Privacy Policy

Last updated: March 8, 2026

MathBuddi ("we," "us," or "our") operates the MathBuddi platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. We are committed to protecting the privacy of all our users, especially children.

1. Information We Collect

We collect the following types of information:

Account Information

  • Parent accounts: First name, last name, email address, and password (stored securely using bcrypt hashing)
  • Child accounts: First name, last name, email address (for login purposes), password, and current grade level

Math Performance Data

  • Diagnostic test results and diagnosed grade level
  • Daily practice session data: questions answered, correct/incorrect responses, topics covered, and session duration
  • Progress metrics: accuracy rates, streaks, experience points, and level progression

Usage Data

  • Session timestamps and frequency of use
  • Feature interactions (e.g., report views, settings changes)
  • Device type and browser information (via standard HTTP headers)

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Generate appropriate math questions, track progress, adapt difficulty, and maintain your account
  • Generate Progress Reports: Create AI-powered analysis of student performance for parents, identifying strengths, weaknesses, and recommended focus areas
  • Improve Our Algorithms: Analyze aggregate performance data to improve question generation, difficulty calibration, and diagnostic accuracy
  • Communicate With You: Send progress report emails (at the frequency you choose), billing notifications, and important service updates
  • Process Payments: Manage your subscription and billing through our payment processor

3. Children's Privacy

We take children's privacy very seriously. Our practices regarding children's data are guided by principles consistent with COPPA (Children's Online Privacy Protection Act):

  • Parental Consent: Child accounts can only be created by a parent or guardian through their parent account. By creating a child account, the parent consents to the collection of their child's data as described in this policy.
  • Minimal Data Collection: We collect only the information necessary to provide the tutoring service — name, login credentials, and math performance data.
  • No Selling of Children's Data: We will never sell, rent, or share children's personal information or performance data with third parties for marketing or advertising purposes.
  • Parent Controls: Parents can view all data collected about their child, control report visibility settings, configure session parameters, and delete their child's account and all associated data at any time.
  • No Behavioral Advertising: We do not display ads to children or use their data for targeted advertising of any kind.

4. AI Usage

MathBuddi's analysis and reporting systems were designed with the help of AI technology:

  • AI-Designed Analysis: Our progress reports, speed analysis, and 2×2 diagnosis system were designed by AI and run automatically within the app. No student data is sent to external AI services during normal use.
  • Not Used for Questions: All math questions are generated procedurally using mathematical algorithms — not by AI. This ensures accuracy, consistency, and zero per-question cost.
  • Data Stays Local: All performance analysis runs on our servers using algorithms designed by AI. Your child's data is never sent to third-party AI services.

5. Data Storage and Security

We take reasonable measures to protect your information:

  • Passwords are hashed using bcrypt and are never stored in plain text
  • All data is transmitted over HTTPS (TLS encryption)
  • Our database is hosted on secure, managed infrastructure with access controls and regular backups
  • Authentication uses secure JWT tokens with appropriate expiration

While we implement commercially reasonable security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Third-Party Services

We use the following third-party services to operate MathBuddi:

  • Stripe — for payment processing. Stripe handles all credit card information directly; we never see or store your full card number. Stripe's privacy practices are governed by their own Privacy Policy.
  • Resend — for sending transactional emails such as progress reports and billing notifications. We share only your email address and email content with Resend for delivery purposes.
  • AI Technology — our analysis algorithms were designed with AI assistance. No student data is sent to external AI services during normal operation.

We do not sell or share your data with any other third parties. We do not use any analytics, advertising, or tracking services.

7. Data Retention and Deletion

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

  • Active Accounts: All data is retained while your subscription is active.
  • Cancelled Subscriptions: We retain your data for 90 days after cancellation, in case you choose to resubscribe. After 90 days, your data may be permanently deleted.
  • Account Deletion: When a parent deletes a child's account or requests deletion of their own account, we permanently remove all associated personal data and performance records within 30 days.
  • Anonymized Data: We may retain anonymized, aggregated data (which cannot identify any individual) for research and product improvement purposes.

8. Cookies

MathBuddi uses only essential cookies required for the Service to function:

  • Session Cookies: Used to maintain your authenticated session after login. These are strictly necessary and cannot be disabled.

We do not use analytics cookies, advertising cookies, or any third-party tracking cookies. We do not participate in any cross-site tracking.

9. Parent Rights

As a parent or guardian, you have the right to:

  • View: Access all data collected about your child through the Parent Dashboard and progress reports
  • Control: Configure your child's session settings, report visibility, and focus topics
  • Download: Request a copy of your child's data by contacting us at support@mathbuddi.com
  • Delete: Remove your child's account and all associated data at any time through the Settings page, or by contacting us
  • Revoke Consent: Withdraw consent for your child's data collection at any time by deleting their account

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service at least 30 days before the changes take effect. The "Last updated" date at the top of this page indicates when this policy was last revised. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

11. Contact Us

If you have any questions about this Privacy Policy, want to exercise your data rights, or have concerns about how we handle your information, please contact us at support@mathbuddi.com.