United States **Framework:** COPPA (federal); California CCPA/CPRA special rules for under-16; FERPA may apply in school use. COPPA covers child-directed services and actual-knowledge scenarios involving under-13 children; covered services need notice, parental consent, parental rights, security and retention/deletion controls. California adds special rules for under-16 sale/sharing. School use may bring FERPA contractual requirements. Sources: FTC; California Privacy Protection Agency; U.S. Department of Education.
EU / EEA **Framework:** GDPR; national child-consent ages under Article 8 vary between 13 and 16 where consent is the legal basis; EU-U.S. transfers may use the EU-U.S. Data Privacy Framework for certified U.S. organizations or other lawful safeguards. Use data minimisation, transparency, lawful basis, children-appropriate safeguards and lawful transfer mechanisms. AI Act Article 50 transparency obligations apply from 2 August 2026, including disclosure when users directly interact with AI. Sources: EUR-Lex; European Commission.
United Kingdom **Framework:** UK GDPR + Data Protection Act 2018; ICO Children's Code. High-privacy defaults, data minimisation, limited sharing, geolocation off by default unless justified, profiling off by default unless justified, and no nudges that weaken privacy. Sources: ICO.
Canada **Framework:** PIPEDA plus applicable provincial privacy laws. Meaningful consent is required; the Canadian privacy regulator generally expects parental/guardian consent for children under 13 except in exceptional circumstances, with maturity considered for youth. Sources: Office of the Privacy Commissioner of Canada.
Australia **Framework:** Privacy Act 1988 + Australian Privacy Principles; Children's Online Privacy Code framework for covered online services. Consent and capacity are assessed with regard to age and maturity; current OAIC guidance states under-15 users may be presumed not to have capacity where individual assessment is impracticable. The Children's Online Privacy Code framework places additional focus on children's privacy. Sources: OAIC.
Taiwan **Framework:** Personal Data Protection Act and Civil Code capacity rules. Processing should be purpose-limited and transparent. For minors, consent/capacity questions depend on the individual circumstances and Civil Code rules; give information in language appropriate to the person's age and understanding. Sources: Taiwan Personal Data Protection Commission / laws.
Japan **Framework:** Act on the Protection of Personal Information (APPI). When personal data is transferred to certain overseas third parties, APPI may require prior consent or another statutory basis and disclosure about the destination and protection system. Minors may require a legal representative where they lack capacity. Sources: Japan PPC.
South Korea **Framework:** Personal Information Protection Act (PIPA). For children under 14, legal-representative consent requirements apply when collecting the child's personal information. Korean authorities also scrutinize age assurance and children's privacy practices by overseas services. Sources: PIPC.
Singapore **Framework:** Personal Data Protection Act (PDPA) and PDPC children's-data guidance. Children aged 13โ17 may in some contexts give valid consent if they understand the consequences; in education contexts a higher parental-consent threshold may be prudent. Purpose limitation, notification, protection, retention and transfer obligations apply. Sources: PDPC.
United Arab Emirates **Framework:** Federal Decree-Law No. 45 of 2021 on Personal Data Protection + Federal Decree-Law No. 26 of 2025 on Child Digital Safety + 2026 implementing measures. The UAE framework restricts processing of personal data of children under 13 unless specified conditions are met, including clear parental/guardian consent, easy withdrawal, clear explanation, and no targeted advertising/commercial exploitation of the child's data. Sources: UAE Government and UAE legislation.
Saudi Arabia **Framework:** Personal Data Protection Law (PDPL) and Implementing Regulations. Consent must be freely given, purpose-specific and documented; separate consent is required for each processing purpose in the regulation. Legal-capacity requirements apply, including guardian involvement where required. Sources: SDAIA.
๐จ๐ณ China โ PIPL (Personal Information Protection Law)
Framework: Personal Information Protection Law (PIPL), with special rules for minors under 14 and the Measures for Cybersecurity Review / data export regimes.
For users in China:
- We follow PIPL requirements for children's personal information (under 14), including guardian consent where required.
- Parents/guardians can request access, correction, or deletion of their child's data.
- Data is stored and processed in compliance with Chinese law where applicable, including cross-border transfer rules where a transfer occurs.
Summary only โ not legal advice. Consult cac.gov.cn for official guidance. Sources: Cyberspace Administration of China; PIPL statutory text.
Appendix B โ Product privacy defaults (carried over from the v1 template)
Data minimisation
The core tutoring flow is designed not to require a student's full name, school, exact birthday, exact grade, home address, contacts or precise location. Learning stage is represented as a broad band for personalisation.
Problem images
Images are processed to recognize and solve the requested problem. The production design aims not to retain raw images longer than necessary. Retention periods and deletion procedures should be documented before launch.
Voice
The preferred V1 interaction is speech-to-text. The reasoning model receives the transcript and current problem context rather than a raw voice recording. If server-side transcription is enabled, the recording must be handled under the configured retention and deletion policy.
Children
Broad stage bands reduce unnecessary precision but do not by themselves remove children's privacy obligations. Where laws require parental authorization, age assurance, special notices or other safeguards, those mechanisms must be implemented.
High privacy by default
CalcElf is designed with no location collection in the core flow, no child-facing targeted advertising by default, no public child leaderboard, and no default public profile. Optional profiling or social features should be off by default and separately disclosed.
AI processors
Problem content may be processed by contracted AI vendors. Before launch, publish the current list of processors and review their data-use, retention, regional processing, security and data-processing terms.
Rights
Provide an accessible route for access, correction and deletion requests, including parent/guardian workflows where required.