Privacy policy
Privacy and data practices
How SocialQuest AI handles parent accounts, child profiles, learning data, AI requests, security, and support requests.
Last updated: July 26, 2026
Back to legal centerWho controls the service
Binoron, LLC provides SocialQuest AI from United States. Families may use the app from the United States, the EU/EEA, Israel, and other countries.
Questions or requests can be sent to hello@littleaiminds.com.
Data we process
Parent account data: email address, authentication state, billing references, support requests, and settings.
Child profile data: a child nickname, age, language level, sensory support preferences, preferred themes, practice goals, and selected address style. Do not enter a surname or other identifying detail.
Learning data: mission attempts, selected choices, helpfulness flags, completed lessons, weekly routine progress, monthly progress reflection notes, and generated or saved scenarios.
Requests and feedback: export, deletion, and support requests (parent_data_requests), waitlist sign-ups (waitlist_signups), and family beta feedback (family_beta_feedback).
Operational records: a fixed list of product events (product_events), low-detail error codes (app_error_events), and one row per AI mission request (ai_generation_events) used for rate limits and cost control. None of these hold child names, mission answers, free text, or diagnoses.
Technical data: security logs, hosting logs, device/browser metadata, and localStorage data used for signed-in, parent-managed device continuity after the child-data gate has opened.
How we use data
We use data to provide parent-led social practice, save progress, recommend next lessons, support account access, process subscriptions, respond to support requests, and keep the service secure.
We do not use child data for public leaderboards, advertising profiles, or biometric scoring. Practice Mirror does not use eye tracking, pupil tracking, face identity detection, or emotion scoring.
One feature carries the child nickname outside our own systems: when a parent chooses to email themselves the weekly progress summary, that message is delivered through Resend to the parent's own address and contains the nickname.
What each AI feature sends
AI missions. When a parent has switched AI missions on, the app asks OpenAI for one practice scenario. The request carries the child's age, language level, sensory support preference, the practice skill, the theme, the difficulty level, and the language the mission should be written in. For Hebrew it also carries the address style the parent chose, as a wording instruction. That is the entire prompt.
The child's name never leaves the app in an AI request. Neither does the parent's email address, nor any answer the child picked in an earlier mission. The model receives a description of a practice situation, not a description of your child.
Safety check. Every generated mission is checked twice before a child can see it: against our own wording rules, and by OpenAI's moderation endpoint (omni-moderation-latest), which receives the generated mission text. If the draft is flagged, or the check cannot be completed at all, the child is shown a prepared fallback mission instead.
Read-aloud. When a read-aloud button is pressed, the text already on the screen — mission or lesson text — is sent to OpenAI's text-to-speech to be turned into audio. Text written by a child and child names are not part of it. We do not store the audio, and read-aloud requires a signed-in parent account.
Reviewed voice clips. Character voice audio is produced by ElevenLabs from a fixed list of reviewed scripts, through an operator-only route. Children cannot trigger it, and no child text is sent there.
Reviewed avatar clips. HeyGen is used to render approved character videos from reviewed scripts. There are no live avatar sessions and no free-form child dialogue.
All AI requests are made from the server and the API keys stay there. Dynamic child audio is off, raw child audio is not stored, and no feature scores faces, eyes, or emotions.
Subprocessors and infrastructure
Current and prepared vendors include Vercel for hosting, Supabase for database/auth/storage, OpenAI for scenario generation, moderation and read-aloud, Stripe for subscriptions, Resend for transactional email, GitHub for code/CI, and HeyGen or ElevenLabs for reviewed media workflows.
These vendors may process data in the United States, the EU/EEA, or other locations under their own security and transfer terms.
How we protect data
Encryption. Traffic between the browser and the app runs over HTTPS/TLS, and stored data is encrypted at rest by our database provider.
Row-level security. The database, not the app, decides who may read a row. Parent accounts, child profiles, scenarios, mission attempts, progress profiles, monthly reflection notes, and consent settings are each scoped to the signed-in parent who owns them, so one family cannot reach another family's records even if a browser asked for them.
Consent and parent verification are checked in the database. A new child profile can only be created when an accepted, current, timestamped parent decision and a receipt for the current notice followed by a positive Stripe card transaction are both on record. Reading, correcting, exporting, and deleting the data your family already has is never gated on consent or on a paid plan.
AI endpoints fail closed. Mission generation and read-aloud verify the sign-in, current parent consent, positive-card parent-verification receipt, and the relevant AI or voice switch before any request leaves the app. They refuse when a required fact cannot be verified. The moderation check also fails safely: an error counts as unsafe, and the child gets the prepared fallback.
Limited operator access. Admin screens and operator-only routes are restricted to a short allowlist of operator email addresses held in server-side configuration (lib/adminAuth.ts). Service keys and API keys stay on the server and are never shipped to the browser.
Where data is stored. The family database and its sign-in service run in the European Union (Frankfurt, eu-central-1). The web app and its server routes are hosted by Vercel, and the vendors listed above may process data in their own regions.
Breach notification. No online service can promise perfect security. If we learn of a security breach affecting family data, we will inform affected parents and the relevant authorities as required by the law that applies to us, and describe what happened and what to do next.
Retention, export, and deletion
Parent account, child profile, progress, and generated content are kept while the account is in use, or until a valid deletion request is completed, unless legal or security obligations require a longer period.
Inactive accounts are deleted automatically. If nobody signs in for 24 months, the account and everything on it is removed. One warning email goes out first, at 23 months, naming the planned date, and deletion waits at least 14 more days after that email — so there is always time to sign in and keep the account, or to download a copy first.
Two kinds of account are never removed by that inactivity job: accounts with a live subscription, and operator accounts.
Billing records may be retained as required for accounting, tax, fraud-prevention, and dispute handling.
Operational records are purged on a schedule, not only when an account closes: product events after 90 days, low-detail error records after 30 days, AI-request records after 90 days, and email delivery receipts after 180 days. All of them are also removed when the parent account is deleted.
Signed-in parents can download a copy of their family's records and delete the account, or a single child profile, from the in-app data and support page. Neither action needs a support ticket, a consent setting, or a paid plan.
Deleting the account removes the parent account, every child profile on it, practice and course history, consent settings, and the scenarios that account created. Invoices held by the payment provider remain with that provider under its own terms.
Backups held by our database provider follow that provider's own recovery window, which can reach beyond the periods above.
Parents can also use that page or email support for access, correction, or anything a button does not cover.
Children and parent controls
SocialQuest AI is designed to be parent-led. Parents create child profiles, choose practice goals, review consent settings, and can turn sensitive features off.
The app does not ask children to enter diagnoses, medical records, or sensitive clinical history.
Need help?
Families can contact support for privacy, billing, cancellation, accessibility, or data requests.
hello@littleaiminds.com