Home
Legal

HeyLabs AI Privacy Policy

Last Updated: March 15, 2026

Section 1: Introduction

HeyLabs AI is an educational AI platform committed to protecting user privacy, particularly for children. The company complies with the Children's Online Privacy Protection Act (COPPA) for users under 13 and follows general privacy best practices for older users.

The policy applies to all users of HeyLabsAI.com, whether they are children, parents, or educators. Children under 13 require parental consent before data collection, while users 13 and older are processed according to applicable privacy laws.

Section 2: Information We Collect

The platform minimizes personal information collection, particularly from children. Data gathered serves only essential operational and educational purposes.

For All Users (Under and Over 13)

The company may collect:

  • Age or birth month/year (age verification)
  • Learning preferences and interests
  • Usage data (session history, time spent, question types)
  • Progress records (completed lessons, badges, feedback)
  • Login credentials (usernames and passwords; real names optional)
  • Parent or teacher email addresses (account management and notifications)

For Children Under 13

The platform does not collect contact details, photos, or location information without parental permission. Parental notification and consent are required before storing or sharing a child's learning progress. Data is deleted within 7 days if consent isn't obtained.

For Users Aged 13 and Over

Email addresses may be collected and progress sharing permitted without additional parental consent. Data collection remains limited to educational and operational purposes, and users can access or delete personal information upon request.

The platform explicitly does not support public posts, community features, or advertising networks that track user data.

Section 3: Age Screening

HeyLabs AI uses a neutral age-determination process for student accounts only, complying with COPPA requirements.

Student Accounts

During registration, children provide their birth month and year. The age entry form remains neutral without encouraging or discouraging age estimates.

If a user is under 13:

  • Temporary platform access is allowed while parental consent is requested
  • The child enters their parent's or guardian's email address
  • A direct notification is sent to the parent requesting verifiable consent
  • Without consent within 7 days, the account is deactivated and all data permanently deleted

Parent and Teacher Accounts

Age information is not collected for parent or teacher accounts. These users create accounts using email or single sign-on options (such as Google Sign-In) and receive standard privacy protections.

Section 5: How We Use Information

HeyLabs AI collects limited information to provide safe, personalized educational experiences while maintaining privacy.

For All Users

Collected information (age, topics, usage patterns) is used to:

  • Personalize learning recommendations and AI interactions
  • Provide progress-tracking badges and motivational feedback
  • Maintain account security and system integrity
  • Conduct usage analytics for service improvement

The platform does not use information for marketing or behavioral advertising.

For Children Under 13

Information is used solely to:

  • Operate educational platform features
  • Display learning progress to parents and parent-approved teachers
  • Maintain internal records (session history, topic preferences)
  • Obtain parental consent or comply with legal obligations

The platform does not:

  • Display public profiles
  • Enable messaging features
  • Collect contact, photo, or location data
  • Use persistent identifiers beyond session management or internal analytics

For Parents and Teachers

Parent and teacher information is used to:

  • Manage linked student accounts
  • Send progress notifications and reports
  • Provide administration dashboard access
  • Offer product updates or support

Parent and educator accounts are never used for advertising or sold to third parties.

Section 6: Information Sharing

HeyLabs AI prioritizes privacy and security. Personal information is never sold, rented, or disclosed to third parties for marketing or advertising.

Permitted Information Sharing

Information is shared only in these circumstances:

Parent-approved teachers: Children's learning progress (completed lessons, badges, time spent) is shared only after parental approval. Children under 13 cannot initiate sharing independently. Parents may revoke access anytime. Teachers may view data only; no platform communication with children is permitted.

Service providers (internal support only): Trusted service providers supporting the platform (cloud hosting, analytics, customer support) access only anonymized or limited data under strict confidentiality obligations. They cannot use data for other purposes, and behavioral advertising is prohibited.

Legal requirements: Information may be disclosed if required by law, regulation, legal process, or to protect child or user safety (court orders, etc.).

Prohibited Practices

The platform does not:

  • Permit third-party advertising networks or tracking services
  • Display public profiles or leaderboards
  • Allow children to share content publicly (forums, comments, etc.)

Section 7: Data Security and Retention

HeyLabs AI implements comprehensive security measures, particularly for child data.

Security Measures

Technical, administrative, and physical safeguards include:

  • Secure HTTPS encryption during data transmission
  • Password protection with minimum strength requirements
  • Firewalls and access controls restricting data access
  • Role-based permissions for internal staff
  • Confidentiality agreements with employees and service providers

The platform does not store sensitive identifiers (photos, location data) and prohibits public information sharing.

Data Minimization

Only necessary information is collected and retained for educational services. The platform operates with minimum data, especially for children under 13.

Data Retention and Deletion

  • Personal information is retained only as long as necessary for active accounts or legal compliance
  • Without parental consent within 7 days of child registration, accounts and all associated data are deleted
  • Upon parent, teacher, or user request, personal data is promptly and securely deleted
  • All deletions use secure methods preventing recovery

Section 8: Your Rights and Choices

HeyLabs AI respects user control over personal information.

For Parents of Children Under 13

Parents have the right to:

  • Review collected personal information about their child
  • Revoke previously provided consent
  • Delete child accounts and associated data anytime
  • Prevent future information collection or use

Parents exercise these rights by:

  • Logging into their parent account
  • Using dashboard tools
  • Contacting the privacy email address (Section 10)

Identity verification may be required before making changes.

For Users Aged 13 and Over

Users may:

  • Access and update account information
  • Request personal information deletion
  • Review linked student progress data (if authorized)

All users can delete accounts anytime; deletion requests are processed promptly.

Section 9: Data Transfers and Third Parties

HeyLabs AI is operated by a US-based company. Using the platform means personal information may be transferred to, stored in, and processed in the United States where servers and service providers are located.

International Users

Users outside the United States, including the EU, should understand that US data protection laws may differ from those in your jurisdiction. Using HeyLabs AI signifies consent to information transfer and processing as described in this policy.

Third-Party Service Providers

Limited third-party service providers support operations, including:

  • Cloud infrastructure and hosting providers
  • Analytics tools (internal service improvement only)
  • Customer support platforms

Service providers are:

  • Contractually obligated to keep data secure and confidential
  • Prohibited from using children's data for advertising or profiling
  • Permitted access only to minimum necessary data

HeyLabs AI does not use behavioral advertising services or permit external advertising networks.

Section 10: Contact, Updates and Complaints

HeyLabs AI commits to protecting privacy and responding promptly to concerns.

Contact Information

Email: [email protected]

 

Postal Address:

HeyLabs AI (operated by HeyLabs, Inc.)

1207 Delaware Avenue #3426

Wilmington, DE 19806

United States of America

Privacy Policy Updates

The policy may be updated periodically. The "Last Updated" date at the top indicates changes. Significant changes trigger email notifications to parents of registered children or dashboard notifications before taking effect. Regular policy reviews are encouraged.

EU Users

EU residents acknowledge that personal data may be transferred to and processed in the United States. Though US protection may differ, HeyLabs AI implements security measures and complies with this Privacy Policy.

Section 11: GDPR Compliance (For Users in the European Union)

Personal data processing for EU-located users is subject to the General Data Protection Regulation (GDPR).

Data Controller

HeyLabs, Inc.

1207 Delaware Avenue #3426

Wilmington, DE 19806

United States of America

 

Email: [email protected]

For GDPR purposes, HeyLabs, Inc. is the data controller.

Legal Basis for Processing

Personal data is processed under one or more legal bases:

  • Consent – Verifiable parental consent for children under 13; direct consent from users 13+
  • Contractual necessity – Providing educational services, granting access, maintaining accounts
  • Legitimate interests – Improving services, maintaining security, communicating with parents/educators
  • Legal obligations – Complying with applicable laws and regulations

GDPR Rights

EU users have these rights:

  • Right of Access: Request copies of held personal data
  • Right to Rectification: Correct inaccuracies in personal data
  • Right to Erasure: Request data deletion ("right to be forgotten")
  • Right to Restriction: Request processing restrictions in certain circumstances
  • Right to Data Portability: Receive data in structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent anytime without affecting previously processed data

To exercise these rights, contact [email protected].

Data Transfers Outside the EU

Personal data may be transferred to and processed in the United States using contractual and organizational security measures complying with GDPR standards.

Special Note Regarding Children

For EU children under 16, parental or guardian consent is required. The platform requires verifiable parental consent for users under 13 before data collection or storage.

HeyLabs AI · heylabsai.com · [email protected]

HeyLabs, Inc. – 1207 Delaware Ave #3426, Wilmington DE 19806, USA