Privacy
What we hold, where it sits, and how to get rid of it
This is the whole policy, written to be read rather than to be defensible. If anything here is unclear, that is our fault and we want to hear about it.
Last updated 6 August 2026. Kaela is an Australian product and this policy is written against the Australian Privacy Principles.
The short version
Everything we store, including your account, the pages you upload, your child’s answers and marks, is stored in Sydney, in theap-southeast-2region. Our API runs in the same region.
One request leaves the country. The text of the material and the photos of your child’s working are sent to our AI provider to be turned into a lesson, a quiz and a mark. They do not retain that content to train their models. Our servers are in Australia; the model is not, and we are not going to word that carefully enough to let you assume otherwise.
We do not train on your child’s work unless you turn that on, and it starts off. There is no third-party analytics SDK in the kid app.
Export everything in one tap. Delete everything in one tap, and deleting removes the rows and the files rather than hiding them.
What we collect
From you
- Your email address, so we can reach you and so you can sign in.
- Your family’s timezone, which decides when “today” starts and when the weekly report is cut. It defaults to Australia/Sydney and you can change it.
- Each child’s first name or nickname and their school year. Nothing else about them. No date of birth, no school name, no address.
- Whether you have an active subscription or trial, and when it ends.
What you upload
- Photos or PDFs of the material you want your child taught from, and the text extracted from them.
- Photos of your child’s handwritten working, when a question asks them to show it.
What the lesson produces
- The lesson and the quiz questions generated from your upload.
- Your child’s answers, whether each one was right, and the overall score.
- Timing for each question: when it was first shown, when it was answered, and how many times the answer was changed. That is what tells us they hesitated, which is what makes the weak-spot section of the report worth reading.
From your child’s device
- A device identifier we generate at pairing, the app version, and the Android or iOS version.
- The lock state the device has applied and confirmed, so we can show you which device has actually received an override.
- Crash and error reports from our own reporting, sent to us and to nobody else.
What we never collect
This list exists because most of the products in this category do collect these things.
- Screenshots or screen recordings. Ever.
- Keystrokes or anything typed outside a Kaela quiz.
- Location. Not the phone’s, not the photo’s.
- Browsing history or search history.
- Message content, call content, contacts or photo library.
- Per-app, per-minute usage logs. We know whether the phone is locked. We do not build a timeline of your child’s day.
- Microphone or camera access outside the moment a photo is deliberately taken.
- Third-party analytics, advertising or attribution SDKs in the kid app. There are none, and there will not be.
Where it is stored
Our database and file storage are hosted on Supabase in the ap-southeast-2 region, which is Sydney. Storage buckets sit inside the same project and therefore the same region. Our API is deployed to Sydney as well.
When we say “Australian servers” on this site, we mean our servers and your data at rest. That is true. It does not mean the AI model runs in Australia, which is covered next.
The one hop that leaves Australia
Kaela uses a third-party AI provider’s models to read the page you uploaded, write the lesson, write the quiz and mark the answers. Those requests go to their API, which does not run in Australia.
What is sent:
- The text and images of the material you uploaded.
- Photos of your child’s handwritten working, when marking one.
- The question and the answer given, when a mark cannot be decided by straight comparison.
What is not sent:
- Your name or email address.
- Your child’s name.
- Your account, device or payment details.
Under our commercial terms with that provider, content sent through the API is not used to train their models. We do not have a second AI provider, and if that ever changes this page changes with it before the code does. We will tell you which provider we currently use if you ask us at privacy@kaela.app.
Training on your child’s work
There is one setting called training, it is off, and it stays off unless you turn it on. When it is off, your child’s uploads, answers and working are used to run the product for your family and for nothing else.
If you do turn it on, you are allowing us to use that content to improve how Kaela writes lessons and marks work. Turning it off again stops that from the moment you do it.
How uploads are handled
- Location and camera metadata are stripped from every image before it is stored. A photo taken at your kitchen table does not arrive carrying your kitchen table’s coordinates.
- Files go into private storage. There is no public bucket. Every read is a short-lived signed link minted after we check that you are allowed to read it.
- File type is checked by inspecting the file itself, not by trusting its name, and there is a size cap.
Who can see it
One family cannot read another family’s rows. That is enforced at the database level rather than in application code, and we hold a test that fails our build if it ever stops being true.
Correct answers never leave our servers. They are not in the quiz payload sent to the phone, not in the lesson, and not in any debug field, because a kid with the right tools would read them.
Kaela staff do not browse your family’s content. Access to production data is limited to the people who need it to keep the service running, and it happens to fix a specific problem, usually one you have told us about.
We do not sell data, we do not share it with advertisers, and we do not have a data-sharing partner.
Export and delete
Both are one tap in the parent app, under your family settings.
Export
You get a file containing your account, your children, every upload, every lesson and quiz, every answer and every report we have generated.
Delete
Deleting removes the rows from our database and the files from storage. It is not a flag that hides them from you while we keep them. Deleted content cannot be recovered by us afterwards, including if you ask.
Backups are the honest exception. Our database backups are encrypted and roll off on a 30-day cycle, so deleted content can persist inside a backup until that backup expires. We do not restore backups to recover deleted family data.
You can also delete a single child, or a single upload and everything generated from it, without closing your account.
How long we keep things
- Active account: for as long as your account is open, because the weekly report and the learner model are built from history.
- Uploads and generated lessons: 12 months, then removed automatically unless you have deleted them sooner.
- Closed account: content removed within 7 days, backups within 30.
- Records we are legally required to keep, such as payment records for tax purposes, are kept for as long as the law requires and no longer.
Payments
Payments are handled by Stripe. Your card number never reaches our servers and we cannot see it. We store the fact that you have a subscription, when it renews, and Stripe’s reference for your customer record.
The 7-day trial takes no card at all, which is the version we recommend if you would rather we held nothing.
This website
This site sets no cookies, runs no third-party analytics and embeds no trackers. Nothing on this page is loaded from a third party. If that changes, this section changes first.
Children’s privacy
The account belongs to a parent or guardian. Children do not create accounts, do not give us an email address and cannot sign in anywhere. The kid app is paired to a family by the parent.
We collect the minimum we need to teach and to mark. That is why we ask for a first name and a school year and nothing else about your child.
You exercise your child’s privacy rights on their behalf, through the same export and delete controls above.
Security
- Everything is encrypted in transit and at rest.
- No client app ever holds a privileged key. The phone in your child’s hand holds a device token that can do exactly two things: ask what the lock state is, and submit answers.
- Every unlock and every override is decided on our server and written to an audit record. A device that claims it passed is not a device that passed.
- If we ever have a breach that puts your family at risk, we will tell you, in plain language, and we will tell the Office of the Australian Information Commissioner as the law requires.
Changes to this policy
If we change something that matters, such as what we collect, where it goes, or who can see it, we will email you before it takes effect, not after. Wording fixes and clarifications get a new date at the top.
Contact and complaints
Privacy questions go to privacy@kaela.app. A person reads it.
If we have not sorted something out to your satisfaction, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. We would rather you told us first, and we are not going to pretend that is a requirement.
Plain-language summaries of the same points are in the privacy questions in the FAQ.