Skip to content

Privacy policy

Last updated 23 August 2026 · Draft for legal review before production launch

WonderMind is built around a simple rule: collect the least data needed to help someone learn how AI works. WonderMind is an independent product concept. No incorporated legal entity is named on this evaluation site. Production operators must name the company, appoint a privacy contact, and finish counsel review before collecting real children's data.

What we collect
We collect account credentials, a learner first name, age/stage, preferences, learning artifacts, progress evidence, and safety events needed to provide the service. We do not need a learner's address, school name, phone number, or precise location.
How we use data
We use data to authenticate users, personalize curriculum depth, save learning work, enforce safety and limits, and show parent-facing aggregate progress. We do not sell personal information or use behavioral advertising for children.
Children's privacy
This evaluation demo is designed around parental consent, data minimization, and PIN login for children. It is not a finished COPPA or GDPR-K program. Do not enroll a real under-13 child as production data until counsel, verifiable consent, and a staffed rights mailbox exist. See /help/coppa-basics.
Named processors
This site's Content-Security-Policy already names the stack. Production operators must put each vendor under contract before launch.
Your choices
Parents can export a learner JSON archive on any plan, delete a child profile from Controls, or close the grown-up account in the parent dashboard. Analytics can be disabled in the browser. CCPA-style do-not-sell: we do not sell personal information — see /do-not-sell.
Retention and security
This demo deletes child profiles immediately. A production 30-day window is a design goal, not a claim that backups and key rotation are finished here. See /security.
Subprocessors

Vercel. Application hosting, CDN, and serverless runtime (United States (and Vercel regions you configure)).

Vercel AI Gateway. Model routing for the Guide and related AI tools (United States (provider regions vary)).

Stripe. Card checkout, invoices, and customer portal — only when live billing is connected (United States / Stripe regions).

Upstash. Optional Redis rate limiting (United States / EU depending on operator config).

Resend. Transactional email (verification, magic links, password reset) when configured (United States).

A longer operator-facing summary lives on the DPA page.

Questions or rights requests: privacy@wondermind.app. This draft is not a substitute for counsel review or a completed data-processing inventory.

Product analytics

Anonymous page-view analytics are enabled when the site operator turns them on.