We collect what we need to run the product and nothing else. We don't sell your data. We don't train on your prompts. You can email hello@aiandplay.com any time to see, export, or delete what we have on you.
Account info. Email, name, and a hashed password. If you pay through Stripe, they handle the card; we just see the last four digits and the receipt.
Usage data. Which modules you've started, how far you've gotten, and the work product you produce inside the simulations.
Prompts and AI conversations. The messages you send to the copilot and the responses, so we can render your progress and let you pick up where you left off.
Technical data. Browser, device type, IP, and timestamps for security and debugging.
To deliver and operate the Service. To send you transactional emails (receipts, password resets, important product updates). To improve the curriculum and copilot using aggregated, de-identified data. To enforce our Terms and prevent abuse.
We send marketing emails only if you opt in. You can unsubscribe at any time.
Your prompts and the copilot's responses are sent to third-party model providers (e.g. OpenAI, Anthropic) to generate replies. We have agreements in place that prohibit those providers from using your data to train their models.
Don't put confidential or regulated data (PHI, PII you don't own, trade secrets) into the simulations.
Service providers we use to run the product: Stripe (payments), our cloud host, our email provider, our model providers, and an analytics tool that we configure to drop IP addresses. We don't sell or rent personal data to advertisers, period.
If we're ever required to disclose information by law, we'll tell you unless legally barred from doing so.
We use a small set of cookies for authentication, session management, and basic product analytics. You can disable cookies in your browser, but parts of the Service won't work without them.
We keep your account data for as long as your account is active. If you delete your account, we delete personal data within 30 days, except where we have to keep records (tax, legal). Aggregated, de-identified analytics may be retained.
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. Email hello@aiandplay.com and we'll respond within 30 days.
We use encryption in transit (TLS) and at rest, scoped access controls, and audit logging. No system is perfectly secure, but we treat your data the way we'd want ours treated.
The Service is not intended for anyone under 16. We don't knowingly collect data from children. If you think your child has signed up, email us and we'll remove the account.
If we make material changes to this policy, we'll notify you by email or an in-product notice. Minor wording changes may be reflected with a new “Last updated” date.
Privacy questions or requests: hello@aiandplay.com.