Skip to main content
BrightSteps-X Read brave. Think visual.
Support Log in Parent sign up

Privacy & safety notice

Children learn. Grown-ups stay in control.

Last updated: August 1, 2026 · Notice version: 2026-08-01-v4

BrightSteps-X is designed for parent- or guardian-managed use by young children. It uses private child profiles, child nicknames, access codes and PINs, and parent-controlled learning settings. It does not provide advertising, public child profiles, child-to-child messaging, or social posting.

Information the service uses

We process adult account details, child-profile settings, learning progress, bookmarks, selected buddy settings, and limited operational and security records. Passwords and child PINs are stored as one-way hashes rather than readable text.

Please use a nickname rather than a child’s full legal name and do not place sensitive personal information in profile fields.

Neural character voice

Welcomes, word help, story comments, Listening Mode narration, and mathematics speech use a server-side AI-generated neural character voice. When an approved clip is already available, it is delivered from a private cache. A missing approved clip may be generated once and saved for reuse. BrightSteps-X does not fall back to the computer’s built-in speech voice.

Custom stories and optional hero photos

Parents or guardians can create private custom stories using a child’s nickname, reading level, selected interests, theme, style, and optional parent-entered title or favorite detail. When Custom Story AI is enabled, those limited story fields are sent to the configured OpenAI story service to prepare a structured draft. The child’s account password, PIN, contact information, progress history, and photo are not included in the text-story request. If the model is disabled, unavailable, or does not pass the application’s story checks, BrightSteps-X uses a safe local story instead.

A parent may upload an optional JPG, PNG, or WebP hero photo. BrightSteps-X decodes the file, rejects unsafe or oversized images, corrects orientation, resizes it when needed, converts it to WebP, and strips embedded EXIF/GPS metadata before private storage. The prepared copy is served only to an authorized child, parent, or administrator session with no-store browser caching and can be removed from the child profile. Upload only an image you are authorized to use and avoid school IDs, documents, addresses, uniforms that reveal a school, or other sensitive details.

BrightSteps-X sends a saved hero photo to the configured OpenAI image service only when personalized illustrations are enabled and the parent checks the separate approval box for that particular story. The image is used as a visual reference to create stylized, fully clothed storybook scenes. Generated scenes remain private, are served without public caching, and are deleted when the parent deletes the custom story. Leaving the approval box unchecked keeps the photo out of the external image request.

Optional Live Buddy

Live Buddy is off by default. A parent or guardian must enable it for an individual child, choose an allowed mode, and set a daily limit. The microphone begins only after a child starts a live session and the browser grants permission.

When enabled, microphone audio is transmitted to the configured OpenAI Realtime service so the buddy can respond. BrightSteps-X does not intentionally save the audio recording or a conversation transcript. It keeps limited usage metadata such as session duration, turn count, activity type, allowance use, and safety events. Parents can disable Live Buddy at any time without disabling stories, visual math, illustrations, or cached word help.

Service providers

BrightSteps-X uses Google Cloud services for application hosting, Firestore records, private media storage, and configured neural-voice generation. OpenAI is used only for optional Live Buddy, enabled Custom Story AI, separately parent-approved hero illustrations, or operator-run content workflows. Deployment safeguards require the operator to review the applicable child-data, retention, consent, and account controls before those optional services are enabled. Providers process information under their own service terms and security controls.

Privacy-safe public-site analytics

The public information pages use first-party aggregate counters only. The counters record the date and a broad page category such as “home” or “privacy.” They do not store an IP address, account ID, child ID, cookie ID, referrer, query string, browser fingerprint, or raw user-agent string. They are not used on child stories, mathematics, account dashboards, login forms, or registration forms.

Requests carrying a browser DNT or Global Privacy Control signal are excluded. Automated crawler traffic is also excluded. Aggregate daily records are configured for retention for up to 90 days.

What BrightSteps-X does not enable

The service does not enable camera access, precise location, public posting, unknown-user contact, behavioural advertising, or sale of personal information. The AI buddy is instructed not to request identifying, contact, account, location, or financial information.

Retention, access, correction, and deletion

Account, learning, custom-story, and private media records are retained while needed to operate the service, meet legal or security obligations, and maintain requested progress. Parents can delete individual custom stories and hero photos from the child profile. Daily AI-allowance records store internal child/family identifiers, category, counts, and timestamps—not story text, prompts, photos, or audio—and exist to control cost and abuse across Cloud Run instances.

A parent or guardian may request access, correction, export, or deletion by contacting jalaljanjua88@gmail.com. We may need to verify the adult account before acting on a request. Limited backup copies may remain temporarily until the normal backup cycle completes.

Safeguarding and security

BrightSteps-X uses signed sessions, secure cookies in production, CSRF protection, role separation, private media storage, and restricted child-facing functionality. No online service can guarantee absolute security. Please contact us promptly if you believe an account or child code has been exposed.

Regional rights and changes

Privacy rights vary by location. Mandatory rights under applicable law are not limited by this notice. Material changes will be reflected by a new “last updated” date and notice version. For privacy questions, contact jalaljanjua88@gmail.com. General help is available on the support page.

© 2026 BrightSteps-X Built for children, controlled by grown-ups.
Privacy & safety Terms Contact & support Accessibility Content sources