BrightDots.org

Privacy Policy

How BrightDots protects children, families, and their data.

← Back to BrightDots

Draft for review. This document is a working draft prepared to describe BrightDots' intended privacy practices. It is not legal advice. Before publication it must be reviewed by qualified counsel, and every bracketed placeholder — company entity, addresses, retention periods, sub-processors, EU/UK representatives, and the age-verification method actually deployed — must be completed and confirmed to match what the service really does.

Our promises to families

1. Who we are

BrightDots.org ("BrightDots", "we", "us") is a voice-first play, learning, and companionship service designed for children and the adults who care for them. BrightDots is operated by [LEGAL ENTITY NAME], [registered address], which is the data controller for the personal information described in this policy.

You can reach our privacy team at privacy@brightdots.org. Our Data Protection Officer can be reached at dpo@brightdots.org.

2. Scope of this policy

This policy covers the BrightDots website, apps, voice experiences, games, and any connected services that link to it. It explains what we collect from three groups of people:

Where this policy says something applies "to children", it applies to every account we know or reasonably believe belongs to a child, and to any child using a family account.

3. Information we collect

3.1 Information a parent gives us

3.2 Information about a child

We deliberately keep this list short.

We do not knowingly collect from children: real name, home or school address, phone number, email address, precise geolocation, photographs or video of the child, biometric identifiers used for recognition, persistent advertising identifiers, or contact lists.

3.3 Information collected automatically

4. Voice, audio & AI

BrightDots is a talking experience, so this section matters most. Voice features are off by default and must be enabled by a parent.

5. How we use information

We never use children's personal information for behavioural advertising, profiling for marketing, building marketing audiences, engagement-maximising "nudge" mechanics, or sale to third parties.

What we do Legal basis
Create and run a family account; deliver requested activities Performance of a contract (Art. 6(1)(b))
Process a child's voice and personalise content for a child Consent of the holder of parental responsibility (Art. 6(1)(a) with Art. 8); explicit consent under Art. 9(2)(a) where audio is treated as special-category data
Safety, moderation, abuse and fraud prevention, security Legitimate interests (Art. 6(1)(f)) — protecting children, balanced by a documented Legitimate Interests Assessment and a Children's Data Protection Impact Assessment
Legal, tax, and regulatory record-keeping Legal obligation (Art. 6(1)(c))
Optional analytics and product research Consent (Art. 6(1)(a)), withdrawable at any time; off by default

We design in line with the UK Age Appropriate Design Code (Children's Code) and equivalent EU guidance: the best interests of the child come first, settings default to high privacy, and we do not use nudge techniques to push children toward weaker privacy choices.

7. Children's privacy & COPPA

BrightDots is directed to children, and we comply with the US Children's Online Privacy Protection Act (COPPA) and its Rule.

7.1 Verifiable parental consent

Before a child can create a profile or use voice features, we obtain verifiable parental consent. Our notice tells the parent what we collect, how we use it, and that they can revoke consent later. We use one or more of the following methods: [a small authorised payment-card transaction / government-ID check with prompt deletion / signed consent form returned by email or upload / knowledge-based authentication / video call with trained staff].

Consent is granular: a parent can approve core play while declining voice recording, optional analytics, or any other non-essential processing. Declining an optional item never blocks the core experience.

7.2 Parental rights under COPPA

At any time, a parent or guardian may:

To exercise these rights, email privacy@brightdots.org from the address on the account or use the Parent Dashboard. We verify the requester is the account parent before acting, and respond within 30 days.

7.3 No conditioning participation

We never require a child to disclose more personal information than is reasonably necessary to take part in an activity.

7.4 If we learn we collected data without consent

If we discover we have collected personal information from a child without the required parental consent, we delete it promptly. If you believe this has happened, contact privacy@brightdots.org and we will act without undue delay.

8. Parental controls — on by default

Every BrightDots family account includes a Parent Dashboard, reachable only after an adult check (a gate that a young child is not expected to pass) and a login. From it, a parent can:

Control Default setting
Microphone & voice recording Off until a parent enables it
Voice transcript history Visible to the parent; auto-deleted on schedule
Contact with other users Disabled — there is no open chat, no friend requests, no user-to-user messaging
External links & web browsing from inside BrightDots Blocked
Purchases and in-app spending Locked behind the parent gate
Advertising and marketing to the child Never permitted — not a setting
Optional analytics / product research Off until a parent opts in
Content age band Set by the parent; the youngest suitable band is preselected
Daily time limits and quiet hours Available; parent-configurable
Data export & account deletion Self-service, any time

Changing a privacy or safety setting to a less protective option always requires passing the adult gate, and we show a plain-language explanation of what the change means before it takes effect.

9. Child protection & safety measures

Privacy and safety are the same job. Our standing measures include:

10. Cookies & similar technologies

On children's experiences we use strictly necessary cookies and local storage only — to keep a session signed in, remember accessibility and safety settings, and protect against abuse. We do not place advertising, cross-site tracking, or third-party behavioural cookies anywhere on BrightDots.

On our public marketing pages we may ask adult visitors for consent to optional analytics cookies. You can decline, and BrightDots works the same either way. We honour Global Privacy Control (GPC) signals as a valid opt-out where the law recognises them.

11. Sharing & service providers

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose personal information only to:

A current list of sub-processors is available at [LINK], and we notify parents before adding a sub-processor that handles children's data.

12. International data transfers

BrightDots is operated from [COUNTRY], and our providers may process data in other countries. When we move personal data out of the EEA, the UK, or Switzerland, we rely on an adequacy decision where one applies, or otherwise on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK transfers), backed by a transfer impact assessment and supplementary safeguards such as encryption in transit and at rest. You may request a copy of the safeguards we use by writing to dpo@brightdots.org.

13. How long we keep data

We keep personal information only as long as it serves the purpose it was collected for.

Data Retention
Raw voice audio [24 hours / deleted immediately after transcription]
Voice transcripts [30] days, then deleted or de-identified
Child profile & progress While the account is active, plus [30] days after deletion is requested
Parent account & consent records Life of the account, plus the period required to evidence consent under COPPA/GDPR
Security & abuse logs [90] days, longer only where an investigation is open
IP addresses [30] days, then truncated or discarded
Billing records As required by tax and accounting law (typically 7 years)
Inactive accounts Flagged after [12] months, deleted after notice to the parent

14. Security

No system is perfectly secure, but we do not treat that as an excuse — we design to limit what a breach could ever expose.

15. Your rights (GDPR / UK GDPR)

If you are in the EEA, the UK, or Switzerland, you have the right to:

Email privacy@brightdots.org. We respond within one month and never charge for a first request. Rights over a child's data are exercised by the parent or guardian; where a child is old enough to act for themselves under local law, we support them directly in age-appropriate language.

Our EU representative (Art. 27) is [NAME, ADDRESS] and our UK representative is [NAME, ADDRESS]. You may also lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office — though we would appreciate the chance to put things right first.

16. US state privacy rights (CCPA/CPRA and similar)

If you are a California resident, you may request to know, delete, or correct the personal information we hold, obtain it in a portable form, and limit the use of sensitive personal information. We do not discriminate against anyone for exercising these rights, and we do not offer financial incentives for personal data.

California's CPRA requires opt-in consent to sell or share the personal information of consumers under 16 — and for children under 13, consent from a parent. We do neither: we do not sell or share personal information of any user, of any age. Residents of other US states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana) have comparable rights and may use the same contact route. Requests may be submitted by an authorised agent with proof of authorisation.

17. No sale, no targeted advertising

To be unambiguous: BrightDots does not sell personal information, does not share it for cross-context behavioural advertising, does not serve targeted advertising to children, and does not permit third-party advertising networks or trackers in children's experiences.

18. Changes to this policy

We may update this policy as BrightDots grows. When a change materially affects how we handle a child's personal information, we will notify the account parent by email in advance and — where the law requires — obtain fresh verifiable parental consent before the change applies. Non-material changes are posted here with an updated "Last updated" date. Previous versions are available on request.

19. Contact us

BrightDots is a project of Centerbeam AI.