Privacy Policy
Effective: October 3, 2026
agarwalmath is a free math website for kids in kindergarten through grade 5. This policy explains what we collect, why, who can see it, and how parents and teachers stay in control.
1. The short version
- Kids can play as guests with nothing collected: their progress stays in the browser.
- Only grown-ups (18 or older) make accounts, with an email and a password. Kids never have email addresses or accounts of their own.
- A kid's profile is a nickname we make up (like “Blue Tiger 42”), an animal picture, and a grade. We never ask for a child's real name, photo, birthday, address, or school.
- We save kids' game progress and answers so their grown-up can see how they're doing.
- There is no chat, no ads, and no selling or renting of anyone's information. We don't use advertising or tracking cookies.
- A teacher sees a kid's practice only if the kid's parent agrees, or for a class profile the teacher made with the school's permission.
- Parents can see, stop sharing, and delete their kids' information at any time.
2. Who we are
agarwalmath is run by Devraj Agarwal (“we”, “us”). You can reach us at agarwalmath@gmail.com. We're the operator responsible for the information described here.
3. Children's privacy (COPPA)
Our site is made for children under 13, so we follow the U.S. Children's Online Privacy Protection Act (COPPA). We collect information about a child only through an account a parent (or a teacher, for a class) controls:
- Guests: a child can play without any account. Their progress is kept only in that browser and isn't sent to us. Guests can join a live race or play a friend's challenge; then only their score is shown, as “Guest”.
- Parent-made profiles: a parent creates the account, confirms they're 18 or older and the child's parent or guardian, and creates each child's profile. Creating a profile is the parent's consent to the collection described in this policy. The parent can review the child's information on the child's Progress page and delete it at any time.
- Class profiles: a teacher can create profiles for their class after confirming they have their school's (or the parents') permission. In that case the school gives consent on the parents' behalf, for school use only. See Classes and schools.
We don't require a child to give more information than a game needs, we don't let children post anything other people can read, and we don't show children ads.
4. What we collect
From grown-ups
- Email address and password (the password is stored only as a secure, one-way hash by our sign-in service).
- Your time zone (so weeks, class reports, and school hours follow where you live).
- Names you give to groups or classes you make (like “Mrs. Lee's Grade 2”), team goals, and class assignments.
- For teachers: the date you confirmed you have permission to make class profiles.
About each child profile
- The generated nickname, the chosen animal picture, and the grade. Our database refuses anything else, so a real name can't be saved as a nickname.
- Game progress: points, coins, levels, badges, items bought in Digit's House, streaks, and settings like sound and read-aloud.
- Rounds and answers: for each question, the computer-made question, the child's answer, whether it was right, how long it took, the difficulty, the Common Core standard, and whether a hint was shown.
- If the parent turns on kid login: a username made from the nickname and a 4-digit PIN (stored only as a secure hash). For class profiles: a login card code.
- Groups and classes the child is in, challenges they make or play, and live races they join.
Automatically
- Our hosting and database services keep short-lived technical logs (like IP addresses, browser type, and the time of a request) to run the site, stop abuse, and fix problems. We don't use them to build profiles of anyone.
- If something on the site breaks, we save an error report (the page's address without any codes, the error message, and the time; no names or answers) so we can fix it. Error reports are deleted after 30 days.
- We don't use analytics, advertising, or social-media trackers.
5. How we use it
- To run the games and save each child's progress across devices.
- To show parents (and, with consent, teachers) how a child is doing, and to suggest what to practice next.
- To send grown-ups account emails (confirming sign-up, resetting a password).
- To keep the site safe and working: preventing abuse, fixing errors, and answering your questions when you contact us.
- To improve the site, using totals (like how many rounds were played in a game), not individual children.
We don't sell or rent information, use it for advertising, or use children's information to train AI. The site doesn't use AI features today; if we add them, they'll be off unless a parent turns them on, and no child's personal information will be sent.
6. Who can see what
- The child's parent: everything about their own kids, on each kid's Progress page.
- Other kids in a group (family, class, or club a parent added them to): only the nickname, animal picture, and points on the group's leaderboard.
- Challenge scoreboards and live races: nickname and picture only for the viewer, their brothers and sisters, and kids in their groups. Everyone else is shown as “A player” or “Racer 2”; guests as “Guest”.
- A class's teacher: a kid's math practice (skills, right and wrong answers, questions missed, and time) only after the kid's parent joins the class and agrees to share, and only from that day on. The parent can stop sharing at any time. Teachers see the nickname, never the parent's email.
- People who run agarwalmath: a small number of people who run the site can look at account details when needed to answer a question you ask us, fix a problem, or stop abuse. They're bound to keep it confidential, and every time they look at an account it's recorded, so it can be checked.
- The law: we may share information if the law requires it or to protect a child's safety.
7. Classes and schools
Teachers use agarwalmath two ways, and they work differently:
- Kids with a home profile: the parent decides. They type the class code, see exactly what the teacher will see, and agree before their child joins. They can stop sharing or leave the class any time.
- Class profiles: for kids without a home profile, the teacher creates profiles after confirming they have permission from their school or the kids' parents. These profiles are used only for school, belong to the class, always share their practice with the teacher, and are deleted when the teacher deletes the class, or automatically after 400 days without being played. Teachers keep their own list of which nickname belongs to which student; real names are never typed into the site.
Parents of a child with a class profile can ask the school or us to see or delete their child's information. Schools that need a data privacy agreement can email us. More for teachers: the Teachers' Guide.
8. Services we use
We use a few service providers to run the site. They process information only on our behalf and under agreements that protect it:
- Supabase: our database and sign-in service, where accounts and progress are stored, in the United States (Oregon).
- Cloudflare: hosts the website and protects it from attacks.
- An email delivery service: sends grown-ups account emails (confirming sign-up, resetting a password). It receives only the grown-up's email address and the email itself.
10. How long we keep it
- Account and profile information: until the parent deletes the profile or the account.
- Class profiles: until the teacher deletes them or the class, or 400 days after the profile was last played.
- Kid login sessions: up to 90 days on a device; changing the PIN or making a new login card ends them.
- Live race rooms close after 2 hours and are deleted the next day (each kid's own rounds stay in their history); challenge links stop working after 30 days.
- When something is deleted, it's removed from our database right away and from backups within 30 days.
11. Your choices and rights
- See your child's information: open your child's Progress page in the Parents area.
- Delete a child's profile and everything saved for it: in the Parents area (two taps).
- Stop sharing with a teacher or leave a group: in the Parents area.
- Delete your whole account, or ask for a copy of your information: email us at agarwalmath@gmail.com. We'll confirm it's you and do it within 30 days.
- Depending on where you live (for example California or the European Union), you may have more rights, like correcting information. Email us and we'll help.
A parent can refuse further collection at any time by deleting the child's profile; the child can still play as a guest.
12. Security
Passwords and PINs are stored only as secure hashes. Every request is checked by our database's access rules, so a family sees only its own kids and a teacher only what parents share. Too many wrong PINs or codes pause login for a while. No system is perfect; if we ever learn of a breach that affects you, we'll tell you promptly.
13. Changes to this policy
If we change this policy, we'll update the date at the top. If a change affects how we collect or share children's information, we'll email parents and ask for consent again where the law requires it.
14. Contact us
Questions, requests, or worries about privacy: email agarwalmath@gmail.com. agarwalmath is run by Devraj Agarwal.