Privacy Policy

Our Privacy Promise

Effective: June 15, 2025Last updated: June 15, 2025

The short version

  • We never sell your family’s data.
  • No ads to your child. No third-party ad networks. Ever.
  • No public AI training on your records.
  • You can review, export, or delete your data any time.
1
WHAT WE COLLECT
From you (the parent): name, email, state, timezone, and a Stripe customer ID for billing. We never see your card number. From your child: first/last name, grade, date of birth, learning profile notes you enter, daily logs and assessments, and any worksheets or drawings you upload. We do not collect precise location, contacts, photos by default, camera or microphone audio, or any behavioral-advertising identifiers.
2
HOW WE USE IT
Only to power the homeschool features you signed up for: rendering your dashboards and schedules, generating state compliance PDFs, powering the kid-safe Child Portal, sending you transactional email about your account, and charging your subscription. That’s the whole list.
3
THIRD-PARTY INFRASTRUCTURE
We rely on a small number of carefully-vetted third-party providers strictly to host, transmit, back up, and operate the platform (authentication, database, payments, hosting, email, object storage). We do NOT sell your data, and we do NOT share or license it outside our own operational infrastructure and these functional providers. Specific vendor identities are treated as confidential business information and are not disclosed publicly; all providers are bound by contractual data-handling and confidentiality obligations.
4
YOUR RIGHTS AS A PARENT
Because families with children under 13 use Rosie’sHQ, we designed the product around the COPPA parental-rights framework. At any time you can:
  • Review everything we store about your child from the Children tab.
  • Export a full JSON archive via Children → Edit → Data & Privacy.
  • Delete a child or your entire account from the same screen or Settings → Danger Zone.
  • Refuse further collection by deleting the child’s profile — participation is never conditioned on extra data.
Questions? Email privacy@rosieshq.com and a real human will respond.
5
RETENTION & SECURITY
Active accounts are retained while your subscription is active. Deleted child records leave production within 30 days; encrypted backups roll off within 60 days. All traffic is encrypted in transit via HTTPS and encrypted at rest by our database and storage providers. No online service can promise perfect security — please keep your Rosie’sHQ password strong and unique.
6
CHANGES & CONTACT
If we materially change how we handle your data, we’ll update the “Last updated” date and, if significant, notify you by email and ask you to re-acknowledge before continuing. Reach us any time at privacy@rosieshq.com. We aim to respond within 5 business days.

🔒Built by parents, for parents. We will never sell your family’s data, never train public AI models on your child’s notes, and your compliance logs belong 100% to you.