elysianminds

Privacy Policy

Last Updated: August 12, 2026

1. Introduction

Welcome to Elysian Minds Innovations Limited ("Elysian Minds," "we," "us," "our," or the "Company"). We are committed to protecting the privacy of our users, especially the children who use our educational platform.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational platform designed for children aged 7-12. We operate on a parent-child model where parents (guardians) create and manage accounts for their children (students).

Please read this Privacy Policy carefully. By using our Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Parent/Guardian Account Information

When a parent or guardian creates an account, we collect the following information:

Data TypeRequiredPurpose
Email AddressYesAccount identifier, sign-in, and communications for email-based accounts. An account may instead be created and secured with a phone number, in which case an email address may not be collected.
Full NameYesAccount personalization and communications
PasswordConditional (hashed)Account security and sign-in for email-based accounts. Phone-based accounts are passwordless and no password is stored.
CountryYesLocalization, legal compliance, and tax purposes
Phone NumberConditionalAccount identifier and sign-in for phone-based accounts, and delivery of one-time login and verification codes over WhatsApp (with SMS as a fallback). Required for phone-based accounts; may otherwise be provided as a contact method.
LanguageYesLanguage preference (the Service is currently available in English)
TimezoneYesProper time display and scheduling

2.2 Student/Child Account Information

When a parent creates a student account for their child, we collect the following information:

Data TypeRequiredPurpose
UsernameYesAccount identification and login
PasswordYes (hashed)Account security
Full NameYesProfile personalization
Date of BirthYesAge-appropriate content delivery (7-12 years)
CurriculumYesEducational content alignment
School YearYesPlacing the student in the correct UK school year (Years 3–8), derived from date of birth

2.3 Student Activity and Progress Data

We automatically collect the following data as students use the platform:

  • Lesson Progress: Tracking educational advancement
  • Answers to Questions: Educational assessment and content improvement
  • Experience Points (XP): Gamification tracking
  • Level and Badges: Achievement tracking
  • Streak Data: Engagement tracking (current and longest streaks)
  • Daily Quest Completions: Wellness activity tracking
  • Last Active Date: Activity monitoring

2.4 Avatar and Customization Data

To provide personalization features, we collect:

  • Gender selection for avatar appearance (stored as part of avatar data, not student account profile)
  • Customization choices (skin color, hair color, hair style)
  • Equipped items (clothes, accessories, effects)
  • Inventory of owned virtual items

2.5 Payment and Subscription Data

For subscription management, we store:

  • Stripe Customer ID (reference for payment processing)
  • Stripe Subscription ID (subscription management)
  • Subscription Status (access control)
  • Current billing period dates

We do NOT store your full credit card details. All payment information is securely processed and stored by Stripe, our PCI-compliant payment processor.

2.6 Automatically Collected Information

When you use our Service, we may automatically collect:

  • Device information (browser type, operating system)
  • IP address (for security and localization)
  • Usage patterns and interactions with the platform
  • Error logs and diagnostic data (for service improvement)
  • Request metadata including IP address, user-agent, request identifiers, and diagnostic correlation IDs (for abuse prevention, debugging, and service reliability)
  • Product analytics events and session recordings used to understand and improve our Service. Session recordings are captured with sensitive form inputs masked, and error replays may be captured when our Service encounters an error. These recordings are not used for advertising and are described further in Section 4 (Third-Party Services).

2.7 AI Chatbot Assistance Data

When students use the AI chatbot assistant, we collect:

  • Chat messages sent to and received from the chatbot
  • Chatbot session identifiers and conversation history
  • Lesson context (lesson slug, step, language, and school year) sent to the chatbot for relevant responses
  • Response metadata including sources and safety-filtering indicators

Chatbot conversation sessions are temporarily cached in our chatbot service with an auto-expiring time-to-live of approximately 15 minutes; once the window expires, the session and message history are removed from the cache. Chatbot data is used solely for providing educational assistance, and all responses are passed through age-appropriate safety filters before being returned to the student.

2.8 Voice Greeting Data

To provide personalized audio greetings, we process:

  • Student first name
  • Language
  • Voice preference selection
  • Generated audio greeting files

Voice greetings are generated through a third-party voice synthesis service (ElevenLabs) and stored on our infrastructure for playback. Greetings may be regenerated when a student's name is changed, and the corresponding audio files are deleted when the student account is deleted.

2.9 Support Ticket Data

When you contact us through our support system, we collect:

  • Email address
  • Message content
  • Language
  • Ticket status (open/closed) and timestamps

Support data is used for responding to your inquiries and follow-up communications. Confirmation and closure emails are sent to the provided email address.

2.10 Virtual Economy Data

Our platform includes a virtual coin economy. We track:

  • Coin balance
  • Coin transaction history (earned, spent, and refunded coins)
  • Virtual item purchases

Transaction history is pruned by an automated daily task to retain only the most recent 100 transactions per student.

2.11 Push Notification Data

We store push subscription data on two separate tracks. On the parent track, when a parent allows notifications in their own browser so we can tell them about their family's progress. On the student track, when a parent has allowed learning reminders and the student then turns notifications on for their device. For each subscribing device we collect and store:

  • The push subscription the browser creates for that device (a unique endpoint address and the encryption keys the browser generates for it)
  • The device's browser user-agent string, to identify the subscribing device
  • Whether the one-time notification reward has already been granted to the student (student track only)

This information exists only to deliver notifications to that specific device. The two tracks are stored separately, so a parent and a student can use the same physical device without one affecting the other. Notification contents are encrypted in transit, and the push delivery services that relay them (see Section 4) cannot read them. The student track is off by default, a parent can withdraw it at any time, and turning notifications off on either track deletes the stored subscription for that device.

3. How We Use Your Information

We use the collected information for the following purposes:

3.1 Service Delivery

  • Providing access to educational content and features
  • Personalizing learning experiences based on age and school year
  • Tracking progress and achievements
  • Enabling avatar customization and gamification features

3.2 Account Management

  • Creating and maintaining user accounts
  • Processing authentication and authorization
  • Managing subscriptions and billing
  • Communicating important account-related information

3.3 Communication

We send transactional messages for the purposes below. These are delivered by email for email-based accounts, and over WhatsApp (with SMS as a fallback) for phone-based accounts:

  • Account activation and verification
  • One-time login and verification codes. For phone-based accounts these are delivered over WhatsApp with SMS as a fallback, and message and data rates may apply.
  • Password reset requests (email-based accounts)
  • Password change notifications (email-based accounts)
  • Account deletion confirmations
  • Subscription-related notifications

3.4 Service Improvement

  • Analyzing usage patterns to improve content and features
  • Identifying and fixing technical issues
  • Developing new educational content

3.5 Security

  • Protecting against unauthorized access
  • Detecting and preventing fraud
  • Enforcing our Terms of Service

3.6 Push Notifications

To a parent, once they allow notifications in their own browser, we may send updates about their family's learning, such as a lesson finished or a badge earned. To a student, with a parent's opt-in consent and only after the student turns notifications on, we may send occasional reminders that support their learning, such as a nudge to continue a lesson or pick up where they left off.

These notifications are educational or informational in purpose and are not advertising. The student track is off by default, limited in how often it is sent, respects quiet hours, and can be turned off at any time by the parent in Settings or by the student on their device. A parent can turn their own notifications off in their browser's site settings at any time.

4. Third-Party Services

We work with trusted third-party service providers to operate our platform. Here is information about our key partners:

4.1 Stripe (Payment Processing)

  • Purpose: All payment processing, subscription management, and billing
  • Data Shared: Parent email (where available; phone-only accounts may not have an email, in which case receipts may be issued without one) and subscription metadata
  • Data Processed by Stripe: Credit card details, billing address
  • Compliance: PCI DSS compliant
  • Privacy Policy: https://stripe.com/privacy

4.2 Amazon Web Services (AWS)

  • Purpose: File storage and content delivery
  • Data Stored: Avatar images, educational content (videos, audio), badge images
  • Privacy Policy: https://aws.amazon.com/privacy/

4.3 Postmark (Email Service Provider)

  • Purpose: Transactional email delivery (account verification, password reset, deletion confirmation, subscription notices, and support replies)
  • Data Processed: Parent email addresses and the contents of the transactional emails we send to them
  • Privacy Policy: https://postmarkapp.com/eu-privacy

4.4 Voice Generation Service (ElevenLabs)

  • Purpose: Generating personalized audio greetings for students
  • Data Shared: Student first name, language, and voice preference
  • Data Processed: Text-to-speech synthesis of greeting audio

Generated audio files are stored on our infrastructure. The voice generation service processes the student's first name only for the purpose of creating a personalized greeting.

4.5 AI Chatbot Service

  • Purpose: Providing AI-powered educational assistance to students
  • Data Shared: User identifier, lesson context (slug, step, language, school year), and chat messages
  • Data Processed: Conversational responses, session management, and source references

Chat sessions are held in temporary cached memory with an auto-expiring time-to-live of approximately 15 minutes; once expired, the session and message history are removed. All chatbot responses are passed through age-appropriate safety filters before being returned to the student.

4.6 Sentry (Error Tracking and Performance Monitoring)

  • Purpose: Capturing application errors, performance traces, and limited session replay on errors so we can diagnose and fix issues affecting our users
  • Data Shared: Error and exception details, stack traces, browser and device metadata, request identifiers, user role (parent or student), and a pseudonymous user identifier
  • Data Processed: Aggregated error reports, performance metrics, and short error-only session replays. We do not transmit passwords or full personal profiles to Sentry.
  • Privacy Policy: https://sentry.io/privacy/

4.7 PostHog (Product Analytics and Session Recording)

  • Purpose: Understanding how parents and students use our Service so we can improve features, measure adoption, and operate feature flags
  • Data Shared: Pseudonymous user identifiers (parent or student ID), navigation and interaction events, device and browser metadata, and session recordings
  • Data Processed: Product analytics events and session recordings in which sensitive form inputs (such as passwords and payment fields) are masked at the source before transmission
  • Privacy Policy: https://posthog.com/privacy

PostHog is used solely for product analytics and reliability — never for behavioral advertising. Session recording can be disabled at any time by Elysian Minds for any user or population.

4.8 GoHighLevel (Customer Relationship Management and Message Delivery)

  • Purpose: Managing parent communications and account lifecycle, and delivering transactional authentication messages such as one-time login and verification codes to phone-based accounts (for example, re-engagement messages, trial reminders, product updates, and login or verification codes sent to parent accounts)
  • Data Shared: Parent name, email address (if provided), phone number (if provided), country, timezone, lifecycle status (trial, active, cancelled, etc.), number of student profiles, and student first names. For authentication messages, the phone number and the code being sent are processed to deliver the message. We do not share student passwords, lesson content, or detailed activity logs with the CRM.
  • Data Processed: Contact records, segmentation tags, and outbound email or messaging workflows directed to parent accounts only
  • Privacy Policy: https://www.gohighlevel.com/privacy-policy

GoHighLevel is never used to communicate directly with children. All marketing and lifecycle communications are sent only to parent accounts. Phone messages, including one-time codes, are delivered over WhatsApp (operated by Meta) with SMS as a fallback; message and data rates may apply.

4.9 Rewardful (Affiliate Program Management)

  • Purpose: Tracking affiliate referrals, attributing conversions to affiliates, and calculating commissions for our affiliate program
  • Data Shared: Affiliate referral identifiers passed through Stripe at checkout and conversion metadata (subscription start, plan, and amount). Personal information about the referred parent is not shared with affiliates beyond aggregate, non-identifying conversion counts.
  • Data Processed: Affiliate dashboards, commission calculations, and referral cookie tracking on the affiliate's promotional links
  • Privacy Policy: https://www.rewardful.com/privacy

4.10 Web Push Delivery Services

  • Purpose: Relaying push notifications to a parent's or a student's device. The delivery service is determined by the browser in use (for example, Apple for Safari, Google for Chrome, Mozilla for Firefox); we do not choose or control it.
  • Data Shared: An encrypted notification addressed to the endpoint that browser provides. Because the notification is encrypted, these services cannot read its contents.

We do not maintain accounts with these services or send them identifying information about parents or students; they act only as the transport layer the browser already uses.

4.11 Google (Sign-In)

  • Purpose: Allowing parents to sign in using their Google account, and to link a Google account to an existing Elysian Minds account
  • Data Shared: When you sign in with or connect Google, we receive your name, email address, and a Google account identifier
  • Data Processed: Verification of your Google sign-in and matching it to your Elysian Minds account
  • Privacy Policy: https://policies.google.com/privacy

4.12 Meta (Facebook Sign-In and WhatsApp Message Delivery)

  • Purpose: Allowing parents to sign in using their Facebook account, and delivering one-time login and verification codes to phone-based accounts over WhatsApp
  • Data Shared: When you sign in with Facebook, we receive your name, email address, and a Facebook account identifier. For WhatsApp delivery, your phone number and the code being sent are processed so the message can reach your device.
  • Data Processed: Verification of your Facebook sign-in, and transport of one-time codes over WhatsApp with SMS as a fallback
  • Privacy Policy: https://www.facebook.com/privacy/policy/

5. Children's Privacy (COPPA Compliance)

We take children's privacy very seriously. Our platform is designed with the following protections in compliance with the Children's Online Privacy Protection Act (COPPA):

5.2 Parental Controls and Rights

Parents have full control over their children's accounts and can:

  • View all student activity and progress
  • Activate or deactivate student accounts
  • Change student passwords
  • Delete student accounts at any time
  • Request access to their child's personal information
  • Request deletion of their child's personal information

5.3 Data Minimization

  • We collect only information necessary for educational purposes
  • We do not engage in behavioral advertising to children
  • We do not allow children to publicly post personal information. Within the Service, an in-app leaderboard visible only to other authenticated students displays top-ranked students' chosen display names (usernames) along with progress metrics such as experience points, current streak, badges earned, and lessons completed. The leaderboard is never made public outside of the Service.
  • Children cannot access or modify other children's data (except viewing limited leaderboard information)

5.4 No Direct Marketing to Children

We do not send marketing or advertising communications to children. With a parent's opt-in consent, we may send non-marketing educational reminders as push notifications to a student's device; these are off by default and can be turned off at any time. All subscription and marketing communications are sent only to parent accounts.

6. Data Security

We implement robust security measures to protect your information:

6.1 Security Measures

  • All data transmitted between your device and our servers is encrypted
  • Passwords are securely stored using industry-standard hashing algorithms
  • Secure authentication mechanisms to protect your account
  • Protection against brute force attacks and unauthorized access attempts
  • Comprehensive validation to protect against common security threats
  • Strict access controls and session management
  • Data is stored securely with appropriate encryption and access controls

7. Data Retention and Deletion

7.1 Data Retention Periods

Data TypeRequiredPurpose
Active User DataN/ARetained for the duration of the account
Student Accounts that were never activatedN/AAutomatically deleted after 7 days of inactivity
Inactive Student AccountsN/AAutomatically deleted after 1 year of inactivity
Unverified Parent AccountsN/AAutomatically deleted after 7 days if the account's channel (email or phone) is not verified
Coin Transaction HistoryN/APruned daily by an automated task to the 100 most recent transactions per student

7.2 Account Deletion

Parent Account Deletion:

  • You can request account deletion through your account settings
  • A confirmation with a verification link or code is sent to the account's registered channel (by email for email-based accounts, or over WhatsApp with SMS as a fallback for phone-based accounts)
  • The deletion verification link is valid for 1 hour
  • One-time verification codes used during account actions expire after 5 minutes
  • Upon confirmation, all data is permanently deleted

What Gets Deleted:

  • Parent profile data
  • All associated student accounts and profiles
  • All lesson progress and achievements
  • Avatar configurations and inventory
  • Subscription will be cancelled through Stripe

8. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

8.1 Access and Portability

You have the right to request access to the personal information we hold about you and your children.

8.2 Correction

You can update your account information at any time through your account settings, or contact us to request corrections.

8.3 Deletion

You can request deletion of your account and all associated data as described in Section 7.2.

8.4 Objection and Restriction

You may object to certain processing of your data or request that we restrict processing in certain circumstances.

8.5 Exercising Your Rights

To exercise any of these rights, please contact us at support@elysianminds.org. We will respond to your request within 1 week.

9. International Data Transfers

Our Service is operated internationally. By using our Service, you consent to the transfer of your information to countries where we or our service providers operate, which may have different data protection laws than your country.

We take appropriate safeguards to ensure your personal information remains protected in accordance with this Privacy Policy.

10. Cookies and Tracking Technologies

We use essential cookies and similar technologies to operate our Service. Our application primarily uses token-based (JWT) authentication for API access, while session cookies may be used for administrative interfaces. These include:

  • Authentication Tokens: JWT-based tokens to authenticate your API requests and maintain your session
  • Session Cookies: Essential cookies for administrative interfaces and session middleware
  • Preference Cookies: To remember your timezone and theme settings
  • Security Cookies: To prevent fraud and protect against unauthorized access

We do not use cookies or any tracking technologies for behavioral advertising. We do use product analytics technologies, including event tracking and session recording with sensitive form inputs masked, to understand how the Service is used and to improve it. These technologies are described in Section 4 (Third-Party Services) and are never used to deliver advertising to children.

11. Guest Mode

You can try a limited set of sample lessons in guest mode without creating an account. This section explains what we do and do not collect when you use guest mode.

What we do not collect

  • We do not ask for or collect account information from guests, such as your name, email address, username, or password.
  • We do not save your guest lesson activity, answers, or progress to an account. Guest session state stays in your browser during the visit and is not stored on our servers.
  • We do not collect payment information in guest mode.

What we do collect

  • We collect anonymous product analytics about how guest mode is used, for example which lessons are tried, how far visitors get, and where they choose to sign up, so we can understand and improve the Service.
  • This analytics data is handled by our analytics provider (PostHog) and is linked to an anonymous identifier, such as a cookie or device identifier, rather than to your real-world identity.
  • As described in Section 4 (Third-Party Services) and Section 10 (Cookies and Tracking Technologies), analytics may use cookies and may include session recordings in which text you type is masked.

If you later create an account, the information you provide at sign-up is governed by the rest of this Privacy Policy.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

For material changes that affect how we process children's personal information, we will provide additional notice and obtain parental consent where required.

We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the Service after changes are posted constitutes acceptance of the updated Privacy Policy.

13. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Elysian Minds Innovations Limited

Innovation 1, DIFC, Dubai, UAE

Email: support@elysianminds.org

For concerns about children's privacy or to exercise parental rights, please use the email above with "Children's Privacy" in the subject line.