Child safety
Our users include children, so safety and privacy are the default rather than an option.
Children do not meet strangers here
- No private messaging between students.
- No public comments and no forums.
- No public profiles — no user can view any student’s details.
- No user-uploaded content is ever shown to other students.
Minimal personal data
- No real name is required; a nickname is encouraged.
- No date of birth, home address, school name, photograph, or identity document number.
- Registration asks only for an email address, a password, and a level.
Parent linking requires the child’s participation
A parent account cannot link to a child by knowing an email address. The child must generate an 8-character code in their own settings, and the link only becomes active once the parent enters it correctly. The child can revoke the link at any time.
No pressure-inducing design
- No public leaderboards.
- No alarming red rankings and no pressure countdowns.
- No random rewards, streak penalties, or other casino-style mechanics.
- Rewards recognise effort, consistency and mastery gains only.
Technical protections
- Every permission is re-checked on the server; hiding a button is never treated as access control.
- Lesson and question copy is never rendered as raw HTML, so script injection is not possible.
- File uploads are restricted by type and size.
- Admin actions are written to an audit log.
- IP addresses in logs are stored only as a salted hash.
If you find a problem
If you see content that is unsuitable for children, or suspect a safety issue, please tell us immediately. This demonstration build has no formal reporting channel yet — that is a required item before launch.