Version 2.0 (DRAFT) · Effective upon the compliance release · Last revised: July 3, 2026
Ollie ("the App," "we," "us") is an AI-powered educational tutor for children in grades K–6 (generally ages 5–12). We are committed to protecting children's privacy and to being accurate and honest about how the App works. This policy explains what data the App handles, who receives it, and the choices parents and guardians have.
Operator: [TBD — legal entity name], [TBD — postal address]. Contact: privacy@ollietutor.com.
"Ollie the Octopus" is an artificial-intelligence character, not a real person. Ollie's responses are generated by Google's Gemini AI models. Ollie can occasionally be wrong; it is a learning aid, not a substitute for a teacher or caregiver.
The App does not ask for or collect a child's name, email address, phone number, date of birth, postal address, photograph, or precise geolocation. No child account is created.
To provide tutoring, the App processes the following. Most stays on the device; some is necessarily sent to service providers to make the App work.
| Data | Where it lives | Leaves the device? |
|---|---|---|
| Grade band (K–6), difficulty & settings, exercise scores, streaks, badges, recent questions and spelled words | The device's local storage only | No |
| The words a child types or speaks to Ollie (the content of questions) | Processed live; not stored on our servers | Yes — sent to Google to generate a reply |
| Voice audio, when a child uses the live-voice microphone | Streamed live; not stored | Yes — the audio is sent to Google's Gemini Live service |
| Parent PIN | Stored on the device as a SHA-256 hash | No |
| Technical connection data (e.g., IP address) and app error reports | Transient | Yes — inherent to any internet request; see providers below |
| Parent email + account (when a parent verifies by email / creates a parent account) | Stored server-side (email + a login session + consent record) to run your account and any subscription | Yes — to our email provider, account store, and payment processor |
| Subscription status (if you subscribe) | Stored server-side (plan/status); card details are held by Stripe, not us | Yes — to/from Stripe |
Because voice audio and IP address can identify a device or person, we treat them as personal information even though we collect no name from the child. The parent account is optional and separate — the child never logs in. We describe all of this plainly rather than claim "nothing is transmitted."
We do not use advertising networks, ad targeting, analytics/tracking SDKs, or social-media integrations, and we do not sell or "share" (as defined by California law) personal information.
Before a child uses features that transmit data (including live voice), the App asks a parent or guardian to provide consent through an email-verification step: the parent enters an email address and confirms a one-time code we send to it. We store only a minimal record of that consent (a hashed email, a timestamp, and the policy version). Parents can revoke consent at any time (see below), which deletes the record.
We are continuing to evaluate, with counsel, whether additional verifiable-parental-consent measures are required for particular data (such as voice). This policy will be updated accordingly.
Verifying your email creates a parent account (only the parent — never the child). We store your email address, a login session token, and your consent record so you can sign in, manage settings, and — if you choose — subscribe. You can log out (ends the session) or delete your account and all data from the parent dashboard at any time.
If you subscribe to a paid plan, payment is handled by Stripe on its secure hosted pages; we store only your subscription status (plan and whether it is active), never card details. You can update or cancel your subscription through the billing portal we link to. Cancellation stops future charges; deleting your account does not automatically cancel an active subscription, so cancel first if you wish to stop billing.
Parents and guardians may, through the PIN-protected parent dashboard or by contacting us:
All network communication uses HTTPS. The parent dashboard is protected by a PIN stored as a SHA-256 hash (the plain-text PIN is never stored). We are hardening how the App connects to Google's live-voice service so that service credentials are not exposed to the device.
EU/EEA & UK (GDPR / UK-GDPR, and the UK Children's Code): the operator named above is the data controller. Our lawful bases are consent and our legitimate interest in providing a safe educational service; for children this is subject to parental consent. You have rights of access, rectification, erasure, restriction, portability, and objection, and may complain to your supervisory authority. Data is processed by providers in the United States; international transfers rely on the providers' transfer mechanisms (e.g., Standard Contractual Clauses / Data Privacy Framework). We design for data minimization and privacy-by-default consistent with the UK Children's Code.
California (CCPA/CPRA) & other US states: we do not sell or share personal information for cross-context behavioral advertising, and we do not use it for targeted advertising. California residents may request access to or deletion of personal information. We honor the design-code principles of the states that have enacted them (California, Maryland, Nebraska, Vermont, South Carolina).
Other countries: we apply these core protections globally. Residents of Canada, Brazil, Australia, and elsewhere may contact us to exercise applicable rights.
We will notify users of material changes in the App and update the version and date above.
Questions, requests, or concerns: privacy@ollietutor.com (and [TBD — postal address] once finalized).