Student Privacy
Board Battle hosted play does not require student accounts. Students can participate from the teacher or host screen without signing in.
Responsible AI
Kleveroo uses AI to help generate and organize board content. AI output should be reviewed before classroom or team use.
Privacy & Data Requests
Users can request access, correction, export, or deletion of their data through our data request process.
Cookies & Tracking
Kleveroo does not currently use advertising cookies, Meta Pixel, Google Analytics, session replay, or cross-site tracking tools.
Security
Kleveroo uses secure infrastructure, HTTPS, database-level access rules, Stripe-hosted payments, and security headers.
Subprocessors
Kleveroo uses third-party service providers — including Cloudflare, Supabase, OpenAI, Google AI / Gemini, and Stripe — to host, secure, operate, and improve the product.
Security practices
We keep the security story boring on purpose: use well-supported infrastructure, keep access rules close to the data, and don't handle anything we don't need to.
- The whole site is served over HTTPS, and the main domain asks browsers to refuse insecure connections.
- Security response headers are configured — including a content security policy, clickjacking protection, MIME-type protection, and a strict referrer policy.
- Database access is governed by row-level access rules, so a signed-in account can only reach its own records. Those rules are enforced by the database itself, not just by the app.
- Card details are handled entirely by Stripe. Kleveroo never sees or stores a card number.
- Privacy and data requests are reviewed in an admin-only area. Anyone can submit a request, but nobody except an administrator can read stored request records.
- Fonts and site assets are served from our own domain, so loading a page doesn't hand your details to a third-party CDN.
Kleveroo has not been independently audited or certified against a security standard, and we don't claim to be. This section describes what we actually do today.
Designed for teacher-hosted classroom play
- Board Battle does not require student accounts.
- Hosted play happens from the teacher or host screen — one screen, one host. Students don't need a device, a login, or a join code.
- Live Trivia, our separate multi-device mode, uses nicknames that players choose themselves. No account, no email.
- Kleveroo does not intentionally collect student personal information anywhere in the product. There is no roster import, gradebook sync, or student profile.
- Teachers should not upload rosters, IEPs, medical or disciplinary information, or other sensitive student records — including inside AI prompts, board text, and clue images.
Responsible AI use
AI features help generate and organize board content. They are optional — every board can be built by hand, and our whole library can be played without touching an AI feature.
- AI may be used for board generation, lesson-plan and file text extraction, clue ranking, metadata suggestions, and our own internal content tools.
- Prompts and text extracted from files you upload are processed to generate your content.
- Based on how Kleveroo works today, prompts and token/cost metadata (model, token counts, estimated cost, latency) may be retained so we can operate, support, and price the feature.
- AI output may be inaccurate. Review a generated board before using it with students or teammates — you're responsible for what you put in front of your group.
- Do not submit sensitive student information into prompts or uploads.
Data access, export, correction, and deletion
- Submit a privacy or data request at any time through our data request form.
- Every request is reviewed by a Kleveroo administrator. We may confirm by email that the request comes from the account holder.
- Automated deletion is not performed without review — nothing is erased by a script the moment a form is submitted.
- Some data may be retained for legal, payment, security, fraud-prevention, or operational reasons. Payment and tax records held by Stripe are the clearest example.
- We'll tell you what was deleted, what was anonymised, and anything we had to keep.
Infrastructure and service providers
Kleveroo is built and operated by Smith Digital Ventures LLC (dba Kleveroo Games). We use a small number of service providers to host, secure, operate, and improve the product. These providers maintain their own privacy and security programs. Vendor certifications apply to those vendors' systems and controls, not to Kleveroo as an independently certified organization.
Not used: Kleveroo does not send prompts, uploaded files, extracted text, or generated content to Perplexity, Anthropic, advertising networks, or third-party analytics tools. Product analytics are first-party and stored in our own database.
| Provider | What we use it for |
|---|---|
| Edge and network — Cloudflare | Serves the Kleveroo website and app at the network edge and secures connections. It may process IP addresses, request headers, and requested URLs. |
| Database, sign-in, storage, and live rooms — Supabase | Hosts our Postgres database, sign-in and session handling, file storage, and the realtime infrastructure behind live rooms. |
| AI model providers — OpenAI and Google AI / Gemini | OpenAI generates boards, categories, clues, and answers using GPT-5 family models. Google uses Gemini family models for uploaded-file text extraction, clue ranking, and metadata suggestions. Requests are routed through Kleveroo's managed AI gateway. |
| Payments — Stripe | Payments, subscriptions, invoices, and sales tax / VAT. Card details go straight to Stripe and are never stored by Kleveroo. |
| Optional sign-in — Google sign-in | Only where you choose 'Sign in with Google'; Google provides your email address and basic profile so we can create your account. |
| Deployment and operational tooling — Lovable | Current service provider for deployment management, managed operational tooling, transactional service support, and AI request routing. |
| Kleveroo MCP endpoint | Our own public, read-only search over published boards and articles, so AI assistants can find and link to them. It exposes only content that is already public and reads no account data. |
Compliance posture
We'd rather be accurate than impressive, so here is exactly where we stand:
- Kleveroo is designed with classroom privacy in mind.
- Kleveroo does not require student accounts for hosted Board Battle play.
- Kleveroo supports data deletion requests.
- Kleveroo is building toward stronger privacy and security practices as the product grows.
We have not completed a formal audit or certification, and we don't describe ourselves as certified or compliant under any framework. If your school, district, or company needs a signed data protection agreement or a security review, email support@kleveroo.com and we'll work through it with you honestly. Privacy and data requests can also be submitted through /data-requests.
Last updated: August 30, 2026. Questions about anything on this page? Email support@kleveroo.com or contact us.
