Last Updated: August 12, 2026
Welcome to Elysian Minds Innovations Limited ("Elysian Minds," "we," "us," "our," or the "Company"). We are committed to protecting the privacy of our users, especially the children who use our educational platform.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational platform designed for children aged 7-12. We operate on a parent-child model where parents (guardians) create and manage accounts for their children (students).
Please read this Privacy Policy carefully. By using our Service, you agree to the collection and use of information in accordance with this policy.
When a parent or guardian creates an account, we collect the following information:
| Data Type | Required | Purpose |
|---|---|---|
| Email Address | Yes | Account identifier, sign-in, and communications for email-based accounts. An account may instead be created and secured with a phone number, in which case an email address may not be collected. |
| Full Name | Yes | Account personalization and communications |
| Password | Conditional (hashed) | Account security and sign-in for email-based accounts. Phone-based accounts are passwordless and no password is stored. |
| Country | Yes | Localization, legal compliance, and tax purposes |
| Phone Number | Conditional | Account identifier and sign-in for phone-based accounts, and delivery of one-time login and verification codes over WhatsApp (with SMS as a fallback). Required for phone-based accounts; may otherwise be provided as a contact method. |
| Language | Yes | Language preference (the Service is currently available in English) |
| Timezone | Yes | Proper time display and scheduling |
When a parent creates a student account for their child, we collect the following information:
| Data Type | Required | Purpose |
|---|---|---|
| Username | Yes | Account identification and login |
| Password | Yes (hashed) | Account security |
| Full Name | Yes | Profile personalization |
| Date of Birth | Yes | Age-appropriate content delivery (7-12 years) |
| Curriculum | Yes | Educational content alignment |
| School Year | Yes | Placing the student in the correct UK school year (Years 3–8), derived from date of birth |
We automatically collect the following data as students use the platform:
To provide personalization features, we collect:
For subscription management, we store:
We do NOT store your full credit card details. All payment information is securely processed and stored by Stripe, our PCI-compliant payment processor.
When you use our Service, we may automatically collect:
When students use the AI chatbot assistant, we collect:
Chatbot conversation sessions are temporarily cached in our chatbot service with an auto-expiring time-to-live of approximately 15 minutes; once the window expires, the session and message history are removed from the cache. Chatbot data is used solely for providing educational assistance, and all responses are passed through age-appropriate safety filters before being returned to the student.
To provide personalized audio greetings, we process:
Voice greetings are generated through a third-party voice synthesis service (ElevenLabs) and stored on our infrastructure for playback. Greetings may be regenerated when a student's name is changed, and the corresponding audio files are deleted when the student account is deleted.
When you contact us through our support system, we collect:
Support data is used for responding to your inquiries and follow-up communications. Confirmation and closure emails are sent to the provided email address.
Our platform includes a virtual coin economy. We track:
Transaction history is pruned by an automated daily task to retain only the most recent 100 transactions per student.
We store push subscription data on two separate tracks. On the parent track, when a parent allows notifications in their own browser so we can tell them about their family's progress. On the student track, when a parent has allowed learning reminders and the student then turns notifications on for their device. For each subscribing device we collect and store:
This information exists only to deliver notifications to that specific device. The two tracks are stored separately, so a parent and a student can use the same physical device without one affecting the other. Notification contents are encrypted in transit, and the push delivery services that relay them (see Section 4) cannot read them. The student track is off by default, a parent can withdraw it at any time, and turning notifications off on either track deletes the stored subscription for that device.
We use the collected information for the following purposes:
We send transactional messages for the purposes below. These are delivered by email for email-based accounts, and over WhatsApp (with SMS as a fallback) for phone-based accounts:
To a parent, once they allow notifications in their own browser, we may send updates about their family's learning, such as a lesson finished or a badge earned. To a student, with a parent's opt-in consent and only after the student turns notifications on, we may send occasional reminders that support their learning, such as a nudge to continue a lesson or pick up where they left off.
These notifications are educational or informational in purpose and are not advertising. The student track is off by default, limited in how often it is sent, respects quiet hours, and can be turned off at any time by the parent in Settings or by the student on their device. A parent can turn their own notifications off in their browser's site settings at any time.
We work with trusted third-party service providers to operate our platform. Here is information about our key partners:
Generated audio files are stored on our infrastructure. The voice generation service processes the student's first name only for the purpose of creating a personalized greeting.
Chat sessions are held in temporary cached memory with an auto-expiring time-to-live of approximately 15 minutes; once expired, the session and message history are removed. All chatbot responses are passed through age-appropriate safety filters before being returned to the student.
PostHog is used solely for product analytics and reliability — never for behavioral advertising. Session recording can be disabled at any time by Elysian Minds for any user or population.
GoHighLevel is never used to communicate directly with children. All marketing and lifecycle communications are sent only to parent accounts. Phone messages, including one-time codes, are delivered over WhatsApp (operated by Meta) with SMS as a fallback; message and data rates may apply.
We do not maintain accounts with these services or send them identifying information about parents or students; they act only as the transport layer the browser already uses.
We take children's privacy very seriously. Our platform is designed with the following protections in compliance with the Children's Online Privacy Protection Act (COPPA):
Parents have full control over their children's accounts and can:
We do not send marketing or advertising communications to children. With a parent's opt-in consent, we may send non-marketing educational reminders as push notifications to a student's device; these are off by default and can be turned off at any time. All subscription and marketing communications are sent only to parent accounts.
We implement robust security measures to protect your information:
| Data Type | Required | Purpose |
|---|---|---|
| Active User Data | N/A | Retained for the duration of the account |
| Student Accounts that were never activated | N/A | Automatically deleted after 7 days of inactivity |
| Inactive Student Accounts | N/A | Automatically deleted after 1 year of inactivity |
| Unverified Parent Accounts | N/A | Automatically deleted after 7 days if the account's channel (email or phone) is not verified |
| Coin Transaction History | N/A | Pruned daily by an automated task to the 100 most recent transactions per student |
Parent Account Deletion:
What Gets Deleted:
Depending on your location, you may have certain rights regarding your personal information:
You have the right to request access to the personal information we hold about you and your children.
You can update your account information at any time through your account settings, or contact us to request corrections.
You can request deletion of your account and all associated data as described in Section 7.2.
You may object to certain processing of your data or request that we restrict processing in certain circumstances.
To exercise any of these rights, please contact us at support@elysianminds.org. We will respond to your request within 1 week.
Our Service is operated internationally. By using our Service, you consent to the transfer of your information to countries where we or our service providers operate, which may have different data protection laws than your country.
We take appropriate safeguards to ensure your personal information remains protected in accordance with this Privacy Policy.
You can try a limited set of sample lessons in guest mode without creating an account. This section explains what we do and do not collect when you use guest mode.
If you later create an account, the information you provide at sign-up is governed by the rest of this Privacy Policy.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
For material changes that affect how we process children's personal information, we will provide additional notice and obtain parental consent where required.
We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the Service after changes are posted constitutes acceptance of the updated Privacy Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
For concerns about children's privacy or to exercise parental rights, please use the email above with "Children's Privacy" in the subject line.