This page is the beta operating charter, not a lawyer-reviewed privacy policy.
Parent-managed records.
Data-light by design.
This beta charter explains what Dungeon Academy should collect, what it should avoid, and what must be finished before broad child-data enrollment.
This is not a final legal policy.
It is the operating charter for the current beta while the formal privacy notice, consent logs, retention policy, vendor inventory, and deletion workflow are prepared.
Broad enrollment should wait for durable consent logs, access controls, deletion handling, and account recovery.
Learner records should be parent-facing and private, not published as social profiles or public leaderboards.
The product should avoid collecting address, school ID, health data, precise location, or payment details inside child-facing play.
Dungeon Academy should not ask a child to manage legal or billing decisions.
The current product focus is learner profile, guardian email, consent state, progress, reports, and sync receipts.
The public demo stays open, but full learner records belong behind parent-managed access.
The academy should not rely on behavioral advertising, public child profiles, or social posting loops.
What parents should understand in one minute
The privacy page should not read like fog. Dungeon Academy records should exist to make learning visible to parents, not to build an ad profile or public child identity.
To show parents what the learner tried, completed, explained, and should do next.
The parent or guardian should control membership, records, reports, consent, correction, export, and deletion requests.
The sampler and public information pages can be used without creating a child account.
Learner profiles, proof work, progress, reports, and family planning belong inside parent-managed access.
Data the school loop may use
Guardian email, parent account ID, member state, and sign-in/session signals when the parent dashboard is used.
Display name, age band, learning path, child profile ID, and consent version in beta records.
Completed rooms, attempts, answers, XP, mastery status, transcript entries, weekly goals, and report packets.
Sync IDs, timestamps, route state, membership status checks, and basic server records needed to operate the beta.
What families should be able to do
Parents should be able to see the learner record, reports, progress, and sync receipts tied to their family account.
Parents should be able to request correction of profile details or learning records that are wrong.
Parents should be able to copy, print, or download reports and mastery packets for their own records.
Parents should have a clear support path to request deletion of beta learner records before broad launch.
Data the school should not ask a child for
Stripe handles billing in the parent path; payment details should not be collected inside child-facing play.
The school does not need GPS or precise location to teach lessons or create reports.
No public friends list, child DMs, public profiles, or unmoderated student posting layer belongs in the current product.
Dungeon Academy learning access should stay inside the parent-managed family account path.
Privacy launch gates
Convert this charter into a formal privacy policy, terms, deletion process, and retention schedule.
Store parent consent, privacy version, terms version, and revocation history in durable backend records.
Document hosting, auth, AI media, analytics, payment, email, and support providers before scaling.
Give parents a safe way to recover access without exposing learner records.
Use parent-specific membership records and checkout receipts for paid Academy access.
Sources parents and counsel should review
These links are not a substitute for legal review. They are the public reference points the beta should track while privacy work matures.
Official rule page for online services directed to children under 13 or with actual knowledge of child users.
Official sourceFTC COPPA compliance planFTC business guidance for determining coverage and planning notice, consent, and parent rights.
Official sourceU.S. Department of Education Student PrivacyFederal student privacy resources, including FERPA and PPRA guidance.
Official sourceFERPA overviewDepartment of Education FERPA resources for education records and parent/student rights.
Official sourceKeep the beta small until the records layer is durable.
The public sampler stays data-light. Full-school access, parent records, and family tools remain protected while consent, deletion handling, checkout entitlements, and account recovery become production-grade.
Read beta termsBest next step after reviewing how parent-managed data should work.
