Legal

Privacy Policy

Last updated: placeholder

1. Overview

CanopyKids, Inc. ("CanopyKids", "we") provides runtime safety and compliance infrastructure for products that put children in front of generative AI. This policy describes how we collect, use, and protect information.[Placeholder — to be replaced with full counsel-reviewed policy.]

2. Children's Privacy (COPPA, GDPR-K, CA AADC)

CanopyKids is designed for COPPA, GDPR-K, and the California Age-Appropriate Design Code. Where our runtime processes child-originated content on behalf of a deployer, we act as a service provider / data processor. Raw prompts are never transmitted off-device beyond what is required to evaluate them in-process; we store SHA-256 hashes only.

3. Information we collect

From deployers: business contact info, integration metadata, audit-log telemetry. From end users (via deployers): jurisdiction signals (IP, locale, timezone), prompt classifications, and policy decisions — never the raw prompt content unless the deployer has separately retained it.

4. How we use information

To operate the runtime, improve detection accuracy under federated learning with differential privacy, and meet regulatory audit obligations.

5. Sharing

We do not sell information. We share with sub-processors strictly necessary to operate the service (listed in our DPA), and as required by law.

6. Retention

Audit logs are retained for the period required by the strictest applicable jurisdiction. Hashed prompt records follow COPPA-aligned retention by default.

7. Your choices and rights

Verifiable parental consent flows are provided to deployers. End users may exercise GDPR-K, CCPA, and analogous rights through the deployer of record.

8. Contact