Guidenby Color Coded Kids← Back to home
πŸ”’

Privacy Policy

How Guiden collects, uses, protects, and shares your information

Effective Date: May 17, 2026
πŸ“Œ
Guiden is an educational platform designed for use by K–12 students. If you are a parent or guardian of a child under 13, please read this policy carefully, particularly the sections on COPPA compliance and children's data. Schools using Guiden operate as our institutional partners and bear consent responsibilities for students under 13 enrolled through their institutions.

1. Who We Are

Guiden is an AI-powered tutoring platform operated by Color Coded Kids LLC, a Missouri limited liability company located in St. Louis, Missouri ("Company," "we," "us," or "our"). Guiden provides AI-assisted academic tutoring services to K–12 students through partnerships with schools and educational institutions ("School Partners").

For privacy inquiries, contact us at: privacy@colorcodedkids.com

2. Scope of This Policy

This Privacy Policy applies to all users of the Guiden platform, including:

  • Students β€” K–12 learners accessing Guiden through a School Partner or independently
  • Teachers and Educators β€” school staff who create classrooms, assign work, and review student activity
  • School Administrators β€” institutional accounts managing school-wide settings
  • Visitors β€” individuals browsing our public website at guiden.colorcodedkids.com

This policy does not apply to third-party websites or services linked from our platform. We are not responsible for the privacy practices of those third parties.

3. Information We Collect

3.1 Information Provided During Registration

Full NameUsed for identification within the platform; displayed to teachers
Email AddressUsed for authentication, account recovery, and administrative communications
PasswordStored as a bcrypt hash β€” we never store plaintext passwords
Grade LevelUsed to calibrate AI tutor language and difficulty (students only)
School NameUsed to associate accounts with School Partner institutions
RoleStudent, Teacher, or Admin β€” determines platform access permissions
InterestsOptional; used to personalize bot interactions (students only)

3.2 Information Generated Through Platform Use

Chat MessagesFull text of conversations between students and AI tutor bots
Assignment SubmissionsStudent work submitted for AI grading, including all chat history
AI Grades & FeedbackScores (0–100), rubric breakdowns, and written feedback generated by AI graders
Session KPIsComputed metrics: hints used, message count, session duration, reasoning scores
Chat Behavior KPIsAI-analyzed metrics: reasoning depth, confidence, persistence, misconceptions (teacher-facing only)
Login TimestampsLast login date/time for security and activity monitoring
Usage CountersDaily message counts, chat counts β€” used for rate limiting only

3.3 Automatically Collected Technical Information

When you use Guiden, we automatically collect limited technical data necessary for the platform to function:

  • Authentication session tokens stored in browser cookies (HttpOnly, Secure)
  • Standard HTTP request logs (IP address, browser type, referring URL) β€” retained for 30 days for security purposes only
  • Cookie consent preference stored in localStorage

We do not collect device fingerprints, behavioral tracking data, advertising identifiers, or geolocation data.

3.4 Pilot Application Data

If you submit a pilot application through our public website, we collect: your name, school name, email, phone number (optional), city, state, role, approximate student count, and any message you provide. This data is used solely to evaluate and respond to pilot program inquiries.

4. How We Use Your Information

We use collected information for the following purposes and no others:

Providing AI TutoringStudent chat history is sent to our AI provider (OpenAI) to generate tutor responses. See Section 6.
AI GradingSubmitted chat history is sent to OpenAI to generate rubric-based grades and feedback.
Analytics & KPI GenerationChat history is analyzed by AI to generate teacher-facing student insights (reasoning depth, misconceptions, etc.)
Teacher VisibilityTeachers can view full chat histories, grades, and KPI data for students enrolled in their classrooms.
AuthenticationEmail and password hash used to verify identity at login.
Safety & ModerationAll student messages are screened by an internal content safety classifier before reaching the AI.
Platform AdministrationUsage counters enforce rate limits set by School Partners. No usage data is sold or shared.
CommunicationsWe may email account holders about critical security issues or service changes. We do not send marketing emails to students.
⚠️
We do not use student data for advertising, marketing, product development unrelated to the student's direct educational experience, or any commercial purpose beyond operating the tutoring service. We do not build advertising profiles on students. This applies regardless of the student's age.

5. Legal Bases for Processing (GDPR)

For users located in the European Economic Area or United Kingdom, we process personal data under the following legal bases:

Contract PerformanceProcessing necessary to provide the tutoring service you or your school has contracted for
Legitimate InterestSecurity logging, fraud prevention, and platform abuse prevention
Legal ObligationCompliance with COPPA, FERPA, and applicable data protection laws
ConsentCookie consent where required; email marketing if opted in (teachers/admins only)

6. AI Processing and Third-Party Data Sharing

6.1 OpenAI (AI Provider)

Guiden uses OpenAI's API to power tutor bot responses, AI grading, and student KPI analysis. When a student sends a message or submits an assignment, the following data is transmitted to OpenAI:

  • The content of chat messages within the session
  • The assignment prompt and rubric (no student PII in the prompt itself)
  • The student's grade level (integer only, no name)
  • The subject name

We do not transmit student names, email addresses, school names, or any other directly identifying information to OpenAI. OpenAI processes this data under its API data processing agreement and does not use API inputs to train its models. See OpenAI's API data usage policy.

6.2 Infrastructure Providers

Database HostingPostgreSQL database hosted on a reputable cloud provider with encryption at rest and in transit
Application HostingNext.js frontend and NestJS backend hosted with SOC 2 compliant infrastructure providers

These providers act as data processors under our direction and may not use your data for any independent purpose.

6.3 No Sale of Data

We do not sell, rent, license, or otherwise transfer personal information to third parties for monetary or other valuable consideration. This prohibition applies specifically to student data and is maintained regardless of any future changes to our business model. Any future change to this policy will require affirmative opt-in consent and 60 days' advance notice.

6.4 School Partners

When a student accesses Guiden through a School Partner, the school has access to that student's data including chat history, grades, and KPI analytics. This access is granted by and through the school's administrative account and is consistent with the school's role as an educational institution with legitimate educational interest under FERPA.

6.5 Legal Disclosure

We may disclose personal information if required by law, court order, or governmental authority, including to comply with FERPA-mandated reporting obligations. We will notify affected users of any such disclosure to the extent permitted by law.

7. COPPA β€” Children Under 13

πŸ“Œ
Guiden is designed to be accessed by children under 13 exclusively through School Partner accounts. We rely on the school consent model under COPPA Rule Β§312.5(b)(1), which permits schools to consent on behalf of parents for educational purposes. Schools using Guiden are responsible for obtaining appropriate parental consent before enrolling students under 13.

7.1 What We Collect from Children Under 13

We limit data collection from children under 13 to what is strictly necessary for the educational service:

  • First and last name
  • School-provided or parent-provided email address
  • Grade level (integer)
  • Chat messages with AI tutors
  • Grades and performance data

We do not collect home addresses, phone numbers, photographs, social media identifiers, or any persistent identifiers tied to advertising for children under 13.

7.2 Parental Rights

Parents and legal guardians of children under 13 have the right to:

  • Review the personal information collected about their child
  • Request deletion of their child's account and associated data
  • Refuse further collection of their child's data (which will require account deactivation)

To exercise these rights, contact your child's school administrator or email us directly at privacy@colorcodedkids.com with your child's name, school name, and your relationship to the child. We will respond within 10 business days.

7.3 No Behavioral Advertising to Children

We do not engage in behavioral advertising, interest-based advertising, or targeted marketing directed at children under 13 under any circumstances. We do not permit third-party advertising networks on the student-facing portions of our platform.

8. FERPA β€” Student Educational Records

Guiden qualifies as a "school official" under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. Β§ 1232g, and its implementing regulations at 34 CFR Part 99. We access student educational records under the "school officials with legitimate educational interest" exception.

Legitimate Educational InterestProviding AI-assisted tutoring, grading, and learning analytics directly in support of the student's education
Scope of AccessLimited to data necessary to provide the contracted tutoring service
Re-disclosure ProhibitionWe do not re-disclose FERPA-protected student records to third parties without school authorization
Data SecurityAll student educational records are encrypted at rest (AES-256) and in transit (TLS 1.3)

Schools retain full control over student educational records and may request deletion or export at any time. Contact privacy@colorcodedkids.com to exercise school-level data rights.

9. Data Retention

Active Account DataRetained for the duration of the account's active status
Chat History & GradesRetained for 3 years after the student's last login, then permanently deleted
KPI Analytics DataRetained for 3 years; deleted with the associated session data
Server Access LogsRetained for 30 days, then automatically deleted
Pilot Application DataRetained for 2 years or until explicitly requested for deletion
Deleted AccountsAll personal data deleted within 30 days of account deletion request
Backup CopiesRemoved from encrypted backups within 90 days of account deletion

Schools may request immediate deletion of a student's data at any time regardless of the above schedule.

10. Your Rights

10.1 All Users

All users have the right to: access their personal data, correct inaccurate data, request deletion, request restriction of processing, and receive a copy of their data in a portable format. To exercise these rights, email privacy@colorcodedkids.com.

10.2 California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

  • Right to know what categories of personal information we collect and how we use it
  • Right to delete personal information (subject to FERPA and COPPA limitations)
  • Right to opt out of sale of personal information (we do not sell data)
  • Right to non-discrimination for exercising privacy rights
  • Right to correct inaccurate personal information
  • Right to limit use and disclosure of sensitive personal information

Student data is further protected under California Education Code Β§ 49073.1 (SOPIPA). We do not use student data for any commercial purpose unrelated to the student's education.

11. Data Security

We implement technical and organizational measures appropriate to the sensitivity of the data:

  • All data encrypted in transit using TLS 1.3
  • Database encrypted at rest using AES-256
  • Passwords hashed using bcrypt (never stored in plaintext)
  • Authentication tokens are HttpOnly, Secure cookies with appropriate expiration
  • Content safety classification applied to all student messages before AI processing
  • Role-based access control β€” teachers can only access data for their enrolled students
  • Admin access requires ADMIN role; all access is auditable
⚠️
In the event of a data breach affecting student personal information, we will notify affected School Partners within 72 hours of discovery, and affected individuals within the timeframes required by applicable state law. Missouri residents will be notified under Mo. Rev. Stat. Β§ 407.1500.

12. International Transfers

Our services are operated from the United States. If you access Guiden from outside the United States, your data will be transferred to and processed in the United States. For EEA/UK users, such transfers are subject to appropriate safeguards including Standard Contractual Clauses where applicable.

13. Changes to This Policy

We will notify users of material changes to this Privacy Policy by email (for account holders) and by posting a notice on our website at least 30 days before the changes take effect. For changes affecting children's data, we will notify School Partners with at least 30 days' notice and provide schools with the opportunity to terminate the service relationship before the new policy takes effect.

14. Contact Us

Privacy Inquiriesinfo@colorcodedkids.com
General Contactinfo@colorcodedkids.com
Mailing AddressColor Coded Kids LLC, St. Louis, MO
Response TimeWe respond to all privacy requests within 10 business days
Privacy PolicyTerms of ServiceCookie PolicyCOPPAFERPAAccessibilityRefund Policy
Β© 2026 Color Coded Kids LLC Β· St. Louis, MO Β· All rights reserved.