Privacy Policy
Last updated: April 27, 2026
1. Introduction
Dex ("Dex," "we," "us," or "our") is an AI-powered math tutoring app designed for children. We are committed to protecting the privacy of children who use our app and their parents or guardians. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Dex complies with the Children's Online Privacy Protection Act (COPPA) and the EU/UK General Data Protection Regulation (GDPR) where applicable. The data controller is Dex, reachable at the contact details at the bottom of this policy.
2. Information We Collect
From Children (via the iPad app):
- First name and grade level (entered during setup)
- Math problem answers, scores, and progress data
- Voice input during tutoring sessions (processed in real-time, not stored)
- Photos of written math work that the child takes to input a problem (processed in real-time for problem recognition, then discarded — not stored on our servers)
- Chat transcripts from tutoring sessions (stored locally on the child's iPad; used to power session replays and parent analytics — not uploaded to our servers)
- Periodic chalkboard screenshots taken during tutoring sessions (stored locally on the child's iPad; used to power session replays and parent analytics — not uploaded to our servers)
From Parents (via the web dashboard):
- Email address (used for sign-in and linking to child profiles)
- Notification preferences
Automatically Collected:
- IP address (used only for rate limiting, not stored long-term)
- Anonymous usage analytics (e.g., features used, problems solved, session duration) to improve the app. This data is not linked to any child's identity.
3. How We Use Information
- To provide personalized math tutoring
- To track learning progress and display it to parents
- To send email notifications to parents (if opted in)
- To prevent abuse and enforce rate limits
- To collect anonymous usage analytics to improve the app experience
We do not use children's data for advertising, profiling, or any purpose unrelated to the tutoring experience.
4. Third-Party Services
We use the following services to operate Dex:
- Anthropic (Claude AI) — powers the tutoring conversations. Child messages are sent to Claude for real-time responses and are subject to Anthropic's Privacy Policy.
- Google Gemini — backup AI service used when our primary AI is unavailable. Child messages may be sent to Gemini for tutoring responses. No data is stored by Google beyond processing.
- ElevenLabs — provides text-to-speech voices for tutor characters. Audio is generated in real-time and is not stored.
- Deepgram — provides speech-to-text transcription. Audio is streamed in real-time and is not stored.
- Supabase — hosts our database and authentication. Data is encrypted at rest and in transit.
- RevenueCat — manages subscription purchases. No personal data is shared beyond purchase receipts.
- Google Sign-In — optional authentication method. Only email address is accessed for account identification.
- Resend — sends transactional emails to parents, such as PIN reset codes and notifications. Only parent email addresses are shared.
- PostHog — anonymous product analytics. Tracks feature usage and app performance to help us improve Dex. No personal information is collected or linked to individual children.
We do not sell or share children's personal information with any third party for commercial purposes.
5. Parental Consent
In accordance with COPPA, we require verifiable parental consent before collecting or using a child's information. Parents provide consent by signing in with their email address and accepting this Privacy Policy during account creation. Parents may withdraw consent at any time by deleting their account.
6. Parental Rights
As a parent or guardian, you have the right to:
- Review your child's personal information (via the Parent Dashboard)
- Request deletion of your child's data
- Delete your entire account and all associated data
- Refuse further collection of your child's information
You can delete all data at any time using the "Delete My Account & All Data" button in the Parent Dashboard, or by contacting us at the email below.
7. Your Rights Under GDPR (EU/UK Users)
If you are located in the European Economic Area or the United Kingdom, you have the following rights under GDPR / UK GDPR in addition to the parental rights described above:
- Access — request a copy of the personal data we hold about you and your child. Use the "Export My Data" option in Help & Legal inside the app, or email us.
- Rectification — correct inaccurate information (e.g., child's grade or display name) directly in the Parent Dashboard.
- Erasure — delete your account and all associated data via "Delete Account & All Data" in Help & Legal.
- Portability — receive your data in a machine-readable JSON format (same Export option as above).
- Restriction & Objection — ask us to stop or limit how we process your data. Email us and we'll respond within 30 days.
- Withdraw consent — revoke consent for any consent-based processing at any time. Doing so doesn't affect lawful processing already carried out.
- Lodge a complaint — if you believe we've mishandled your data, you may contact your national data protection authority.
Lawful basis. We process personal data on these legal bases: (a) performance of contract — providing the tutoring service the parent signed up for; (b) consent — for marketing emails and any optional processing (revocable in app settings); (c) legitimate interests — fraud prevention, abuse mitigation, security, and product analytics balanced against your privacy; and (d) legal obligation — where retention or disclosure is required by law.
International transfers. Dex is operated from the United States. The third-party services listed above (Anthropic, Google Gemini, ElevenLabs, Deepgram, Supabase, RevenueCat, Resend, PostHog, Google Sign-In) may also process data outside the EU/UK. Each vendor's standard terms include the European Commission's Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism for international transfers.
Automated decision-making. Dex's AI tutor adapts difficulty and explanations to a child's answers. This is not automated decision-making that produces legal or similarly significant effects under GDPR Article 22.
8. Data Retention & Deletion
We retain child data only as long as the account is active. When a parent deletes their account, all associated children's data (progress, scores, activity logs, and redemptions) is permanently deleted from our database. Rate limit logs are automatically purged after 24 hours.
Chat transcripts and chalkboard screenshots are stored locally on the child's iPad, not on our servers. They are removed when the child profile is deleted from the app or when the app is uninstalled.
9. Data Security
We use industry-standard security measures including: encrypted data transmission (TLS), encrypted data at rest, row-level security ensuring parents can only access their own children's data, rate limiting on all API endpoints, and server-side validation of all data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify parents via email before the changes take effect.
11. Contact Us
For privacy questions, GDPR / COPPA requests, or to exercise any of the rights described above:
privacy@learnwithdex.com
For all other questions, you can reach us at alex@learnwithdex.com. We aim to respond to all privacy requests within 30 days, in line with GDPR Article 12(3).