Skip to content
Aivo Learning
Compliance

AIVO COPPA Compliance Notice (Children's Privacy)

Version: 2.1 · Last updated: August 15, 2026

Back to home
On this page

Aivo AI Learning Technologies Inc. ("AIVO," "we," "us") operates an AI‑powered adaptive learning platform used by children, including children under 13. This Notice explains, in detail, how we comply with the Children's Online Privacy Protection Act of 1998 and the FTC's COPPA Rule, 16 CFR Part 312, including the amendments adopted in 2025, and how parents and schools exercise their rights.

This Notice supplements our Privacy Policy and works alongside our FERPA Compliance Notice. Where this Notice is more protective of children, it controls.


1. Operator and Contact Information

The operator that collects and maintains children's personal information through the Services is:

Aivo AI Learning Technologies Inc. 1400 Van Buren Street NE, Suite 200, Minneapolis, MN 55413, USA Children's‑privacy contact: [email protected]

Any third party that collects personal information directly from children through our Services (for example, a sub‑processor that powers a feature) is identified, by category and name, in our Trust Center sub‑processor list. You may request the names and contact information of all operators at any time.


2. Summary of Our Commitments for Children

  • We collect only the information reasonably necessary for a child to participate, and we do not condition participation on disclosing more than is necessary.
  • We obtain verifiable parental consent (or valid school authorization) before collecting personal information from a child under 13.
  • We never sell or rent children's personal information.
  • We never show third‑party advertising to children and never allow third‑party behavioral‑tracking technologies on child‑directed surfaces.
  • We never use children's personal information to train third‑party AI foundation models.
  • We obtain separate verifiable parental consent before disclosing a child's personal information to third parties for purposes that are not integral to the Services (where such disclosure occurs), consistent with the amended Rule.
  • We give parents and schools the ability to review, correct, delete, and stop further collection of a child's information at any time.
  • We maintain a written data‑retention policy and a written information‑security program for children's data, and we delete children's data when it is no longer needed for the purpose collected.

3. Personal Information We Collect From Children

We collect only what is reasonably necessary to operate the Services for the child:

Data elementWhy we collect it
Username or first nameIdentify the learner within the account
Age band (precise birth date avoided where feasible)Provide age‑appropriate content and apply protections
Parent contact email (family accounts) or school identifier (school accounts)Provide direct notice / obtain consent; link to the responsible adult/school
Authentication credentials (hashed)Secure sign‑in
Learning activity — assessments, lessons attempted, answers, hints, AI‑tutor interactionsDeliver and adapt the learning experience
Virtual Brain session dataPersonalize difficulty, pacing, modality, and sensory presentation for the child
Limited device/log data (app version, device identifier, error logs)Operate and secure the Services (internal operations)

We do not require a child to disclose more than is reasonably necessary to participate, and we do not ask children to provide contact information beyond what is necessary, or to disclose more than is needed to use a feature.


4. How We Use Children's Information

We use children's personal information only to:

  1. provide and personalize the learning experience (including building and updating the child's Virtual Brain and operating the AI tutors);
  2. make the child's progress available to the authorized parent and, for school accounts, to authorized School Personnel and invited collaborators;
  3. maintain the security and integrity of the Services and detect/prevent abuse; and
  4. comply with our legal obligations.

We do not use children's personal information for behavioral advertising, to build non‑educational profiles, or to train third‑party foundation models.


5. Direct Notice to Parents

For family accounts, before collecting personal information from a child under 13, we provide a direct notice to the parent that includes: (a) that we collected the parent's online contact information to provide notice and obtain consent; (b) the categories of personal information we seek to collect from the child and how it will be used; (c) that the child's participation cannot be conditioned on collecting more than is reasonably necessary; (d) that the parent's consent is required before collection; (e) how the parent can provide consent; (f) the parties (or categories) to whom information may be disclosed; and (g) how the parent can later review, delete, or refuse further collection. If we do not obtain consent within a reasonable time, we delete the parent's contact information.


6. Verifiable Parental Consent (Family Accounts)

Before collecting personal information from a child under 13 through a family account, we obtain verifiable parental consent using a method reasonably designed to ensure that the person providing consent is the child's parent. Depending on the context, we use one or more FTC‑recognized methods, which may include:

  • a consent form signed by the parent and returned electronically;
  • requiring a transaction (such as a payment‑card transaction with confirmation) that provides notice of the charge;
  • a toll‑free telephone or video‑conference confirmation with trained personnel;
  • a knowledge‑based authentication challenge; or
  • another method the FTC recognizes as reasonably designed to verify parental identity.

We will update our accepted methods as technology and FTC guidance evolve. We collect a parent's contact information solely to provide notice and obtain consent and, if consent is not obtained within a reasonable time, we delete it.


7. School Authorization (School Accounts)

When AIVO is used through a school or district, we rely on the school‑authorization exception recognized under COPPA: the school may provide consent on behalf of parents for the collection of students' personal information for the use and benefit of the school and for no other commercial purpose. In that context:

  • the school is responsible for providing required parental notice;
  • AIVO acts as the school's service provider under its direction;
  • AIVO uses student information only to provide the educational service to the school; and
  • AIVO does not use student information for any commercial purpose unrelated to providing the Services.

See the FERPA Compliance Notice for details on roles and rights in the school context.


8. The "Support for Internal Operations" Exception

On child‑directed surfaces we use persistent identifiers (and only Strictly Necessary cookies) where reasonably necessary to support the internal operations of the Services — such as authentication, security, maintaining the integrity of the Services, and personalizing the learner's experience for that learner — and not to contact a specific individual (including behavioral advertising), to amass a profile for non‑educational purposes, or for any other prohibited use.


9. Parental Rights and How to Exercise Them

If your child uses AIVO through a family account, you have the right to:

  • review the personal information we have collected from your child;
  • correct inaccurate information;
  • direct us to delete your child's personal information;
  • refuse to permit further collection or use of your child's information; and
  • revoke consent at any time.

How to exercise. Write to [email protected] stating the right you wish to exercise and the child/learner involved. We will verify that you are the child's parent before granting access to, or acting on, the child's information, using account information and, where appropriate, an additional verification step. We aim to respond promptly and, in any event, within the timeframe required by applicable law.

Effect. If you revoke consent or ask us to delete information, we will stop collecting information from the child going forward and delete the information we hold, which may mean the child can no longer use some or all of the Services. We will confirm completion of a deletion request.

If your child uses AIVO through a school, requests to review, correct, or delete student information are generally directed to the school (which controls the education record), and AIVO will assist the school.


10. Disclosure of Children's Information and Third Parties

We disclose children's personal information only:

  • to service providers / sub‑processors that perform functions on our behalf (such as cloud hosting, error monitoring, and AI model providers) under written contracts that limit their use to providing services to us and that require confidentiality and security (AI model providers are contractually prohibited from using children's inputs/outputs to train or improve public foundation models);
  • to the parent (family accounts) or the school and authorized collaborators (school accounts) associated with the child;
  • as required by law or to protect the safety of a child or the public.

We do not permit third parties to collect children's personal information through our child‑directed surfaces for their own purposes. The categories and names of our sub‑processors are listed in the Trust Center.


11. Separate Consent for Non‑Integral Third‑Party Disclosure

Consistent with the amended COPPA Rule, where we would disclose a child's personal information to a third party for a purpose that is not integral to providing the Services (for example, a disclosure that is optional rather than necessary to operate the learning experience), we will obtain separate verifiable parental consent for that disclosure, and we will not condition the child's participation on agreeing to such optional disclosure. We do not engage in third‑party advertising disclosures of children's data.


12. Data Retention and Deletion

We retain children's personal information only as long as reasonably necessary to provide the Services and fulfill the purpose for which it was collected, after which we delete or de‑identify it, consistent with our written retention policy. We delete a child's personal information promptly upon a verified parental deletion request, upon a school's instruction, or when an account is closed, subject to any legal‑hold requirements. We do not retain children's information indefinitely, and we do not retain it for secondary purposes.


13. Security Program for Children's Data

We maintain a written information‑security program and protect children's personal information with administrative, technical, and physical safeguards appropriate to its sensitivity, including encryption in transit and encrypted storage for uploaded documents, access controls and least‑privilege access, multi‑factor authentication for administrative access, monitoring, vendor due diligence, and incident response. For more detail, see the Security page.


14. Assistive Input and Biometric Identifiers

Where a child uses assistive input — AAC devices, switch access, or eye‑gaze/eye‑tracking — AIVO uses the resulting signals only to operate the interface for that child. We do not use these signals to create a biometric identifier, for advertising, or for any purpose other than running the Services. If any feature would collect a biometric identifier as defined by applicable law, we would provide the required notice and obtain the additional consent the law requires before doing so.


15. No Targeted Advertising; No Model Training on Children's Data

We do not deliver targeted or behavioral advertising to children, do not allow third‑party advertising or tracking technologies on child‑directed surfaces, do not build non‑educational profiles of children, and do not use children's personal information to train third‑party AI foundation models. Our AI model providers are contractually barred from training or improving their public models on our learners' data.


16. Changes to This Notice

If we make material changes to our practices regarding children's personal information, we will notify parents (and, where applicable, schools) and obtain new consent where COPPA requires before applying those changes to previously collected information. The "Last updated" date indicates the latest revision.


17. More Information and Contact

To learn more about COPPA and children's privacy, see the FTC's resources for parents at the Federal Trade Commission's website. For questions about AIVO's children's‑privacy practices or to exercise a parental right:

[email protected] Aivo AI Learning Technologies Inc., 1400 Van Buren Street NE, Suite 200, Minneapolis, MN 55413, USA


# Annexes

Annex A — Verifiable Parental Consent Methods (Mechanics)

For family accounts, we select a method reasonably designed to ensure the person consenting is the child's parent, calibrated to how we use the child's information. Methods we may use include:

MethodHow it worksTypically used when
Signed consent form ("print‑and‑send" or e‑signature)Parent reviews the direct notice and signs electronically or returns a signed formGeneral collection for the learning experience
Monetary transaction with noticeA payment‑card transaction (e.g., starting a paid plan) that sends the parent a confirmation of the chargeWhen the account involves a verifiable payment method
Government‑ID check (delete after match)Parent submits a government‑issued ID checked against a database; the ID copy is promptly deleted after verificationHigher‑assurance verification
Knowledge‑based authenticationParent answers dynamic, multiple‑choice questions that are difficult for someone other than the parent to answerWhere supported and reliable
Video conference / trained personnelA live or recorded confirmation reviewed by trained staffAlternative high‑assurance path
Toll‑free verificationParent confirms via a monitored toll‑free numberAlternative path

We update accepted methods as the FTC recognizes new ones (for example, evolving knowledge‑based or facial‑match approaches). We collect a parent's contact information solely to give notice and obtain consent and delete it if consent is not completed within a reasonable time.

Annex B — Consent, Authorization, and Deletion Records

To demonstrate compliance, we maintain internal records sufficient to show:

RecordContentsPurpose
Parental consent recordMethod used, date/time, account/learner reference, scope of consentShow valid VPC before collection
School authorization recordSchool/district identifier, authorizing contact/role, date, scopeShow valid school‑authorization basis
Direct‑notice recordVersion of notice provided, delivery method, dateShow parents received required notice
Revocation / refusal recordRequest, verification performed, action taken, dateShow we stopped collection/use as requested
Deletion recordRequest, verification, data deleted, completion date, certification (school)Show timely deletion
Sub‑processor list versionOperators with access, categories, datesProvide on request; show who may access child data

Records are retained only as long as needed to evidence compliance and are protected under our information‑security program.

Annex C — What Is (and Isn't) Collected From Children, by Feature

FeatureCollected from the childNot collected
Sign‑inUsername/first name; hashed credentialsPersistent advertising identifiers
Adaptive lessonsResponses, hints, progressPrecise geolocation
AI tutorPrompt/response content for the sessionData used for third‑party model training
Virtual BrainLearning‑interaction signals for that learnerCross‑service behavioral profiles
Assistive input (eye‑gaze/switch/AAC)Operational input to run the interfaceBiometric identifier/template (unless separately noticed + consented)
App diagnosticsApp version, device identifier, error logs (internal operations)Marketing/behavioral tracking

Annex D — FTC Safe‑Harbor and Oversight

COPPA permits FTC‑approved safe‑harbor programs that certify operators' children's‑privacy practices. AIVO does not currently participate in an approved safe‑harbor program, and we will not claim safe‑harbor certification unless and until one completes. Regardless of safe‑harbor status, AIVO is directly responsible for COPPA compliance and welcomes questions at [email protected].

This page is provided for transparency and is not legal advice. Questions? Email [email protected] (privacy: [email protected]).