Who may use OHM School
OHM School is designed for learners with family or guardian oversight where required by local law. Self-service registration requires an age-eligibility confirmation. A managed child account can be created only from an authenticated parent account after the adult records an authority attestation and acknowledges this notice and the Terms. The product records that event and later withdrawals; this engineering record does not itself establish that a particular legal consent standard has been met. We collect learner age to personalize lessons, reading level, examples, and pacing.
Information we collect
We collect account details such as email and display name; learning-profile details such as age, grade, language, goals, and learning preferences; course activity such as answers, progress, scores, notes, tutor conversations, and certificates; and basic security and diagnostic data such as timestamps, request identifiers, and error logs.
How we use information
We use information to authenticate users, deliver and personalize lessons, grade work, preserve progress, issue certificates, improve reliability, prevent abuse, and respond to account or privacy requests. We do not sell personal information or use it for targeted ads.
Service providers
OHM School uses Supabase for authentication and database services and Vercel for hosting. When AI features are used, relevant prompts and learning context may be processed by Google Gemini. YouTube and Giphy content may be requested when media features are used. Those providers process data under their own terms and privacy policies.
Retention and security
We retain account and learning data while an account is active and delete account-linked records when the user completes account deletion. A minimized deletion receipt and security audit record remain for 90 days. AI tutor conversations are account-linked records and are deleted with the account; content-free operational telemetry may remain under the security-log schedule. Encrypted backups are not edited in place and expire under the provider's configured recovery window rather than being edited in place. The operator must publish the active recovery window before production launch; limited legal or security retention may apply. Managed-child consent records are removed when the child account is deleted. We use access controls, encrypted transport, and restricted server credentials, but no online service can guarantee absolute security.
Your choices
You can review or correct core profile information in your profile, download a one-time JSON export of active account and learning records, reset your password from the login page, and permanently delete your account from the profile page. Export links are authenticated, single-use, expire after 15 minutes, and are not stored as public files. A parent may request this export for an explicitly managed child, but not for an independently registered learner who only shared a family link. For another privacy request, email support@ohmschool.org with "Privacy request" in the subject line. We aim to respond within 30 days. A parent can withdraw managed-child authorization from the family dashboard; withdrawal disables sign-in but retains the child record so the parent can reactivate after a new attestation or separately complete permanent deletion.
Changes
We may update this policy as the service changes. The effective date above identifies the current version. Material changes will be presented in the service when practical.