY TYPE] formed in [STATE / COUNTRY], whose registered address is [REGISTERED ADDRESS]. Data protection enquiries: info@gen3academy.org.
Nothing is registered yet. A privacy policy that does not name a legal person is not one anybody can enforce against, or comply with.
Two different things live at this address, and they are not the same in privacy terms:
- The public pages — this page, the home page, About, Curriculum and The Vessels. They are brochures. They have no accounts, no forms, no analytics and no cookies. You can read every one of them without us learning anything about you beyond what our host records to serve the page.
- The platform — the game at
/vesselsand the portal at/portal. Using it needs an account, and an account is issued by a school. That is where everything below applies.
The short version
If you read nothing else:
- We hold no email address, no surname, no date of birth, no home address, no phone number, no photograph and no location for any student.
- There is no advertising, no analytics and no tracking of any kind, anywhere on this site. We have never installed any, and the site’s Content Security Policy would block a third-party script if somebody tried.
- We set one cookie, and only after you sign in. It keeps you signed in and does nothing else. See the Cookie Policy.
- Conversations with the AI teacher are recorded, and a teacher can read them. They are deleted automatically after 90 days. This is the part of the policy we most want a parent to read.
- Nothing is ever sold, rented, or used to build a profile for any purpose other than teaching the student it belongs to.
What we collect
From students
| What | Why we need it |
|---|---|
| Username | To sign in. Chosen by the student; it need not be their real name. |
| First name only | So a teacher and a parent can tell one account from another. |
| Grade, and class if the school uses classes | To give the right lessons, and to scope which teacher can see them. |
| Password | Stored only as a salted hash. We cannot read it, and neither can anyone else. |
| Progress | Inner Flame, score, streak, checkpoints passed, quests completed — the state of the game. |
| Daily deeds claimed | Which deeds a student says they did, and whether a parent confirmed it. |
| Conversations with the AI teacher | To check the reasoning is the student’s own. See section 6. |
| Written reflections | Short pieces a student writes inside the game. |
| Grades and teacher remarks | Set by their teacher, shown to the student and their parent. |
| Activity counts | How many checkpoints, quests and lessons on which day. Numbers, not writing. |
| Sign-in attempts and IP address | Briefly, to stop somebody guessing passwords. Deleted after about a day. |
From parents
- A username, a first name and a hashed password.
- Which children they are linked to, and whether each link is confirmed.
- Their decisions on the household deeds their child claimed.
- Any gift milestone they set — an amount, a target score and a short note to their child.
From teachers and staff
- A username, a first name and a hashed password; which classes they teach; whether they are the head teacher.
- A record of every time they open a student’s conversations, view a student, export a roster, reset a password or delete an account.
From everybody who loads a page
Our host, Cloudflare, records the ordinary things a web server records in order to serve a page and to absorb attacks: an IP address, the time, the page requested, and the browser’s user-agent string. We do not combine these with any account, and we do not use them for analytics. We do not run analytics.
What we never collect
The list below is not a promise about the future — it is a description of the database. There is no column for any of it.
Never held for a student
- Email address
- Surname or family name
- Date of birth or age
- Home address or phone number
- Photograph or video of the student
- Geolocation of any precision
- Payment or card details
- Contacts, calendar or device identifiers
Never done, by anyone
- No advertising, ever
- No analytics or measurement scripts
- No social media pixels or share widgets
- No selling, renting or sharing for money
- No profiling for anything but teaching
- No automated decision with a legal or similarly significant effect
- No behavioural targeting of any kind
Because we hold no email address for a student, we cannot contact your child directly, and a forgotten password has to be reset by their teacher in person. That is a deliberate trade: it costs convenience and buys a category of risk we would rather not carry.
Why we are allowed to hold it
Accounts are issued through a school for a genuine educational purpose. That shapes the answer everywhere.
In the United States
Under COPPA, an operator of a service directed to children under 13 needs verifiable parental consent. Where a school has contracted with us to provide an educational service, the school may give that consent on parents’ behalf for the educational context. That is the ordinary route for classroom software, and it is the route we rely on. We also ask the family to accept the Family Agreement at registration, so a parent sees the same facts directly.
Under FERPA, where student records are involved we act as a school official with a legitimate educational interest, under the school’s direct control. We do not use student records for our own purposes, and we do not disclose them onward except as this policy describes.
If a family is in the UK or the EU
Our lawful bases would be performance of a contract (Art. 6(1)(b)) for the account and progress needed to deliver the course the family enrolled in, and our legitimate interests (Art. 6(1)(f)) for security logging and for a teacher reviewing work for academic honesty. Where consent is the right basis we ask for it, and it can be withdrawn.
We are not currently set up to serve UK or EU families to that standard. There is no Data Protection Officer, no Article 30 record, no completed Data Protection Impact Assessment for the AI feature, and no signed data processing agreement with the AI providers. If the academy intends to enrol families in the UK or the EU, those must exist first — see section 16.
The AI teacher, and where a child’s words go
At each checkpoint, a student discusses the lesson with an AI teacher instead of answering multiple choice. The AI asks questions and gives hints. It never gives the answer, never invents a verse or a hadith, and never issues a religious ruling.
These conversations are recorded, and the student’s teacher can read them. That is how the school checks a student reasoned the answer out rather than talking the AI into passing them.
Students are told this plainly on their own page, in words they will understand. A child who knows they are being read writes more honestly, and the openness is part of the design rather than a formality.
What the AI provider receives. To answer, we send the lesson text and what the student typed to Google (Gemini), or to Groq when Google is unavailable. We do not send the student’s username, their name, their school, or any identifier. The provider sees the words, not the child.
Retention. Conversations are deleted automatically after 90 days. A scheduled job runs nightly.
What parents see. A parent sees whether a checkpoint was passed and the points earned — not the text of what their child wrote. If you want to read your own child’s conversations, ask the school and they will arrange it.
Please talk to your child about this. Children sometimes write personal things into a box that feels private — a worry, a family situation. Ask them to treat the AI teacher as they would a teacher sitting beside them, because that is what it is.
We have not yet signed a data processing agreement with Google or with Groq covering student data, and we have not yet obtained a contractual commitment that they will not train models on what is sent. Until we have, do not enter anything into the AI teacher that you would mind a third party holding.
Who can see what
| Student | Parent | Teacher | Head teacher | |
|---|---|---|---|---|
| Their own progress | Yes | Their children | Their class | Everyone |
| Another child’s progress | No | No | Not other classes | Yes |
| AI conversations | Their own | Result only | Their class | Everyone |
| Grades and remarks | Their own | Their children | Sets them | Sets them |
| Deed confirmations | Their own | Confirms them | Their class | Everyone |
| Gift milestone a parent set | Their own | Their own | Their class | Everyone |
A family code alone never opens a child’s record. When somebody joins using a child’s family code, it creates a request, and the student has to accept it. Until they do, that person sees nothing but the child’s first name. Usernames can be guessed; if naming one were enough to become a child’s parent, a stranger could read their progress.
Every time a teacher opens a child’s conversations, that is recorded — who looked, at whose, and when. An adult reading a child’s private writing should leave a trace.
How long we keep it
| What | Kept for |
|---|---|
| AI conversations | 90 days, then deleted automatically every night |
| Sign-in attempts and IP address | About 24 hours |
| Rate-limiting records | About 2 days |
| Sign-in sessions | 30 days, or until sign-out |
| Activity counts | 1 year — counts only, never writing |
| Account, progress, grades, deeds, reflections | Until the account is deleted |
Ask the school to delete your child’s account at any time and it goes, along with their progress, deeds, grades, reflections and conversations. Deletion cannot be undone.
Deleting an account removes the progress, the deeds, the grades, the reflections, the conversations and the record of which flame awards were made. That last one used to survive: each row held a quest reference and a date, and because the quest list is a public file on this site, that was enough to reconstruct what a child claimed to have done, day by day. It is now deleted with everything else.
What deliberately remains is the staff audit log — the record of which adult opened which child’s private writing, and when. The child’s identifier is redacted from those entries at deletion, so the rows still prove that a member of staff read something on a given date without naming the child. Erasing the log itself would let a deletion destroy the evidence of who had been reading.
Other companies involved
Running the platform means a small number of other companies handle data on our behalf. There are no analytics providers, no advertising networks and no social media trackers on this list, because we use none.
| Company | What they do | What they receive |
|---|---|---|
| Cloudflare | Hosts the site, the database and the API | Everything. All student data is stored here. |
| Google (Gemini) | Provides the AI teacher | Lesson text and what a student typed. No name, no username, no identifier. |
| Groq | Backup AI provider, used when Google is unavailable | The same content, on the same terms. |
| everyayah.com | Supplies the Qur’an recitation audio | An IP address, when a student plays a verse. |
Google Fonts was removed on 6 September 2026. Every page used to fetch its
typefaces from fonts.googleapis.com, which handed Google an IP address on every
page load of a children’s service. The fonts are now served from this site. The only
remaining third-party request a browser makes is the recitation audio, and only when a
student presses play.
Children’s privacy (COPPA and FERPA)
This platform is built for children, so the following are commitments rather than boilerplate.
- We collect from a child only what the platform needs to teach them. Section 4 lists what we deliberately do without.
- We do not condition a child’s participation on giving us more than is reasonably necessary.
- We do not use a child’s data for advertising, for behavioural profiling, or to build any commercial audience.
- We do not knowingly allow a child to make their information public. There is no chat between students, no public profile and no user-to-user messaging.
- A parent may review what we hold about their child, ask us to correct it, and ask us to delete it — and may refuse further collection while keeping what has already been taught. Section 11 says how.
Where the school is the FERPA record-holder, requests to inspect or amend an education record are handled by the school, and we support the school in answering them.
Your rights, and how to use them
Whatever jurisdiction you are in, you may ask us to:
- See what we hold about your child;
- Correct anything wrong;
- Delete the account and everything attached to it;
- Export it in a portable form;
- Stop a particular use, or object to it;
- Complain to a regulator — in the UK the Information Commissioner’s Office, in the EU your national supervisory authority, in the US your state Attorney General.
Ask your child’s teacher, or write to info@gen3academy.org. We will respond within 30 days. We will never charge for a first request, and we will never make you give a reason.
Today these requests are handled by hand: a teacher performs the deletion, and an export is assembled manually. There is no self-service button in the portal yet, and the audit log that records who read a child’s conversations has no route that would let us show it to you. Both are on the fix list. Until they exist, the commitment above is a human promise rather than a product feature, and you should hold us to it in writing.
How it is protected
- The whole site is served over HTTPS only.
- Passwords are stored as salted hashes, never in a form we could read.
- The session cookie is HttpOnly and Secure, so no script on the page can read it and it never travels unencrypted.
- Repeated failed sign-ins are rate-limited and briefly locked out.
- A Content Security Policy blocks third-party scripts, framing and any network call to a host not on a short fixed list. Adding a tracker would visibly break the page rather than quietly work.
- A teacher can only reach students in their own class; only the head teacher sees the whole academy.
- Every staff read of a child’s conversations is written to an audit log.
No system is perfectly secure. If we discover a breach affecting personal data, we will tell the school and affected families without undue delay, and notify regulators where the law requires it.
Where the data lives
Data is stored on Cloudflare’s network, and Cloudflare’s D1 database, which may place data in the United States or in other countries where Cloudflare operates. The AI providers process requests in the United States.
If we serve families in the UK or the EU, transfers out of those regions need an approved mechanism — Standard Contractual Clauses, or the UK Addendum, plus a transfer risk assessment. Those are not in place yet. Section 16.
Changes to this policy
If we change what we collect, how long we keep it, or who can see it, we will change the date at the top and tell the school before the change takes effect, asking them to pass it on to families. For a change that materially reduces protection for a child, we will seek fresh consent rather than rely on a quiet update.
Previous versions are kept, and we will supply one on request.
Contact
Privacy questions, or a request to see, correct, export or delete data:
- Email info@gen3academy.org
- Or speak to your child’s teacher, who can act immediately
Postal address: [REGISTERED ADDRESS — to be completed].
Open questions
Published rather than hidden, because a policy that quietly overstates its own readiness is worse than one that admits what is missing. Each of these must be closed before this document stops being a draft.
- The legal entity, its type, its formation state and its registered address.
- A lawyer’s review of this policy, the Terms, and the Family Agreement.
- A signed data processing agreement with Google and with Groq covering student data, including a commitment not to train on it.
- A written agreement with each school setting out that we act under its direction, and naming who at the school answers data requests.
- Whether any family will be in the UK, the EU or Canada — which would add a Data Protection Impact Assessment, an Article 30 record, transfer safeguards, and possibly a representative and a Data Protection Officer.
- A family-facing route to export and delete data, rather than a manual one.
- A route that lets a school read the audit log it is meant to hold us to.
- What happens to accounts at the end of a school year.