Privacy Policy
Last updated: February 15, 2026
Our Commitment to Children's Privacy
BrightEras is committed to protecting the privacy of children and families who use our platform. We comply with the Children's Online Privacy Protection Act (COPPA) and take extra precautions to safeguard the personal information of minors. This policy explains how we collect, use, and protect your family's data.
Information We Collect
Parent Information
Email address (for account creation and authentication), first and last name. This information is stored separately from child data in an encrypted identity store.
Child Information
First name and date of birth (used to determine age group for age-appropriate content). We do not collect last names, addresses, phone numbers, or other personally identifiable information from children.
Assessment Data
Responses to career exploration assessments, calculated career dimensions, and communication style profiles. This data is stored separately from identity information and cannot be linked to a child without proper authentication.
How We Use Information
- Generate personalized career exploration recommendations using AI
- Track progress and interest development over time
- Provide age-appropriate content and communication style insights
- Generate parent coaching reports to support your child's development
Data Protection & Encryption
All data is encrypted at rest using AWS Key Management Service (KMS) with separate encryption keys for identity data (PII) and assessment data. Data in transit is protected with TLS 1.2+.
Identity information (parent and child profiles) is stored in a dedicated encrypted database, physically separated from assessment and recommendation data. This architecture ensures that even in the unlikely event of a data breach, assessment data cannot be linked to a specific child without access to both systems.
No Third-Party Sharing
We do not sell, trade, or share your family's personal information with third parties. Assessment data is processed by Amazon Bedrock (Claude AI) to generate recommendations, but no personally identifiable information is included in AI prompts -- only anonymized assessment scores and age group information.
Data Retention
Assessment data and recommendations are retained for as long as your account is active to support longitudinal trend tracking. You may request deletion of all data associated with your account at any time by contacting our support team. Upon account deletion, all data is permanently removed within 30 days.
Parental Rights (COPPA)
As a parent or guardian, you have the right to:
- Review all personal information collected about your child
- Request deletion of your child's data at any time
- Refuse further collection of your child's information
- Withdraw consent for data processing
Parental consent is required before any assessment data is collected. You will be asked to provide consent for each child before their first assessment.
Contact Us
If you have questions about our privacy practices or wish to exercise your rights under COPPA, please contact us at privacy@brighteras.com.
