← Help Center
Compliance Statement

COPPA Compliance

Effective: April 22, 2026  ·  Last reviewed: March 28, 2026  ·  Governing rule: FTC COPPA Rule, 16 C.F.R. Part 312 (2025 amendments)

Bottom line

ThinkKits does not collect, use, or disclose personal information from children under 13. Our platform is built for adult school administrators, district leaders, and education vendors — not for students. We rely exclusively on aggregate, publicly available federal data about schools and districts.

1. Overview and Applicability

The Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, and the FTC's implementing rule at 16 C.F.R. Part 312, protect the online privacy of children under 13 by restricting operators of websites and online services directed to children — or with actual knowledge of child users — from collecting their personal information without verifiable parental consent.

On January 14, 2025, the FTC published its final amended COPPA Rule, with most provisions effective April 22, 2026. The 2025 amendments strengthen child privacy protections by, among other things: expanding the definition of personal information, imposing stricter consent requirements, adding a targeted advertising prohibition, requiring a written information security program, and mandating separate consent for third-party data sharing.

ThinkKits is not directed to children under 13 and does not have actual knowledge that any child under 13 uses the platform. This page explains how our product design, data practices, and security measures align with COPPA and the 2025 amendments.

2. ThinkKits Does Not Collect Data From Children Under 13

ThinkKits is a B2B intelligence platform designed exclusively for adult professionals: school principals, district administrators, curriculum directors, purchasing officers, and education vendors. Children are never the intended users of this service.

Who our users are

Account registration

To create an account, users must provide a professional work email address (which we verify), a full name, and confirm they are 18 years of age or older. We do not permit account creation by anyone under 13, and our Terms of Service prohibit use by minors without parental consent consistent with applicable law.

We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided personal information, we will promptly delete it and terminate any associated account.

If you believe a child's information was submitted

Contact us immediately at privacy@thinkkits.com. We will investigate and delete any such information within 5 business days.

3. Our Data: Aggregate School and District Information From Public Federal Sources

The knowledge graph powering ThinkKits contains data about schools and districts as institutions — not about individual students or children. Every data point in our system originates from publicly available federal datasets.

Data sources

What this data is and is not

All enrollment, demographic, and performance figures in ThinkKits represent aggregate counts and percentages at the school or district level. No data record in our system corresponds to a named individual student, a student ID, a student's grades, a student's test scores, or any other record that could identify a specific child.

This data is the same information published on federal agency websites and accessible to any member of the public. ThinkKits organizes and surfaces it through a structured knowledge graph and scoring engine — we do not generate, infer, or enrich any data about individual children.

No child PII — by design

Our data integrity policy prohibits loading any personally identifiable student data into our systems. Every node in our knowledge graph must carry a source property pointing to a public federal dataset. Synthetic or student-level data is categorically banned.

4. School Administrators as Operators

When a school or district professional uses ThinkKits, they are the operator under their institution's policies and applicable law. ThinkKits provides analytical tools and reports to those adult professionals. We do not provide services that the school then deploys to students.

In the COPPA framework, the "operator" is the entity that collects personal information from children through an online service. ThinkKits does not operate any service that students interact with. We interact only with the adult administrators who use our platform.

If a school purchases ThinkKits and a district IT administrator uses it to analyze Title I funding eligibility, the interaction is entirely between ThinkKits and that adult professional. No student data flows into or out of our systems as part of that workflow.

5. No Advertising, No Monetization of Child-Related Data

ThinkKits earns revenue through subscription fees paid by adult professionals and institutions. We do not:

The 2025 COPPA amendments prohibit conditioning a child's participation in an activity on the disclosure of personal information beyond what is reasonably necessary, and prohibit using personal information of children for targeted advertising. These prohibitions are consistent with our existing practices, which prohibit any advertising monetization model entirely.

Our business model is subscriptions — not data

Our SaaS tiers (Explorer, Starter, Professional, Business) are the only revenue source associated with the ThinkKits platform. Subscriber data is used solely to operate and improve the platform.

6. Written Information Security Program (WISP)

The 2025 COPPA amendments require operators to establish, implement, and maintain a written information security program (WISP) appropriate to the size and nature of the operator's activities and the sensitivity of the information collected. The following is a summary of our program.

6.1 Program governance

6.2 Technical safeguards

6.3 Administrative safeguards

6.4 Incident notification

In the event of a security incident that affects personal information, we will notify affected users and applicable regulators in accordance with applicable federal and state breach notification laws. We maintain an incident response runbook and log all security events.

7. Data Retention Policy

Aggregate institutional data (school/district knowledge graph)

Because our knowledge graph contains aggregate, institution-level data sourced from public federal datasets — not personal information about any individual — standard COPPA deletion obligations regarding child PII do not apply to this data. We retain this data to maintain the accuracy and completeness of our platform's intelligence layer. We update it regularly as new federal data releases become available.

User account data (adult professionals)

Personal information associated with adult user accounts (name, work email, usage logs) is retained for the duration of the active subscription plus 24 months, after which it is deleted or anonymized. Users may request deletion of their account data at any time by contacting privacy@thinkkits.com.

No child PII to retain or delete

Because ThinkKits does not collect personal information from children under 13, there is no child PII subject to COPPA's retention and deletion requirements. If we ever discover that child PII was inadvertently submitted, it is deleted immediately and not retained.

Data Category Contains Child PII? Retention Period
School/district aggregate data (NCES, Title I) No — aggregate only Indefinite (updated with new federal releases)
Adult user account information No — adults only Subscription term + 24 months
Platform usage logs No 90 days rolling
Inadvertently submitted child PII Deleted immediately Zero — immediate deletion upon discovery

8. Third-Party Data Sharing — 2025 Amendment Requirements

The 2025 COPPA amendments require that operators obtain separate, specific consent before disclosing children's personal information to third parties, beyond what is necessary for the internal operation of the service. Third parties receiving child personal information must certify that they will not use the data for any other purpose and must comply with COPPA themselves.

Because ThinkKits does not collect personal information from children, these requirements apply to us primarily as an organizational policy commitment rather than as an active data-sharing restriction. Nonetheless:

Current third-party service providers

None of these providers receive child personal information as part of their service to ThinkKits.

9. COPPA 2025 Compliance Summary

2025 Amendment Requirement ThinkKits Status Notes
Not directed to children under 13 Compliant B2B platform for adult professionals only
No collection of child personal information Compliant No student data collected; aggregate federal data only
Verifiable parental consent (where applicable) N/A No child users; consent mechanism not required
No targeted advertising using child data Compliant No advertising of any kind on the platform
No conditioning on excess disclosure Compliant No child users; policy prohibition in place
Written information security program (WISP) Compliant See Section 6 above
Data retention limits Compliant No child PII; aggregate data retention policy in place
Separate consent for third-party disclosure of child data N/A No child data to disclose; policy prohibition in place
Safe harbor program participation (optional) Not enrolled Not required; direct compliance maintained

10. Contact and Reporting

Questions about this COPPA compliance statement or our data practices may be directed to:

Concerns about children's online privacy may also be reported to the Federal Trade Commission:

Was this article helpful?

← Back to Help Center