Privacy policy
Version 2026-10 · Last updated: October 1, 2026
Draft: this text is being reviewed by a lawyer before the pilot and may change.
This policy explains what we collect about families on Kids Coding Platform, why, and what you can do about it. We collect as little as we can, and we never sell it.
What we collect
About parents: your email address, a name we use only in emails to you, your password (stored scrambled so nobody can read it), your country and language, and when you accepted these policies.
About children: the nickname, preset avatar and username the parent chooses, the password (stored scrambled), the year of birth (not the full date), the country, and, if the parent adds them, a region and city. We never ask children for their real name, photo, school or email.
What children do while learning: lessons finished, code written in challenges and projects, shipped projects, XP, levels and streaks.
Settings and choices: the parent's choices about public leaderboards and public projects, with the date each was made.
Payments: the plan you chose, and invoices and payments (amount, date, status). Card details go straight to our payment provider, Stripe: we never see or store them.
Certificates: the nickname, module and date on each certificate a child gets.
Messages: anything sent to us with the Feedback button, with the page it was sent from.
Team rooms: what children send in the rooms of their teams, classes and events (ready-made phrases, and from 13 typed messages), and reports about messages with what moderators did. Room messages are deleted after 90 days.
Hackathon teams: the team's name, who is in it (each child only with a parent's approval), and the team's work in a private repository on our own git server: files, commits (with the child's nickname as the author), pull requests, reviews, comments, what was handed in, and the judges' scores and rank.
Classes and schools: the classes a child joins (each only with a parent's approval), the lessons their teacher set and whether they were done. For schools with a licence: the school's name and city, a contact person's name and email for invoices, the licence and its payments.
The hub readiness check: the page a student builds in the timed check, when they started and handed it in, and the mentor's scores and comments.
Waitlist: if you join the waitlist on our website, your email address, country, language and your child's age range.
Security records: when someone signs in, and the internet address and browser used, so we can protect accounts and investigate problems.
Why we use it
- to run accounts, lessons, projects, XP and leaderboards;
- to send parents the emails the service needs (for example, confirming the email address, resetting a password or a payment receipt), and a monthly progress email that parents can switch off;
- to take payments for plans;
- to keep children safe and the service secure;
- to understand, with numbers that don't identify anyone, how the pilot is going and what to improve.
We don't show advertising, we don't use trackers or third-party analytics, and we don't build profiles of children for any other purpose.
Who can see it
- Other users only ever see a child's nickname, avatar and XP on public leaderboards, and their projects through a share link — each only if the parent switches it on. Shared projects open on a separate website address used only for children's code.
- Teammates in a hackathon see each other's nickname and avatar and the team's work. The team's repository is private: only the team, its mentor, the event's judges and our team can open it.
- A child's teacher (an adult our team added for their school, who signs in with two-factor codes) sees the nicknames and avatars in their class, progress on the lessons they set, and a weekly board of nicknames and XP. Classmates see that board too.
- Anyone with a certificate's code can check it: they see the nickname, the module and the date, nothing else.
- Our team: only the people who need it to run the service and keep it safe, and what they do is recorded.
- Service providers that host the site, store files, send emails and take card payments (Stripe) for us, only to do that job for us and under contract.
- Authorities, only when the law requires it.
The real-world hub (ages 15 and up)
Students of 15 and older can work on paid projects for real clients, only with a parent's agreement for each project. For this we also keep:
- the parent's agreement (to paid work and to receiving the earnings) and its version, the lead developer's sign-off, and the parent's approval of each project;
- the work: tasks, the time a student's timer ran (the platform limits the hours), code in the project's private repository, reviews and scores from the lead developer;
- money: what each student earned on each project, payouts to the parent, and our accounting records;
- the parent's payout account: the account holder's name and the IBAN (or other account details), stored encrypted. Only the last four characters are shown; staff look at the full details only to check them, and each look is recorded. Changes need the parent's password and can be paid only after 48 hours;
- clients: the business's name and country, and its people's names and emails, their project requests and files, messages with our team, and invoices.
Clients never see who a student is: they see "Developer A", "Developer B" and the work, never a nickname, name, age, country or photo, and they can't message students. Payouts go through our payout provider (Wise) or our bank, which receive the parent's name and account details and the amount, only to send the money. A short story about a student's hub work appears on our website only if a parent says yes (first name only), and the parent can take it back at any time. We keep earnings, payout and accounting records for as long as tax and accounting law requires, tied to an anonymous account if the family's account is deleted; payout account details are deleted when the parent's account is.
Cookies
We use only the cookies the site needs to work: one to keep you signed in and one to remember your language. No advertising or tracking cookies.
How long we keep it
We keep account information while the account is open. When a parent deletes a child's account, we remove the child's nickname, avatar, sign-in details, location, code, projects, certificates and messages straight away. We keep lesson progress and XP only as anonymous numbers. When a parent deletes their own account, the same happens for every child in it, and the parent's email, name and password are removed too. We keep invoices, payment records and records of parents' consent for as long as the law requires, tied to an anonymous account. Waitlist addresses that are never confirmed are deleted after 30 days. Security records are kept for a limited time and then deleted.
Your choices and rights
As a parent, you can at any time on your dashboard see and change your child's details and sharing choices, switch off the monthly email, download a copy of your family's information, and delete a child's account or your whole account. To correct something you can't change yourself, contact us and we will answer within 30 days. Depending on where you live, you may also have the right to complain to your data protection authority.
Keeping it safe
Passwords are stored scrambled, connections are encrypted, children's code runs in a separate sandbox, and staff accounts use two-step sign-in.
Changes and contact
If we change this policy in an important way, we will email parents before the change takes effect. Questions? Use the Feedback button once you're signed in, or reply to any email from us.