Policy
Privacy Policy
Kuros Lab is built for kids in classrooms. We treat data the way we'd want our own kid's data treated. This page explains what we collect, why, and what we don't do.
In this policy
Who this applies to
This Privacy Policy applies to the Kuros Lab mobile app, the Kuros Lab website (kuroslab.com), and any related services we operate. It covers two groups of people:
- Teachers and adult administrators who create accounts and manage classes.
- Kids in classrooms who enter the app via a teacher-issued class code.
For kids specifically, our Children's Privacy notice explains the additional protections we apply.
What we collect from teachers
When a teacher creates an account, we collect:
- Email address — used as the sign-in identifier.
- Display name — what kids and other teachers see on shared screens.
- Password — stored only as a one-way hash; we never see or store it in readable form.
- Session token — kept on the device (Android: encrypted shared preferences; iOS: Keychain) so you stay signed in across app restarts.
That's the entire list. We don't collect a phone number, a school address, payment information, or any background data. We don't track you across other websites.
What we collect about kids
Kids never create an account. They join via a class code the teacher hands out. The only kid-related data we hold is:
- Nickname — what the teacher entered (e.g. “Mina K.”). No last name required.
- Grade or class group — chosen by the teacher.
- Activity attempts — which mission, which answer, which step order, accuracy.
We do not collect:
- Email addresses, phone numbers, or home addresses for kids
- Photos, voice recordings, or video
- Precise location
- Device identifiers used for advertising (we have no ads)
- Browser history or cross-app behavior
How we use it
We use the data above only to:
- Sign teachers into their accounts and keep their sessions alive
- Run kid missions and record their attempts so the teacher can see progress
- Show learning-outcome summaries on the teacher dashboard
- Email you about your account (sign-in, password reset) — never marketing
- Diagnose and fix bugs (server logs that contain only request paths, status codes, and timestamps — never request bodies)
We do not use kid attempt data to train any AI models, third-party or our own. We do not profile children for any purpose.
How long we keep it
| Data | How long |
|---|---|
| Teacher account (email, name, password hash) | Until you delete the account |
| Kid nickname + activity attempts | Until the teacher removes the kid or class, or 24 months of inactivity, whichever comes first |
| Server diagnostic logs (no request bodies) | 30 days |
| Backups | Rotated out within 35 days of original deletion |
Your rights
Whichever country you're in, you can ask us to:
- Show you what we have on you (or any kid in your class).
- Correct it if anything's wrong.
- Delete it entirely — your account and any kid data tied to it.
- Export it in a common format (JSON or CSV).
Email privacy@kuroslab.com with the request. We aim to respond within 14 days; the legal maximum in many regions is 30 days.
If you're a parent or guardian and want a kid's data removed, the fastest route is asking the teacher who set up the class. They can revoke the class code, which removes that kid's identity from the app immediately. You can also email us directly.
Changes to this policy
If we make a material change (something that affects what we collect or what we do with it), we'll notify signed-in teachers by email at least 30 days before the change takes effect. Older versions live at the bottom of this page.
Questions?
Email privacy@kuroslab.com.
Postal mail: Kuros Lab, [Street address — to be filled in], [City, Country].