Draft - Private Beta This document is a working draft prepared to describe BrightDots' intended privacy practices. It is not legal advice. Before publication it must be reviewed by qualified counsel, and every bracketed placeholder — company entity, addresses, retention periods, sub-processors, EU/UK representatives, and the parent-access method actually deployed — will be completed and confirmed after the private beta test phase. The product and vendor configuration will soon be audited to confirm that the child-facing games do not transmit, retain, or use child personal information.
Our promises to families
- Children are not a product. We do not sell or share personal information, and we never use Game Center activity for behavioural or targeted advertising.
- Parents hold the keys. A parent or guardian creates and controls the account, approves access for each child, manages purchases and settings, and can review, export, or delete the parent's information and associated Game Center records.
- No child personal information. The child-facing games do not ask for, capture, store, use, sell, share, or disclose a child's name, contact details, precise location, photograph, voice, messages, advertising identifier, or other personal information.
- Limited game data. We use only non-identifying session, device, household, or parent-account game data needed to operate, secure, remember progress, and improve the games. We do not use it to identify, contact, profile, or advertise to a child.
- Safety by default. Privacy-protective settings are on from the first launch. Purchases, external links, account controls, and less-protective settings remain behind an adult gate.
- No open chat. Children cannot message, friend, post publicly, or be contacted by strangers through BrightDots Game Center.
1. Who we are
BrightDots Game Center ("BrightDots", "Game Center", "we", "us") is a parent-controlled play and learning service for children age four and older. BrightDots is a project of Centerbeam.AI and is operated by [CENTERBEAM AI], Los Gatos, CA, which is the data controller for the parent and account information described in this policy.
The child-facing games are designed not to collect or use child personal information. A parent or legal guardian creates and controls the account, approves access, manages settings and purchases, and exercises privacy rights for the account.
You can reach our privacy team at drew@centerbeam.ai. Our Data Protection Officer can be reached at drew@centerbeam.ai.
2. Scope and who may use Game Center
This policy covers the BrightDots website, parent account, Game Center games, subscriptions, support, parent-controlled settings, and connected services that link to it.
2.1 Parents and legal guardians
Only an adult parent or legal guardian may create or manage an account, approve a child's access, purchase or manage a subscription, change privacy or game settings, contact support about the account, or submit a privacy request. By approving access, the adult confirms that they are the child's parent or legal guardian or are otherwise legally authorised to make that decision.
2.2 Children age four and older
Children age four and older may use only the games approved by the parent or guardian. Children do not create accounts, make purchases, change privacy settings, communicate with other users, or submit personal information through the child-facing experience. Parents should supervise use in a manner appropriate to the child's age, development, and abilities.
2.3 Services outside this policy
This policy does not govern independent app stores, payment processors, device manufacturers, operating systems, websites, or services operated by third parties. Their activities are governed by their own privacy policies and terms.
3. Information we collect
3.1 Information a parent gives us
- Parent or guardian name and email address.
- Username, display name, account identifier, and account preferences.
- Account credentials, stored using appropriate cryptographic protections and never in plain text.
- Parent-access and approval records, including what was approved, when, and by which account.
- Country, state, or general region where needed for legal or service settings.
- Subscription, receipt, refund, and limited transaction information.
- Communications, attachments, and account details a parent provides when contacting support.
Complete payment card numbers, security codes, and payment passwords are normally handled directly by the payment processor or app store. We generally receive only the information needed to confirm the purchase, manage the subscription, provide receipts, process refunds, prevent fraud, and maintain financial records.
3.2 No child personal information
The child-facing Game Center experience is designed not to collect, retain, or use personal information from children. We do not ask a child for, or create a child record containing:
- a name, nickname, initials, username, email address, phone number, home or school address;
- a birth date, exact age, school, classroom, contact list, or social-media identifier;
- a photograph, video, voice recording, voiceprint, biometric identifier, or precise geolocation;
- free-form chat, private messages, public posts, or unrestricted user-generated content;
- health, medical, financial, government-identification, or other sensitive information;
- an advertising identifier or identifier used to track a child across unaffiliated services; or
- a named or identifiable child profile.
Parent approval permits access to the games. It does not authorise BrightDots to collect personal information from the child.
3.3 In-game activity and saved progress
To operate the games, remember parent-approved settings or progress, identify errors, and improve gameplay, we may collect limited in-game information such as the game selected, session start and end time, level or stage reached, score, achievements, settings, difficulty, feature interactions, virtual items, response time, crashes, and general performance statistics.
This information is maintained at the game-session, device, household, or parent-account level. It is not associated with a child's name or identity and is not used to contact, identify, infer sensitive traits about, advertise to, or build a commercial profile about a child. A local profile or save slot must use a generic label or parent-selected non-identifying label and must not contain child personal information.
3.4 Technical and security information
On parent account, purchase, support, and security surfaces, we may process IP address, browser or device type, operating system, application version, language, general region, login time, session identifier, request identifier, error and crash data, network performance, and suspected fraud or abuse information.
The child-facing game client must not transmit advertising identifiers, precise location, contact data, or a persistent identifier used to recognise a child. Connection information that is technically necessary to deliver a game must not be retained or used to identify or profile the child. Where possible, technical records are truncated, rotated, aggregated, de-identified, or deleted promptly.
3.5 Accidental submission of child information
Parents should not send a child's photograph, voice recording, precise location, school information, health information, government identifier, or other sensitive information to support unless we specifically request it for a lawful and necessary purpose.
If we learn that child personal information was submitted or collected unintentionally, we will stop using it, restrict access, delete it from active systems, instruct applicable service providers to delete it, investigate how the collection occurred, correct the relevant product or configuration, and notify the parent or guardian where appropriate.
4. Child data, voice & AI
BrightDots Game Center does not record, transcribe, store, transmit, or use a child's voice, image, messages, or free-form input. The child-facing games do not create voiceprints or use biometric identification.
If a game offers a sound or microphone-based control, it must operate without sending or retaining the child's audio. A feature that cannot meet that requirement must remain disabled until this policy, the product design, the parent notice, and any legally required parental-consent process are updated.
Automated or AI-supported systems may be used to create or operate game content, test game quality, detect technical failures, or provide parent-facing support. Child personal information is not submitted to those systems, and non-identifying Game Center data is not used to train a general-purpose model unless it has first been aggregated or de-identified so that it cannot reasonably identify a person or household.
Automated content can make mistakes. Child-facing content is limited by age-appropriate design, predetermined game rules, content testing, and safety controls. Game Center does not offer children open AI chat or unrestricted conversational input.
5. How we use information
We use parent information, technical information, and non-identifying game activity to:
- create, maintain, authenticate, and protect the parent account;
- record parent-approved access and settings;
- provide, operate, and maintain Game Center and its games;
- remember parent-selected settings and game progress where enabled;
- process subscriptions, purchases, receipts, and refunds;
- respond to parent support and privacy requests;
- diagnose errors, crashes, compatibility issues, and service failures;
- prevent fraud, abuse, and unauthorised access;
- measure game and service performance using aggregated or non-identifying information;
- improve accessibility, reliability, age appropriateness, and gameplay;
- comply with legal, financial, tax, and regulatory obligations; and
- protect the rights, safety, and security of parents, children, BrightDots, and others.
We do not use child personal information because the Game Center is designed not to collect it. We do not use in-game activity for behavioural advertising, cross-context tracking, marketing profiles, or engagement-maximising techniques directed at a child.
6. Legal bases for processing (GDPR / UK GDPR)
| What we do | Legal basis |
|---|---|
| Create and run the parent account; provide approved games, saved settings, subscriptions, and support | Performance of a contract (Art. 6(1)(b)) |
| Account security, fraud prevention, troubleshooting, service reliability, and protection of children | Legitimate interests (Art. 6(1)(f)), balanced against the rights and reasonable expectations of parents and children |
| Legal, tax, accounting, regulatory, and security-incident records | Legal obligation (Art. 6(1)(c)) |
| Optional parent marketing, non-essential cookies, or optional parent-facing analytics | Consent (Art. 6(1)(a)), withdrawable at any time |
We do not rely on a young child's consent. Parent approval controls access to Game Center; it is not a legal basis for collecting child personal information. We apply privacy by design and by default, data minimisation, purpose limitation, high-privacy defaults, and the best interests of the child as product design principles.
7. Children's privacy & COPPA
BrightDots Game Center is directed to children, including children under 13, and is designed so that the child-facing games do not collect personal information from them.
7.1 Parent-approved access
A parent or legal guardian must create and control the account and approve a child's access before the child can use Game Center. The parent receives this policy and the applicable terms and can disable access at any time.
Parent approval is an access-control and supervision measure. Because the child-facing games are designed not to collect child personal information, the approval is not permission for BrightDots to collect such information.
7.2 If a future feature needs child personal information
We will not activate a feature that collects, uses, or discloses child personal information unless we first update the product design and privacy notice, identify the information and purpose, minimise the collection, provide direct notice to the parent, obtain verifiable parental consent where required, and provide the legally required review, deletion, and withdrawal controls.
7.3 Parental rights
At any time, a parent or guardian may:
- review the parent's account information and associated Game Center records;
- obtain a copy in a portable format where applicable;
- correct inaccurate parent-account information;
- request deletion of the account, saved progress, or associated records;
- withdraw optional consent and disable the child's Game Center access; and
- ask whether any child personal information was accidentally received and request its deletion.
To exercise these rights, email drew@centerbeam.ai from the address on the account or use the Parent Dashboard. We verify that the requester controls the parent account before acting. We do not require a child to provide personal information to verify a request.
7.4 No conditioning participation
We do not require a child to disclose personal information to play a game. Optional parent choices do not authorise collection from the child.
7.5 If we learn that child information was collected
If we discover that child personal information was collected or submitted, we will stop the processing, delete the information promptly unless retention is legally required, instruct applicable providers to delete it, investigate the cause, and correct the affected feature. A parent may report a concern to drew@centerbeam.ai.
8. Parental controls — on by default
Every BrightDots family account includes a Parent Dashboard, reachable only after an adult gate and account authentication. From it, a parent can:
| Control | Default setting |
|---|---|
| Child access to Game Center | Off until a parent approves access |
| Child profiles and personal information | Not collected — no named child account or profile |
| Voice, camera, chat, and free-form messaging | Disabled / not offered in the child-facing Game Center |
| Contact with other users | Disabled — no open chat, friend requests, or user-to-user messaging |
| External links and web browsing from inside Game Center | Blocked or protected by the adult gate |
| Purchases and in-app spending | Locked behind the parent gate |
| Advertising and marketing to the child | Never permitted — not a setting |
| Optional parent-facing analytics or communications | Off until the parent opts in where consent is required |
| Age-appropriate game selection | Selected and controlled by the parent without storing a child's exact age or birth date |
| Daily time limits and quiet hours | Available; parent-configurable |
| Data export, saved-progress deletion, and account deletion | Parent controlled |
Changing a privacy or safety setting to a less protective option requires the adult gate and a plain-language explanation. A setting cannot be used to enable the collection of child personal information without an updated policy and any legally required parental-consent process.
9. Child protection & safety measures
Privacy and safety are designed together. Our standing measures include:
- Closed environment. No open chat, public user-generated content, friending, direct messaging, or way for a stranger to contact a child through Game Center.
- No child-input collection. No child voice recording, free-form AI chat, photograph upload, public posting, or named child profile.
- Age-appropriate content. Games use predetermined rules, tested content, and age-appropriate design rather than unrestricted conversational generation.
- Parent gates. Purchases, external links, account controls, support, and less-protective settings require an adult action.
- No dark patterns. No loot boxes, manipulative streak pressure, privacy-degrading nudges, or engagement mechanics designed to override a parent's limits.
- Minimal telemetry. Operational game events are non-identifying and used only for service operation, safety, reliability, accessibility, and improvement.
- Vendor standards. Providers are contractually restricted to the approved purpose and may not use Game Center data for behavioural advertising, independent profiling, or general-purpose model training.
- Reviews and impact assessments. We review child-facing features, vendors, data flows, and material changes for privacy and safety risk before deployment.
- Report a concern. Anyone can raise a safety or privacy issue at drew@centerbeam.ai.
10. Cookies, local storage & analytics
10.1 Child-facing games
The child-facing experience does not use advertising cookies, cross-site trackers, advertising IDs, or identifiers used to recognise a child across unaffiliated services. Local device storage may be used for sound, accessibility, difficulty, parent-approved settings, or saved progress without placing a child's name or other personal information in the record.
Where an operational session identifier is necessary, it must be randomly generated, limited to the current technical purpose, rotated or deleted promptly, and not used to identify, contact, profile, or advertise to a child.
10.2 Parent account and public pages
Necessary cookies or storage may be used to keep a parent signed in, maintain security, remember account settings, process purchases, and protect against abuse. On public or parent-facing pages, we may request adult consent before activating optional analytics where applicable law requires it.
10.3 Analytics
We may use privacy-protective analytics to understand whether games load correctly, which features work, where errors occur, general session duration, aggregate completion and difficulty patterns, device compatibility, accessibility, and service performance.
Analytics must be configured to minimise collection and must not identify, advertise to, or profile a child. We do not combine Game Center activity with information from unaffiliated services to create an advertising or commercial profile. We honour legally recognised opt-out preference signals, including Global Privacy Control, where applicable.
11. Sharing & service providers
We do not sell personal information, share it for cross-context behavioural advertising, or disclose child personal information because the child-facing Game Center is designed not to collect it.
We may disclose limited parent, technical, transaction, or non-identifying game information to:
- Service providers / processors that provide cloud hosting, database, storage, security, authentication, content delivery, error monitoring, customer support, payment processing, email, backup, and privacy-protective analytics.
- Professional advisers, including lawyers, auditors, accountants, and security consultants, where reasonably necessary.
- Legal and safety recipients where required by law, valid legal process, fraud or security investigation, or protection of a child or another person.
- A successor entity in a merger, acquisition, financing, restructuring, insolvency, or asset transfer, subject to applicable notice and consent requirements.
Providers may process information only for the contracted purpose and under appropriate confidentiality, security, deletion, and data-protection obligations. Child-facing configurations must prohibit advertising, independent profiling, unrelated use, and general-purpose AI model training.
A current list of sub-processors is available at [LINK]. We will provide notice of a material provider change where required.
12. International data transfers
BrightDots is operated from [COUNTRY], and providers may process parent, account, transaction, support, technical, or non-identifying game information in other countries. We do not intentionally transfer child personal information because the child-facing games are designed not to collect it.
When personal data is transferred outside the EEA, UK, or Switzerland, we rely on an adequacy decision where available or an approved transfer mechanism such as the European Commission's Standard Contractual Clauses and, for applicable UK transfers, the UK Addendum or International Data Transfer Agreement. We use supplementary safeguards appropriate to the risk, including access controls, data minimisation, and encryption where appropriate.
Parents may request information about applicable safeguards by writing to drew@centerbeam.ai.
13. How long we keep data
We retain information only for as long as reasonably necessary for the purpose described, legal and financial obligations, security, fraud prevention, support, dispute resolution, and backup rotation.
| Data | Retention |
|---|---|
| Child personal information, voice, images, messages, or named child profile | Not intentionally collected or retained. Accidental submissions are deleted promptly unless retention is legally required. |
| Raw non-identifying in-game telemetry | [90] days, then deleted, aggregated, or de-identified |
| Parent-managed saved progress and settings | While the account or save record is active, plus [30] days after deletion is requested |
| Parent account and approval records | Life of the account, plus the period required for legal, security, fraud, or recordkeeping purposes |
| Parent support records | While the request is active and for [24] months afterward, unless a longer period is needed for a dispute or legal obligation |
| Security and abuse logs | [90] days, longer only where an investigation or legal obligation is open |
| Parent-account IP and login records | [30] days, unless needed longer for security, fraud, or legal compliance |
| Child-facing connection information | Not retained for identification or profiling; transient routing data is discarded or de-identified as soon as technically practicable |
| Billing records | As required by tax and accounting law, typically 7 years |
| Aggregated or de-identified statistics | May be retained while they cannot reasonably identify a person, child, or household |
| Inactive accounts | Flagged after [12] months and deleted after notice to the parent |
Residual copies may remain in backups until overwritten through the ordinary backup cycle. Before publication, the bracketed periods must be matched to the deployed systems, provider settings, contracts, and legal requirements.
14. Security
- Encryption in transit using current supported TLS and encryption at rest where appropriate.
- Role-based access control, least privilege, and multi-factor authentication for privileged staff.
- Passwords stored only using salted, computationally hard password hashing.
- Separation of parent-account functions from the child-facing game experience.
- Data minimisation, short retention, and aggregation or de-identification where practical.
- Logging, monitoring, vulnerability management, secure development, and incident-response procedures.
- Contractual and technical restrictions on service providers.
- Backup, recovery, and business-continuity controls appropriate to the service.
No system is perfectly secure. We design the service to limit the information available in the first place, especially in the child-facing experience.
Where a personal-data breach is likely to create a risk to individuals, we will notify the relevant supervisory authority within the legally required period and notify affected parents when required.
15. Your rights (GDPR / UK GDPR)
If you are in the EEA, UK, or Switzerland, you may have the right to:
- Access the parent personal data and associated account records we hold;
- Rectify inaccurate or incomplete information;
- Erase information where the legal conditions are met;
- Restrict or object to particular processing;
- Portability for applicable information provided under contract or consent;
- Withdraw consent for optional processing at any time;
- Object to direct marketing directed to the parent;
- receive information about applicable international-transfer safeguards; and
- lodge a complaint with the relevant supervisory authority.
We do not rely on a young child's consent and do not use child personal information for automated decision-making. A parent may also request confirmation that no child personal information is held and report an accidental submission for deletion.
Email drew@centerbeam.ai. We will respond within the period required by applicable law and may verify that the requester controls the relevant parent account. We do not require a child to provide personal information for verification.
Our EU representative (Art. 27) is [IN PROCESS] [NAME, ADDRESS] and our UK representative is [NAME, ADDRESS], where those appointments are required.
16. US state privacy rights (CCPA/CPRA and similar)
This section applies to the extent a US state privacy law applies to BrightDots or Centerbeam.AI.
16.1 Categories of personal information
During the preceding 12 months, we may have collected the following categories concerning parents or account holders:
- Identifiers: parent name, email address, account identifier, IP address, and login information.
- Customer-record information: parent account, approval, subscription, and support information.
- Commercial information: purchases, subscriptions, refunds, and transaction history.
- Internet or electronic-network activity: parent device, browser, session, security, and Game Center usage information.
- Approximate location: general region derived from a parent-account IP address where needed.
- Preferences or inferences: limited service settings derived from choices made by the parent.
- Sensitive personal information: account login credentials used only to authenticate and secure the account.
We do not knowingly collect these categories directly from children through the child-facing game experience.
16.2 California and other state rights
Subject to applicable exceptions, a resident may have the right to:
- know the categories and specific pieces of personal information collected;
- know the sources, purposes, and categories of recipients;
- request deletion or correction;
- receive applicable information in a portable format;
- opt out of sale, sharing, targeted advertising, or qualifying profiling;
- limit certain uses of sensitive personal information;
- appeal a denied request where state law provides that right; and
- receive service without unlawful discrimination for exercising privacy rights.
We do not sell personal information, share it for cross-context behavioural advertising, use sensitive personal information to infer characteristics, or offer a financial incentive in exchange for personal information. We do not sell or share personal information concerning consumers under 16.
We honour legally recognised opt-out preference signals where applicable. An authorised agent may submit a request with proof of authority, and we may verify the consumer and the agent as permitted by law.
17. No sale, no targeted advertising
To be unambiguous: BrightDots does not sell personal information, share it for cross-context behavioural advertising, serve targeted advertising to children, or permit third-party advertising networks or tracking technologies in the child-facing Game Center.
We do not use in-game activity to select advertisements, create marketing audiences, infer sensitive characteristics, or build a commercial profile about a child. We do not condition gameplay on a child viewing personalised advertising.
If sponsorships, contextual promotions, or an advertising-supported feature are proposed later, the feature must remain disabled until the product, parent notice, policy, age-appropriateness review, and applicable consent controls are updated.
18. Automated processing
We may use automated systems to identify suspicious parent-account logins, detect fraud or malicious traffic, diagnose game errors, adjust a game according to non-identifying gameplay events, or recommend parent-selected age-appropriate content.
We do not use child personal information for automated processing and do not make a solely automated decision about a parent or child that produces legal or similarly significant effects where prohibited by applicable law. A parent may contact us to request review of an automated security restriction affecting the parent account.
19. Third-party services
Game Center may rely on or link to app stores, payment platforms, operating systems, hosting providers, or external websites selected by the parent. Those third parties independently determine how they process information within their own services, and their activities are governed by their own privacy policies and terms.
Child-facing external links are blocked or protected by an adult gate where reasonably necessary. Parents should review the privacy practices and parental controls of the device, app store, payment provider, and other third-party services they choose to use.
20. Changes to this policy
We may update this policy in response to changes in law, regulatory guidance, Game Center features, service providers, security practices, technology, or business operations.
When a material change affects parent information, child-facing design, or the commitment not to collect child personal information, we will notify the account parent in advance by email, account notice, or another reasonable method. Where law requires renewed consent or verifiable parental consent, we will obtain it before activating the relevant change. Previous versions are available on request.
21. Contact us
- Privacy: drew@centerbeam.ai
- Data Protection Officer: drew@centerbeam.ai
- Child safety or accidental-data concerns: drew@centerbeam.ai
- Post: Cloud Media Works, LLC — Centerbeam Division, Los Gatos, California, [FULL MAILING ADDRESS]
Please include enough information to identify the parent account and explain the request. Do not include unnecessary personal information about a child.
BrightDots is a project of Centerbeam.AI.
22. Parent acknowledgment
By creating or maintaining a Game Center account, the parent or legal guardian acknowledges that:
- the parent controls the account and approves the child's access;
- the parent has reviewed this Privacy Policy and the applicable terms;
- the child should not submit personal information through Game Center;
- Game Center collects parent information and non-identifying in-game information, but is designed not to collect or use child personal information;
- the parent is responsible for supervising use as appropriate; and
- the parent may withdraw access or contact BrightDots about privacy at any time.