Skip to the policy
Generation 3 Academy
Home About Curriculum The Vessels Enter The Vessels

Draft — not yet in force. Generation 3 Academy is not yet incorporated, so the operator, its registered address and its governing law are shown below as bracketed placeholders. This document has not been reviewed by a lawyer.

Until those brackets are filled in and a lawyer has read it, treat this as a statement of intent rather than a binding policy — and do not take money from families against it. Every open question is listed in the last section.

Privacy Policy

What we record about your child, who can see it, how long we keep it, and how to have it removed. Written to be read by a parent, not by a lawyer.

Version 0.1 (draft) Last updated 6 September 2026 gen3academy.org

On this page

  1. Who we are
  2. The short version
  3. What we collect
  4. What we never collect
  5. Why we are allowed to hold it
  6. The AI teacher, and where a child’s words go
  7. Who can see what
  8. How long we keep it
  9. Other companies involved
  10. Children’s privacy (COPPA and FERPA)
  11. Your rights, and how to use them
  12. How it is protected
  13. Where the data lives
  14. Changes to this policy
  15. Contact
  16. Open questions

1Who we are

Generation 3 Academy operates gen3academy.org and the learning platform called The Vessels, an Islamic Studies course for students in grades 6–12. This policy explains what the site and the platform record about the people who use them.

To be completed before this policy is issued

The operator is [LEGAL ENTITY NAME], a [ENTITY TYPE] formed in [STATE / COUNTRY], whose registered address is [REGISTERED ADDRESS]. Data protection enquiries: [email protected].

Nothing is registered yet. A privacy policy that does not name a legal person is not one anybody can enforce against, or comply with.

Two different things live at this address, and they are not the same in privacy terms:

  • The public pages — this page, the home page, About, Curriculum and The Vessels. They are brochures. They have no accounts, no forms, no analytics and no cookies. You can read every one of them without us learning anything about you beyond what our host records to serve the page.
  • The platform — the game at /vessels and the portal at /portal. Using it needs an account, and an account is issued by a school. That is where everything below applies.

2The short version

If you read nothing else:

  • We hold no email address, no surname, no date of birth, no home address, no phone number, no photograph and no location for any student.
  • There is no advertising, no analytics and no tracking of any kind, anywhere on this site. We have never installed any, and the site’s Content Security Policy would block a third-party script if somebody tried.
  • We set one cookie, and only after you sign in. It keeps you signed in and does nothing else. See the Cookie Policy.
  • Conversations with the AI teacher are recorded, and a teacher can read them. They are deleted automatically after 90 days. This is the part of the policy we most want a parent to read.
  • Nothing is ever sold, rented, or used to build a profile for any purpose other than teaching the student it belongs to.

3What we collect

From students

Data collected from student accounts and why
WhatWhy we need it
UsernameTo sign in. Chosen by the student; it need not be their real name.
First name onlySo a teacher and a parent can tell one account from another.
Grade, and class if the school uses classesTo give the right lessons, and to scope which teacher can see them.
PasswordStored only as a salted hash. We cannot read it, and neither can anyone else.
ProgressInner Flame, score, streak, checkpoints passed, quests completed — the state of the game.
Daily deeds claimedWhich deeds a student says they did, and whether a parent confirmed it.
Conversations with the AI teacherTo check the reasoning is the student’s own. See section 6.
Written reflectionsShort pieces a student writes inside the game.
Grades and teacher remarksSet by their teacher, shown to the student and their parent.
Activity countsHow many checkpoints, quests and lessons on which day. Numbers, not writing.
Sign-in attempts and IP addressBriefly, to stop somebody guessing passwords. Deleted after about a day.

From parents

  • A username, a first name and a hashed password.
  • Which children they are linked to, and whether each link is confirmed.
  • Their decisions on the household deeds their child claimed.
  • Any gift milestone they set — an amount, a target score and a short note to their child.

From teachers and staff

  • A username, a first name and a hashed password; which classes they teach; whether they are the head teacher.
  • A record of every time they open a student’s conversations, view a student, export a roster, reset a password or delete an account.

From everybody who loads a page

Our host, Cloudflare, records the ordinary things a web server records in order to serve a page and to absorb attacks: an IP address, the time, the page requested, and the browser’s user-agent string. We do not combine these with any account, and we do not use them for analytics. We do not run analytics.

4What we never collect

The list below is not a promise about the future — it is a description of the database. There is no column for any of it.

Never held for a student

  • Email address
  • Surname or family name
  • Date of birth or age
  • Home address or phone number
  • Photograph or video of the student
  • Geolocation of any precision
  • Payment or card details
  • Contacts, calendar or device identifiers

Never done, by anyone

  • No advertising, ever
  • No analytics or measurement scripts
  • No social media pixels or share widgets
  • No selling, renting or sharing for money
  • No profiling for anything but teaching
  • No automated decision with a legal or similarly significant effect
  • No behavioural targeting of any kind

Because we hold no email address for a student, we cannot contact your child directly, and a forgotten password has to be reset by their teacher in person. That is a deliberate trade: it costs convenience and buys a category of risk we would rather not carry.

5Why we are allowed to hold it

Accounts are issued through a school for a genuine educational purpose. That shapes the answer everywhere.

In the United States

Under COPPA, an operator of a service directed to children under 13 needs verifiable parental consent. Where a school has contracted with us to provide an educational service, the school may give that consent on parents’ behalf for the educational context. That is the ordinary route for classroom software, and it is the route we rely on. We also ask the family to accept the Family Agreement at registration, so a parent sees the same facts directly.

Under FERPA, where student records are involved we act as a school official with a legitimate educational interest, under the school’s direct control. We do not use student records for our own purposes, and we do not disclose them onward except as this policy describes.

If a family is in the UK or the EU

Our lawful bases would be performance of a contract (Art. 6(1)(b)) for the account and progress needed to deliver the course the family enrolled in, and our legitimate interests (Art. 6(1)(f)) for security logging and for a teacher reviewing work for academic honesty. Where consent is the right basis we ask for it, and it can be withdrawn.

Honest limitation

We are not currently set up to serve UK or EU families to that standard. There is no Data Protection Officer, no Article 30 record, no completed Data Protection Impact Assessment for the AI feature, and no signed data processing agreement with the AI providers. If the academy intends to enrol families in the UK or the EU, those must exist first — see section 16.

6The AI teacher, and where a child’s words go

At each checkpoint, a student discusses the lesson with an AI teacher instead of answering multiple choice. The AI asks questions and gives hints. It never gives the answer, never invents a verse or a hadith, and never issues a religious ruling.

Please read this part

These conversations are recorded, and the student’s teacher can read them. That is how the school checks a student reasoned the answer out rather than talking the AI into passing them.

Students are told this plainly on their own page, in words they will understand. A child who knows they are being read writes more honestly, and the openness is part of the design rather than a formality.

What the AI provider receives. To answer, we send the lesson text and what the student typed to Google (Gemini), or to Groq when Google is unavailable. We do not send the student’s username, their name, their school, or any identifier. The provider sees the words, not the child.

Retention. Conversations are deleted automatically after 90 days. A scheduled job runs nightly.

What parents see. A parent sees whether a checkpoint was passed and the points earned — not the text of what their child wrote. If you want to read your own child’s conversations, ask the school and they will arrange it.

Please talk to your child about this. Children sometimes write personal things into a box that feels private — a worry, a family situation. Ask them to treat the AI teacher as they would a teacher sitting beside them, because that is what it is.

Not yet settled

We have not yet signed a data processing agreement with Google or with Groq covering student data, and we have not yet obtained a contractual commitment that they will not train models on what is sent. Until we have, do not enter anything into the AI teacher that you would mind a third party holding.

7Who can see what

Which role can see which category of a student's data
StudentParentTeacherHead teacher
Their own progressYesTheir childrenTheir classEveryone
Another child’s progressNoNoNot other classesYes
AI conversationsTheir ownResult onlyTheir classEveryone
Grades and remarksTheir ownTheir childrenSets themSets them
Deed confirmationsTheir ownConfirms themTheir classEveryone
Gift milestone a parent setTheir ownTheir ownTheir classEveryone

A family code alone never opens a child’s record. When somebody joins using a child’s family code, it creates a request, and the student has to accept it. Until they do, that person sees nothing but the child’s first name. Usernames can be guessed; if naming one were enough to become a child’s parent, a stranger could read their progress.

Every time a teacher opens a child’s conversations, that is recorded — who looked, at whose, and when. An adult reading a child’s private writing should leave a trace.

8How long we keep it

Retention period for each category of data
WhatKept for
AI conversations90 days, then deleted automatically every night
Sign-in attempts and IP addressAbout 24 hours
Rate-limiting recordsAbout 2 days
Sign-in sessions30 days, or until sign-out
Activity counts1 year — counts only, never writing
Account, progress, grades, deeds, reflectionsUntil the account is deleted

Ask the school to delete your child’s account at any time and it goes, along with their progress, deeds, grades, reflections and conversations. Deletion cannot be undone.

The one thing that survives, and why

Deleting an account removes the progress, the deeds, the grades, the reflections, the conversations and the record of which flame awards were made. That last one used to survive: each row held a quest reference and a date, and because the quest list is a public file on this site, that was enough to reconstruct what a child claimed to have done, day by day. It is now deleted with everything else.

What deliberately remains is the staff audit log — the record of which adult opened which child’s private writing, and when. The child’s identifier is redacted from those entries at deletion, so the rows still prove that a member of staff read something on a given date without naming the child. Erasing the log itself would let a deletion destroy the evidence of who had been reading.

9Other companies involved

Running the platform means a small number of other companies handle data on our behalf. There are no analytics providers, no advertising networks and no social media trackers on this list, because we use none.

Third parties that process data, and what each receives
CompanyWhat they doWhat they receive
CloudflareHosts the site, the database and the APIEverything. All student data is stored here.
Google (Gemini)Provides the AI teacherLesson text and what a student typed. No name, no username, no identifier.
GroqBackup AI provider, used when Google is unavailableThe same content, on the same terms.
everyayah.comSupplies the Qur’an recitation audioAn IP address, when a student plays a verse.

Google Fonts was removed on 6 September 2026. Every page used to fetch its typefaces from fonts.googleapis.com, which handed Google an IP address on every page load of a children’s service. The fonts are now served from this site. The only remaining third-party request a browser makes is the recitation audio, and only when a student presses play.

10Children’s privacy (COPPA and FERPA)

This platform is built for children, so the following are commitments rather than boilerplate.

  • We collect from a child only what the platform needs to teach them. Section 4 lists what we deliberately do without.
  • We do not condition a child’s participation on giving us more than is reasonably necessary.
  • We do not use a child’s data for advertising, for behavioural profiling, or to build any commercial audience.
  • We do not knowingly allow a child to make their information public. There is no chat between students, no public profile and no user-to-user messaging.
  • A parent may review what we hold about their child, ask us to correct it, and ask us to delete it — and may refuse further collection while keeping what has already been taught. Section 11 says how.

Where the school is the FERPA record-holder, requests to inspect or amend an education record are handled by the school, and we support the school in answering them.

11Your rights, and how to use them

Whatever jurisdiction you are in, you may ask us to:

  • See what we hold about your child;
  • Correct anything wrong;
  • Delete the account and everything attached to it;
  • Export it in a portable form;
  • Stop a particular use, or object to it;
  • Complain to a regulator — in the UK the Information Commissioner’s Office, in the EU your national supervisory authority, in the US your state Attorney General.

Ask your child’s teacher, or write to [email protected]. We will respond within 30 days. We will never charge for a first request, and we will never make you give a reason.

Honest limitation

Today these requests are handled by hand: a teacher performs the deletion, and an export is assembled manually. There is no self-service button in the portal yet, and the audit log that records who read a child’s conversations has no route that would let us show it to you. Both are on the fix list. Until they exist, the commitment above is a human promise rather than a product feature, and you should hold us to it in writing.

12How it is protected

  • The whole site is served over HTTPS only.
  • Passwords are stored as salted hashes, never in a form we could read.
  • The session cookie is HttpOnly and Secure, so no script on the page can read it and it never travels unencrypted.
  • Repeated failed sign-ins are rate-limited and briefly locked out.
  • A Content Security Policy blocks third-party scripts, framing and any network call to a host not on a short fixed list. Adding a tracker would visibly break the page rather than quietly work.
  • A teacher can only reach students in their own class; only the head teacher sees the whole academy.
  • Every staff read of a child’s conversations is written to an audit log.

No system is perfectly secure. If we discover a breach affecting personal data, we will tell the school and affected families without undue delay, and notify regulators where the law requires it.

13Where the data lives

Data is stored on Cloudflare’s network, and Cloudflare’s D1 database, which may place data in the United States or in other countries where Cloudflare operates. The AI providers process requests in the United States.

If we serve families in the UK or the EU, transfers out of those regions need an approved mechanism — Standard Contractual Clauses, or the UK Addendum, plus a transfer risk assessment. Those are not in place yet. Section 16.

14Changes to this policy

If we change what we collect, how long we keep it, or who can see it, we will change the date at the top and tell the school before the change takes effect, asking them to pass it on to families. For a change that materially reduces protection for a child, we will seek fresh consent rather than rely on a quiet update.

Previous versions are kept, and we will supply one on request.

15Contact

Privacy questions, or a request to see, correct, export or delete data:

  • Email [email protected]
  • Or speak to your child’s teacher, who can act immediately

Postal address: [REGISTERED ADDRESS — to be completed].

16Open questions

Published rather than hidden, because a policy that quietly overstates its own readiness is worse than one that admits what is missing. Each of these must be closed before this document stops being a draft.

  1. The legal entity, its type, its formation state and its registered address.
  2. A lawyer’s review of this policy, the Terms, and the Family Agreement.
  3. A signed data processing agreement with Google and with Groq covering student data, including a commitment not to train on it.
  4. A written agreement with each school setting out that we act under its direction, and naming who at the school answers data requests.
  5. Whether any family will be in the UK, the EU or Canada — which would add a Data Protection Impact Assessment, an Article 30 record, transfer safeguards, and possibly a representative and a Data Protection Officer.
  6. A family-facing route to export and delete data, rather than a manual one.
  7. A route that lets a school read the audit log it is meant to hold us to.
  8. What happens to accounts at the end of a school year.

The other documents

  • Terms & Conditions
  • Cookie Policy
  • Refund Policy
  • Family Agreement
Generation 3 Academy · Preparing the Third Generation
Curriculum content is under scholarly review. · Enter The Vessels
Privacy Terms Cookies Refunds Family Agreement