Legal
Privacy Policy
Last updated: placeholder
1. Overview
CanopyKids, Inc. ("CanopyKids", "we") provides runtime safety and compliance infrastructure for products that put children in front of generative AI. This policy describes how we collect, use, and protect information.[Placeholder — to be replaced with full counsel-reviewed policy.]
2. Children's Privacy (COPPA, GDPR-K, CA AADC)
CanopyKids is designed for COPPA, GDPR-K, and the California Age-Appropriate Design Code. Where our runtime processes child-originated content on behalf of a deployer, we act as a service provider / data processor. Raw prompts are never transmitted off-device beyond what is required to evaluate them in-process; we store SHA-256 hashes only.
3. Information we collect
From deployers: business contact info, integration metadata, audit-log telemetry. From end users (via deployers): jurisdiction signals (IP, locale, timezone), prompt classifications, and policy decisions — never the raw prompt content unless the deployer has separately retained it.
4. How we use information
To operate the runtime, improve detection accuracy under federated learning with differential privacy, and meet regulatory audit obligations.
5. Sharing
We do not sell information. We share with sub-processors strictly necessary to operate the service (listed in our DPA), and as required by law.
6. Retention
Audit logs are retained for the period required by the strictest applicable jurisdiction. Hashed prompt records follow COPPA-aligned retention by default.
7. Your choices and rights
Verifiable parental consent flows are provided to deployers. End users may exercise GDPR-K, CCPA, and analogous rights through the deployer of record.
8. Contact
Questions: anusua@canopykids.ai.