1. Parent-first by design
A child cannot open an account, and a child's data is never collected before a parent is in control. The flow is deliberate:
- A parent creates the account and verifies that they are a parent.
- Only then can the parent add child profiles — using a nickname and avatar, not a full legal identity.
- The parent owns every profile and can view, manage, or delete it at any time.
- Children sign in with a private username and passcode the parent sets, or are handed off from the parent's device — they never need an email or password of their own.
2. Verifiable parental consent
Before any child profile is active, we capture and record a verifiable consent step by the parent. We keep an auditable record of that consent, and a parent can withdraw it at any time, which removes the child's profile and data.
3. Data minimisation
We collect the least we can to run lessons. For a child that means a nickname, an avatar, a date of birth (used only to confirm the profile is a minor), and their learning records. We do not ask children for contact details, and children are never shown pricing or payment screens.
4. No advertising, no tracking, no profiling
- No advertising is shown anywhere on the platform.
- We do not use third-party advertising or cross-site tracking cookies.
- We do not build marketing profiles of children.
5. Controlled data sharing
Any transfer of a child's personal data to a service provider passes through a single controlled point in our system, so a child's data is only ever shared where a parent has consented and only with the vetted providers listed in our Privacy Policy.
6. Technical protections
- Access to a child's records is restricted at the database level to that child's parent.
- Passcodes are stored only as cryptographic hashes; repeated login attempts are rate-limited.
- Deleting a parent account triggers a cascading erasure of the children's personal data.
- Teachers may share learning materials only from the platform's own library — external links are not permitted in sessions with children.
7. How we align with the law
COPPA (United States)
For children under 13, we obtain verifiable parental consent before collecting personal information, collect only what a lesson needs, and give parents the ability to review and delete their child's data.
GDPR-K (European Union / UK)
We treat children's data as a special case: consent is given and controlled by the parent, data is minimised, and the right to erasure is honoured in full.
DPDPA (India)
For minors, we obtain verifiable parental consent, avoid processing that could harm a child, and do not use children's data for behavioural monitoring or targeted advertising.
8. Reporting a concern
If you believe a child is at risk or you have a safeguarding concern, contact us immediately at safety@buzzlessons.com. We review safeguarding reports as a priority and will act, including suspending accounts where necessary.
9. Parental controls at a glance
- See and manage every one of your children's profiles.
- Approve or decline any request for lesson credits.
- Withdraw consent and delete a profile at any time.
- Request access to, or erasure of, your child's data by emailing privacy@buzzlessons.com.