How we protect children
This page exists so that a data protection officer and a parent can read the same thing and both come away reassured, for different reasons.
Accounts
No student creates an AI account. Not in any age band, not at school and not at home: the request goes out from our server with our key. The major AI tools require users to be 18, so this isn't a preference of ours — it's the only configuration that is lawful and that also scales to a class of 25.
With one exception, and we say it inside the sentence rather than in a footnote: in the 15+ band, if the school wants professional tooling, the school provisions the account with a school email address and parental consent. The student never creates it.
Data
- We collect no name, surname, email, photograph or date of birth from any student.
- Each child works under an alias they choose themselves.
- What we keep for 90 days are their instructions under that alias, so an adult can check that nothing inappropriate appeared. Deleted sooner on request.
- Their projects are theirs: before we delete anything, we offer to export them.
Supervision
The adult sees live what each child writes and what the AI answers. There is a filter before the model is called and one after, which also inspects the generated code to block calls to external domains, data-submitting forms and third-party scripts. And there is a written procedure for when something gets through anyway, because sometimes it will.
Transparency
Every child is told, in their own language, that they are talking to a machine and that it sometimes gets things wrong. This satisfies Article 50 of the EU AI Act and, more importantly, it is the foundation of the critical thinking we're after.
And what isn't in place yet
We are finalising the data processing agreement with our AI provider, the documented basis for international transfers, and civil liability cover. We say so here because a school will ask, and we would rather they read it before asking.