What happens to information about you?
- A parent or carer creates the family account and chooses what child profile information to add.
- We remember lesson progress so your parent or carer can see what you completed and help you continue.
- We do not sell your information, show behavioural advertising, or provide open social chat.
- Do not type secrets or identifying details into a lesson. Ask a trusted adult if you are unsure.
- Lesson feedback for children uses fixed choices. Only an adult should add written details, an email address, or a screenshot.
- You and your parent or carer can ask us questions or request access to, export of, or deletion of learning data.
1. Who this policy covers
This policy applies to The Lighted Path website and its family, child-device, lesson, and administration areas. “We”, “us”, and “The Lighted Path” refer to the operator of this learning service. A parent or carer should create and control the primary family account. Child access can then be provided through a parent-generated QR code or manual pairing code without giving the child the parent’s password.
2. Information we collect
Parent and staff accounts
When you sign in with Google through Clerk, we may receive your verified email address, name, profile image, and an authentication identifier. Our application database stores the account identifier, email address, name, role, preferred household language, communication preferences, and account timestamps needed to provide and secure your account. We do not request access to Google Drive, Gmail, contacts, calendars, or other Google content.
Optional account communications
A signed-in parent can choose independently whether to receive lesson releases, product announcements, offers and pricing, parent research invitations, or educational resources. These optional choices begin off. We store each choice, its consent version, and relevant consent or withdrawal times. Essential service, security, and account messages are handled separately.
Child profiles and learning records
A parent or carer may provide a child’s nickname and birth month/year. We derive the current age and age band needed for appropriate lessons. The household has one preferred-language setting; we do not ask for a separate language preference for each child. We record allowlisted learning information such as lessons started or completed, current and furthest steps, activities completed, bounded attempt and duration information, approved assessment results, and curriculum concept-support indicators. We do not use these records to judge a child’s faith, sincerity, worth, or personality.
Child-device access
We process pairing-code and child-device-session information, expiry and revocation times, an optional device label, and last-use information. Pairing and session secrets are stored as cryptographic hashes. The child-device cookie is designed to be host-scoped, HTTP-only, same-site, time-limited, and revocable.
Typed reflections
Some free starter lessons allow an optional typed reflection. For applicable age bands, the reflection, lesson title, prompt, and age band may be processed to provide short feedback and identify sensitive content. An accepted non-sensitive response may be stored with a one-way network hash, limited browser information, and feedback metadata. If a response is marked as sensitive, the raw response is replaced in our database with a withholding notice. Spoken reflections are not recorded by the website. Other lesson areas explicitly labelled “private reflection” keep the words in the browser or in memory and do not send them away from the page.
Product analytics and technical information
We collect bounded events such as site and lesson surfaces visited, navigation choices, lesson and activity lifecycle events, hints, stalls, recovery actions, and technical failures. We may also derive coarse device, browser, operating-system, country, or hosting-edge categories. Product analytics do not store raw URLs or query values, CSS selectors, pointer coordinates, page text, raw answers, reflection text, IP addresses, precise location, session replay, or device fingerprints. Signed-in actors are represented by a keyed pseudonym rather than their raw account or child identifier.
Feedback and problem reports
A learner can use fixed choices to report a lesson problem or say whether a completed lesson felt difficult, okay, or great. Those child-safe choices do not accept typed text, contact details, or screenshots. An adult can separately confirm that they are an adult and send written feedback, optionally request a reply using an email address, and explicitly choose a screenshot. Adults should remove names, faces, account details, messages, or other private information before attaching an image.
A feedback record may include the page path without its query string, lesson and activity identifiers, age band, coarse device/browser/operating-system and viewport categories, orientation, submission time, and application build. For abuse prevention we store a short-lived keyed value derived from network information rather than the raw network address or full browser identifier. Screenshots are decoded, resized, stripped of metadata, and re-encoded as JPEG before storage. Feedback and screenshots are available only to authorised administrators and are not emergency, crisis, or safeguarding monitoring.
Browser storage and cookies
Clerk uses cookies and similar technology to maintain parent and staff authentication. The Lighted Path uses browser storage for lesson state, completion state, queued learning events, private local drafts where offered, a marker showing that a completion pulse was already sent, and basic session continuity. Feedback form text, email addresses, and screenshots are not saved as browser drafts. When account setup finds a completed guest Lesson 1 on the same device, the parent can choose which age-matched child profile receives that completion; private responses and unverified scores are not imported. Child-device access uses a secure session cookie. Clearing browser data may remove unsynchronised or intentionally local information.
3. Why we use information
- authenticate adults and protect parent, staff, and administration areas;
- create child profiles and provide age-appropriate lessons;
- save progress, restore lessons, and show parent-visible learning summaries;
- pair and revoke child devices without exposing the parent password;
- process optional typed reflections and provide limited learner feedback;
- review feedback and structured lesson problem reports, respond when an adult requests it, and improve lessons;
- detect errors, protect the service, prevent abuse, and investigate lesson abandonment or confusion;
- improve accessibility, reliability, lesson design, and curriculum delivery; and
- meet legal obligations and respond to valid requests.
We do not sell personal information or use child learning records for targeted advertising.
4. Google user data
Google sign-in data is used only to authenticate you, create or match your account, display basic account identity, assign authorised roles, and protect account-only features. We do not use Google user data for advertising, sell it, or permit humans to read it except where necessary for security, support, legal compliance, or with your permission. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
5. When information is shared
We disclose information only as needed to operate the service, including to:
- Clerk and Google, for account authentication and identity processing;
- Railway and its infrastructure providers, for application and database hosting;
- Resend, for email delivery when you enable an optional communication category or when we send an essential account message;
- YouTube/Google, when embedded lesson video resources load or play;
- professional advisers, regulators, courts, or authorities where reasonably necessary or legally required; and
- a successor operator if the service is reorganised, provided information remains subject to appropriate protections.
These providers may process information in countries other than Australia. Their own privacy terms also apply to information they process as independent providers.
6. Children and parental control
The service is designed for children to learn under the direction of a parent, carer, school, or authorised adult. The adult account holder is responsible for creating child profiles, choosing appropriate access, and supervising use. Children should not create an adult account or submit personal contact details, school details, photographs, screenshots, recordings, addresses, health information, or other secrets in lesson responses or feedback.
Parent dashboards are intentionally limited to factual learning progress. They exclude private reflection prose, raw answers, exact click history, analytics identity keys, and operational error telemetry.
7. Retention
Account, child-profile, and durable learning records are retained while needed to provide the family account, meet operational or legal requirements, and resolve disputes. A parent can export a child’s progress and submit a deletion request from the parent dashboard. Free-lesson reflection records are retained for service operation, safety review, and abuse prevention until deleted under our retention process or following a verifiable applicable request.
Product-analytics retention is currently:
- anonymous and system raw analytics: 30 days;
- linked pseudonymous raw analytics: 90 days;
- deterministic aggregate insights: 365 days; and
- aggregate rollups and analytics-access audit records: 730 days.
Feedback records, optional reply email addresses, and processed screenshots are retained for up to 180 days, unless earlier deletion is appropriate or longer retention is required to handle a legal, security, or active support matter. Removing a signed-in adult account also removes feedback contact records linked to that account.
Backups and security records may persist for a limited additional period before routine deletion or overwrite.
8. Access, correction, export, and deletion
Parents can view their children’s learning summaries, download the available progress export, revoke child-device sessions, and request deletion of a child profile and associated learning records from the protected parent dashboard. You may also contact us to request access to or correction or deletion of applicable personal information. We may need to verify your identity and authority over a child’s records before acting.
9. Security and data incidents
We use access controls, server-side authorisation, hashed pairing secrets, scoped sessions, bounded data contracts, feedback request limits, image decoding and re-encoding, and restricted administration tools. No online service can guarantee absolute security. If we become aware of a qualifying data breach, we will assess it and provide notifications required by applicable law.
10. Changes and contact
We may update this policy as the service or legal requirements change. The effective date above will be updated, and material changes may also be communicated in the service.
For privacy questions, complaints, or verifiable data requests, email support@thelightedpath.org. You can also review our Terms of Service.
