Preview — site in soft-launch review
Year 5 & 6 selective entry preparation · Perth, Western Australia admin@korvaacademy.com.au Parent login

HomeSafety & privacy

Safety & privacy

How Korva protects your child’s privacy and safety

What we collect, why, who else sees it, and what the law asks of us — in plain English, with the documents behind it.

1 · Our strongest commitments

Our strongest commitments

  • No advertising to children Korva does not advertise to children, and shows no third-party advertising to anyone.
  • No data sold Korva does not sell child data, and does not use it for targeted marketing.
  • No child names collected Korva does not collect a child’s real name, age, date of birth, school or location. Your child picks a nickname from fixed word lists.
  • No tracking Korva uses no third-party trackers or analytics.
  • Used for practice only Your child’s answers, mistakes, writing and progress are used only to run practice and the Masterclass, and to show progress to you.

What we hold about your child

What we collect, and what we don’t

We collect

  • A nickname your child picks from fixed word lists
  • An optional PIN, set by you
  • Their practice answers
  • Their Mistake Bank — questions to try again
  • Their writing — the text is deleted 24 hours after feedback; the score and feedback stay
  • Their Masterclass progress
  • When they practised

We don’t collect

  • Their real name
  • Their age or date of birth
  • Their year level
  • Their school
  • Their location
  • Photos or voice recordings
  • Sensitive information, such as health or background

For you, the parent, we hold your name, email address, a hashed password, your consent choices and, if you subscribe, the Stripe reference for your subscription.

2 · The law

What the law requires and how we meet it

Korva is built to the draft Children’s Online Privacy Code, the Australian Privacy Principles and the Notifiable Data Breaches scheme.

The Code is still a draft. The Children’s Online Privacy Code was published by the Office of the Australian Information Commissioner as an exposure draft and is expected to be registered by 10 December 2026. Its section numbers and wording may change. This table describes Korva’s good-faith approach to the draft — it is not a certification, and no regulator has reviewed or approved it. Korva applies the Code to every user, whatever their age.
Children’s Online Privacy Code (exposure draft)
ObligationSourceHow Korva meets it
Work out which users are children, or treat everyone as oneCode s7–8 Korva is a service for Year 5 and 6 children, so the Code covers it. We apply the Code to every account rather than checking ages (s8(5)), so no one is asked to prove their age.
Collect only what is strictly necessary, by defaultCode s9 Practice needs answers, a nickname and progress. Anything optional — such as sending answers to our AI provider — is a separate choice in consent settings.
Collect, use and share only in the child’s best interestsCode s10–11 We have written down why each piece of information helps the child, in our best-interests assessment. No ads, no profiling for marketing, no sale of data.
A parent consents for a child under 15, and we confirm they are a parentCode s13 Only parents give consent; children sign nothing. Only a parent account can add a child, and at sign-up the parent confirms they are 18 or over and the child’s parent or legal guardian. That confirmation is recorded. Each child then gets a short, age-appropriate notice the first time they sign in.
Consent is voluntary and not bundledCode s14 Each use is asked about separately, and nothing that is not strictly needed is a condition of using Korva.
Consent is informed, with a written notice firstCode s15 Each consent names the information, the purpose, how long we rely on it (never more than 12 months), what happens if you say no, and how to withdraw.
Consent can be withdrawn easilyCode s17 Every consent has a withdraw switch in consent settings. No email or phone call needed.
Consent is specificCode s18 One consent per purpose — data collection, AI processing, overseas transfer and email delivery are asked for separately.
Consent is unambiguousCode s19 No pre-ticked boxes, and carrying on using Korva is never treated as a yes.
Ask the child too, in some casesCode s20 Korva does not collect sensitive information, does not use children’s information for new purposes and does no direct marketing, so the cases this section covers do not arise. Children still see a short welcome notice the first time they sign in.
No pressure or tricks to get consentCode s21 No countdowns, no pre-selected options and no wording that makes saying no harder than saying yes.
A privacy policy written for childrenCode s23 A separate privacy page for kids, in short sentences, linked from the child’s home screen.
Tell children clearly when we collect informationCode s24 Children see a short notice the first time they sign in, and their privacy page is one tap from home.
Review privacy practices every year, and keep recordsCode s25 An annual review is scheduled and recorded in a compliance log we can hand to the Commissioner on request.
Let children and parents see and ask about their informationCode s27–28 Parents see every question and answer on their child’s activity page. Anyone can ask how information is handled; we reply within 30 days, in child-friendly words when a child asks.
Destroy a child’s information on requestCode s32 Request it from your settings. We destroy it within 30 days and confirm in writing; if anything must be kept by law, we say what and why.
Tell a child when a parent can monitor themCode s33 The parent dashboard shows a child’s progress, and the child is told so on their first sign-in and on their home screen. Korva collects no location data.
Child-friendly information about rights, and a way to complainCode s35–36 A privacy concern form that a parent or child can use, with or without a name, and our complaints process. We aim to deal with each within 30 days.
Assess privacy impact before new features, and publish a registerCode s38–39 A privacy impact assessment for Korva as it stands, and a public register of every assessment.
Privacy training for anyone who handles children’s informationCode s40 Everyone with access completes training when they start and every year after, and it is recorded. See our team.
Australian Privacy Principles and the breach scheme
ObligationSourceHow Korva meets it
Be open about how information is handled, and say so at collectionAPP 1, APP 5 A privacy policy for parents, one for children, and notices at sign-up and at a child’s first sign-in.
Allow a pseudonym where practicalAPP 2 Children are known only by a nickname they pick. Parents give a name and email because an account and billing need them.
Collect only what is needed, fairly, and deal with anything unasked-forAPP 3, APP 4 No real name, school, photo or location for a child. Anything we receive that we did not ask for is deleted.
Use and share information only for the reason it was collected; no unwanted marketingAPP 6, APP 7 Used to run practice and show progress. No direct marketing, and the only emails are a password reset and an account-deletion confirmation.
Protect information sent overseasAPP 8 Four providers, all in the United States, each named below with what they receive. Overseas transfer is a separate consent.
Do not adopt government identifiersAPP 9 Korva collects no tax file numbers, Medicare numbers or other government identifiers.
Keep information accurate and secure, and destroy it when no longer neededAPP 10, APP 11 Encrypted connections, hashed passwords, written answers deleted 24 hours after marking, and account deletion from settings.
Give access to information, and correct itAPP 12, APP 13 Parents see their child’s record in the dashboard and can change details in settings. Ask us for anything else; we reply within 30 days.
Notify eligible data breachesPrivacy Act Part IIIC (Notifiable Data Breaches scheme) If a breach is likely to cause serious harm, we tell affected families and the Commissioner as soon as practicable, consistent with the scheme. See our breach response summary.

3 · Our documents

Our documents

4 · Regulators

Who regulates us

Office of the Australian Information Commissioner (OAIC)

Privacy, the Australian Privacy Principles, the Children’s Online Privacy Code and data breaches. oaic.gov.au/privacy/privacy-complaints

Australian Competition and Consumer Commission (ACCC)

Your rights as a consumer under the Australian Consumer Law, including refunds and fair dealing. accc.gov.au/consumers

5 · Sharing

Who we share data with

Four companies help run Korva, all in the United States. Anthropic is the only one that receives your child’s practice content — answers when they ask for a hint, and writing for feedback. Stripe and Postmark receive parent details only. Railway hosts the site. Pages load no third-party trackers or analytics.

We use Anthropic (makers of Claude AI) to generate practice hints and writing feedback. We send only the question and the child’s response — never their nickname, the parent’s email or any other identifier — so Anthropic cannot see who wrote it. (If a child types their own name into a piece of writing, that text is sent as written.)

CompanyWhat they receiveWhyWhereOpting out
Anthropic
AI provider
Your child’s answers, their hint and explanation requests, and their written responses. No name at all — not even the nickname — and no email or account details. To give hints, explain answers, give writing feedback and prepare lessons. United States Withdraw “AI processing” in consent settings. The consequence: no hints and no writing feedback (nor explanations or personalised lessons) while it is withdrawn.
Stripe
Payments
The parent’s email and payment details, entered on Stripe’s own page. Korva never sees the card number. No child information. To take the subscription payment and send receipts. United States, with global processing Only used if you subscribe. The free trial needs no card. Without it, Korva cannot take payment, so access ends when the trial does.
Postmark
Email delivery
The parent’s email address and the message. No child information. To send a password reset when you ask, and confirmation when you delete your account. Nothing else. United States Withdraw “email delivery” in consent settings. You will then get no reset or deletion emails — write to us instead.
Railway
Hosting
Everything Korva stores, because it runs the servers and the database. To run the website. United States Korva cannot run without hosting. If you do not want your information held in the US, the honest option is to ask us to destroy it or delete your account.

6 · Our team

Our team

Korva is operated by Ashlin Alex, sole founder. Anyone with access to children’s personal information completes privacy training every year.

7 · Concerns

What to do if something’s wrong