Privacy Policy
Airbotix Pty Ltd — Privacy Policy for Kids OpenCode, Airbotix Workshops, and any other product or service operated under the Airbotix or Kids in AI brands (collectively, the "Services").
This is a kid-aware Privacy Policy. We aim to explain what we do in plain English so that a 12-year-old and their parent both understand it.
Last updated: 2026-08-06 · Version: 0.5 (engineering-side draft pending qualified-AU-lawyer review)
In one paragraph
Airbotix collects the smallest amount of information we need to give you a safe coding experience. We never sell your data. We never use your kid's data or code to train AI models. We never show ads inside our products, and no page a child uses carries an advertising tag. Kid project files stay on your family's own computer — they don't come to our servers. The AI conversations get routed through our gateway (DeepRouter) which adds safety filters, and we keep a record of which tools the AI used in your sessions so you (the parent) can see exactly what happened. You can ask for your data, delete it, or close the account at any time. We respond within 14 days.
1. Who we are
| Legal entity | Airbotix Pty Ltd, an Australian proprietary company |
| Registered office | New South Wales, Australia |
| Operator-of-record for kids' data | Airbotix Pty Ltd |
| Privacy Officer | Lightman, Founder · privacy@airbotix.ai |
| Australian Privacy Act 1988 covered? | Yes. We are an APP entity. |
We operate the website airbotix.ai, the Kids in AI brand at kidsinai.org, the kids-opencode command-line tool, and related software.
2. What information we collect, and why
We collect different information depending on who you are and how you interact with us.
2.1 If you are a parent who creates a Family Account
| Information | Why we need it | How long we keep it |
|---|---|---|
| Your email address | To send you account-related messages and to log you in | Until you close your account |
| Your phone number (optional) | Two-factor authentication and account recovery | Until you close your account |
| Your billing details (handled by Airwallex, not stored by us) | To process purchases (Stars Packs and class bookings) | We hold a payment reference only, not card numbers |
| The country and timezone you live in | To bill you correctly, route to a nearby server, and apply the right legal regime | Until you close your account |
| Your family's city, state, and postcode (all optional) | To match you with nearby in-person classes and workshops | Until you close your account |
| Your preferred language and how you heard about us (optional) | To serve you in the right language and understand which channels work | Until you close your account |
| Your consent record — the date, time, and document version current when you accepted our Terms, Privacy Policy, and Parental Consent | To prove we obtained your informed consent, as the Privacy Act requires | For as long as we are required to keep evidence of consent |
We do not collect: your street address, your date of birth, your real name (unless you choose to provide it), your government identifiers, or your social-media handles.
2.2 If you are a child whose parent has set up a Kid Profile
| Information | Why we need it | How long we keep it |
|---|---|---|
| Your age in years (e.g. "9" — never your birthday) | To choose AI behaviour and class level appropriate to your age | Until your parent closes the profile |
| Display nickname (your choice; not your real name) | So the AI can address you and so your work has your label on it | Until you change it or your parent closes the profile |
| A 4-digit sign-in PIN (stored only as a one-way hash — we cannot read it back) | So you can sign in with your family code on your family's devices | Until you or your parent change it, or the profile is closed |
| Course Pack progress | So you can pick up where you left off | Until your parent closes the profile |
| AI audit log (what tools the AI used and when, summarised) | So your parent can see what happened in your sessions and so we can investigate any safety incident | 90 days fully accessible, then 3 years in encrypted archive, then deleted |
| HSC school assessment details — your subjects, each task's name, due date, school-set weight and the mark you achieved out of the maximum, if your parent uses the HSC Planner | So the Planner can show your real school-assessment progress and your next deadline | While the plan is in use, then 12 months after 31 December of that school year, then deleted |
We do not collect: your real name, your birthday, your school's name, your address, your phone, your photo, your voice, your fingerprint, or anything else that could uniquely identify you in the physical world (unless your parent specifically adds it to a project, which we discourage).
About HSC assessment marks. If your parent uses the HSC Planner, the marks they enter are real school results, so we treat them as sensitive. They are only ever visible to your own family — never to another family, never in a shareable link, never in our analytics, and never used to train an AI model. Your parent owns the record: you can see everything saved about you in the Learn app, and a parent can delete any assessment, any subject or the whole plan at any time from the Parent Portal. We also delete plans automatically once the school year they cover has been over for 12 months, whether or not anyone asks.
2.3 If you (parent or child) use the Kids OpenCode CLI
Kids OpenCode runs on your own computer. The kid's code and project files stay on your computer — they never come to our servers.
The only data that leaves your computer is:
| Data | Where it goes | Why |
|---|---|---|
| The text you type into the AI ("I want a portfolio website about dragons") | DeepRouter, our gateway → the AI model (Anthropic / OpenAI / etc.) | So the AI can respond. Stripped of personal identifiers. |
| The AI's response | Back to your computer | So you see it |
| A summary of which AI tool was used (e.g., "wrote a file called index.html") | Our audit-log endpoint | So your parent can see what the AI did. We do not log the file contents. |
| The number of tokens consumed | Our billing endpoint | So we can deduct the right number of Stars from your wallet |
2.4 If you visit airbotix.ai or kidsinai.org
We keep server-side request logs (IP, user-agent, URL, timestamp) for 30 days for security and abuse-prevention purposes. On the airbotix.ai marketing website, Google Analytics 4 and first-party browsing analytics are on by default, and you can turn them off at any time using the Your analytics choice control at the bottom of this page. While they are on we use a random browser-session identifier and campaign labels such as source, medium, campaign, content, landing page, resource open/download and enquiry-form progress. We do not put names, email addresses, phone numbers, children's details, form answers, full IP addresses or full user-agent strings into marketing analytics events. First-party raw marketing events are kept for up to 13 months and daily aggregate channel snapshots for up to 25 months.
We also use advertising measurement tags (Google Ads, and where a campaign is running, Meta or TikTok) on the marketing website so we can tell which advertising brought a family to us. These record that an enquiry happened and which campaign it came from. They never run on Kids Learn, Teacher Console, or any other child-facing surface, and they are also switched off on the playable demo pages on this website (/try and the Story Blocks / Creative Code Studio product demos), because a child is the one using those pages. On those demo pages we still measure usage ourselves, but the advertising signals are withheld, so nothing a child does contributes to an advertising profile. Turning analytics off (see the control at the bottom of this page) also turns these tags off.
2.5 If you contact us by email or phone
We keep the message text in our support system for as long as needed to handle your question, then no more than 24 months.
3. What we DO NOT do with your data
To be explicit:
- ❌ We do not sell your data to anyone. Not for advertising, not for analytics, not for any reason.
- ❌ We do not use your kid's project files, AI conversations, or audit log to train any AI model. Not ours, not anyone else's.
- ❌ We do not sell or share your personal details (name, email, phone, your child's details) with advertisers, data brokers, or social-media platforms. Advertising measurement tags on the public marketing website tell a platform that an enquiry happened and which campaign it came from — never who you are or anything about your child. See §2.4 and §10.
- ❌ We do not embed third-party tracking or advertising pixels on any page a kid uses — not in Kids Learn, and not on the playable demo pages of this website.
- ❌ We do not let anyone outside Airbotix read your kid's audit log, except: when legally required (court order, regulator subpoena) or when investigating a safety incident affecting that specific kid.
- ❌ We do not send marketing communications to children. Adult-parent email accounts may receive product-update emails; opt out anytime.
4. Where your data lives
| Data type | Where stored | Region |
|---|---|---|
| Family / Kid Profile data | Neon Serverless PostgreSQL | AWS ap-southeast-2 (Sydney, Australia) |
| Audit log (90-day hot) | Postgres above | AWS ap-southeast-2 |
| Audit log (3-year cold archive) | AWS S3 with at-rest encryption (AES-256) | AWS ap-southeast-2 |
| AI conversation pipeline | DeepRouter /v1 | DeepRouter operates Singapore + Sydney pop-of-presence |
| Provider data (Anthropic / OpenAI / Doubao) | Their own servers | Per their respective privacy policies — see §5 |
Australian families: your data stays in Australia (Sydney region) for all data we directly control. For AI provider round-trips, the prompt is sent to the provider's region (typically US for OpenAI/Anthropic, China for Doubao); for Anthropic and OpenAI we force Zero Data Retention so they do not keep your data after responding.
5. AI providers and Zero Data Retention
When you use Kids OpenCode, your prompts are sent to a large language model run by Anthropic, OpenAI, Doubao, or another provider we work with. We route every request through our gateway (DeepRouter) which:
- Strips identifying information about you from the request metadata
- Forces Zero Data Retention mode on OpenAI requests (their strictest privacy mode — the data is not retained by OpenAI after the response is sent)
- Forwards a kid-safe system prompt that constrains what the AI will discuss
- Filters content at the input and output (blocks harmful content categories)
The current providers are listed at airbotix.ai/compliance §7 and the list will be kept current.
Each provider has its own privacy policy:
- Anthropic: https://www.anthropic.com/legal/privacy
- OpenAI: https://openai.com/policies/privacy-policy
- Doubao (Volcengine): https://www.volcengine.com/docs/6256/64902
- DeepSeek: https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html
- DeepRouter (our gateway): https://deeprouter.ai/legal/privacy
6. Where your kid's conversations are kept
We treat your kid's conversations with the AI as some of the most sensitive data we hold. Where they live depends on which product your kid uses — and in both cases you, the parent, are in control.
6.1 In the Learn app (app.airbotix.ai)
When your kid creates with the AI in the Learn app, the conversation — each thing the kid asks and each reply the AI gives — is saved inside your Family Account, tied to that specific kid. We store it so your kid can come back and continue where they left off, and so you (and, in a class, the kid's teacher) can replay the full thread and see exactly what happened.
- It lives in our database in AWS Sydney, scoped to your family — no other family can ever see it.
- We never use it to train any AI model, never sell it, and never show ads against it.
- Retention is the same as the rest of your data: fully accessible to you for 90 days, then a 3-year encrypted archive, then deleted.
- When you delete a kid's profile or close the account, the kid's conversations are deleted with it (full deletion within 30 days).
- You can view, export, or delete these conversations any time — see §7, Your rights.
6.2 In Kids OpenCode (the desktop tool)
Kids OpenCode is different by design: your kid's actual project files stay on your own computer — they never come to our servers. There we keep only a short audit log of which tools the AI used (e.g., "wrote a file called index.html"), so you can review the session. The conversation itself is routed through our gateway (DeepRouter) with Zero Data Retention forced on the AI providers — see §5.
6.3 The one-line version
Your kid's chats belong to your family. In the Learn app we keep them safely under your Family Account so you and the kid can look back; on the desktop tool they mostly stay on your own machine. Either way: yours to read, export, or delete — never ours to sell or train on.
7. Your rights and your kid's rights
7.1 Right to access
You can ask us what personal information we hold about you (or your kid). We will provide it within 14 days. Free of charge. Email privacy@airbotix.ai from the parent email on the account.
7.2 Right to correction
If something we hold is wrong, you can ask us to correct it. We will correct within 14 days, or explain why if we disagree.
7.3 Right to delete
You can ask us to delete:
- Your entire family account (all data deleted, full deletion within 30 days)
- A specific kid profile (all that kid's data deleted within 30 days)
- A specific audit-log range
- A specific session
You do not need to ask us for HSC Planner data: a parent can delete a single assessment, a whole subject or the entire plan directly from the Parent Portal, and it is removed immediately. Deleting a subject also deletes the assessments saved under it.
Once deleted, we cannot recover the data. Anonymised aggregate metrics (e.g., "we had 1000 active families this month") may be retained.
One honest exception: backups. Deleting removes the data from our live systems straight away, and from any copy we derive from them. Our encrypted backups are not rewritten — they age out on their normal schedule, so a deleted record can persist in a backup until that copy expires. We do not restore deleted records from backup, and we do not use backups to serve the product.
7.4 Right to export
You can ask us for a machine-readable export (JSON) of all your data. Provided within 14 days. Useful if you want to leave the platform and take your records with you.
7.5 Right to withdraw consent
You can pause AI processing for a kid profile at any time without deleting it. Take a break, come back later.
7.6 Right to complain
If you think we have not handled your data correctly:
- Email us first at
privacy@airbotix.ai— we want to fix things - If you are still unsatisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au/privacy/privacy-complaints
- For online-safety concerns specifically about kid content, you can also contact the eSafety Commissioner at https://www.esafety.gov.au
8. Special protections for children
We follow stricter rules for kids than for adults:
- Default-private: kid projects stay on your family's device. Sharing requires explicit parent + kid action.
- No targeted advertising: ever. To kids or adults.
- No nudge techniques: no streaks, no infinite scroll, no engagement-optimised notifications, no social-comparison metrics.
- No profile-building for advertising: we do not build behavioural profiles of kids.
- AI disclosure: the AI is always clearly identified as AI to the kid.
- Self-harm response: if the AI detects signs of self-harm, it is designed to stop the coding conversation and refer the kid to Kids Helpline (Australia: 1800 55 1800). Like any AI safety layer, detection is not guaranteed — parents remain the primary safeguard.
- Audit logging: parents can see what the AI did, in plain English, in the audit log.
We comply with:
- The Australian Privacy Act 1988 and the Australian Privacy Principles
- The Children's Online Privacy Code 2026 (when it takes effect on 10 December 2026; we have engaged with the OAIC consultation)
- The Online Safety Act 2021 and the Basic Online Safety Expectations
- Anthropic's "Organizations Serving Minors" guidelines
- OpenAI's Under-18 API Guidance
- The Voluntary AI Safety Standard's 10 guardrails
If you live outside Australia, additional local laws may apply. Our public Compliance Statement (airbotix.ai/compliance) summarises which.
9. Data breaches
If we have a data breach that could seriously harm you, we notify you within 30 days (often much sooner) and also notify the OAIC. We do this under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988).
For kid-related breaches, we presume serious harm — meaning we err on the side of notifying you even when the law might not strictly require it.
Our incident response runbook is documented at github.com/kidsinai/kids-opencode/blob/main/docs/runbook/ndb-incident.md for transparency.
10. Cookies and tracking
The airbotix.ai marketing website uses essential storage (login session and language preference). Campaign labels are kept in the current browser session so that, if you voluntarily submit a booking or contact form, we can record which public page or campaign led to that request. This session-only attribution does not send browsing or engagement events.
Google Analytics 4 and Airbotix first-party marketing analytics are on by default on the public marketing website. Australian privacy law does not require us to ask permission before measuring how a website is used, but it does require us to tell you plainly and to give you a genuine way to say no — so this policy describes it, and the Your analytics choice control at the bottom of this page turns it off. Choosing Turn off analytics stops Google Analytics, our first-party events and all advertising tags, and clears the campaign record we had kept for that browser. The choice is remembered for 30 days on that browser, then returns to the default. Clearing browser storage has the same effect sooner.
While analytics is on, we measure aggregate page views, resource reading/downloads, campaign links and enquiry-form conversions across visits. We use this only to understand which public resources and campaigns help families. It is not linked to a child's learning profile, and we do not attempt fingerprinting or cross-device identification.
Advertising measurement tags (Google Ads; Meta or TikTok while such a campaign is running) tell those platforms that an enquiry happened and which campaign produced it. They run only on the parent-facing pages of the public marketing website. They are switched off on /try and on the Story Blocks and Creative Code Studio product-demo pages, because a child is the one using those pages, and they never run in Kids Learn, Teacher Console, or any other child-facing surface.
Social platforms and Metricool provide aggregate post metrics such as impressions, clicks, reactions, comments and shares. We connect those aggregate figures to campaign links; we do not receive or try to identify the individual LinkedIn or social-media user who clicked.
The Kids OpenCode CLI does not use cookies; it is not a web product.
The Airbotix-AI/airbotix-app dashboard (for parents) uses essential cookies only.
11. Changes to this policy
We may update this policy from time to time. When we do:
- Material changes (anything affecting what we collect, share, or how long we retain): we email all active family accounts at least 30 days before the change takes effect
- Minor clarifications: we update the policy and the "last updated" date
The current version of this policy is always at airbotix.ai/privacy. Older versions are at airbotix.ai/privacy/archive/v0.X.
12. Contact
If you have any question about this Policy or your privacy with Airbotix:
| Channel | Contact |
|---|---|
| privacy@airbotix.ai | |
| Postal address available on request via privacy@airbotix.ai | |
| OAIC complaint | https://www.oaic.gov.au/privacy/privacy-complaints |
13. Jurisdiction
This Privacy Policy is governed by the laws of New South Wales, Australia, and the Commonwealth of Australia. For users in other jurisdictions, local consumer-protection and privacy laws may grant additional rights that this Policy cannot waive.
Revision history
| Version | Date | Note |
|---|---|---|
| 0.5 | 2026-08-06 | Marketing-site analytics moved from opt-in to on-by-default with an opt-out notice (Google Consent Mode v2). Disclosed advertising measurement tags (Google Ads / Meta / TikTok) on parent-facing marketing pages, and their exclusion from /try and the product-demo pages plus all child-facing surfaces. Clarified that the "no sharing with advertisers" commitment covers personal details, not the campaign-level conversion signal. /contact messages now go to our booking inbox rather than an email client. Still awaiting AU privacy lawyer confirmation. |
| 0.4 | 2026-08-04 | Names HSC school assessment marks as a collected category for children whose parent uses the HSC Planner: what is stored, that it is family-only and never shared, trained on or put in a link, the parent's immediate self-serve deletion path, and the automatic delete 12 months after the school year ends. States plainly that encrypted backups age out rather than being rewritten. Still awaiting AU privacy lawyer confirmation. |
| 0.3 | 2026-07-21 | Added opt-in 30-day first-party/GA4 marketing analytics, session-only attribution when analytics is declined, Metricool aggregate social metrics, data minimisation and 13/25-month retention disclosures. Still awaiting AU privacy lawyer confirmation. |
| 0.2 | 2026-07-10 | Registration consent record; family profile fields collected at signup (city/state/postcode, language, acquisition channel); kid age in years + hashed sign-in PIN; purchases wording covers class bookings; GA4 marketing-site disclosure (2026-06-12) folded in. Still awaiting AU privacy lawyer confirmation. |
| 0.1 | 2026-05-15 | Engineering-side draft. Awaiting AU privacy lawyer confirmation. |
