1. Description of the service
Korva Academy is a subscription website that gives Year 5 and 6 students in Western Australia practice for selective entry testing: multiple-choice practice in four sections, writing practice with AI feedback, a Mistake Bank, Masterclass lessons on a digital chalkboard, and a weekly mock and challenge. A parent or guardian opens the account, pays, and creates child profiles. The child picks a profile and practises. Korva is run by one person, a sole trader, with no staff.
Korva is "primarily concerned with the activities of children" (draft Code section 5(b)) and so expects to be bound by the Code. It applies the Code to every user regardless of age (section 8(5)).
2. Scope
This assessment covers the whole service as it runs on 2026-10-07: registration, consent, child profiles, every practice and lesson surface, the parent dashboard, billing, email, hosting, privacy requests, and the administrator surface. It does not cover the bank of practice questions, which is authored content and holds no personal information.
3. Context
- Users: parents and guardians (adults), and children aged about 9 to 12.
- Relationship: the parent holds the account; the child has no account, no email address and no login of their own.
- Expectations: a parent expects practice to be marked and progress shown. A child expects to practise; they are not expected to understand data flows, so the children's privacy policy and first sign-in notice explain them in plain words.
- Scale: soft launch; small numbers of families.
4. Information flows
| Step | Information | From | To | Stored where |
|---|---|---|---|---|
| Registration | Parent email, optional name, password (hashed); consent records with IP and user agent | Parent | Korva | Railway (US) |
| Child profile | Nickname picked by the child from fixed word lists; optional PIN (hashed) | Child; parent | Korva | Railway (US) |
| Practice | Answers, time, right/wrong, hints, reveals; session times | Child | Korva | Railway (US) |
| Hints and explanations | The question and the child's answer | Korva | Anthropic (US) | Not kept by Korva beyond the practice record |
| Writing feedback | The child's writing text | Korva | Anthropic (US) | Text erased by Korva after about 24 hours |
| Masterclass | Lesson position and board working | Child | Korva | Railway (US); blanked about 24 hours after last touch |
| Parent dashboard | The child's practice, scores, writing (while it exists), feedback | Korva | Parent | — |
| Payment | Parent email, card details (entered on Stripe's page) | Parent | Stripe (US and others) | Stripe; Korva keeps customer and subscription ids |
| Parent email, password-reset link or deletion confirmation | Korva | Postmark (US) | Postmark | |
| Privacy requests | Message, optional contact, dates, response | Parent or child | Korva | Railway (US) |
5. Purposes
To mark practice and choose the next question; to return mistakes for review; to give hints, explanations and writing feedback; to let a child resume a lesson; to show a parent their child's progress; to take payment; to send the two account emails; to keep evidence of consent; to answer privacy requests and complaints.
6. Strict necessity (draft Code section 9)
| Information | Strictly necessary? | Explanation |
|---|---|---|
| Nickname | Yes | A profile must be selectable and distinguishable from a sibling's. |
| PIN | No — optional | Off unless the parent sets it. |
| Practice responses | Yes | Practice cannot be marked or adapted without them. |
| Mistake Bank | Yes | It is a core feature of practice. |
| Writing text | Yes, briefly | Needed to produce feedback; erased about 24 hours later. |
| Masterclass board working | Yes, briefly | Needed to resume a lesson; blanked about 24 hours after last touch. |
| Session information | Yes | Needed to group practice and show the parent activity. The end-of-session note is optional. |
| AI processing by Anthropic | Needed for hints, explanations and writing feedback | These features cannot run without it. The parent gives a separate consent and can withdraw it. [lawyer review recommended: whether AI hints are "strictly necessary" to the service, or an optional feature that must work without consent under section 9(2)(a)] |
Information that is not collected — real name, date of birth or age, year level, school, address or location, photo, video, voice and any sensitive information — is listed with reasons in the best interests assessment.
7. Lawful and fair collection
- Information about a child is collected only after a parent or guardian has given consent, separately for each purpose, with no pre-ticked boxes and no bundled requests (draft Code sections 13-19, 21).
- The parent confirms they have parental responsibility for each child (section 13(2)(b)).
- The child is never asked to consent. On first sign-in they receive an age-appropriate notice of what is kept, why, who can see it and how to ask a question or change their mind (section 13(3)).
- No dark patterns: refusing an optional consent does not block the service; withdrawing is available at /settings/consent.
- Nothing is collected from third parties, and there is no tracking or analytics on any page.
8. Best interests (draft Code sections 10-11)
Every category of information and every use and disclosure was assessed, with reasoning, in the best interests assessment, dated 2026-10-07. Every collection, use and disclosure was assessed as consistent with the child's best interests; direct marketing, advertising, sale and profiling for any other purpose were assessed as not in the child's interests and are not done.
9. How Korva complies with the draft Code
| Section | Requirement (summary) | How Korva meets it |
|---|---|---|
| 7-8 | Application; age assurance | Code applied to everyone (s8(5)); no age check needed |
| 9 | Strictly necessary by default | Section 6 above; optional items off by default |
| 10-11 | Best interests | Published best interests assessment |
| 13 | Parental consent; notice to child | Consent at /settings/consent and registration; child notice at /practice/welcome |
| 14-19 | Voluntary, informed, current (12 months), withdrawable, specific, unambiguous consent | Five separate consents, no pre-ticked boxes, renewed within 12 months, withdrawable at /settings/consent |
| 20 | Child assent for sensitive information, secondary use or direct marketing | Does not arise: no sensitive information, no secondary use, no direct marketing |
| 21 | No coercion | No incentives or penalties tied to consent |
| 23 | Children's privacy policy | /privacy?for=kids |
| 24 | Age-appropriate collection notice | First sign-in notice; children's policy |
| 25 | Annual review, with records | Annual review recorded in the compliance log; next due 2027-10-07 |
| 26 | Cross-border information for children | Children's policy names all four overseas providers in plain words |
| 27-28 | Access; information about handling; 30 days | Requests via /privacy-concern or email; answered within 30 days |
| 29 | Opting out of direct marketing | No direct marketing is sent |
| 30-31 | Access and correction for children within 30 days | Same process, age-appropriate answers |
| 32 | Destruction on request, written notice, 30 days | /settings/destruction-request; written confirmation |
| 33 | Tell the child about parental monitoring | First sign-in notice; children's policy |
| 35-36 | Children's rights information; child-friendly complaints, anonymous option, 30 days | /legal/privacy-complaints and /privacy-concern |
| 38-39 | PIA and published register | This document; /legal/pia-register |
| 40 | Training for people with regular access | Training record for the operator, to be signed; access register |
10. Compliance with the Australian Privacy Principles
| APP | How Korva meets it |
|---|---|
| 1 Open and transparent management | Two-version privacy policy; annual review; this PIA; breach response plan |
| 2 Anonymity and pseudonymity | Children use nicknames; general questions and complaints can be anonymous. A parent account needs an email because it holds a subscription |
| 3 Collection of solicited information | Only what is listed in section 6; consent-based; no sensitive information |
| 4 Unsolicited information | Free-text fields are few (writing, end-of-session note, privacy messages). Writing is erased after about 24 hours; children are told not to type private things |
| 5 Notification of collection | Privacy policy; child notice; consent screens |
| 6 Use or disclosure | Only for the purposes in section 5 |
| 7 Direct marketing | None |
| 8 Cross-border disclosure | Four US recipients named in both policies; parent consent to overseas disclosure; provider terms reviewed. [lawyer review recommended: APP 8.1 "reasonable steps" — Korva relies on the providers' standard terms] |
| 9 Government identifiers | None collected |
| 10 Quality | Data comes directly from the user; parents can correct |
| 11 Security | Hashed passwords and PINs, HTTPS, no card data, administrator audit log, short retention for writing and board working |
| 12 Access | Dashboard plus requests answered within 30 days |
| 13 Correction | Settings, plus requests answered within 30 days |
| NDB scheme | Breach response plan; assessment within 30 days; notification as soon as practicable |
11. Risks of harm and mitigations
| Risk | Kind of harm | Likelihood before mitigation | Mitigations | Residual risk |
|---|---|---|---|---|
| A child types personal details (name, school, feelings) into writing or a note | Emotional; physical if location is revealed | Medium | Writing text erased after about 24 hours; no real-name fields; children told not to type private things; only the parent sees it | Low |
| A database breach exposes children's practice records | Emotional (embarrassment about scores); material for parents | Low | No real names, ages or schools held, so records are hard to link to a child; hashed passwords and PINs; short retention for writing; breach response plan | Low |
| AI feedback is wrong or discouraging | Emotional; developmental | Medium | Feedback rules are tested; scores labelled estimates; Fo's tone is encouraging; answers verified against certified explanations | Low to medium |
| Overseas provider misuses data | Material; emotional | Low | Only the question, answer and writing sent to Anthropic, with no name or contact detail; providers' no-training terms | Low |
| Pressure from scores and readiness estimate | Emotional; developmental | Medium | No points, streak rewards or leaderboards shown to children; no comparison with other children | Low to medium |
| A sibling or another person uses the wrong profile | Emotional | Medium | Optional PIN; parent can see and remove activity | Low |
| Parent oversight the child does not know about | Emotional | Medium | Child is told on first sign-in and in the children's policy that a grown-up can see their work | Low |
| Unauthorised administrator access | Material; emotional | Low | One operator; password-only admin sign-in with throttling and forced password change; audit log; training before access | Low |
12. Recommendations and actions
- Run every future feature that changes how children's information is handled through a PIA before it ships, and add it to the register.
- Record the operator's signed privacy training before 2026-12-10.
- Record the first annual privacy review by 2027-10-07.
- Obtain legal review of this PIA, the privacy policies and the Terms before the Code commences. [lawyer review recommended]
- Confirm that the two 24-hour purges run on the production server, not only in development.
13. Sign-off
Prepared: 2026-10-07. Operator approval: pending signature, recorded in Korva's compliance log when given.