Privacy Policy
We believe you deserve to understand — in plain language — how your family's data is handled. This policy is written for parents, not lawyers.
Last updated: March 1, 2026
What's in this policy
1. Introduction
MentorStar ("we," "us," or "our") operates the MentorStar platform — an AI-powered, game-based learning experience for children aged 4–16. We are headquartered in Abu Dhabi, United Arab Emirates.
This Privacy Policy explains what information we collect, why we collect it, how we use it, and what rights you have. It applies to our website (mentorstar.com), our mobile applications, and all related services.
We built this policy to be read by real people — not lawyers. If anything is unclear, please reach out to us at [email protected] and we'll explain it in plain language.
2. Information We Collect
We collect the minimum amount of information needed to deliver a safe, personalized learning experience. Here's what that includes:
- Account information: Parent's name, email address, and password. Children's accounts are created and managed by parents.
- Child profile: First name (or nickname), age range, and grade level — provided by the parent during setup.
- Learning data: Progress through quests, skill assessments, time spent learning, and interactions with the AI mentor. This data powers personalization.
- Device and usage data: Basic technical information like device type, operating system, and app version — used to ensure the platform works correctly.
- Support communications: If you contact us, we keep records of those conversations to help resolve issues.
3. How We Use Information
Every piece of data we collect serves your child's learning experience. Specifically, we use information to:
- Personalize learning: Adapt quest difficulty, pacing, and content to each child's unique strengths and areas for growth.
- Track progress: Show parents and children how skills are developing over time through the Skills Passport and dashboard.
- Improve the platform: Understand how children learn best so we can make MentorStar more effective. This is done with aggregated, anonymized data — never individual profiles.
- Ensure safety: Monitor for misuse, enforce community standards, and keep the platform secure.
- Communicate with parents: Send progress reports, account updates, and (only if opted in) product news.
4. Information We Don't Collect
What we don't collect is just as important as what we do. We want to be explicit about this:
- No location tracking of children: We do not collect GPS, geolocation, or precise location data from children's devices.
- No biometric data: We do not collect fingerprints, face scans, voice prints, or any biometric identifiers.
- No social media profiles: We do not connect to, collect from, or share data with any social media platforms.
- No behavioral advertising profiles: We never build profiles to serve targeted ads. There are no ads on MentorStar — period.
- No contact lists or photos: We never access a child's camera roll, contacts, or phone/messaging history.
5. Data Storage & Security
We treat your family's data with the same care we'd want for our own. Our security measures include:
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256). This is the same standard used by banks.
- Secure infrastructure: Our servers are hosted in SOC 2-aligned data centers with multi-layered physical and digital security.
- Access controls: Only authorized team members can access personal data, and only when necessary. All access is logged and audited.
- Regular audits: We conduct regular security assessments and penetration testing to identify and fix vulnerabilities.
- Incident response: We have a defined protocol for responding to any security incident, including notification to affected families.
6. Children's Privacy
Children's privacy is the cornerstone of everything we build. Our approach is rooted in these principles:
- Parental consent is required: A parent or legal guardian must create and authorize a child's account before any data is collected.
- Data minimization: We collect only what's strictly necessary for the learning experience. If we don't need it, we don't ask for it.
- No direct marketing to children: Children never receive marketing communications. All account-related communications go to the parent.
- Parent can review and delete: Parents can view all data associated with their child's account and request deletion at any time.
- COPPA-aligned practices: We follow the principles of the Children's Online Privacy Protection Act, including verifiable parental consent and strict data handling standards.
7. UAE PDPL Compliance
As a company headquartered in Abu Dhabi, we comply with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). This means:
- Lawful basis for processing: We process personal data based on consent (provided by the parent) and our legitimate interest in delivering educational services.
- Purpose limitation: Data is collected for specific, stated purposes and is not used beyond those purposes.
- Data protection officer: We have designated a data protection point of contact who can be reached at [email protected].
- Cross-border transfers: If data is transferred outside the UAE, we ensure equivalent protection through standard contractual clauses and appropriate safeguards.
8. GDPR Rights
If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation. We respect these rights for all users, regardless of location:
- Right of access: You can request a copy of all personal data we hold about you or your child.
- Right to rectification: You can ask us to correct any inaccurate or incomplete data.
- Right to erasure: You can request that we delete your data. We will comply unless there is a legal obligation to retain it (we will tell you if that's the case).
- Right to data portability: You can request your data in a structured, machine-readable format to transfer to another service.
- Right to object: You can object to data processing based on legitimate interests. We will stop unless we have compelling grounds to continue.
- Right to restrict processing: You can ask us to limit how we use your data while a concern is being resolved.
9. Third-Party Services
We use a small number of carefully vetted third-party services to operate MentorStar. Every provider is selected based on their security practices and data protection standards.
- Infrastructure providers: Cloud hosting and content delivery — bound by strict data processing agreements.
- Analytics: Privacy-focused analytics to understand how the platform is used. No personal data is shared. No advertising identifiers.
- Payment processing: Subscription payments are handled by PCI DSS-compliant payment processors. We never see or store your full credit card number.
We do not sell, rent, or share personal data with any third party for marketing or advertising purposes. We do not allow third-party advertising on our platform.
10. Data Retention
We keep your data only for as long as it serves a clear purpose:
- Active accounts: Data is retained while your account is active to provide the learning experience.
- After account deletion: When you delete your account, we remove personal data within 30 days. Some anonymized, aggregated data may be retained for research and platform improvement.
- Legal obligations: In rare cases, we may retain certain data as required by law (e.g., financial records for tax compliance). We will inform you if this applies.
You can request deletion of your account and all associated data at any time by contacting [email protected] or through the parent dashboard.
12. Changes to This Policy
If we make meaningful changes to this policy, we will:
- Notify you in advance: We'll send an email to all registered parents at least 30 days before significant changes take effect.
- Post updates clearly: The updated policy will be published on this page with a new "Last Updated" date.
- Require re-consent if needed: If changes affect how we handle children's data, we will ask for fresh parental consent before proceeding.
13. Contact Us
If you have any questions about this Privacy Policy, your data, or your child's privacy, we genuinely want to hear from you.
Related Policies
Full transparency means giving you access to everything. No fine print.