For parents (COPPA notice)
Last updated: 2026-06-27
Why you're reading this
Your child uses (or is about to use) Eaalim Lessons — a Quran and Arabic learning platform. We're required by the U.S. Children's Online Privacy Protection Act (COPPA) to tell you exactly what we collect from children under 13, why, and how you can review or remove it.
We're also designed to meet the UK Information Commissioner's (ICO) Age-Appropriate Design Code, so the same protections apply to UK families.
What we collect from your child
The full list — nothing else:
- Display name(e.g. "Aisha") — set by you or by the teacher when the account is created.
- Arabic name (optional) — for personalised lesson content.
- Student ID — an auto-generated identifier (e.g. STU-001). This is how your child signs in — no password, no email.
- Lesson attempts and scores — what blocks the child completed and how they performed, so the teacher can give feedback.
- Audio recordings— when a block asks the child to recite, the recording is sent to their teacher for review. It's deleted from our servers 90 days after the lesson is graded.
- Certificates earned — the lessons your child has completed, displayed as a printable PDF certificate.
We do not collect: real name (unless you provide it as display name), home address, phone number, school name, geolocation, photographs, or biometric data.
What we don't collect (advertising)
Eaalim Lessons has no advertising. We don't show ads to children. We don't share their data with advertisers, data brokers, or third-party marketing services. We don't use behavioural profiling.
How parental consent works
Under COPPA, we need verifiable parental consent before collecting personal information from a child under 13. In our setup, you give consent in one of two ways:
- Family plan signup:if you create a parent account and add students yourself, your account creation + payment information serves as verifiable consent under §312.5(b)(2) of the COPPA Rule ("monetary transaction" method).
- Teacher / school enrollment:if a teacher adds your child to a class, the teacher is acting on your behalf under §312.5(c)(6) ("school exception") — the teacher must have already obtained your written consent offline. We provide tools to help teachers track this.
Your rights as a parent
You can, at any time:
- Review the personal information we have about your child.
- Have us delete that information (we'll do so within 14 days of receiving a written request).
- Refuse to allow us to collect more information about your child going forward.
- Have your child's account terminated entirely.
To exercise any of these rights, contact us with your child's Student ID and the name of the parent account holder. We may ask for a small piece of verification (e.g. the email address on the family plan) to confirm you are the parent before acting.
A self-serve "review and delete my child's data" page is on our short-term roadmap. Until it launches, email is the fastest path.
How long we keep your child's data
- Active accounts: for as long as your child is enrolled.
- After account deletion: 30-day soft-delete grace period (in case of accident), then permanent hard-delete.
- Audio recordings: 90 days after the lesson is graded, then auto-purged.
- Certificates: we keep certificate metadata so the public verification URL stays valid; you can request removal at any time.
Third parties involved in processing
We use the following service providers to operate the platform. Each one only processes data on our behalf and is contractually bound to keep it confidential:
- Neon — database hosting.
- Stripe — payment processing (parent accounts only; never children).
- Resend — email delivery (parents + teachers only; never children).
- UploadThing — audio + certificate file storage.
- Pusher — real-time updates to teachers.
- Inngest — background tasks (certificate generation, etc.).
PostHog and Sentry are disabled by default. They only activate if a parent or teacher explicitly opts in via cookie preferences — never for child sessions.
Questions?
Contact us and we'll respond within 5 business days. For COPPA-specific questions, please reference "COPPA inquiry" in the subject line so we can route quickly.
You may also contact the U.S. Federal Trade Commission at ftc.gov/coppa or the UK Information Commissioner's Office at ico.org.uk.