Privacy Policy
Last updated 3 August 2026
Cordia holds information about children, which is a trust we do not take lightly. This policy explains what we collect, why each piece exists, who processes it, and the controls you have. We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles. The short version: we collect the minimum the product needs, we never sell it, children's identifying details are kept away from AI providers wherever the product allows, and you can take your family's data with you or have it deleted.
1. What we collect, and why
About you (the parent): your email address and login credentials; your subscription and payment status (card details are held by Stripe, our payment provider — we never see the card number); your state or territory (to show the right registration guidance); messages you send us.
About your child, provided by you: first name, date of birth, year level, interests and personality notes, and an optional photo if you create their avatar. Each exists to personalise their learning: the date of birth suggests a year level and times birthday moments; interests and personality shape stories and examples.
Created by your child while learning: lesson answers and progress, writing and creative work, photos of completed worksheets you scan, food diary entries, messages to the in-app learning helper, and badges and activity records. This is your child's schoolwork — it exists so you can review it and evidence it for registration.
We do not collect more than this, and we do not ask children for information directly — the account, and every setting in it, belongs to the parent.
2. AI processing — what leaves, and what never does
Cordia generates learning materials using AI models from third-party providers (currently OpenAI, Google and Anthropic). To personalise a lesson, the generation systems are given your child's first name, year level, interests and relevant schoolwork context.
- Your child's date of birth is never sent to an AI model. It is used inside our own systems to suggest a year level, and that is all.
- AI providers process this data to generate the requested content. Our agreements use API services whose terms exclude using customer data to train their models.
- Messages your child sends to the in-app helper are answered by an AI system inside guardrails built for children, and are visible to the parent account.
3. Where your data lives
Your family's data is stored in our database and file storage provider (Supabase) and served through our hosting provider (Cloudflare). Payment processing is handled by Stripe. Some of these providers, and the AI providers above, process data on servers outside Australia (including the United States). Where data crosses a border, it does so under the provider's contractual data-protection commitments; we remain accountable for it under the Australian Privacy Principles.
4. What we never do
- We never sell personal information — anyone's, and especially not a child's.
- We never use your child's information for advertising, and we do not show third-party advertising at all.
- We never publish a child's work or identity. Anything public on our website is either fictional or used with explicit permission.
- We do not disclose personal information to anyone except the service providers above doing the processing described, or where the law requires us to.
5. A note on the food diary and wellbeing features
Some features touch information that deserves extra care — a food diary entry can reveal things about a child's health. These features are optional, off unless you use them, visible only to your family, never used for any purpose beyond showing your child their own records, and deleted with the rest of your data on request.
6. Your controls
- See and correct: everything about your family is visible in your account; anything you cannot edit yourself, we will correct on request.
- Export: ask and we will provide your family's data — including your child's work — in a portable form.
- Delete: closing your account deletes your family's personal information from live systems, with backups expiring on their rotation schedule. We keep only what tax and company law requires us to keep (billing records), which does not include your child's schoolwork.
7. Security
Data is encrypted in transit, access is controlled per household at the database layer (your family's rows are invisible to any other account by design, enforced in the database itself, not just the app), child work is stored in private buckets that are never publicly addressable, and generation systems run under per-family limits that contain misuse. No system is unbreachable; if a breach ever affects your family's data we will tell you promptly and plainly, and notify the OAIC where the law requires.
8. Cookies
We use cookies for one thing: keeping you signed in. No advertising cookies, no cross-site trackers. Our public website uses privacy-respecting aggregate analytics that do not identify you.
9. Changes and contact
If this policy changes materially we will tell you by email or in the app before the change takes effect. Questions, access requests and complaints:support@cordiahomeschool.com.au. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
The agreement this policy forms part of is ourTerms of Service.