Privacy Policy
Version: 2026-08-27
Last updated: 27 August 2026
This Privacy Policy explains how Braintiva (“we”, “us”, “our”) collects, uses, stores, and discloses personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and with OAIC guidance on students’ personal information.
A plain-language companion is available in our Consent & Privacy Guidelines. Product questions are also covered in the public Help & FAQ.
1. Who we are and how to contact us
Braintiva is an Australian primary-school EdTech product for families (Foundation to Year 6).
Privacy contact: see the contact email shown at the top of this page (configured for this deployment).
You may use that address to ask privacy questions, request access or correction, or request deletion of your family’s data. Signed-in parents may also use Contact Us in the product for general support (not a substitute for a formal deletion request).
2. What personal information we collect
2.1 Parent / family manager
| Information | Purpose |
|---|---|
| First name, last name | Identify your account and display your name in the parent workspace |
| Email address | Login identifier, account communications, optional email verification, password reset |
| Password (stored hashed) | Authenticate your account |
| Optional family timezone | Show dates and reward deadlines in your local day |
| Consent records (document, version, time, IP / user agent) | Evidence that you accepted Terms and Privacy at registration |
2.2 Student profiles — created by the parent
| Information | Purpose |
|---|---|
| First name, last name, preferred name (optional) | Display name and greetings in the Student Console |
| Login ID (username) and password (hashed) | Student login (no student email required) |
| Grade / year level and curriculum authority (e.g. ACARA, VCAA, NESA) | Marketplace defaults, rank paths, and cohort tooling |
| Link to parent account | Family management and entitlements |
2.3 Learning activity (signed-in students)
| Information | Purpose |
|---|---|
| Quest attempts, answers, scores, timers, completion status | Deliver quests, progress, parent review, and resume |
| Brainpower and science-rank progress | Show practice progression by grade and curriculum path |
| Subject offering unlocks / pack allocations | Provide complimentary or purchased curriculum access |
| Custom family reward text (optional) | Parent-set incentives |
| In-app notification receipts | Alert families to offerings, rewards, and Contact Us replies |
2.4 Contact Us and support
| Information | Purpose |
|---|---|
| Message type, topic, and typed message | Respond to parent inquiries and issues |
| Optional feedback sentiment (e.g. happy / neutral / unhappy) | Product improvement analytics |
| Operator replies and read/unread state | Support history for your family |
2.5 Guests (no account)
If you use public pages only (landing, Help & FAQ, or the guest sample test):
- we do not create a parent or student account;
- sample answers and scores stay in the temporary browser session for that visit and are not saved as a lasting learning record on a student profile;
- ordinary technical data (for example IP address, browser user agent, and session cookies needed for security) may still be processed by our hosting stack.
2.6 Technical data
| Information | Purpose |
|---|---|
| Session identifiers, IP address, browser user agent | Security, session management, abuse prevention |
| Password-reset and email-verification tokens (when those features are used) | Account recovery and verification |
2.7 What we do not collect today
We do not currently collect date of birth, home address, phone number, school name, government identifiers, or photos/avatars of students. If that changes, we will update this Policy (new version) and provide appropriate notice.
3. Why we collect personal information (APP 3 / 6)
We collect and use personal information only as reasonably necessary to:
- create and secure parent and student accounts;
- provide Subject Offerings, question packs, quests, rewards, notifications, and parent dashboards;
- process unlocks / purchases (including complimentary grants);
- respond to Contact Us items and improve reliability (in aggregated or de-identified form where practicable);
- send account emails such as verification or password reset when those features are enabled;
- meet legal obligations and protect against fraud or misuse.
We do not sell personal information. We do not use student profiles for behavioural advertising.
4. Students and parental authority
Braintiva is built for primary-school students, but accounts are created by adults.
When you create a student seat, you confirm you are the parent or legal guardian (or otherwise have authority) and that you may provide that student’s limited personal information for educational use of the Service.
We minimise student identifiers (no student email by default; login ID + first/last name only as needed for the product). Student password resets are performed by the supervising parent after re-authentication, not via a public student email flow.
5. How we disclose information
We may disclose personal information to:
- Hosting and infrastructure providers that store the application and database under contract;
- Email delivery providers used for password reset, verification, or operator alerts;
- Payment processors (when live card payments are enabled) — limited billing data as required to take payment;
- Professional advisers or regulators where required by law.
Artificial intelligence (content seeding): We use Google Gemini (or similar models) to help generate curriculum question content for approved Subject Offerings. Operator prompts for that pipeline use curriculum context and skill briefs — not parent names, emails, or student profile PII. Quest answers stored in our database are not sent to Gemini as part of ordinary quest play. Guest sample answers are likewise not sent to Gemini.
6. Overseas disclosure
Some subprocessors (for example cloud hosting or Gemini API endpoints) may process data in locations outside Australia. Where that occurs, we take reasonable steps consistent with APP 8 (including contractual and technical measures appropriate to the service). If your deployment uses only local hosting, overseas disclosure may be limited to AI content-seeding calls by operators.
7. Security (APP 11)
We take reasonable steps to protect personal information, including:
- hashing of passwords;
- authenticated sessions and role-based access (parent / student / admin);
- optional multi-factor authentication for operator (admin) accounts;
- rate limits on public password-reset requests;
- restricting Operator Console access to verified admins.
No method of transmission or storage is completely secure. Please choose strong passwords and keep student credentials within the family.
8. Access, correction, and deletion (APP 12 / 13)
- Parents may update their first and last name, password, and optional timezone via Manage Profile in the Parent Hub.
- Parents may update student preferred name, grade, and curriculum context from seat management (subject to product rules).
- To request a copy of the personal information we hold about your family, or to request correction or deletion, email our privacy contact. Deletion requests are handled manually by an operator in this product version.
We may need to verify your identity before acting on a request. We may retain limited records where required by law (for example consent evidence, support history, or transaction history).
9. Retention
We retain account and learning data while your account is active and for a reasonable period afterwards to provide the Service, resolve disputes, and meet legal requirements. In-app notifications older than our retention window (currently 365 days) are pruned automatically. When an account is deleted following a verified request, we take reasonable steps to destroy or de-identify personal information that is no longer needed.
10. Complaints
If you have a privacy complaint, contact us first using the privacy email on this page. We will aim to respond within a reasonable time.
If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC): https://www.oaic.gov.au.
11. Changes to this Policy
We may update this Privacy Policy by publishing a new version with a new version date. New parent registrations accept the then-current version at signup. Material changes for existing users may be notified by email or in-product notice in a later release.