COPPA Compliance
ThinkKits does not collect, use, or disclose personal information from children under 13. Our platform is built for adult school administrators, district leaders, and education vendors — not for students. We rely exclusively on aggregate, publicly available federal data about schools and districts.
1. Overview and Applicability
The Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, and the FTC's implementing rule at 16 C.F.R. Part 312, protect the online privacy of children under 13 by restricting operators of websites and online services directed to children — or with actual knowledge of child users — from collecting their personal information without verifiable parental consent.
On January 14, 2025, the FTC published its final amended COPPA Rule, with most provisions effective April 22, 2026. The 2025 amendments strengthen child privacy protections by, among other things: expanding the definition of personal information, imposing stricter consent requirements, adding a targeted advertising prohibition, requiring a written information security program, and mandating separate consent for third-party data sharing.
ThinkKits is not directed to children under 13 and does not have actual knowledge that any child under 13 uses the platform. This page explains how our product design, data practices, and security measures align with COPPA and the 2025 amendments.
2. ThinkKits Does Not Collect Data From Children Under 13
ThinkKits is a B2B intelligence platform designed exclusively for adult professionals: school principals, district administrators, curriculum directors, purchasing officers, and education vendors. Children are never the intended users of this service.
Who our users are
- School and district administrators (adults employed by educational institutions)
- Education technology vendors and their sales teams
- Curriculum and purchasing decision-makers
- Grant writers and funding specialists
Account registration
To create an account, users must provide a professional work email address (which we verify), a full name, and confirm they are 18 years of age or older. We do not permit account creation by anyone under 13, and our Terms of Service prohibit use by minors without parental consent consistent with applicable law.
We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided personal information, we will promptly delete it and terminate any associated account.
Contact us immediately at privacy@thinkkits.com. We will investigate and delete any such information within 5 business days.
3. Our Data: Aggregate School and District Information From Public Federal Sources
The knowledge graph powering ThinkKits contains data about schools and districts as institutions — not about individual students or children. Every data point in our system originates from publicly available federal datasets.
Data sources
- NCES Common Core of Data (CCD) — school and district identifiers, enrollment counts, grade spans, locale codes
- NCES EDGE (Education Demographic and Geographic Estimates) — geographic and socioeconomic characteristics at the district level
- NCES Free and Reduced-Price Lunch (FRL) data — aggregate school-level eligibility percentages (not individual student records)
- U.S. Department of Education Title I allocations — aggregate funding data by district
- USASpending.gov — federal grant and contract award data to institutions
- State education agency open data portals — publicly released proficiency, assessment, and demographic summaries
What this data is and is not
All enrollment, demographic, and performance figures in ThinkKits represent aggregate counts and percentages at the school or district level. No data record in our system corresponds to a named individual student, a student ID, a student's grades, a student's test scores, or any other record that could identify a specific child.
This data is the same information published on federal agency websites and accessible to any member of the public. ThinkKits organizes and surfaces it through a structured knowledge graph and scoring engine — we do not generate, infer, or enrich any data about individual children.
Our data integrity policy prohibits loading any personally identifiable student data into our systems. Every node in our knowledge graph must carry a source property pointing to a public federal dataset. Synthetic or student-level data is categorically banned.
4. School Administrators as Operators
When a school or district professional uses ThinkKits, they are the operator under their institution's policies and applicable law. ThinkKits provides analytical tools and reports to those adult professionals. We do not provide services that the school then deploys to students.
In the COPPA framework, the "operator" is the entity that collects personal information from children through an online service. ThinkKits does not operate any service that students interact with. We interact only with the adult administrators who use our platform.
If a school purchases ThinkKits and a district IT administrator uses it to analyze Title I funding eligibility, the interaction is entirely between ThinkKits and that adult professional. No student data flows into or out of our systems as part of that workflow.
5. No Advertising, No Monetization of Child-Related Data
ThinkKits earns revenue through subscription fees paid by adult professionals and institutions. We do not:
- Display targeted or behavioral advertising of any kind
- Sell, license, or broker any data (aggregate or otherwise) about children or student populations
- Use school demographic data to build advertising profiles
- Permit third parties to use our platform data for advertising purposes
- Monetize any data through secondary markets
The 2025 COPPA amendments prohibit conditioning a child's participation in an activity on the disclosure of personal information beyond what is reasonably necessary, and prohibit using personal information of children for targeted advertising. These prohibitions are consistent with our existing practices, which prohibit any advertising monetization model entirely.
Our SaaS tiers (Explorer, Starter, Professional, Business) are the only revenue source associated with the ThinkKits platform. Subscriber data is used solely to operate and improve the platform.
6. Written Information Security Program (WISP)
The 2025 COPPA amendments require operators to establish, implement, and maintain a written information security program (WISP) appropriate to the size and nature of the operator's activities and the sensitivity of the information collected. The following is a summary of our program.
6.1 Program governance
- A designated data security lead is responsible for coordinating and overseeing the WISP
- The program is reviewed at least annually and after any significant system change or security incident
- All personnel with access to personal data receive security awareness training at onboarding and annually
6.2 Technical safeguards
- Encryption in transit: All data transmitted between users and ThinkKits is encrypted using TLS 1.2 or higher
- Encryption at rest: Database volumes and backup storage are encrypted using AES-256
- Authentication: User accounts are protected by Clerk, with support for multi-factor authentication (MFA)
- Access controls: Role-based access control (RBAC) limits data access to personnel who need it for their job functions; least-privilege principles are applied
- API security: All API endpoints are authenticated; rate limiting and Content Security Policy headers are enforced
- Infrastructure: Production services run on Railway Pro with isolated environments; network-level access controls are in place
6.3 Administrative safeguards
- Vendor contracts include data processing agreements where required
- Background checks for personnel with access to personal data
- Incident response plan with defined escalation paths and notification timelines
- Periodic vulnerability assessments and dependency scanning
6.4 Incident notification
In the event of a security incident that affects personal information, we will notify affected users and applicable regulators in accordance with applicable federal and state breach notification laws. We maintain an incident response runbook and log all security events.
7. Data Retention Policy
Aggregate institutional data (school/district knowledge graph)
Because our knowledge graph contains aggregate, institution-level data sourced from public federal datasets — not personal information about any individual — standard COPPA deletion obligations regarding child PII do not apply to this data. We retain this data to maintain the accuracy and completeness of our platform's intelligence layer. We update it regularly as new federal data releases become available.
User account data (adult professionals)
Personal information associated with adult user accounts (name, work email, usage logs) is retained for the duration of the active subscription plus 24 months, after which it is deleted or anonymized. Users may request deletion of their account data at any time by contacting privacy@thinkkits.com.
No child PII to retain or delete
Because ThinkKits does not collect personal information from children under 13, there is no child PII subject to COPPA's retention and deletion requirements. If we ever discover that child PII was inadvertently submitted, it is deleted immediately and not retained.
| Data Category | Contains Child PII? | Retention Period |
|---|---|---|
| School/district aggregate data (NCES, Title I) | No — aggregate only | Indefinite (updated with new federal releases) |
| Adult user account information | No — adults only | Subscription term + 24 months |
| Platform usage logs | No | 90 days rolling |
| Inadvertently submitted child PII | Deleted immediately | Zero — immediate deletion upon discovery |
8. Third-Party Data Sharing — 2025 Amendment Requirements
The 2025 COPPA amendments require that operators obtain separate, specific consent before disclosing children's personal information to third parties, beyond what is necessary for the internal operation of the service. Third parties receiving child personal information must certify that they will not use the data for any other purpose and must comply with COPPA themselves.
Because ThinkKits does not collect personal information from children, these requirements apply to us primarily as an organizational policy commitment rather than as an active data-sharing restriction. Nonetheless:
- We do not share any user data with third parties for advertising, marketing, or analytics purposes without consent
- We do not sell user data under any circumstances
- Service providers (infrastructure, authentication, payment processing) receive only the minimum data necessary to perform their functions and are contractually bound to confidentiality and data protection obligations
- If we ever develop features that involve processing data about students or children, we will implement separate, COPPA-compliant consent flows before any such feature is launched
Current third-party service providers
- Clerk — user authentication and identity management
- Stripe — payment processing (subject to PCI-DSS)
- Railway — cloud infrastructure hosting
- Pinecone — vector database for platform memory (no child PII)
- Neo4j (Railway) — knowledge graph database (aggregate institutional data only)
None of these providers receive child personal information as part of their service to ThinkKits.
9. COPPA 2025 Compliance Summary
| 2025 Amendment Requirement | ThinkKits Status | Notes |
|---|---|---|
| Not directed to children under 13 | Compliant | B2B platform for adult professionals only |
| No collection of child personal information | Compliant | No student data collected; aggregate federal data only |
| Verifiable parental consent (where applicable) | N/A | No child users; consent mechanism not required |
| No targeted advertising using child data | Compliant | No advertising of any kind on the platform |
| No conditioning on excess disclosure | Compliant | No child users; policy prohibition in place |
| Written information security program (WISP) | Compliant | See Section 6 above |
| Data retention limits | Compliant | No child PII; aggregate data retention policy in place |
| Separate consent for third-party disclosure of child data | N/A | No child data to disclose; policy prohibition in place |
| Safe harbor program participation (optional) | Not enrolled | Not required; direct compliance maintained |
10. Contact and Reporting
Questions about this COPPA compliance statement or our data practices may be directed to:
- Email: privacy@thinkkits.com
- Subject line: COPPA Inquiry
- Response time: Within 5 business days
Concerns about children's online privacy may also be reported to the Federal Trade Commission:
- FTC Online: reportfraud.ftc.gov
- FTC Phone: 1-877-FTC-HELP (1-877-382-4357)