Legal
Privacy Policy
Last updated: 2026-06-05
What you should know up front
- We collect what we need to teach you better — voice, answers, mastery.
- We don't sell your data.
- Children under 13 use parent-owned accounts (COPPA).
- You can delete your data any time.
1. Information we collect
Account info. Name, email, grade band, date of birth (used for COPPA gating), language preference.
Learning activity. Voice recordings during sessions, typed chat messages, answers to practice problems, hint usage, mastery scores, attempt counts, time spent.
Device and connection. Browser, OS, IP address, session duration, error logs. Used to keep the service running and detect abuse.
Optional. Parent contact info (for child accounts).
1a. Sign in with Google / Apple
When you sign in with Google or Apple, we request the standard openid email profile scopes only. The provider returns a signed identity token that we verify against the provider's public keys.
What we extract from the Google id_token and persist:
email— your Google email address (used as your account identifier and login key).name— your Google profile name (stored as your display name; falls back to the email prefix if missing).locale— your Google language preference (defaults toenif absent).sub— Google's stable subject identifier for your account. We store it so future logins re-match to the same Aria account even if you change your email.
What we read but do NOT persist:
picture— your Google profile photo URL. The token includes it; we discard it before writing to our database. We do not display Google profile photos anywhere in the product today.
What we explicitly do NOT collect or request:
- Google access tokens or refresh tokens. The identity-token flow we use does not return them; we cannot call Google APIs on your behalf.
- Any scope beyond
openid email profile. Specifically: no access to your Gmail, Drive, Calendar, Contacts, YouTube, Photos, location, or browsing history.
Apple sign-in (when enabled): Same model. Apple's id_token includes sub, an optional email (or Apple Private Relay forwarding alias), and (on first login only) the name you choose to share. We persist the same five fields as for Google. We do not request or store any other Apple-account data.
You can disconnect Google or Apple sign-in from your account at any time via Settings. You can also revoke our access from the provider's side at myaccount.google.com/permissions or appleid.apple.com.
2. How we use it
- Teach better. Voice and answers feed Aria's adaptive engine — diagnosing misconceptions, choosing the next problem, tuning pacing.
- Track progress. Mastery and attempt history let you and your parent / teacher see how you're doing.
- Improve the product. Aggregate (de-identified) usage data informs which skills need better content or hints.
- Keep the service safe. Rate limits, abuse detection, account recovery.
3. What we don’t do
- We don't sell personal data.
- We don't use children's data to train AI models for unrelated commercial purposes.
- We don't show third-party advertising on child accounts.
4. Children under 13 (COPPA)
For learners under 13:
- A parent/guardian creates the account and provides verifiable consent.
- The child profile has no email, no password, and no public-facing identity.
- Parents can review activity, change settings, or delete the profile at any time from the parent dashboard.
- We don't share child data with third parties except service providers strictly necessary to deliver the Service (LLM providers, voice infrastructure, hosting), under data-processing agreements that forbid secondary use.
- If you believe a child has used the Service without parental consent, contact us — we'll delete the account.
5. How we share data
We share data only with:
- Service providers who run pieces of the platform (LLM APIs, voice infra, cloud hosting, analytics). They're contractually limited to using data only to provide their service.
- Parents and educators for accounts they own.
- Legal authorities when required by valid legal process. We push back on overbroad requests.
- In a corporate transaction (acquisition, merger). We'd notify you and your data would remain subject to the privacy commitments in this policy.
6. Your rights
Depending on your jurisdiction (GDPR, CCPA, India DPDP, etc.) you have the right to:
- Access the data we hold about you.
- Correct inaccuracies.
- Delete your account and data.
- Export your data in a portable format.
- Object to certain processing (e.g., analytics).
Contact us to exercise any of these.
7. Data retention
Voice recordings: 30 days unless you opt to keep them for longer review. Practice attempts and mastery: kept for the life of the account. Analytics: aggregated and de-identified after 90 days. Deleted accounts: removed within 30 days, with backups expiring within 90.
8. Security
We use TLS in transit, encryption at rest, role-based access controls, and audit logging. No system is perfectly secure; we'll notify affected users promptly of any breach as required by law.
9. International transfers
We're an India-first product but use cloud infrastructure that may process data outside your country. We rely on standard contractual clauses or equivalent safeguards for cross-border transfers.
10. Changes to this policy
We'll post material changes here and notify users at least 7 days before they take effect.
11. Contact
Privacy questions, data requests, parental concerns: Contact us.