Skip to content
KidsKnowRights

Privacy Policy

Last reviewed: 2026-07-30

Draft policy. This text was prepared editorially and must be reviewed by a licensed attorney before it can be considered final.

The short version

This site is built to need as little of your information as possible. You can read every lesson, practice every scenario, print every card, use the Rights Navigator, and ask the assistant a question without creating an account, giving your name, or being tracked across the web. There are no advertising trackers, no analytics companies, no social media pixels, and nothing here is ever sold or shared for marketing.

Who this policy is for

Most people reading this site are young, and many are under 18. That shaped every decision below. Where a feature could work either by collecting something or by not collecting it, it does not collect it. Where a record would be useful to us but risky for a reader, the record does not exist.

What we collect, and when

Forms you choose to send. If you submit the partnership or contact form, we receive what you type — typically a name, an email address, an organization, and your message. We use it only to respond to your request, and we ask you not to include confidential legal details.

An optional account, if you create one. It stores a username you choose, a display name, a password (kept only as a salted PBKDF2 hash — we cannot read it), an optional recovery email, your language preference, and which lessons, scenarios, or articles you marked as finished. That is the complete list. We do not ask for your real name, age, birthday, school, address, or phone number, and there is no field to enter them.

Aggregate page counts. We count how many times each page was viewed, per day and per language. No IP address, cookie, device identifier, session, account link, or referring website is recorded with that count. Because there is no per-visitor identifier at all, we can tell you how many times a page was read and we genuinely cannot tell how many people read it — and we would rather report the true number than estimate a flattering one. Admin and account pages are never counted.

Server logs. Like nearly every website, our hosting infrastructure keeps short-lived technical logs for security and reliability. We do not use them for analytics.

The assistant, and why it stores nothing you type

The question you type into the assistant is never written to our database. Not the text, not a summary, not a copy for quality review. The only thing recorded is a counter: on this day, in this language, a question about this topic was asked, and whether the assistant found site content to point at.

The reason is specific. A young person might ask that assistant about a family member's immigration status, an injury at home, or a school discipline case. A log of those questions would be a genuine danger to the people who most need this site, so there is nowhere to put one. If a question is sent to a language model to be reworded, it is sent for that request only and is not used to train anything.

We still ask you not to type personal details into it — your name, address, school, immigration status, medical information, or the specifics of a real case. The assistant is for general questions, and a real situation deserves a real person.

What we never do

We never sell, rent, or trade information about you. We never place advertising trackers, third-party analytics, or social media pixels. We never build a profile of a reader, link your reading to an advertising identity, or share what you have read with anyone. No administrator screen in this project shows an individual learner's username, email, or progress, because no endpoint returns it.

Cookies

We set no advertising or analytics cookies. If you sign in to an optional account, two cookies are set: one holds an opaque session identifier and is HttpOnly, so no script on the page can read it; the other holds a value used to protect your account against cross-site request forgery. Both disappear when you sign out. Where a lesson remembers your place mid-page, that lives in your own browser's session storage and is never sent to us.

Your choices, and deleting your account

You can use this entire site without an account. If you have one, you can change your display name, add or remove a recovery email, change your password, and delete the account outright from the Your progress page. Deleting removes the account, its sessions, and all of its progress immediately. There is no archived copy and no recovery window, which is the point.

For anything else — a question about your data, or a request to delete a form submission you sent us — write to us at the address at the bottom of this page and we will handle it.

Children's privacy

This site is written for young people, and we designed it so that a reader under 13 can use everything it offers without providing personal information: no account is required for any lesson, scenario, card, article, the Rights Navigator, or the assistant. If you are a parent or guardian and believe a child has provided information you would like removed, write to us and we will delete it.

Security

Passwords are stored only as salted PBKDF2-HMAC-SHA256 hashes and are never readable by us, by an administrator, or in any log. Sessions are opaque server-side records rather than data encoded in a cookie. The site is served over HTTPS. No system is perfect, and if we ever become aware of a breach affecting your information we will say so plainly rather than quietly.

Changes to this policy

If this policy changes in a way that affects what we collect or how we use it, we will update the date at the top of this page. The review status above is honest: this text was written editorially and still needs a licensed attorney's review before it should be treated as final.

Questions: info@kidsknowrights.com