This Privacy Policy explains how Focus on Foundations (“Focus on Foundations,” “we,” “us,” or “our”) collects, uses, discloses, and protects information through our website, family account and learning services, and QRAG question-answering service (collectively, the “Services”).
1. Scope of the Alpha
The current alpha is offered directly to families in the United States. It is not a school-directed service, and we do not currently contract with schools or act on behalf of schools. A parent or legal guardian must manage any use by a child under 13. A person 13 or older may create an individual account for themselves. Independent accounts are not available for children under 13.
This 2026-08-18 update names Kids Web Services (KWS) Parent Verification, KWS’s AgeGraph, the signed-form verification path, and where verification data may be processed. It is a material change. Signed-in adults will be asked to accept the updated Terms and Privacy Policy before continuing.
2. Information We Collect
The information we collect depends on which Service you use.
Adult and guardian accounts
When an adult or guardian creates or uses an account, we collect:
- Account and authentication information, including the email address, account identifier, and authentication status. Passwords are processed by our authentication provider; Focus on Foundations does not receive the account password in readable form.
- Profile information, such as a display name.
- Family membership and account-management records.
- Records of agreement to our Terms of Service and Privacy Policy, including the version and date or time of consent.
Guardian-created child accounts and learning data
A child under 13 cannot self-register. An authenticated parent or legal guardian creates and manages the child account after email-plus consent (a direct-notice email, a confirmation-code response, and a follow-up email that consent can be revoked). For a guardian-created child account, we collect:
- A guardian-owned plus-address email, such as
youremail+kidname@whatevermail.com, used as the child’s sign-in address and routed to the guardian’s inbox. - The child’s display name, account identifier, authentication status, and family relationship.
- Learning activity and progress, including answers, attempts, assignments, app settings, and related educational interactions.
- Learning data files, including SQLite files created by learning applications and stored for account synchronization.
- Consent provenance, including the consenting guardian’s account identifier, the consent statement or version, and the date or time consent was recorded.
Please choose a child display name that does not reveal more personal information than is needed to use the Service.
Parent verification and tutor-disclosure consent
If a guardian invites a tutor who can see a child’s display name, we collect a stronger verification record before that disclosure. The record includes the verification method, status, and time, and the exact consent text and version the guardian accepted. Depending on the method the guardian chooses, it also includes:
- KWS Parent Verification. We send KWS the guardian’s verified email address and an opaque correlation token. KWS emails the guardian and uses Stripe to make a refundable $0.05 credit- or debit-card charge to check adult status. We keep a KWS transaction identifier as evidence. We do not receive or store the card number.
- Focus on Foundations Stripe fee. Stripe’s hosted Checkout processes a non-refundable $0.50 payment. We keep Stripe session or payment identifiers. We do not receive or store the card number.
- Signed form. The guardian prints a generated form, signs it by hand, and uploads a scan or photograph. We store that document privately. A typed name or a signature drawn on the same device is not accepted for this method.
We do not send child names, child identifiers, tutor email addresses, family identifiers, or account identifiers to KWS or Stripe. KWS verifies adult status. It does not verify that the person is the parent of a specific child. The guardian’s attestation and verified Focus on Foundations account remain our record of that authority.
QRAG service data
QRAG is separate from the family account and child learning services. QRAG may be used without an account and without providing an email address. We collect:
- Questions and other text submitted to QRAG, along with the generated response and supporting service metadata.
- An email address only when a user optionally provides it for an email-related feature.
- A self-selected name or label if the QRAG interface requests one.
Use without an account or email may be described as anonymous use, but the technical usage and security logs described below may still be generated. QRAG questions and selected source context may be sent to an LLM provider, such as OpenAI or Anthropic, to generate a response. Do not submit sensitive personal information in a QRAG question.
Usage, device, and security data
We and our service providers collect operational data needed to deliver and protect the Services. This may include IP address where applicable, browser and device information, pages or features used, timestamps, request and error metadata, authentication events, security events, and similar usage logs. We may use cookies, browser storage, and comparable technologies for authentication, session continuity, consent state, preferences, and security.
3. How We Use Information
We use information to:
- Create, authenticate, and administer adult, guardian, and child accounts.
- Provide learning activities, save and synchronize progress, and let guardians manage family data.
- Complete parent verification when a guardian chooses to authorize a tutor relationship, and keep the resulting consent evidence.
- Operate QRAG, answer submitted questions, and provide optional email features.
- Communicate about accounts, verification, support, privacy requests, and material Service changes.
- Maintain, debug, understand, and improve the Services, including internal product research. We may publish de-identified or aggregated findings that cannot reasonably identify a child.
- Detect abuse, protect users and the Services, enforce our terms, and comply with legal obligations.
We do not sell personal information. We do not use personal information for targeted or cross-context behavioral advertising. We do not market to children. Focus on Foundations does not independently share identifiable child information with third parties. A parent or legal guardian may separately start, scope, and revoke a tutor relationship after a stronger verification step; in that case we disclose only the tutor relationship and the child’s display name to that tutor. If we intend to share identifiable child information with other third parties — for example with research organizations or partner nonprofits — we would request additional consent for that.
4. How We Disclose Information
We disclose information only as needed for the purposes described in this Policy:
Hosting and service providers. We use service providers to authenticate accounts, run our APIs, store account, family, consent, and application records, store user files and signed-form uploads, deliver the website, and send transactional email.
Kids Web Services (KWS). If a guardian chooses KWS Parent Verification, we send KWS the guardian’s verified email address and an opaque correlation token. KWS, operated by Kids Web Services Ltd in the Epic Games family of companies, emails the guardian, checks adult status with a credit or debit card through Stripe (a refundable $0.05 charge), and returns the result to us. After the guardian interacts with KWS, KWS’s privacy policy governs the card check and KWS’s own records. Child names, child identifiers, tutor email addresses, family identifiers, and account identifiers are not sent to KWS.
If verification succeeds, KWS stores a hashed version of the guardian’s email and verification status in AgeGraph, a network KWS uses so the same adult may not have to verify again for other apps that use KWS. AgeGraph is controlled by KWS, not by Focus on Foundations. Deleting a Focus on Foundations account does not delete the AgeGraph record. A guardian can ask KWS to remove them from AgeGraph by emailing privacy@kidswebservices.com or using the opt-out link in KWS’s verification email. KWS’s other service providers are listed in KWS’s public register.
Stripe. Stripe is used in two ways. If a guardian chooses KWS Parent Verification, Stripe processes KWS’s refundable $0.05 card check; that card data is provided to Stripe by KWS, not by us. If a guardian chooses the optional Focus on Foundations parental-verification fee, Stripe’s hosted Checkout processes the $0.50 payment and receives the guardian’s payment and contact data required for Checkout. Child names, child identifiers, tutor email addresses, and account identifiers are not sent to Stripe by us.
Signed-form reviewers. If a guardian chooses the print-and-sign method, authorized Focus on Foundations reviewers open the uploaded document only to approve or reject it. The document is not sent to KWS or Stripe.
LLM providers for QRAG. QRAG questions and related context may be sent to OpenAI or Anthropic to generate answers. We do not send identifiable child account or learning data to OpenAI, Anthropic, or other LLM providers.
Legal and safety needs. We may disclose information when reasonably necessary to comply with law or legal process, protect rights or safety, investigate fraud or abuse, or secure the Services.
Organizational changes. If Focus on Foundations is involved in a merger, financing, reorganization, or transfer of Services, information may be transferred subject to this Policy and applicable law.
At your direction. We may disclose information when an adult user or guardian directs us to do so, including the tutor disclosure described in this Policy.
Our providers may process information only to perform services for us under their applicable contractual and legal obligations. We do not allow providers to use child information for advertising or marketing. KWS acts as our service provider when we send the guardian email and KWS sends the verification email. For the card check, AgeGraph, and related verification records, KWS acts as an independent organization under its own privacy policy.
5. Children’s Privacy: Direct Notice to Parents and Legal Guardians
This section gives parents and legal guardians direct notice of our practices for children under 13. Our privacy commitments are subject to any legal obligations required by court orders or government authorities.
How a child account is created
A child under 13 may not create an account independently. An adult must first create and authenticate a parent account, including email-plus consent. The parent or legal guardian then creates the child account, supplies the guardian-controlled plus email address and child display name, and affirmatively agrees to the child-consent statement bound to that standing consent. We record the consent provenance described above.
What we collect from a child
Through the child account and learning applications, we collect the child’s guardian-controlled plus email address, display name, persistent account identifier, learning activity and progress, assignments and settings, SQLite learning files, and usage or security data. We do not require a child to provide more information than is reasonably necessary to participate in the available learning activities.
How we use and disclose child information
We use child information to authenticate the child, provide and personalize learning activities, save and show progress, allow guardian oversight, maintain and secure the Services, and comply with law. We disclose it to our service providers only as needed to operate the account and learning Services, or when legal or safety needs require disclosure. We do not send identifiable child account or learning data to OpenAI, Anthropic, or other LLM providers. We do not send child information to KWS or Stripe. We do not sell child information, use it for targeted advertising, or market to children. If a guardian completes a separate tutor-disclosure verification, we disclose the tutor relationship and the child’s display name to that tutor only. If we intend to share identifiable child information with other third parties — for example with research organizations or partner nonprofits — we would request additional consent for that.
Guardian choices and rights
A parent or legal guardian may:
- Review the child information associated with the family account.
- Correct the child’s display name or other editable account information.
- Delete the child account and its saved learning data through family account controls.
- Withdraw consent by deleting the child account.
- Cancel a pending verification, revoke a later tutor relationship, or contact us to request access, correction, or deletion, or to ask questions about our child-data practices.
We may need to verify the requester’s identity and authority over the child account before fulfilling a request. A guardian may consent to our collection and use of child information without permitting disclosure beyond the disclosures that are integral to providing the Services, as described in this Policy.
6. Retention and Deletion
Adult account, family, child account, consent, and learning data in current records is retained while the relevant account remains active, until an authorized user uses self-service deletion, or until we perform alpha or Service cleanup. Current user files remain available while the account is active. During the alpha, we do not automatically delete account data merely because an account has been inactive.
Temporary child-consent confirmation challenges expire after about 10 minutes, and family invitations expire after 7 days. We enforce those expiration times when the records are used. Background deletion of expired temporary records is asynchronous, so an expired record may remain in storage for a limited time after it can no longer be used.
Security and operational logs are retained for 90 days. Superseded, noncurrent versions of user files expire after 30 days; the current file version remains while the account is active. Pending signed-form uploads expire after 30 days and are removed if the guardian account is deleted before approval. QRAG questions, optional email information, and other Service records are retained only as reasonably needed to provide and improve the applicable Service, maintain security, resolve support issues, and perform alpha operations.
Completed tutor-disclosure consent and the minimum verification evidence — the method, a KWS transaction identifier or Stripe payment identifier where used, and an approved signed form — remain after a tutor relationship is removed or an account is deleted, until a shorter approved schedule exists. We do not store card numbers.
When self-service account or child deletion succeeds, it removes the applicable current records under our control. It does not delete records that are not under our control, such as KWS’s AgeGraph record or other records KWS keeps under its own policy. Limited information may remain temporarily in service-provider backups or point-in-time recovery until those provider-managed windows expire. We may also retain narrowly limited legal or security records when reasonably necessary or required by law. Backup and restricted records are not used to continue the deleted account or for marketing.
7. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These include managed authentication, access controls, encrypted network connections, storage protections, and logging or monitoring for security events. No internet transmission or storage system is completely secure, and we cannot guarantee absolute security.
8. Your Privacy Rights and Choices
Depending on applicable law, an adult account holder or verified guardian may request access to, correction of, or deletion of personal information; obtain information about our collection and disclosure practices; or withdraw consent. Account and family controls provide self-service access to certain correction and deletion functions.
To make a request that cannot be completed through the account controls, contact us using the information below. We may verify identity and authority before acting. We will not discriminate against a user for exercising an applicable privacy right.
Requests about KWS’s AgeGraph or KWS’s copy of verification data should be sent to KWS at privacy@kidswebservices.com. We can help identify that path; we cannot delete KWS’s independent records ourselves.
9. United States Processing
The alpha is limited to United States families. Focus on Foundations stores and processes account, family, learning, and consent records in the United States. If information is submitted from outside the United States, it will be transferred to and processed in the United States.
If a guardian uses KWS Parent Verification, KWS and its service providers may process the guardian’s email and verification data in the United Kingdom, the European Union, the United States, and other countries where they operate.
10. Third-Party Links
The Services may link to third-party websites or media services, including KWS’s verification pages and email. Their privacy practices are governed by their own policies, not this Policy.
11. Changes and Re-consent
We may update this Policy as the alpha and our practices change. We will post the revised Policy and update its date. If a change materially affects how we collect, use, or disclose account or child information, we will provide additional notice and request updated consent when appropriate or required by law. Consent records identify the policy or consent version accepted.
12. Contact Us
For privacy questions or requests, including requests concerning a child account, contact:
Focus on Foundations
Email: contact@focusonfoundations.org
This notice describes current implementation and practices for the alpha. It is not a representation that a lawyer or regulator has approved the Services or this Policy.