brights.ai
Courses How it works AI assistant ESA families FAQ
Login

Brights Privacy Policy

Effective date: August 26, 2026

Last updated: August 26, 2026

This Privacy Policy explains how Magent Tech Inc., a Delaware corporation, doing business as Brights (“Brights,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when families use brights.ai, brights.study, parent and student accounts, personalized courses, diagnostic activities, the AI learning assistant, parent progress reporting, course documentation, and related services (collectively, the “Services”).

Brights provides K–12 curriculum and educational software. Because children may use the Services, this Policy includes a dedicated children's privacy section and is intended to support compliance with the U.S. Children's Online Privacy Protection Act and Rule (“COPPA”).

1. Contact and operator information

The operator responsible for the Services is:

Magent Tech Inc.

Doing business as Brights

Delaware corporation, United States

Email: support@brights.ai

The service providers that may collect or maintain children's personal information through the Services are identified in Section 8.

2. Scope

This Policy applies to information collected through the Services and related support communications. It does not apply to a third-party website, ESA marketplace, payment provider, or other service that operates under its own privacy policy, except where that provider processes information for Brights on our instructions.

The Services are designed so that a parent or legal guardian (“Parent”) creates and manages a minor student's account and access. A student profile is not a public social-media profile, and the Services are not designed to let children publicly post personal information.

3. Information we collect

We limit collection to information reasonably necessary to provide and support the Services, personalize learning, maintain safety and security, comply with law, and fulfill the other purposes described below.

A. Parent and account information

We may collect:

  • Parent name, email address, telephone number, mailing or billing address, and account credentials;
  • relationship to the student and confirmation of authority to act for the student;
  • communication preferences and records of consent;
  • selected course, subject, grade or level, access period, and enrollment information;
  • support requests, feedback, and communications; and
  • limited identity-verification information when reasonably necessary to verify parental consent, authority, or a privacy request.

We do not store full payment-card numbers. Payment providers process payment details under their own policies and provide us with limited transaction information such as payment status, amount, date, method type, and transaction identifier.

B. Student profile and personalization information

Depending on the course, we may collect:

  • student's name or profile name, age or birth month and year, grade or level, and Parent-linked account identifier;
  • learning goals, interests, preferred examples or formats, available study time, schedule, and learning preferences;
  • reading or accessibility needs that a Parent chooses to provide;
  • diagnostic responses, current skill levels, strengths, and topics that need review; and
  • course selections and personalized learning-plan settings.

Please do not provide a medical diagnosis, disability record, government identifier, precise location, financial information, or other sensitive information unless we specifically request it, explain why it is necessary, and obtain any required consent. A Parent may describe practical learning or accessibility preferences without providing a diagnosis.

C. Learning activity and educational content

We may collect:

  • lessons, modules, practice sets, and projects accessed or completed;
  • answers, assignments, project submissions, quizzes, assessment results, and completion status;
  • pacing, time and date of activity, milestones, recommended next steps, and topics to review;
  • course-support requests and whether the student requested additional explanation or practice; and
  • course completion records or certificates.

D. AI learning assistant information

When a student or Parent uses the AI learning assistant, we may collect prompts, questions, responses, the related course and lesson context, feedback, safety signals, and technical metadata. The assistant is intended for course-related learning support. Users should not include personal information that is not needed to ask the learning question.

We may use automated filters and limited human review by authorized personnel or service providers when reasonably necessary to investigate a safety issue, abuse, technical failure, or a reported response. Human access is restricted according to role and business need.

We may select, replace, or use one or more AI technology providers in our reasonable discretion. When an AI provider receives personal information on our behalf to provide the Services, we require it by contract to process that information only for specified service purposes, apply appropriate confidentiality and security safeguards, follow applicable deletion requirements, and not use identifiable student content or children's personal information to train a general-purpose AI model or for the provider's independent purposes. We assess providers before use and maintain oversight appropriate to the sensitivity of children's information.

AI providers' models, systems, and outputs may be inaccurate or change over time. We do not guarantee their technical performance, but we remain responsible for our obligations under applicable privacy and children's-protection law.

E. Device, log, and website information

We and service providers may automatically collect limited technical information needed to operate and secure the Services, such as IP address, device and browser type, operating system, pages or features used, timestamps, referring page, session identifiers, crash information, and security events.

We may use cookies, local storage, or similar technologies for authentication, account preferences, load balancing, fraud prevention, security, and other functions necessary to provide the Services. We do not use children's personal information for targeted advertising or cross-context behavioral advertising.

F. ESA and transaction information

If a family uses an ESA or similar program, we may collect the program and state, provider or marketplace identifiers, order and authorization status, invoice details, course documentation requested, reimbursement status, and related communications. We ask families not to send government identifiers, bank information, benefit credentials, or unrelated eligibility records unless specifically required through an approved secure process.

4. Sources of information

We collect information:

  • directly from Parents;
  • directly from students using a Parent-managed profile;
  • automatically from devices and use of the Services;
  • from service providers acting for us, such as hosting, authentication, payment, support, and AI providers; and
  • from an ESA marketplace, program administrator, or other organization when the Parent directs or authorizes the transaction.

We do not purchase children's personal information from data brokers.

5. How we use information

We use personal information to:

  • create and manage Parent accounts and student profiles;
  • verify parental authority and obtain and document parental consent;
  • deliver purchased curriculum and personalize course sequence, pacing, examples, practice, projects, review, and format;
  • administer diagnostics, lessons, practice, projects, quizzes, assessments, and completion records;
  • provide course-specific explanations, hints, examples, additional practice, and checks for understanding through the AI learning assistant;
  • provide Parents with progress reports, recent activity, assessment results, strengths, topics to review, and recommended next steps;
  • process orders, payments, refunds, and ESA documentation;
  • communicate about accounts, courses, security, updates, and support;
  • maintain accessibility, quality, safety, fraud prevention, and technical performance;
  • debug, analyze, and improve the Services using aggregated or de-identified information where reasonably possible;
  • enforce our Terms of Use and protect users, Brights, and others; and
  • comply with legal, tax, accounting, reporting, and regulatory obligations.

We will not condition a child's participation on disclosing more personal information than is reasonably necessary for the relevant activity.

6. How we disclose information

We may disclose personal information only as described below.

A. Within the family account

The Parent can access information associated with the Parent-managed student profile, including learning plans, activity, progress, assessment results, AI-support activity, and completion information. Students may access the materials and activity available in their own profile.

B. Service providers

We may disclose information to vendors that help us host, secure, authenticate, personalize, support, communicate, process payments, provide AI functionality, and operate the Services. These providers may use the information only to perform contracted services for us or as otherwise permitted by law. We require appropriate confidentiality, security, deletion, and purpose restrictions, particularly for children's personal information.

C. Parent-directed and ESA transactions

At a Parent's direction, we may provide order, course, invoice, enrollment, or completion information to an ESA marketplace, program administrator, school, evaluator, or other recipient identified by the Parent. We will request separate authorization before disclosing children's personal information for a purpose that is not integral to the Service or otherwise permitted by law.

D. Legal and safety reasons

We may disclose information if we reasonably believe disclosure is necessary to comply with law or valid legal process; protect the rights, safety, or security of a child, user, Brights, or another person; investigate fraud, abuse, or security incidents; or enforce our agreements. We assess requests for children's information carefully and disclose no more than reasonably necessary.

E. Business transactions

Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to applicable law and continued protection consistent with this Policy. We will provide notice and obtain consent where required.

F. Aggregated or de-identified information

We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably be linked to a particular person. We maintain measures designed to prevent re-identification and do not attempt to re-identify it except to test the effectiveness of those measures or as permitted by law.

7. No sale, targeted advertising, or public profiles

Brights does not sell personal information. Brights does not share personal information for cross-context behavioral advertising and does not use children's personal information for targeted advertising. We do not knowingly permit third-party advertising networks to collect personal information through student areas of the Services.

Student profiles, assignments, diagnostic answers, and AI conversations are not made public through the Services. We will not publicly identify a child in testimonials, marketing, or product examples without the Parent's separate, specific permission and any consent required by law.

If these practices change, we will update this Policy in advance, provide legally required choices, and obtain separate verifiable parental consent before disclosing children's personal information for targeted advertising or another non-integral third-party purpose.

8. Service providers

We may select and change service providers that help us operate the Services, including providers of infrastructure, authentication, payments, communications, support, security, and AI functionality. We require providers that process personal information on our behalf to follow contractual purpose, confidentiality, security, retention, and deletion restrictions. If a change materially affects how children's personal information is collected, used, or disclosed, we will notify Parents and obtain new consent where required by law.

9. Children's privacy and parental controls

A. Parental notice and verifiable consent

Before collecting personal information online from a child under 13, we provide the Parent with a direct notice describing the information, purposes, operators, disclosures, retention, and Parent rights, and we obtain verifiable parental consent unless a COPPA exception applies. A child cannot begin the diagnostic, use a student profile, or access the AI learning assistant until this process is complete.

Our primary consent methods are:

  • Parent-paid purchase: the Parent affirmatively accepts the direct notice and provides consent in connection with a credit card, debit card, or other monetary transaction through a payment system that notifies the primary account holder of each transaction; or
  • ESA, direct-pay, scholarship, or no Parent payment: the Parent signs a consent form and returns it by electronic scan or another identity-verifying electronic-signature process reasonably designed to confirm that the signer is the Parent.

If a Parent cannot or does not wish to use the primary method, we may offer verification through a video conference with trained personnel, a government-issued identification check followed by prompt deletion of the identification, or another method permitted by COPPA. We keep a record of the consent, the direct-notice version, the method, the date and time, the Parent account, and the covered student and purposes.

Consent for the core educational Service does not authorize disclosure of children's information for targeted advertising or another non-integral third-party purpose. Brights does not engage in those practices. If we ever propose such a disclosure, we will request separate verifiable parental consent as required by law.

B. Information collected from children

Depending on the course, we collect the categories described in Sections 3.B–3.E, including profile identifiers, grade or age information, goals and interests, diagnostic and coursework responses, progress, assessment results, AI questions and responses, and limited technical identifiers. We use this information for the purposes in Section 5 and disclose it as described in Sections 6 and 8.

Children cannot make their personal information publicly available through the Services.

C. Parent rights

A Parent may at any time:

  • review the specific personal information collected from the child;
  • request correction or deletion of the child's personal information;
  • withdraw consent and refuse further collection or use; and
  • request a description of the types of children's information collected and the operators that handle it.

To exercise these rights, use the controls in the Parent account or contact support@brights.ai. We will verify the requester's identity and authority using reasonable methods that do not collect more information than necessary.

Withdrawing consent or deleting information needed to provide the course may require us to close the student profile or discontinue affected features. We will explain the effect before completing the request. We may retain limited information only when legally permitted or required, such as transaction, consent, security, or legal records, and will not use it for another purpose.

D. Data minimization and security program

We do not require a child to provide more personal information than is reasonably necessary to participate in a course or activity. We maintain a written information-security program designed to protect the confidentiality, security, and integrity of children's personal information, including risk assessment, access controls, service-provider oversight, incident response, and periodic review.

10. Data retention and deletion schedule

We retain personal information only for as long as reasonably necessary for the specific disclosed purpose, to provide the requested Service, and to meet legitimate legal or recordkeeping needs. Children's personal information is not retained indefinitely.

The following retention schedule applies to Brights' systems:

CategoryBusiness needRetention period and deletion timeframe
Parent account and contact informationOperate the family account, communicate, and handle requestsWhile the account is active, then up to 24 months after the last course access ends or the account becomes inactive; deletion from active systems within 30 days after the retention period or an approved request
Student profile, personalization, diagnostics, coursework, progress, and assessmentsDeliver and personalize the course and allow Parent reviewWhile the course is active, then up to 12 months after the access period ends; deletion or de-identification from active systems within 30 days after the retention period or an approved Parent request
AI prompts, responses, and associated lesson contextProvide the assistant, investigate reported errors, and maintain safetyUp to 90 days, unless attached to a saved learning record or reasonably necessary for a documented safety or abuse investigation; investigation records up to 24 months after closure
Minimal completion recordProvide course documentation and respond to Parent or ESA record requestsUp to 6 years after course completion, unless the Parent requests earlier deletion and no legal or program requirement prevents it
Verifiable parental-consent recordsDemonstrate and manage lawful consentUp to 6 years after the last collection or use authorized by the consent, or longer if required by law
Transaction, invoice, tax, refund, and ESA purchase recordsAccounting, tax, fraud prevention, disputes, and program documentationUp to 7 years after the transaction, or longer if required by law
Support communicationsResolve requests, maintain quality, and document disputesUp to 3 years after the request is closed
Security and access logsProtect accounts, investigate incidents, and prevent abuseUp to 12 months, unless needed longer for a documented investigation or legal obligation
BackupsDisaster recovery and business continuityDeleted or overwritten on a rolling basis within 90 days after deletion from active systems and not restored except for recovery, security, or legal needs

When information is no longer reasonably necessary, we delete it or de-identify it using reasonable measures designed to protect against unauthorized access or use during deletion. If a legal hold or mandatory recordkeeping rule applies, we isolate the relevant information, retain only what is required, and delete it after the obligation ends.

11. Security

We use administrative, technical, and physical safeguards appropriate to the nature of the information, including access controls, encryption, logging, backup controls, staff confidentiality obligations, service-provider review, vulnerability management, and incident-response procedures.

No system is completely secure. Parents should use a unique password, protect Parent credentials, and contact support@brights.ai immediately if they suspect unauthorized access.

We will provide legally required notices if a security incident affects personal information.

12. Privacy rights for Parents and other users

Depending on where you live and subject to legal exceptions, you may have the right to:

  • know or access the personal information we collect, use, and disclose;
  • obtain a portable copy;
  • correct inaccurate information;
  • delete personal information;
  • withdraw consent;
  • opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling;
  • limit certain uses or disclosures of sensitive personal information;
  • appeal a denied request; and
  • receive equal service and pricing without unlawful discrimination for exercising privacy rights.

Brights does not sell personal information or use it for targeted advertising. To submit a request, email support@brights.ai. We may verify identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity confirmation.

If we deny a request, our response will explain the reason and any available appeal process. To appeal, email support@brights.ai with the subject line “Privacy Appeal.”

We honor legally required browser-based opt-out preference signals, such as Global Privacy Control, if we begin processing covered information in a way to which the signal applies. Because we do not sell or share personal information for cross-context behavioral advertising, there is currently no such processing to opt out of.

13. Communications

We may send Parents transactional messages about accounts, courses, purchases, progress, security, legal notices, and support. These messages are necessary to provide the Services and may not offer a marketing opt-out.

If a Parent opts in to promotional email, the Parent may unsubscribe using the link in the message or by contacting us. We do not send behavioral advertising or promotional messages directly to children based on their personal information.

14. International access

The Services are operated by a United States company. If information is transferred across national borders, we use safeguards required by applicable law. The current Services and this Policy are primarily designed for United States families and U.S. education and ESA programs.

15. Changes to this Policy

We may update this Policy to reflect changes in the Services, law, providers, or practices. We will post the updated version and revise the effective date. If a change materially affects how we use or disclose personal information, we will provide reasonable advance notice. We will obtain new parental consent before materially changing the collection, use, or disclosure of children's personal information when required by law.

16. Contact us

Questions or requests about this Policy or children's privacy may be sent to:

Magent Tech Inc.

Attn: Privacy / Children's Privacy

Delaware corporation, United States

Email: support@brights.ai

brights.ai
Courses State availability Terms of use Privacy Policy Refund policy

Questions about a course — hello@brights.ai

ESA support — esa@brights.ai

🌐 English

All rights reserved

We provide personalized, self-paced curriculum and educational software. We are not a school and do not issue diplomas, transcripts, or state-recognized academic credit. ESA availability varies by state, program, provider status, and exact offering.