GiftedRoute

Privacy Policy
← Back to the app

Last updated: September 14, 2026.

This policy explains exactly what GiftedRoute stores about the parent who signs up and about the kids whose CogAT practice is tracked. It's written specifically for this app, not copied from a template — if something below no longer matches how the app behaves, that's a bug to file, not a feature we're hiding.

Short version. One parent account per family. The only thing we store about a kid is a first name, an emoji avatar, their grade level, and their quiz history on this app. Nothing about your kid ever leaves your family's private data unless you export it yourself. You can delete everything from Parent Settings at any time.

1. What we collect

1.1 About the parent (the account holder)

1.2 About each child on the roster

We do not ask for or store: the child's last name, date of birth, home address, phone number, school, photograph, voice, or any real-world identifier beyond the first name the parent chose.

2. What we do not collect

3. Who can see this data

We do not sell or share the data with anyone else. There are no ad networks or "data partners" in our stack.

Voluntary badge sharing. The student dashboard includes an optional "Share" button on each earned badge. If a child taps it, the device's native share sheet opens with a short message containing only the child's first name (as entered by the parent) and the badge name — for example, "Alex just earned the '3-Day Streak' badge on GiftedRoute!" No scores, grades, or any other information are included. Sharing is entirely opt-in and child-initiated; GiftedRoute itself never sends or stores this message. Parents who prefer to disable sharing can remove the child's first name (or use a nickname) in the roster settings.

4. Third-party service providers

The app is built on top of these services. Each one processes only what it needs to do its job, and each one has been chosen because it has a clear commitment to not sell customer data:

5. Parental consent (COPPA)

GiftedRoute is designed for use by kids under 13 with a parent involved. Because of that, we require the parent to explicitly consent to their child's data being collected as described here, before any child data is entered. The consent step is a checkbox shown after sign-up and its timestamp is stored on the family's account row.

The parent can withdraw consent at any time by deleting the account (see §7), which erases every row belonging to that family from our systems.

6. Data retention

Family data stays on our systems as long as the family is actively using the app. "Active" means either the parent has signed in or one of the kids has finished a practice session. If a family goes inactive for 17 months, our nightly job marks the account as pending deletion. If the family is still inactive 60 days after that (so 19 months from last activity), the account is hard-deleted — every row belonging to the family, including the parent's auth account, is removed. Once we've integrated email delivery, we'll send a warning to the parent's email at the moment the account is first marked, so you have the full 60-day window to sign back in if you want to keep the data.

7. Deleting your family's data

Sign in as the parent → Parent area → Settings → "Delete my family's account". Deletion is immediate and permanent — there is no soft delete, no 30-day grace period, and no way for us to bring it back. That's deliberate; when you ask for the data to be gone, it's gone.

8. Exporting your family's data

Sign in as the parent → Parent area → Settings → "Download JSON" or "Download CSV". The JSON export includes every field we have on your family (except password hashes and auth tokens). The CSV export is a spreadsheet-friendly row per practice session.

9. Changes to this policy

If we materially change what data is collected or who can see it, we will update the "Last updated" date at the top of this page and surface a notice inside the app the next time you sign in. Cosmetic edits (fixing a typo, reformatting) may happen silently.

10. Contact

Questions or requests about your family's data: email the address listed on the app's landing page, or open an issue on the app's public repository if one is linked from that page.