1. Scope and responsibility
Promptogo Inc. (the Company) operates PrompToGo. This Privacy Policy describes personal information handled through promptogo.ca, learning accounts, classroom tools, enrollment enquiries and support. It also explains how an individual can raise a privacy request.
Questions or complaints should be directed to the Privacy Contact at promptogo.learn@gmail.com. The Company’s registered office is 2905-88 Queen St E, Toronto, Ontario M5C 0B6, Canada. This is not a walk-in classroom.
2. Information collected
Account information includes names, email addresses, account identifiers, requested account type, approval status and sign-in records. Password authentication is handled by the authentication service. Users should never send a password to staff.
Learning information can include class and room membership, parent-student links, lesson completion, and EXP awards and reasons. It can also include recorded participation and reports that staff prepare and share. Where collaborative or AI activities are enabled, records can include prompts, messages, suggestions, project code, uploads, generated responses and project versions.
Forms and support requests may collect contact details, the student’s age band or grade, and program preferences. They may also collect quiz answers, results and information provided in a message. Enrollment and payment records may include the selected program, transaction status and billing or receipt information. Payment providers process payment details through their own systems.
Hosting and security systems can process technical information such as an IP address, browser or device information, request time, errors and access logs. Authentication uses cookies or browser storage to keep a User signed in. Browser storage may also preserve activity state or preferences. Disabling that storage can prevent account features from working.
3. Purposes and consent
The Company uses information to create and approve accounts, assign classes, deliver activities, record progress and share authorized reports. It also uses information to respond to enquiries, administer enrollment and payments, prevent misuse and maintain the service. It may also use records to resolve complaints and meet legal obligations.
A form or activity may provide an additional notice about the information it requests. Optional promotional communications and identifiable publicity require an appropriate separate permission. A person may decline optional uses or ask to withdraw consent, subject to legal or contractual limits. Withdrawal can affect a service that needs the information. The Company will explain the relevant effect.
Registration does not require email verification. Administrator approval controls learning access. Neither that approval nor an email address, by itself, proves a parent’child relationship or establishes parental consent.
4. Children and parent access
A Parent must contact the Company before creating an account for a child under 13. This also applies when a child cannot understand the proposed handling of personal information. The Company must arrange appropriate parental or guardian consent for that participation. Older students should review the service and this policy with a Parent.
Parent access requires staff to establish an authorized account link. Linked Parents may see the classes and student reports made available through the parent portal. Parent access is subject to the student’s rights and applicable law. It is not an unrestricted right to every record.
A Parent who believes a child supplied information without appropriate permission should contact the Privacy Contact. The Company will assess the request, restrict access where appropriate, and address consent or deletion as required. Users should not include another child’s private information in a prompt, project or support message.
5. Access, sharing and service providers
Authorized administrators and teachers access information needed for their work. Staff-linked Parents receive the records made available to their linked account. Participants in a shared activity may see the names, messages and work shared in that activity. A shared classroom is not a private diary.
The platform uses Supabase for account authentication and database services and Vercel for hosting. Other providers may process information for payments, communications, support or an enabled learning activity. Providers receive the information needed for the relevant function. A separately accessed external service is also subject to its own privacy policy.
The Company does not sell personal information or use student personal information for advertising targeting. It may disclose information where required or permitted by law, including to respond to a lawful request or protect participants and the service. Public use of identifiable student work, images, recordings or testimonials requires separate permission.
Information may be stored or processed outside Canada by service providers. It can be subject to the laws and lawful access procedures of the country where it is processed. This policy does not promise Canadian-only storage.
6. AI processing and classroom records
For an enabled AI classroom feature, the platform may send prompts, relevant conversation history, project context and selected uploads to Google’s Gemini service. A teacher may also introduce a separate external tool, subject to that tool’s eligibility and privacy requirements.
Prompts, responses and project history may be retained in classroom records. They are not necessarily discarded after a response or stored only on a User’s device. Users must not submit sensitive personal information to an AI activity.
Provider retention and model-improvement practices depend on the service and account configuration used. This policy does not make a blanket promise that every external AI provider excludes all inputs from training. A Parent or student may ask which tool is proposed and how information is handled before taking part.
7. Retention and safeguards
The Company retains information for the purposes described in this policy. These include active program delivery, account support, record correction, complaints, payment administration and legal obligations. Different records can require different retention periods. Information should be deleted or de-identified when no longer required for those purposes, subject to applicable requirements.
A closure or deletion request may not remove every copy immediately. Backups, transaction records, security records and information subject to a legal hold may remain for an applicable period. The Company will explain relevant restrictions when responding to a request.
The platform uses authenticated accounts and role-based access controls for protected learning records. These measures reduce risk but cannot guarantee absolute security. A User should keep passwords and private setup links confidential and promptly report suspected unauthorized access.
8. Access, correction, deletion and complaints
An individual may send a privacy request to promptogo.learn@gmail.com. Requests can concern access, correction, account closure, deletion, withdrawal of an optional consent or a privacy complaint. The request should identify the relevant account and the requested action without including a password or unnecessary sensitive information.
The Company may require proportionate verification of identity or authority before disclosing or changing records. It will respond within the time required by applicable law and explain a refusal or limitation where required. Access may be limited to protect another person’s information or meet a legal requirement.
An individual may contact a privacy authority if the Company does not resolve a concern. This includes the Office of the Privacy Commissioner of Canada or another authority with jurisdiction. This policy does not restrict that right.
9. Changes to this policy
The effective date identifies this version. The Company will provide appropriate notice of material changes and obtain fresh consent where required for a new use of personal information. Posting an updated policy does not, by itself, authorize an incompatible new use of previously collected information.