---
title: "Children's Privacy Notice | DuckyHelper"
url: "https://duckyhelper.com/legal/children/"
description: "Kids under 13 need a yes from a parent or guardian to use DuckyHelper. What we keep until then, how parents say yes, and how they see, change or delete it."
updated: "2026-10-01"
---

# Children's Privacy Notice

Version 1.1 · Effective October 2, 2026

In short

- Kids under 13 can use DuckyHelper only after a parent or guardian says yes. Until then we keep only the child's first name and the parent's email, only to ask, and we delete both after 14 days if the parent doesn't answer.
- The parent reads what we'd collect and why, makes a parent account, chooses what's on, and confirms they're a grown-up with a 50-cent card charge that we refund right away.
- A child's voice, typed messages and screen go to OpenAI to run the tutor. Nothing is ever used for ads, sold, or used to train AI models.
- Parents can see, download or delete what we keep, change what's on, or withdraw their OK (which deletes the account), any time.

This notice explains how **MingLLM, Inc.**, a Delaware corporation, collects, uses and shares information from children under 13 who use DuckyHelper, and the choices parents have. It follows the US Children's Online Privacy Protection Act (COPPA) and the FTC's COPPA Rule. It adds to our [Privacy Policy](https://duckyhelper.com/privacy/), which explains how DuckyHelper works for everyone.

**The operator.** MingLLM, Inc. is the only operator collecting children's information through DuckyHelper.

- Email: **privacy@duckyhelper.com**
- Mail: MingLLM, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA
- Phone: our phone line is being set up. Until then, please email **privacy@duckyhelper.com**.

## 1. How a child's account starts

1. **The age question.** Everyone who signs up is asked their birthday. We keep only an age group, never the birthday.
2. **Under 13: we ask a parent.** If the birthday says the child is under 13, the sign-up form sends nothing the child typed into it (no email). The child is asked for only **their first name** and **a parent's or guardian's email address**. For a day afterwards, that browser stays on the "ask a parent" page, so entering a different birthday can't skip it.
3. **The email to the parent.** We send the parent one email with this notice in short form: why they got it, what DuckyHelper is, what we'd collect and why, who receives it, how long we keep it, their rights, and a link to say yes. It also says that we won't collect, use or share anything about the child unless the parent says yes, and that if they don't say yes within **14 days**, we delete the child's first name and the parent's email address.
4. **The parent says yes.** The link opens a page where the parent: • reads the notice; • signs in to their DuckyHelper account, or makes one (they agree to our [Terms of Service](https://duckyhelper.com/terms/) and [Privacy Policy](https://duckyhelper.com/privacy/) for themselves and for the child); • chooses the email address the child will sign in with, by a one-time code sent to it (for a child who doesn't have an account yet); • chooses what's on (below); • confirms they are the child's parent or legal guardian and 18 or older, and agrees to the collection and use described here; • **confirms with a card**: Stripe charges 50 cents to a credit or debit card and we refund it right away. The card company notifies the account holder of the charge. We never see the card number. This is how we verify that a grown-up with a payment card is giving consent.
5. **The account turns on** as soon as the card check succeeds, and we email the parent a confirmation with a link to the parent page.

If a child already had an account from before we asked ages and says they're under 13, the account is paused (nothing but the explanation is available) and we email the parent the same way. If the parent doesn't say yes within 14 days, we delete the account and everything in it.

## 2. What we collect from a child, once a parent says yes

- **Their voice**, while they talk to Ducky. It goes straight from the Mac app or the browser to OpenAI to run the conversation. We don't record or keep it.
- **What they type to Ducky**, when they type instead of talking. It goes through our servers to OpenAI so Ducky can answer. We don't keep the messages themselves.
- **Pictures of their screen**, when they ask Ducky to look or Ducky needs to, and short descriptions of what's on it. They go to OpenAI; we don't keep them. A child should close anything private before asking Ducky to look.
- **What they click and type** while Ducky checks a step they're doing (never what's in a password field). Used during the session only.
- **Written transcripts and short summaries** of each session, their progress by topic and skill, tests and grades, flashcards, mistake patterns, and short notes Ducky keeps so it can help them next time.
- **What they tell Ducky about themselves**, such as their grade, subjects, interests, learning style or the name they like to be called.
- **Their sign-in email**, chosen by the parent, and their first name.
- **Pictures Ducky makes** for them on request.
- **Code they run** in a lesson. In the Mac app it runs on the Mac. In the web app, Python code runs on our servers, in a sandbox with no internet access. Running it doesn't make us keep a copy.
- **Technical information** our servers log for 30 days (requests, errors, and the network address they came from).

**Only if the parent turns them on** (off by default):

- **Pictures and files in memory**: Ducky keeps pictures of the screen or of worksheets, and files the child adds, to look at later.
- **Google connections**: the child may connect Google Calendar, Gmail or Google Docs. Ducky reads them when asked and writes only what the child confirms.

**Never, for a child's account**: payments, and news, offers or marketing email.

**Invites and where sign-ups come from: none of this applies to children.** For a child under 13, we don't keep which link or website the sign-up came from, we never ask how they heard about DuckyHelper, and their account can't invite friends, get minutes from an invite or earn a reward. If an account says it's under 13 after it was made, we delete those records when we ask the parent for consent.

## 3. How we use it

Only to provide DuckyHelper to the child: to tutor them, pick up where they left off, show their progress to them and to their parent, keep the service secure, and meet legal obligations. We **don't** use a child's information for advertising, we don't build profiles for anything but tutoring them, we don't sell it, and we don't use it to train AI models.

A weekly learning report goes to the parent's email; it can't be sent to anyone else from the child's account. The child may get account emails (such as a sign-in from a new device), study reminders and a weekly recap; reminders and the recap can be switched off in the app's email settings. The newsletter is off by default.

## 4. Who receives it

Only service providers that run parts of DuckyHelper for us, under contracts that limit their use to doing that work:

- **OpenAI**, to run the voice and typed conversation, the tutor, screen descriptions, pictures and pronunciation scoring. Under OpenAI's API terms it doesn't use the data to train its models, and it may keep it for up to 30 days to check for abuse.
- **Amazon Web Services**, to store the data, run Python code from the web app and send email, in the United States.
- **Google**, only if the parent turns on a Google connection, to run that connection.
- **Stripe** receives the parent's card for the 50-cent check, not the child's information.

We disclose a child's information to no one else, except when the law requires it or to protect someone's safety. We don't disclose it for any purpose that isn't part of running DuckyHelper, so there is no separate consent for such disclosures to ask for. If that ever changes, we'll ask the parent first, separately.

## 5. How long we keep it (our retention policy)

We keep a child's information only as long as it's needed to tutor them:

- **The child's first name and the parent's email**, before the parent says yes: deleted after 14 days if there's no answer.
- **Each session, with its transcript and summary**: 1 year, then deleted. We keep sessions this long so the child's dashboard and Ducky's recaps can show what they worked on and how they've progressed.
- **Everything else** (account, progress, tests, flashcards, memories, reports): while the account is used. **An account nobody uses for 1 year is deleted with everything in it.**
- **Voice, screen pictures and pronunciation recordings**: not kept by us.
- **Server logs**: 30 days. **Backups**: up to 35 days after deletion.
- **The record of consent** (that a parent said yes, when, what they turned on, and when they withdrew) is kept after the account is deleted, without the child's learning data, so we can show we followed the law.

A parent can delete any of it sooner, any time.

## 6. Parents' rights

A parent can, at any time:

- **see** what we keep about their child, and **download** a copy;
- **delete** it (the account stays) or **change what's on**;
- **withdraw consent**: we delete the child's account and everything in it, and stop collecting anything from the child;
- refuse to let us collect more information while still letting us keep what we have, or ask any question.

Do it on the **parent page** (the link is in the confirmation email: sign in with the parent account), or write to **privacy@duckyhelper.com** from the parent's email address. We'll confirm the request comes from the parent before acting.

A parent can agree to collection and use of their child's information without agreeing to disclosures to third parties that aren't needed to run DuckyHelper; we make none.

## 7. Schools

DuckyHelper isn't offered through schools today, and we don't accept consent from schools in place of parents. A school or teacher who wants students under 13 to use DuckyHelper should contact us first.

## 8. Security

Children's information gets the same protections as everyone's (see the [Privacy Policy](https://duckyhelper.com/privacy/), "Security", and [Security & Responsible Disclosure](https://duckyhelper.com/legal/security/)), including encryption in transit and at rest, and access only by the child's account and the parent's.

## 9. Changes

If we change what we collect from children or how we use or share it in a material way, we'll notify parents and ask for their consent again before the change applies. Each version of this notice has a number and an effective date, listed on the [legal page](https://duckyhelper.com/legal/).

## 10. Contact

**privacy@duckyhelper.com**. If you believe we collected information from a child under 13 without a parent's consent, tell us and we'll delete it.
