Aivo AI Learning Technologies Inc. ("AIVO," "we," "us") operates an AI‑powered adaptive learning platform used by children, including children under 13. This Notice explains, in detail, how we comply with the Children's Online Privacy Protection Act of 1998 and the FTC's COPPA Rule, 16 CFR Part 312, including the amendments adopted in 2025, and how parents and schools exercise their rights.
This Notice supplements our Privacy Policy and works alongside our FERPA Compliance Notice. Where this Notice is more protective of children, it controls.
1. Operator and Contact Information
The operator that collects and maintains children's personal information through the Services is:
Aivo AI Learning Technologies Inc. 1400 Van Buren Street NE, Suite 200, Minneapolis, MN 55413, USA Children's‑privacy contact: [email protected]
Any third party that collects personal information directly from children through our Services (for example, a sub‑processor that powers a feature) is identified, by category and name, in our Trust Center sub‑processor list. You may request the names and contact information of all operators at any time.
2. Summary of Our Commitments for Children
- We collect only the information reasonably necessary for a child to participate, and we do not condition participation on disclosing more than is necessary.
- We obtain verifiable parental consent (or valid school authorization) before collecting personal information from a child under 13.
- We never sell or rent children's personal information.
- We never show third‑party advertising to children and never allow third‑party behavioral‑tracking technologies on child‑directed surfaces.
- We never use children's personal information to train third‑party AI foundation models.
- We obtain separate verifiable parental consent before disclosing a child's personal information to third parties for purposes that are not integral to the Services (where such disclosure occurs), consistent with the amended Rule.
- We give parents and schools the ability to review, correct, delete, and stop further collection of a child's information at any time.
- We maintain a written data‑retention policy and a written information‑security program for children's data, and we delete children's data when it is no longer needed for the purpose collected.
3. Personal Information We Collect From Children
We collect only what is reasonably necessary to operate the Services for the child:
| Data element | Why we collect it |
|---|---|
| Username or first name | Identify the learner within the account |
| Age band (precise birth date avoided where feasible) | Provide age‑appropriate content and apply protections |
| Parent contact email (family accounts) or school identifier (school accounts) | Provide direct notice / obtain consent; link to the responsible adult/school |
| Authentication credentials (hashed) | Secure sign‑in |
| Learning activity — assessments, lessons attempted, answers, hints, AI‑tutor interactions | Deliver and adapt the learning experience |
| Virtual Brain session data | Personalize difficulty, pacing, modality, and sensory presentation for the child |
| Limited device/log data (app version, device identifier, error logs) | Operate and secure the Services (internal operations) |
We do not require a child to disclose more than is reasonably necessary to participate, and we do not ask children to provide contact information beyond what is necessary, or to disclose more than is needed to use a feature.
4. How We Use Children's Information
We use children's personal information only to:
- provide and personalize the learning experience (including building and updating the child's Virtual Brain and operating the AI tutors);
- make the child's progress available to the authorized parent and, for school accounts, to authorized School Personnel and invited collaborators;
- maintain the security and integrity of the Services and detect/prevent abuse; and
- comply with our legal obligations.
We do not use children's personal information for behavioral advertising, to build non‑educational profiles, or to train third‑party foundation models.
5. Direct Notice to Parents
For family accounts, before collecting personal information from a child under 13, we provide a direct notice to the parent that includes: (a) that we collected the parent's online contact information to provide notice and obtain consent; (b) the categories of personal information we seek to collect from the child and how it will be used; (c) that the child's participation cannot be conditioned on collecting more than is reasonably necessary; (d) that the parent's consent is required before collection; (e) how the parent can provide consent; (f) the parties (or categories) to whom information may be disclosed; and (g) how the parent can later review, delete, or refuse further collection. If we do not obtain consent within a reasonable time, we delete the parent's contact information.
6. Verifiable Parental Consent (Family Accounts)
Before collecting personal information from a child under 13 through a family account, we obtain verifiable parental consent using a method reasonably designed to ensure that the person providing consent is the child's parent. Depending on the context, we use one or more FTC‑recognized methods, which may include:
- a consent form signed by the parent and returned electronically;
- requiring a transaction (such as a payment‑card transaction with confirmation) that provides notice of the charge;
- a toll‑free telephone or video‑conference confirmation with trained personnel;
- a knowledge‑based authentication challenge; or
- another method the FTC recognizes as reasonably designed to verify parental identity.
We will update our accepted methods as technology and FTC guidance evolve. We collect a parent's contact information solely to provide notice and obtain consent and, if consent is not obtained within a reasonable time, we delete it.
7. School Authorization (School Accounts)
When AIVO is used through a school or district, we rely on the school‑authorization exception recognized under COPPA: the school may provide consent on behalf of parents for the collection of students' personal information for the use and benefit of the school and for no other commercial purpose. In that context:
- the school is responsible for providing required parental notice;
- AIVO acts as the school's service provider under its direction;
- AIVO uses student information only to provide the educational service to the school; and
- AIVO does not use student information for any commercial purpose unrelated to providing the Services.
See the FERPA Compliance Notice for details on roles and rights in the school context.
8. The "Support for Internal Operations" Exception
On child‑directed surfaces we use persistent identifiers (and only Strictly Necessary cookies) where reasonably necessary to support the internal operations of the Services — such as authentication, security, maintaining the integrity of the Services, and personalizing the learner's experience for that learner — and not to contact a specific individual (including behavioral advertising), to amass a profile for non‑educational purposes, or for any other prohibited use.
9. Parental Rights and How to Exercise Them
If your child uses AIVO through a family account, you have the right to:
- review the personal information we have collected from your child;
- correct inaccurate information;
- direct us to delete your child's personal information;
- refuse to permit further collection or use of your child's information; and
- revoke consent at any time.
How to exercise. Write to [email protected] stating the right you wish to exercise and the child/learner involved. We will verify that you are the child's parent before granting access to, or acting on, the child's information, using account information and, where appropriate, an additional verification step. We aim to respond promptly and, in any event, within the timeframe required by applicable law.
Effect. If you revoke consent or ask us to delete information, we will stop collecting information from the child going forward and delete the information we hold, which may mean the child can no longer use some or all of the Services. We will confirm completion of a deletion request.
If your child uses AIVO through a school, requests to review, correct, or delete student information are generally directed to the school (which controls the education record), and AIVO will assist the school.
10. Disclosure of Children's Information and Third Parties
We disclose children's personal information only:
- to service providers / sub‑processors that perform functions on our behalf (such as cloud hosting, error monitoring, and AI model providers) under written contracts that limit their use to providing services to us and that require confidentiality and security (AI model providers are contractually prohibited from using children's inputs/outputs to train or improve public foundation models);
- to the parent (family accounts) or the school and authorized collaborators (school accounts) associated with the child;
- as required by law or to protect the safety of a child or the public.
We do not permit third parties to collect children's personal information through our child‑directed surfaces for their own purposes. The categories and names of our sub‑processors are listed in the Trust Center.
11. Separate Consent for Non‑Integral Third‑Party Disclosure
Consistent with the amended COPPA Rule, where we would disclose a child's personal information to a third party for a purpose that is not integral to providing the Services (for example, a disclosure that is optional rather than necessary to operate the learning experience), we will obtain separate verifiable parental consent for that disclosure, and we will not condition the child's participation on agreeing to such optional disclosure. We do not engage in third‑party advertising disclosures of children's data.
12. Data Retention and Deletion
We retain children's personal information only as long as reasonably necessary to provide the Services and fulfill the purpose for which it was collected, after which we delete or de‑identify it, consistent with our written retention policy. We delete a child's personal information promptly upon a verified parental deletion request, upon a school's instruction, or when an account is closed, subject to any legal‑hold requirements. We do not retain children's information indefinitely, and we do not retain it for secondary purposes.
13. Security Program for Children's Data
We maintain a written information‑security program and protect children's personal information with administrative, technical, and physical safeguards appropriate to its sensitivity, including encryption in transit and encrypted storage for uploaded documents, access controls and least‑privilege access, multi‑factor authentication for administrative access, monitoring, vendor due diligence, and incident response. For more detail, see the Security page.
14. Assistive Input and Biometric Identifiers
Where a child uses assistive input — AAC devices, switch access, or eye‑gaze/eye‑tracking — AIVO uses the resulting signals only to operate the interface for that child. We do not use these signals to create a biometric identifier, for advertising, or for any purpose other than running the Services. If any feature would collect a biometric identifier as defined by applicable law, we would provide the required notice and obtain the additional consent the law requires before doing so.
15. No Targeted Advertising; No Model Training on Children's Data
We do not deliver targeted or behavioral advertising to children, do not allow third‑party advertising or tracking technologies on child‑directed surfaces, do not build non‑educational profiles of children, and do not use children's personal information to train third‑party AI foundation models. Our AI model providers are contractually barred from training or improving their public models on our learners' data.
16. Changes to This Notice
If we make material changes to our practices regarding children's personal information, we will notify parents (and, where applicable, schools) and obtain new consent where COPPA requires before applying those changes to previously collected information. The "Last updated" date indicates the latest revision.
17. More Information and Contact
To learn more about COPPA and children's privacy, see the FTC's resources for parents at the Federal Trade Commission's website. For questions about AIVO's children's‑privacy practices or to exercise a parental right:
[email protected] Aivo AI Learning Technologies Inc., 1400 Van Buren Street NE, Suite 200, Minneapolis, MN 55413, USA
# Annexes
Annex A — Verifiable Parental Consent Methods (Mechanics)
For family accounts, we select a method reasonably designed to ensure the person consenting is the child's parent, calibrated to how we use the child's information. Methods we may use include:
| Method | How it works | Typically used when |
|---|---|---|
| Signed consent form ("print‑and‑send" or e‑signature) | Parent reviews the direct notice and signs electronically or returns a signed form | General collection for the learning experience |
| Monetary transaction with notice | A payment‑card transaction (e.g., starting a paid plan) that sends the parent a confirmation of the charge | When the account involves a verifiable payment method |
| Government‑ID check (delete after match) | Parent submits a government‑issued ID checked against a database; the ID copy is promptly deleted after verification | Higher‑assurance verification |
| Knowledge‑based authentication | Parent answers dynamic, multiple‑choice questions that are difficult for someone other than the parent to answer | Where supported and reliable |
| Video conference / trained personnel | A live or recorded confirmation reviewed by trained staff | Alternative high‑assurance path |
| Toll‑free verification | Parent confirms via a monitored toll‑free number | Alternative path |
We update accepted methods as the FTC recognizes new ones (for example, evolving knowledge‑based or facial‑match approaches). We collect a parent's contact information solely to give notice and obtain consent and delete it if consent is not completed within a reasonable time.
Annex B — Consent, Authorization, and Deletion Records
To demonstrate compliance, we maintain internal records sufficient to show:
| Record | Contents | Purpose |
|---|---|---|
| Parental consent record | Method used, date/time, account/learner reference, scope of consent | Show valid VPC before collection |
| School authorization record | School/district identifier, authorizing contact/role, date, scope | Show valid school‑authorization basis |
| Direct‑notice record | Version of notice provided, delivery method, date | Show parents received required notice |
| Revocation / refusal record | Request, verification performed, action taken, date | Show we stopped collection/use as requested |
| Deletion record | Request, verification, data deleted, completion date, certification (school) | Show timely deletion |
| Sub‑processor list version | Operators with access, categories, dates | Provide on request; show who may access child data |
Records are retained only as long as needed to evidence compliance and are protected under our information‑security program.
Annex C — What Is (and Isn't) Collected From Children, by Feature
| Feature | Collected from the child | Not collected |
|---|---|---|
| Sign‑in | Username/first name; hashed credentials | Persistent advertising identifiers |
| Adaptive lessons | Responses, hints, progress | Precise geolocation |
| AI tutor | Prompt/response content for the session | Data used for third‑party model training |
| Virtual Brain | Learning‑interaction signals for that learner | Cross‑service behavioral profiles |
| Assistive input (eye‑gaze/switch/AAC) | Operational input to run the interface | Biometric identifier/template (unless separately noticed + consented) |
| App diagnostics | App version, device identifier, error logs (internal operations) | Marketing/behavioral tracking |
Annex D — FTC Safe‑Harbor and Oversight
COPPA permits FTC‑approved safe‑harbor programs that certify operators' children's‑privacy practices. AIVO does not currently participate in an approved safe‑harbor program, and we will not claim safe‑harbor certification unless and until one completes. Regardless of safe‑harbor status, AIVO is directly responsible for COPPA compliance and welcomes questions at [email protected].