Draft for review. This document is a working draft prepared to describe BrightDots' intended privacy practices. It is not legal advice. Before publication it must be reviewed by qualified counsel, and every bracketed placeholder — company entity, addresses, retention periods, sub-processors, EU/UK representatives, and the age-verification method actually deployed — must be completed and confirmed to match what the service really does.
Our promises to families
- Children are not a product. We never sell or share children's personal information, and we never use it for behavioural or targeted advertising.
- Parents hold the keys. A parent or guardian creates the account, grants consent, and can review, export, or delete their child's data at any time.
- We collect the minimum. If a feature can work without personal data, we build it that way.
- Voice stays private. Children's voice recordings are used to operate the experience, kept only as long as needed, and are never used to train general-purpose AI models.
- Safety by default. The strictest privacy and safety settings are on from the first launch. Parents can loosen them; we never loosen them for you.
- No open chat. Children cannot message, friend, or be contacted by strangers on BrightDots.
1. Who we are
BrightDots.org ("BrightDots", "we", "us") is a voice-first play, learning, and companionship service designed for children and the adults who care for them. BrightDots is operated by [LEGAL ENTITY NAME], [registered address], which is the data controller for the personal information described in this policy.
You can reach our privacy team at privacy@brightdots.org. Our Data Protection Officer can be reached at dpo@brightdots.org.
2. Scope of this policy
This policy covers the BrightDots website, apps, voice experiences, games, and any connected services that link to it. It explains what we collect from three groups of people:
- Children — users under 13 (United States) or under the applicable digital-consent age in their country (13–16 in the EU/EEA; 13 in the UK).
- Parents and guardians — the adults who create and control a family account.
- Adult visitors — anyone browsing our public pages.
Where this policy says something applies "to children", it applies to every account we know or reasonably believe belongs to a child, and to any child using a family account.
3. Information we collect
3.1 Information a parent gives us
- Parent name and email address (to create the account and verify consent).
- Account credentials (stored as salted hashes — never in plain text).
- Consent records: what was consented to, when, and by which verification method.
- Optional: billing details, handled by our payment processor. We never see or store full payment card numbers.
3.2 Information about a child
We deliberately keep this list short.
- A display name or nickname. We ask parents not to use a real full name, and we block names that look like email addresses or phone numbers.
- An age band (for example 4–6, 7–9, 10–12) — not a full date of birth — used to serve age-appropriate content.
- A chosen avatar from our own library. We do not accept child photographs.
- Play and progress data: which activities were opened, progress markers, and settings.
- Voice audio and transcripts, as described in Section 4.
We do not knowingly collect from children: real name, home or school address, phone number, email address, precise geolocation, photographs or video of the child, biometric identifiers used for recognition, persistent advertising identifiers, or contact lists.
3.3 Information collected automatically
- Device and technical data: device type, operating system, browser, language, and approximate region derived from IP address (city/country level only).
- IP address, used for security, fraud prevention, and regional legal compliance — then truncated or discarded on the schedule in Section 13.
- Diagnostic and crash data.
- Service usage events (feature opened, session length), collected in aggregated or pseudonymised form for children's accounts.
4. Voice, audio & AI
BrightDots is a talking experience, so this section matters most. Voice features are off by default and must be enabled by a parent.
- When we listen. The microphone is active only while a child is intentionally speaking to BrightDots — press-and-hold or an explicit wake action. There is no always-on background listening, and a visible, animated indicator shows whenever the microphone is live.
- What happens to the audio. Speech is converted to text so the experience can respond. Audio and transcripts are processed to generate a reply, keep the conversation coherent within the session, and run safety checks.
- Retention. By default, raw audio is deleted within [24 hours / immediately after transcription]. Transcripts are retained for [30] days so parents can review them, then deleted or de-identified.
- No model training. We do not use children's voice recordings or transcripts to train, fine-tune, or improve general-purpose AI models, and we contractually prohibit our AI vendors from doing so.
- Not voiceprints. We do not create voiceprints or use voice for biometric identification. Where voice audio is treated as biometric or sensitive data under law, we process it only with the explicit consent recorded from the verified parent, and only for the purposes stated here.
- Parent access. Parents can view session transcripts, mute the microphone entirely, and delete voice history at any time from the Parent Dashboard.
- AI limitations. BrightDots uses automated systems to generate responses. They are not perfect. We layer content filters, blocked-topic lists, and human review of flagged sessions on top — see Section 9.
5. How we use information
- To provide, operate, and personalise age-appropriate activities.
- To understand and respond to a child's spoken requests.
- To keep children safe: content filtering, abuse detection, and enforcing our rules.
- To let a parent supervise, review, and control their child's experience.
- To maintain security, prevent fraud, and diagnose faults.
- To improve BrightDots using aggregated or de-identified data that cannot reasonably identify a child.
- To communicate with parents about the service, updates, and safety notices.
We never use children's personal information for behavioural advertising, profiling for marketing, building marketing audiences, engagement-maximising "nudge" mechanics, or sale to third parties.
6. Legal bases for processing (GDPR / UK GDPR)
| What we do | Legal basis |
|---|---|
| Create and run a family account; deliver requested activities | Performance of a contract (Art. 6(1)(b)) |
| Process a child's voice and personalise content for a child | Consent of the holder of parental responsibility (Art. 6(1)(a) with Art. 8); explicit consent under Art. 9(2)(a) where audio is treated as special-category data |
| Safety, moderation, abuse and fraud prevention, security | Legitimate interests (Art. 6(1)(f)) — protecting children, balanced by a documented Legitimate Interests Assessment and a Children's Data Protection Impact Assessment |
| Legal, tax, and regulatory record-keeping | Legal obligation (Art. 6(1)(c)) |
| Optional analytics and product research | Consent (Art. 6(1)(a)), withdrawable at any time; off by default |
We design in line with the UK Age Appropriate Design Code (Children's Code) and equivalent EU guidance: the best interests of the child come first, settings default to high privacy, and we do not use nudge techniques to push children toward weaker privacy choices.
7. Children's privacy & COPPA
BrightDots is directed to children, and we comply with the US Children's Online Privacy Protection Act (COPPA) and its Rule.
7.1 Verifiable parental consent
Before a child can create a profile or use voice features, we obtain verifiable parental consent. Our notice tells the parent what we collect, how we use it, and that they can revoke consent later. We use one or more of the following methods: [a small authorised payment-card transaction / government-ID check with prompt deletion / signed consent form returned by email or upload / knowledge-based authentication / video call with trained staff].
Consent is granular: a parent can approve core play while declining voice recording, optional analytics, or any other non-essential processing. Declining an optional item never blocks the core experience.
7.2 Parental rights under COPPA
At any time, a parent or guardian may:
- review the personal information we hold about their child;
- obtain a copy in a portable format;
- request deletion of some or all of it;
- refuse further collection or use, and revoke consent — after which we stop collecting and delete what we hold, except records we must keep by law;
- disable voice, personalisation, or the account entirely.
To exercise these rights, email privacy@brightdots.org from the address on the account or use the Parent Dashboard. We verify the requester is the account parent before acting, and respond within 30 days.
7.3 No conditioning participation
We never require a child to disclose more personal information than is reasonably necessary to take part in an activity.
7.4 If we learn we collected data without consent
If we discover we have collected personal information from a child without the required parental consent, we delete it promptly. If you believe this has happened, contact privacy@brightdots.org and we will act without undue delay.
8. Parental controls — on by default
Every BrightDots family account includes a Parent Dashboard, reachable only after an adult check (a gate that a young child is not expected to pass) and a login. From it, a parent can:
| Control | Default setting |
|---|---|
| Microphone & voice recording | Off until a parent enables it |
| Voice transcript history | Visible to the parent; auto-deleted on schedule |
| Contact with other users | Disabled — there is no open chat, no friend requests, no user-to-user messaging |
| External links & web browsing from inside BrightDots | Blocked |
| Purchases and in-app spending | Locked behind the parent gate |
| Advertising and marketing to the child | Never permitted — not a setting |
| Optional analytics / product research | Off until a parent opts in |
| Content age band | Set by the parent; the youngest suitable band is preselected |
| Daily time limits and quiet hours | Available; parent-configurable |
| Data export & account deletion | Self-service, any time |
Changing a privacy or safety setting to a less protective option always requires passing the adult gate, and we show a plain-language explanation of what the change means before it takes effect.
9. Child protection & safety measures
Privacy and safety are the same job. Our standing measures include:
- Closed environment. No open chat, no user-generated public content, no friending, no direct messaging, no way for a stranger to reach a child through BrightDots.
- Layered content filtering. Every AI response passes through age-band-appropriate safety filters and blocked-topic controls before a child hears it.
- Distress and risk routing. If a child says something suggesting harm, abuse, or crisis, BrightDots responds with a calm, age-appropriate message encouraging them to talk to a trusted adult, surfaces relevant local help resources, and — consistent with law and our safeguarding policy — notifies the account parent.
- Human review, narrowly scoped. Trained reviewers may examine sessions that our automated systems flag, strictly for safety and quality. Reviewers are background-checked, bound by confidentiality, and see the minimum data needed.
- Zero tolerance for child sexual abuse and exploitation (CSAE). Any such material or conduct is removed, the account is terminated, and we report to the appropriate authorities (including NCMEC in the United States) as required by law.
- No dark patterns. No loot boxes, no manipulative streak pressure, no engagement mechanics designed to keep a child playing past a parent's limits.
- Vendor standards. Every processor handling children's data is contractually bound to child-safety and data-protection terms at least as strict as this policy, and is reviewed before onboarding.
- Staff training and impact assessments. We maintain a Children's Data Protection Impact Assessment, review it when features change materially, and train staff on safeguarding.
- Report a concern. Anyone can raise a safety issue at safety@brightdots.org. Reports involving a child's immediate safety are triaged first.
10. Cookies & similar technologies
On children's experiences we use strictly necessary cookies and local storage only — to keep a session signed in, remember accessibility and safety settings, and protect against abuse. We do not place advertising, cross-site tracking, or third-party behavioural cookies anywhere on BrightDots.
On our public marketing pages we may ask adult visitors for consent to optional analytics cookies. You can decline, and BrightDots works the same either way. We honour Global Privacy Control (GPC) signals as a valid opt-out where the law recognises them.
11. Sharing & service providers
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose personal information only to:
- Service providers / processors who run BrightDots on our behalf — cloud hosting, speech-to-text and AI response generation, error monitoring, and payment processing for parents. Each is bound by a written data-processing agreement, may use the data only on our instructions, and may not use children's data for their own purposes or model training.
- Legal and safety recipients — where we must comply with law, respond to valid legal process, protect our rights, or protect the safety of a child or another person.
- A successor entity in a merger, acquisition, or asset sale — in which case the data remains subject to this policy, we notify parents in advance, and material changes require fresh consent where the law requires it.
A current list of sub-processors is available at [LINK], and we notify parents before adding a sub-processor that handles children's data.
12. International data transfers
BrightDots is operated from [COUNTRY], and our providers may process data in other countries. When we move personal data out of the EEA, the UK, or Switzerland, we rely on an adequacy decision where one applies, or otherwise on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK transfers), backed by a transfer impact assessment and supplementary safeguards such as encryption in transit and at rest. You may request a copy of the safeguards we use by writing to dpo@brightdots.org.
13. How long we keep data
We keep personal information only as long as it serves the purpose it was collected for.
| Data | Retention |
|---|---|
| Raw voice audio | [24 hours / deleted immediately after transcription] |
| Voice transcripts | [30] days, then deleted or de-identified |
| Child profile & progress | While the account is active, plus [30] days after deletion is requested |
| Parent account & consent records | Life of the account, plus the period required to evidence consent under COPPA/GDPR |
| Security & abuse logs | [90] days, longer only where an investigation is open |
| IP addresses | [30] days, then truncated or discarded |
| Billing records | As required by tax and accounting law (typically 7 years) |
| Inactive accounts | Flagged after [12] months, deleted after notice to the parent |
14. Security
- Encryption in transit (TLS 1.2+) and at rest for stored personal data.
- Role-based access control, least privilege, and multi-factor authentication for staff.
- Passwords stored only as salted, computationally hard hashes.
- Pseudonymisation of children's records wherever it does not break the experience.
- Logging, monitoring, regular vulnerability scanning, and periodic independent penetration testing.
- A written incident response plan. Where a breach is likely to result in a risk to individuals, we notify the relevant supervisory authority within 72 hours and affected parents without undue delay.
No system is perfectly secure, but we do not treat that as an excuse — we design to limit what a breach could ever expose.
15. Your rights (GDPR / UK GDPR)
If you are in the EEA, the UK, or Switzerland, you have the right to:
- Access the personal data we hold about you or your child;
- Rectify inaccurate or incomplete data;
- Erase data ("right to be forgotten") — which we apply with particular force to data collected from a child;
- Restrict or object to processing, including processing based on legitimate interests;
- Portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, without affecting processing already carried out;
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. BrightDots makes no such decisions about children.
Email privacy@brightdots.org. We respond within one month and never charge for a first request. Rights over a child's data are exercised by the parent or guardian; where a child is old enough to act for themselves under local law, we support them directly in age-appropriate language.
Our EU representative (Art. 27) is [NAME, ADDRESS] and our UK representative is [NAME, ADDRESS]. You may also lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office — though we would appreciate the chance to put things right first.
16. US state privacy rights (CCPA/CPRA and similar)
If you are a California resident, you may request to know, delete, or correct the personal information we hold, obtain it in a portable form, and limit the use of sensitive personal information. We do not discriminate against anyone for exercising these rights, and we do not offer financial incentives for personal data.
California's CPRA requires opt-in consent to sell or share the personal information of consumers under 16 — and for children under 13, consent from a parent. We do neither: we do not sell or share personal information of any user, of any age. Residents of other US states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana) have comparable rights and may use the same contact route. Requests may be submitted by an authorised agent with proof of authorisation.
17. No sale, no targeted advertising
To be unambiguous: BrightDots does not sell personal information, does not share it for cross-context behavioural advertising, does not serve targeted advertising to children, and does not permit third-party advertising networks or trackers in children's experiences.
18. Changes to this policy
We may update this policy as BrightDots grows. When a change materially affects how we handle a child's personal information, we will notify the account parent by email in advance and — where the law requires — obtain fresh verifiable parental consent before the change applies. Non-material changes are posted here with an updated "Last updated" date. Previous versions are available on request.
19. Contact us
- Privacy: privacy@brightdots.org
- Data Protection Officer: dpo@brightdots.org
- Child safety concerns: safety@brightdots.org
- Post: [LEGAL ENTITY NAME], [ADDRESS]
BrightDots is a project of Centerbeam AI.