Legal
Privacy policy
Confidaint spends a lot of words telling families to find out what a tool records before they use it. This page is our own answer to that question: what we store, why we store it, who else handles it, and how to ask us to change or remove it. It describes what the service does today, not what we hope it will do later.
Effective
Who we are, and what this covers
Confidaint is an online service that helps parents and children understand AI. In this policy, “we” and “us” mean Reed Stories LLC, the company that operates Confidaint, and “you” means the adult who visits the site or holds an account.
This policy covers the Confidaint website and the signed-in app at the same address. It does not cover the other companies’ AI tools we write about. Those have their own policies, and reading them carefully is one of the things this site is here to teach.
Business address
Reed Stories LLC1500 N Grant St Ste RDenver, CO 80203United StatesWhat we store
Reading the public pages needs no account and stores nothing about you on our servers. Everything below exists only once you create an account or use a feature that needs one.
- Your account
- Your email address, the name you give us, whether the address has been verified, whether the account is a member or a staff account, and the appearance and language settings you last chose. Staff status is permission to run the site; it is never something anyone can buy.
- Your household
- A household record that holds your plan, and the list of accounts that belong to it. One is created for you the first time something needs it.
- Learners
- A learner is whoever the learning belongs to. A child learner is a display name you type — nothing more. Children get no account by default, and we never ask you for a child’s age, birthday, school, or photograph.
- Lesson progress
- For each piece of a lesson: which lesson, which piece, whether it is in progress or finished, and when it was last opened and completed.
- Guardianship grants
- Who you have allowed to see a learner’s record, what that grant permits, who issued it, when it was accepted, and when it was withdrawn.
- Plan grants
- What your household is entitled to, where that entitlement came from, when it starts and ends, and whether it has been withdrawn.
- Subscription records
- The customer and subscription identifiers Stripe gives us, the plan, its status, the end of the current paid period, and whether it is set to cancel. Card numbers go to Stripe and never reach our servers.
- AI Lab usage
- One row for each generation you ask for: whether it succeeded, failed, or was declined, which model ran, how many tokens it used, what it cost us, and how long it took. We also keep a monthly running total for your household so the monthly limit can be enforced.
- Saved AI Lab runs, only if you ask
- Nothing here unless you switch saving on in the Lab. If you do, we store the topic you typed and the three answers the model wrote, against your household, so they reach your other devices. Your household keeps the most recent fifty and each new run drops the oldest. Switching the setting off deletes them.
- Sign-in sessions
- A record of each signed-in session, when it expires, and the network address and browser it was created from.
- Staff actions
- When a staff member acts on an account, we append a record of who acted, what they did, and what they acted on. That record is never edited or deleted, so it survives the departure of the person who made it.
We never ask for a postal address, a phone number, a date of birth, or a payment card. We do not buy information about you from anyone else, and we do not build advertising profiles.
Children’s information
Confidaint is built so a parent holds the account and a child learns beside them. A child learner is a display name you type, and nothing else. We do not require a child to have a login, and we never ask you for a child’s age, birthday, school, or photograph.
If a child ever does hold their own login, what is stored about them is the same short list above. Progress belongs to the learner rather than to a login, which is why a child’s record does not depend on a child having an account.
Please do not type a child’s full name, school, address, or health details into the AI Lab. What you type there is sent to another company, and this site’s own guidance is to write around those details rather than include them.
Where your progress is kept
Lesson progress is written into your browser’s local storage first. That is what lets you read a public lesson, mark it done, and keep the credit while signed out or offline. Nothing is sent anywhere for that to work.
When you are signed in, the app reconciles that local record with the copy on our servers so the two agree across your devices. Clearing your browser’s storage clears the local copy; the copy on our servers stays until you delete it from your account page.
The AI Lab
The Lab asks you for a topic, never for a prompt. You type something like “photosynthesis”, and we place it into three prompts we wrote, so you can see how the same subject asked three ways produces three different answers. There is no path through the Lab that sends your words to a model as instructions.
The topic you type is sent to Anthropic, which runs the model that writes the comparison, and is handled there under Anthropic’s own terms for the requests it receives.
By default we store neither the topic you typed nor the text the model wrote back. What we keep is measurement: which model ran, how many tokens it used, what it cost, how long it took, and whether it succeeded, failed, or was declined. That is enough to answer “is this working and what does it cost”, and it is deliberately all we take. The same rule governs the analytics event we send about a generation — it carries the numbers and never the words.
There is one exception, and it is yours to switch on. On the Lab’s own page you can ask us to keep your runs on your account instead of in your browser. It is off until you turn it on, and if you never do, the paragraph above describes everything we hold. Turn it on and we store the topic and the three answers, so the same runs reach your other devices. Your household keeps the most recent fifty and each new run drops the oldest — a count rather than a number of months, because a count is a limit the code applies on every save rather than a promise waiting on a cleanup job we do not run. Switching the setting off deletes what was stored. Saved runs are in your account download, and they go when you delete your account.
Measurement
We use PostHog to see which pages are useful and to catch errors that would otherwise go unreported. In the browser, nothing is measured until you say yes: a banner asks, your answer is kept in your browser, and the analytics code is not even downloaded unless you agree. Decline and we stop, and we do not ask again.
Two things are switched off on purpose. We do not capture every click and keystroke automatically, and we never record your screen. On our servers we send one event when a subscription changes and one when a Lab generation finishes; both are labeled with a household identifier rather than with you, and neither carries anything you typed.
Cookies and browser storage
We use a small number of cookies and browser storage entries. None of them are advertising cookies.
- Sign-in session cookie
- Holds your session so you stay signed in. Without it, signing in cannot work.
- Language cookie
- A cookie named NEXT_LOCALE remembering the language you chose, so the signed-in app opens in it.
- Appearance
- Browser storage holding your light or dark preference and your chosen palette. It is read before the page paints, so the site does not flash the wrong colors at you.
- Your analytics answer
- Browser storage holding your yes or no to measurement, so we only ask once and never override it.
- Lesson progress
- Browser storage holding the progress described above, so it works signed out.
- Analytics, if you agree
- If you accept measurement, PostHog sets its own cookie and storage entries to recognize a returning browser. Decline and they are never created.
Who else handles your information
We use a small set of companies to run the service. Each one receives only what it needs to do its job, and none of them may use your information for their own purposes.
- Cloudflare
- Hosts and serves the site. Every request passes through it.
- Neon
- Hosts the database that stores the records listed above. It runs in a United States region.
- Stripe
- Takes payments and runs the subscription. Card details go to Stripe directly and never reach us; we keep only the identifiers Stripe hands back.
- SendGrid
- Sends sign-in links and other service email. It receives the address a message is going to.
- PostHog
- Receives product measurement — in your browser only after you agree, and from our servers only as counts and costs.
- Anthropic
- Runs the model behind the AI Lab, and receives the topic you type there.
We do not sell your information and we do not share it with advertising networks. We will hand over information if the law requires it, and we would tell you unless we were forbidden to. If the service is ever transferred to another company these records would move with it, and we would say so here first.
Where information is processed
Reed Stories LLC operates from the United States, and that is where the records above are held. The database that stores your account, household, learner, progress, plan, and Lab usage records — along with any Lab runs you have chosen to save — runs with Neon in a United States region.
The other companies above are international. Cloudflare answers a request from whichever of its locations is nearest you, so a page opened in Europe is served in Europe. Stripe, SendGrid, Anthropic, and PostHog each operate in more than one country. A payment, a sign-in email, a Lab topic, or a measurement event may therefore be handled outside the country you live in, even though the records we hold ourselves stay in the United States.
Who can see a learner’s record
Access to a learner’s record is an explicit grant to one person, for one learner, that you can withdraw at any time. It does not follow from sharing a household, because sharing a household is at once too broad — a blended family, or a teenager with their own login — and too narrow, since a grandparent or a tutor lives somewhere else.
An invitation gives no access until the recipient signs in with the invited address and accepts it. Withdrawing access ends it. Staff accounts get nothing automatically: running the site is not the same as being entitled to read one child’s learning record, and if it were, the list of who can see your child would be a lie.
A guardian invitation may be sent before the recipient has an account. We store one-way hashes of the invited address and the invitation token, not readable copies. The review link expires after seven days, and it grants no access by itself.
How long we keep things
Different records are kept for different lengths of time. Sign-in sessions are not in the list below, because they expire on their own.
- Account and learning records
- Your account, your household, every learner in it, and all of their lesson progress are kept for as long as the account exists. Nothing here is on a timer: it lasts until you delete the account, and then it goes.
- Deleting your account
- Your details and settings, your household, every learner in it, all of their progress, your plan and subscription records, your Lab usage, and any Lab runs you had saved leave the live database at once, in a single transaction, when you press the button on your account page. There is no waiting period, no queue, and no hidden “deleted” flag that keeps a row readable.
- Backups
- Neon keeps its own backups and point-in-time recovery snapshots of the database, and a record you deleted can still sit inside one of those for about thirty days before it ages out. That window belongs to the hosting provider and is not a timer this application runs: we cannot reach into a snapshot to edit it, and we do not restore one in order to bring a deleted account back.
- AI Lab usage
- The per-generation rows and the monthly totals are kept for twenty-four months, or until you delete your account, whichever comes first. They hold no topic and no generated text — only which model ran, what it used, what it cost, and whether it worked. That stays true whatever you have chosen about keeping runs; saved runs are a separate record with its own entry here.
- Saved AI Lab runs
- Kept until one of three things happens: you switch saving off, you delete them from the Lab page, or you delete your account. There is no time limit here because there is a count limit instead — your household keeps the most recent fifty, and the oldest is dropped in the same transaction that saves a new one. We would rather state a bound the code applies on every save than a number of months nothing here would enforce.
- Billing records
- Subscription and payment records are kept for seven years, which is the span United States tax and accounting practice expects a business to be able to produce its own records over. Deleting your account removes our copy sooner than that. Stripe keeps its own record of a payment it processed, under its own terms, and that one is not ours to delete.
- The staff action log
- Kept for seven years, for the same accounting reason, and never edited. It survives your deletion, because it records that a staff member did something — not what your family was learning.
- Withdrawn guardianship grants
- Kept indefinitely. Withdrawing one marks the record rather than removing it. A withdrawn grant gives nobody any access; it is the record that the access existed and when it ended, and “who could see my child, and when” is exactly the question it is there to answer. The one thing that removes it is deleting the learner it points at — at that point the record is a privacy liability rather than a useful history.
Three things survive on purpose. Access you held over a child in another household is marked withdrawn rather than erased, because that record answers a question for their family. Entries in the staff action log keep the fact that an action happened, because a log that can be edited afterwards is not a log. And the account row itself is emptied and left anonymous rather than removed outright, so those withdrawn grants still have something to point at — it holds no name, no address anyone can reach, no settings, and no staff role, and nobody can sign in to it.
Your choices and your requests
You can change your name, your language, and your appearance settings yourself at any time on your account page. You can download everything held here for you from the same page, and you can delete your account there too. A subscription is cancelled by you in Stripe’s customer portal. For anything else, write to us and a person will deal with it.
- A copy of what we hold
- Ask, and we will tell you what is stored against your account.
- A correction
- Tell us what is wrong and we will fix it.
- An export
- Download it yourself, from your account page: one file with your account, household, learner, progress, plan, subscription, and Lab usage records, plus any Lab runs you have saved.
- A deletion
- Delete your account yourself, from your account page. It is immediate, and it takes every learner’s progress with it.
Deleting your account is a button on your account page rather than a request you send us. It happens immediately, it cannot be undone, and it destroys each child learner’s whole progress history along with your own. If a subscription is still live we will refuse and send you to Stripe’s customer portal first, because we do not cancel a subscription on your behalf and an account that keeps billing after it is gone helps nobody. Three things are kept on purpose, and the retention section above says which. Write to us instead if you would rather a person did it, or if you want something corrected. Depending on where you live, local law may give you further rights; we will honor those where they apply.
How we protect it
Signing in uses a single-use link sent to your email address, valid for 24 hours and stored on our side only as a hash, so the link itself cannot be read back out of our database. You can sign in with Google instead if you prefer. Sessions live in our database rather than only in a token, which means we can end one. Traffic to the site is encrypted.
Staff access is limited to running the service and is written to the log described above. No service is perfectly secure and we will not pretend otherwise; if a breach affected your information, we would tell you.
Changes to this policy
When we change this policy we update the effective date at the top. If a change materially affects what we collect or who receives it, we will say so on the site and, where we can, by email before it takes effect.
How to reach us
Write to us about anything on this page: a question, a copy of your records, a correction, or a deletion. A person answers, not a form. Post reaches us at the business address in the first section.