Privacy Policy

Last updated 5 August 2026. Applies to the ProsperAI website, the ProsperAI web app (one app with a guardian role and a reading role), the ProsperLens browser add-in, and the ProsperAI Android app (us.prosperai.family).

ProsperAI has no server. There is no account to create, nothing to log in to, and no copy of your reading anywhere but on your own device. This page exists to say precisely what that means — and, just as important, the few moments when something does leave your device.

The short version. We collect nothing. We receive nothing. We could not hand over your child's reading history if we were asked to, because we have never had it. When the app uses AI, your device talks directly to Anthropic using your own API key — we are not in the middle of that conversation and we cannot see it.

1. What we collect

Nothing. ProsperAI operates no servers, no databases, no analytics, and no logging of any kind. There is no ProsperAI account. We do not know that you have installed the app, how often you open it, what you read, or that you exist.

The apps contain no advertising, no advertising identifier, no tracking pixels, and no third-party analytics or crash-reporting SDKs.

2. What is stored, and where

Everything the app knows lives in storage private to the app, on your own device:

On Android the API key is held by the Android Keystore, and Android Auto Backup is switched off for this app — which means none of the above is copied to Google Drive, even though that is the system default. In the web apps the equivalent data lives in your browser's localStorage for that site, on that device.

None of this is ever transmitted to us, because there is nowhere for it to be transmitted to.

3. When something does leave your device

The app has an offline Demo mode in which nothing leaves your device at all — no network connection is made. Everything below applies to Live mode, which you turn on yourself by entering an Anthropic API key.

Who receives itWhat they receiveWhen
Anthropic
api.anthropic.com
The text being edited or translated; the reader's age and reading standards; and, in "Talk about it", what the reader said in answer to a question about the story. Never a reader's name — the prompt carries an age and nothing that identifies anyone. At the moment an edition is made, a page is translated, or a reply in a conversation is requested.
A website you choose An ordinary web request for the page, made by your device. Only at the moment a guardian types or pastes an address and taps Fetch. Nothing is pre-fetched, polled, or refreshed in the background.
Google
accounts.google.com, gmail.googleapis.com
An authorization request, and then read-only access to your own mailbox. Only if a guardian chooses to connect their own Gmail account. This connector is not included in the Google Play release of the Android app.

That list is exhaustive. Each entry is your device talking to a party you chose, with nothing of ours in between. In particular there is no ProsperAI server in any of those paths — there isn't one to put there.

Your API key

Your Anthropic API key is sent only to Anthropic, only in the authorization header of a request you caused, and it is never written into a log, an error message, or a screen. We never see it. Charges for API use are between you and Anthropic; your Anthropic console is the only real record of that billing.

4. The microphone

"Talk about it" lets a reader answer questions about a story they have just finished. Only the Android app listens. The web app does not, and the difference is deliberate rather than a feature that has not been built yet.

A conversation is not a channel for telling someone something

ProsperReader is a reading companion for one conversation about one story, and it is built to stay there. The instruction sent with every turn tells it that it is not the reader's friend, teacher or parent; that it may talk only about the story on the screen; and that it must never ask about the reader's life, family, school or home, or repeat anything identifying if the reader says it. If a reader brings up their own life anyway, ProsperReader steers back to the story and nothing is written down.

The consequence, stated plainly: if a reader says something worrying, ProsperAI will not tell anyone — not a parent, not a teacher, not us. It does not judge what a reader says, does not keep it, and has no way to raise it. There is no record to disclose, and none to subpoena. A reader who needs to be heard needs a person, and the app says so on the reader's own screen every time a conversation is open.

5. The camera and nearby devices

The Android app can use the camera to read a pairing QR square, and Bluetooth and local Wi-Fi to pass a request between two devices in the same room. No photograph is stored or transmitted; the camera is a barcode reader and nothing else. Nearby pairing is device-to-device and reaches no network. Location permissions appear in the Android manifest only because older versions of Android required them for a Bluetooth scan; the app never reads your position.

6. Children

ProsperAI is designed to be set up by a parent, guardian or teacher and used by children. We take the same position for a child as for anyone else, which is that we hold nothing:

Because we collect nothing, there is no data about a child for us to disclose, sell, or delete on request. If you believe otherwise, please contact us and we will investigate.

7. AI-generated content, and how to report it

Text in this app is edited, and sometimes written, by an AI model. Models make mistakes. Editions are produced against the standards a guardian set, and a guardian can always compare an edited version with the original.

Both the Android app and the web app have a “Something here is wrong” button on the reading screen and in every conversation. Tapping it flags the exact text to the guardian on their own device, where it appears on the first screen they see. Nothing is sent to ProsperAI, because there is nowhere to send it — the guardian is the person who can act, and they can re-edit the story, change the reader's standards, or switch the feature off.

What that flag carries is bounded on purpose: it quotes what the app displayed, and never what the reader typed or said. A report is not allowed to become the transcript this product refuses to keep.

If you want to tell us about AI output, please email the address at the foot of this page. Doing so is entirely your choice and sends us only what you write in that email.

8. Keeping, and deleting, your information

Your data stays until you remove it. Because it lives only on your device, you remove it yourself and it is gone:

There is no account to close and no request to send us, because we hold nothing to erase.

9. Optional features that change this

ReaderRelay is an experimental, off-by-default feature of the web apps only. It is not present in the Android app. When a person deliberately turns it on, messages between a guardian's device and a reader's device pass through a third-party message host, and both apps display a permanent on-screen banner for as long as it is running. Those messages are encrypted on your device with a key derived from your pairing secret, which never leaves your devices, so the host cannot read them — but it can see that messages are passing, how large they are and when. While it is on, the honest sentence is “nothing readable leaves your device”, and the banner exists so that this can never be true without your knowing it.

10. Security

Keeping everything on one device removes whole categories of risk — there is no central database to breach. It also means the security of your information depends on the security of your device. We recommend a device lock, and the app supports a guardian PIN so a reader cannot reach the control surface. The PIN is a gate rather than a boundary: an adult with full access to the device can reach the underlying files, and we would rather say so than imply otherwise.

11. For schools and districts

The usual student-data-privacy question is "what will you do with our students' data, and what will you sign?" The honest answer here is unusual enough to be worth stating plainly.

There may be nothing for us to sign

A data privacy agreement governs what a vendor does with student data it receives. We receive none. ProsperAI operates no servers, so a district adopting it is not sending student information to a third party at all — it is installing software that runs on district devices and keeps everything there. If your process requires an agreement regardless, we are glad to sign one; what it will say is that we hold nothing.

FERPA and COPPA

Mandated reporting — what this app is and is not

A teacher reviewing "Talk about it" asked the question that matters: if a student tells the AI something about what is happening at home, and the teacher never sees it, where does that leave a mandated reporter?

The answer is that ProsperAI is not a disclosure channel and must not be treated as one. It is fenced to the story on the screen (see section 4), it keeps no transcript, and it makes no judgement about what a student says. It will never surface a concern to a teacher, an administrator or a parent, because it does not detect one and does not retain the words.

We considered building a narrow safety signal — a model deciding that a student's answer crossed a threshold, and writing one line so an adult knew it had happened, with no quote. It is deliberately not built. It would put a model in the position of judging children's disclosures, it would be wrong in both directions, and an adult who came to rely on it would be relying on something that misses things. Saying clearly that the app is not watching is more honest than a signal that watches badly.

Practically, for a school: this changes nothing about a reporter's duties, and it removes nothing from their view. A student's disclosure to a person is the path it has always been. What a school should not do is deploy this believing that an adult will be alerted — and that is exactly why this paragraph exists rather than being left unsaid.

Anthropic is the one subprocessor, and the district holds that relationship directly

In Live mode the device sends the text being edited to Anthropic. This is the one place a third party is involved, and a district evaluating us should evaluate that relationship on its own terms — not through us, because we are not a party to it. The API key is the district's own, the account is the district's own, and the billing and the terms are between the district and Anthropic.

Two specifics worth putting in front of counsel:

What a district cannot get from us, and why

These are consequences of the design rather than features not yet built, so no roadmap will deliver them:

12. Accessibility

Stated the way we would want a vendor to state it to us — what has been done, and what has not been checked.

There is no VPAT for this product, and no third-party accessibility audit has been carried out. A VPAT is a conformance claim, and a conformance claim that has not been audited is not worth the page it is on. We would rather tell a district that up front than hand over a document we filled in about ourselves.

What the apps do today:

What has not been verified: contrast ratios across every theme and state, focus order and visible focus on every control, screen-reader labelling of the icon-only buttons, and behaviour at very large text sizes. If any of these blocks a reader in your district, write to the address below and tell us which one — that is more useful to us than a checklist, and we will fix it.

13. Changes to this policy

If what leaves your device ever changes, this page changes in the same release — not afterwards. The date at the top is the date of the last change.

14. Contact

ProsperAI · prosper.ai.xu@gmail.com

Questions about this policy, about what the apps do, or about anything you believe contradicts what is written here, are all welcome at that address.