HeyLabs AI Privacy Policy
Last Updated: March 15, 2026
Table of Contents
Section 1: Introduction
HeyLabs AI is an educational AI platform committed to protecting user privacy, particularly for children. The company complies with the Children's Online Privacy Protection Act (COPPA) for users under 13 and follows general privacy best practices for older users.
The policy applies to all users of HeyLabsAI.com, whether they are children, parents, or educators. Children under 13 require parental consent before data collection, while users 13 and older are processed according to applicable privacy laws.
Section 2: Information We Collect
The platform minimizes personal information collection, particularly from children. Data gathered serves only essential operational and educational purposes.
For All Users (Under and Over 13)
The company may collect:
- ●Age or birth month/year (age verification)
- ●Learning preferences and interests
- ●Usage data (session history, time spent, question types)
- ●Progress records (completed lessons, badges, feedback)
- ●Login credentials (usernames and passwords; real names optional)
- ●Parent or teacher email addresses (account management and notifications)
For Children Under 13
The platform does not collect contact details, photos, or location information without parental permission. Parental notification and consent are required before storing or sharing a child's learning progress. Data is deleted within 7 days if consent isn't obtained.
For Users Aged 13 and Over
Email addresses may be collected and progress sharing permitted without additional parental consent. Data collection remains limited to educational and operational purposes, and users can access or delete personal information upon request.
The platform explicitly does not support public posts, community features, or advertising networks that track user data.
Section 3: Age Screening
HeyLabs AI uses a neutral age-determination process for student accounts only, complying with COPPA requirements.
Student Accounts
During registration, children provide their birth month and year. The age entry form remains neutral without encouraging or discouraging age estimates.
If a user is under 13:
- ●Temporary platform access is allowed while parental consent is requested
- ●The child enters their parent's or guardian's email address
- ●A direct notification is sent to the parent requesting verifiable consent
- ●Without consent within 7 days, the account is deactivated and all data permanently deleted
Parent and Teacher Accounts
Age information is not collected for parent or teacher accounts. These users create accounts using email or single sign-on options (such as Google Sign-In) and receive standard privacy protections.
Section 4: Parental Consent
HeyLabs AI requires verifiable parental consent before collecting, using, or storing personal information from children under 13, in accordance with COPPA.
Consent Request Process
When a child indicates they are under 13 during registration:
- ●The child enters their parent's or guardian's email address
- ●A direct notification is sent explaining what information may be collected, how it will be used, and the consent process
- ●A link to the full Privacy Policy and approval/decline instructions are provided
Non-Compliance
- ●Children may use the platform in limited mode for up to 7 days while awaiting consent
- ●Without verifiable parental consent within 7 days, the account is deactivated and all data permanently deleted
Acceptable Consent Forms
Depending on feature sensitivity, acceptable consent includes:
- ●Email confirmation from the parent (verification link or reply confirmation)
- ●For public sharing or external communications: stronger forms such as credit card verification, signed consent forms, or telephone/video confirmation
Parental Rights
Parents may:
- ●Review collected personal information about their child
- ●Revoke consent at any time
- ●Request account deletion and associated data removal
Section 5: How We Use Information
HeyLabs AI collects limited information to provide safe, personalized educational experiences while maintaining privacy.
For All Users
Collected information (age, topics, usage patterns) is used to:
- ●Personalize learning recommendations and AI interactions
- ●Provide progress-tracking badges and motivational feedback
- ●Maintain account security and system integrity
- ●Conduct usage analytics for service improvement
The platform does not use information for marketing or behavioral advertising.
For Children Under 13
Information is used solely to:
- ●Operate educational platform features
- ●Display learning progress to parents and parent-approved teachers
- ●Maintain internal records (session history, topic preferences)
- ●Obtain parental consent or comply with legal obligations
The platform does not:
- ●Display public profiles
- ●Enable messaging features
- ●Collect contact, photo, or location data
- ●Use persistent identifiers beyond session management or internal analytics
For Parents and Teachers
Parent and teacher information is used to:
- ●Manage linked student accounts
- ●Send progress notifications and reports
- ●Provide administration dashboard access
- ●Offer product updates or support
Parent and educator accounts are never used for advertising or sold to third parties.
Section 6: Information Sharing
HeyLabs AI prioritizes privacy and security. Personal information is never sold, rented, or disclosed to third parties for marketing or advertising.
Permitted Information Sharing
Information is shared only in these circumstances:
Parent-approved teachers: Children's learning progress (completed lessons, badges, time spent) is shared only after parental approval. Children under 13 cannot initiate sharing independently. Parents may revoke access anytime. Teachers may view data only; no platform communication with children is permitted.
Service providers (internal support only): Trusted service providers supporting the platform (cloud hosting, analytics, customer support) access only anonymized or limited data under strict confidentiality obligations. They cannot use data for other purposes, and behavioral advertising is prohibited.
Legal requirements: Information may be disclosed if required by law, regulation, legal process, or to protect child or user safety (court orders, etc.).
Prohibited Practices
The platform does not:
- ●Permit third-party advertising networks or tracking services
- ●Display public profiles or leaderboards
- ●Allow children to share content publicly (forums, comments, etc.)
Section 7: Data Security and Retention
HeyLabs AI implements comprehensive security measures, particularly for child data.
Security Measures
Technical, administrative, and physical safeguards include:
- ●Secure HTTPS encryption during data transmission
- ●Password protection with minimum strength requirements
- ●Firewalls and access controls restricting data access
- ●Role-based permissions for internal staff
- ●Confidentiality agreements with employees and service providers
The platform does not store sensitive identifiers (photos, location data) and prohibits public information sharing.
Data Minimization
Only necessary information is collected and retained for educational services. The platform operates with minimum data, especially for children under 13.
Data Retention and Deletion
- ●Personal information is retained only as long as necessary for active accounts or legal compliance
- ●Without parental consent within 7 days of child registration, accounts and all associated data are deleted
- ●Upon parent, teacher, or user request, personal data is promptly and securely deleted
- ●All deletions use secure methods preventing recovery
Section 8: Your Rights and Choices
HeyLabs AI respects user control over personal information.
For Parents of Children Under 13
Parents have the right to:
- ●Review collected personal information about their child
- ●Revoke previously provided consent
- ●Delete child accounts and associated data anytime
- ●Prevent future information collection or use
Parents exercise these rights by:
- ●Logging into their parent account
- ●Using dashboard tools
- ●Contacting the privacy email address (Section 10)
Identity verification may be required before making changes.
For Users Aged 13 and Over
Users may:
- ●Access and update account information
- ●Request personal information deletion
- ●Review linked student progress data (if authorized)
All users can delete accounts anytime; deletion requests are processed promptly.
Section 9: Data Transfers and Third Parties
HeyLabs AI is operated by a US-based company. Using the platform means personal information may be transferred to, stored in, and processed in the United States where servers and service providers are located.
International Users
Users outside the United States, including the EU, should understand that US data protection laws may differ from those in your jurisdiction. Using HeyLabs AI signifies consent to information transfer and processing as described in this policy.
Third-Party Service Providers
Limited third-party service providers support operations, including:
- ●Cloud infrastructure and hosting providers
- ●Analytics tools (internal service improvement only)
- ●Customer support platforms
Service providers are:
- ●Contractually obligated to keep data secure and confidential
- ●Prohibited from using children's data for advertising or profiling
- ●Permitted access only to minimum necessary data
HeyLabs AI does not use behavioral advertising services or permit external advertising networks.
Section 10: Contact, Updates and Complaints
HeyLabs AI commits to protecting privacy and responding promptly to concerns.
Contact Information
Postal Address:
HeyLabs AI (operated by HeyLabs, Inc.)
1207 Delaware Avenue #3426
Wilmington, DE 19806
United States of America
Privacy Policy Updates
The policy may be updated periodically. The "Last Updated" date at the top indicates changes. Significant changes trigger email notifications to parents of registered children or dashboard notifications before taking effect. Regular policy reviews are encouraged.
EU Users
EU residents acknowledge that personal data may be transferred to and processed in the United States. Though US protection may differ, HeyLabs AI implements security measures and complies with this Privacy Policy.
Section 11: GDPR Compliance (For Users in the European Union)
Personal data processing for EU-located users is subject to the General Data Protection Regulation (GDPR).
Data Controller
HeyLabs, Inc.
1207 Delaware Avenue #3426
Wilmington, DE 19806
United States of America
For GDPR purposes, HeyLabs, Inc. is the data controller.
Legal Basis for Processing
Personal data is processed under one or more legal bases:
- ●Consent – Verifiable parental consent for children under 13; direct consent from users 13+
- ●Contractual necessity – Providing educational services, granting access, maintaining accounts
- ●Legitimate interests – Improving services, maintaining security, communicating with parents/educators
- ●Legal obligations – Complying with applicable laws and regulations
GDPR Rights
EU users have these rights:
- ●Right of Access: Request copies of held personal data
- ●Right to Rectification: Correct inaccuracies in personal data
- ●Right to Erasure: Request data deletion ("right to be forgotten")
- ●Right to Restriction: Request processing restrictions in certain circumstances
- ●Right to Data Portability: Receive data in structured, machine-readable format
- ●Right to Object: Object to processing based on legitimate interests
- ●Right to Withdraw Consent: Withdraw consent anytime without affecting previously processed data
To exercise these rights, contact [email protected].
Data Transfers Outside the EU
Personal data may be transferred to and processed in the United States using contractual and organizational security measures complying with GDPR standards.
Special Note Regarding Children
For EU children under 16, parental or guardian consent is required. The platform requires verifiable parental consent for users under 13 before data collection or storage.
HeyLabs AI · heylabsai.com · [email protected]
HeyLabs, Inc. – 1207 Delaware Ave #3426, Wilmington DE 19806, USA