Trust, privacy, and how it actually works
Built so no one has to take our word for it.
Privacy here isn’t a policy bolted on at the end — it’s the architecture. Here is exactly how each product handles a child’s data, and why, in the places that matter most, there’s nothing to handle.
Why we built it this way
Sending words to a server used to be the only way to make AI useful.
Once a child’s data sits on servers, the incentives change — profiles, personalisation, monetisation.
So we waited. Until useful AI could run on the device itself.
Now the learning conversation happens locally.
That’s not a privacy policy. It’s architecture.
A policy is a promise. Architecture is a constraint.
Three modes, one principle
Honest about where the AI runs.
The connections an unlinked device makes
The app connects only for limited operational reasons.
None of these is designed to carry a child’s conversation. When a device isn’t linked to a classroom, this is the shape of everything it sends.
The principles, stated plainly
No server-side student.
In Class and in the national Index there is, by construction, no student record on any server. There’s no child’s learning conversation sitting on our servers — nothing from it to sell, nothing from it to breach.
No trackers. No advertising. No data brokers.
The apps carry no third-party tracking, no advertising and no data brokers. There’s no behavioural profile being built, and nothing being sold.
No real money in a child’s hands.
Through launch, every market and every transaction is a simulation. No child moves real money inside TWin.
Designed against the frameworks that matter.
We build to be defensible to the people who answer for children — DPDP, KHDA, ADEK, COPPA, GDPR-K, FERPA. The test we set ourselves: could we show any screen to a thoughtful regulator without apologising for it?
The Index — privacy as a public good.
Anonymised, aggregated classroom scores become a public instrument for financial literacy — designed so an aggregate can’t be resolved back to a single child.