Privacy Policy
Last updated 5 August 2026. Applies to the ProsperAI website, the
ProsperAI web app (one app with a guardian role and a reading role), the
ProsperLens browser add-in, and the ProsperAI Android app
(us.prosperai.family).
ProsperAI has no server. There is no account to create, nothing to log in to, and no copy of your reading anywhere but on your own device. This page exists to say precisely what that means — and, just as important, the few moments when something does leave your device.
1. What we collect
Nothing. ProsperAI operates no servers, no databases, no analytics, and no logging of any kind. There is no ProsperAI account. We do not know that you have installed the app, how often you open it, what you read, or that you exist.
The apps contain no advertising, no advertising identifier, no tracking pixels, and no third-party analytics or crash-reporting SDKs.
2. What is stored, and where
Everything the app knows lives in storage private to the app, on your own device:
- The names, ages and reading standards you set up for each reader
- The books, articles and other text on the shelf, and the edited versions made for each reader
- Requests to see an original, and the decisions made about them
- The activity log, and any settings including your daily spending limit
- Your Anthropic API key
On Android the API key is held by the Android Keystore, and
Android Auto Backup is switched off for this app — which
means none of the above is copied to Google Drive, even though that is the
system default. In the web apps the equivalent data lives in your browser's
localStorage for that site, on that device.
None of this is ever transmitted to us, because there is nowhere for it to be transmitted to.
3. When something does leave your device
The app has an offline Demo mode in which nothing leaves your device at all — no network connection is made. Everything below applies to Live mode, which you turn on yourself by entering an Anthropic API key.
| Who receives it | What they receive | When |
|---|---|---|
Anthropicapi.anthropic.com |
The text being edited or translated; the reader's age and reading standards; and, in "Talk about it", what the reader said in answer to a question about the story. Never a reader's name — the prompt carries an age and nothing that identifies anyone. | At the moment an edition is made, a page is translated, or a reply in a conversation is requested. |
| A website you choose | An ordinary web request for the page, made by your device. | Only at the moment a guardian types or pastes an address and taps Fetch. Nothing is pre-fetched, polled, or refreshed in the background. |
Googleaccounts.google.com,
gmail.googleapis.com |
An authorization request, and then read-only access to your own mailbox. | Only if a guardian chooses to connect their own Gmail account. This connector is not included in the Google Play release of the Android app. |
That list is exhaustive. Each entry is your device talking to a party you chose, with nothing of ours in between. In particular there is no ProsperAI server in any of those paths — there isn't one to put there.
Your API key
Your Anthropic API key is sent only to Anthropic, only in the authorization header of a request you caused, and it is never written into a log, an error message, or a screen. We never see it. Charges for API use are between you and Anthropic; your Anthropic console is the only real record of that billing.
4. The microphone
"Talk about it" lets a reader answer questions about a story they have just finished. Only the Android app listens. The web app does not, and the difference is deliberate rather than a feature that has not been built yet.
- On Android, the audio never leaves the device and is never written to a file. Speech is turned into words by Android's on-device recogniser, which by construction cannot reach a network. On versions of Android without that recogniser — anything before Android 12 — the app does not listen at all and takes a typed answer instead, rather than falling back to a service that would upload the recording.
- In a browser there is no such guarantee, so ProsperAI does not ask for a microphone at all. The web speech API that browsers offer sends the recording to the browser vendor's servers, and no setting changes that. On the web a reader types their answer, and the app says so on the screen where they type it.
- The words the reader said are shown on their screen, and are sent to Anthropic only when the app asks for a reply to them.
- There is no wake word, no background listening, and no recording between button presses. The microphone is used only while a reader is holding a conversation they started.
- No transcript is kept, on either platform. A conversation leaves one line in the activity log saying it happened, and nothing else. Reading aloud is separate and needs no permission: it uses a voice already installed on the device.
A conversation is not a channel for telling someone something
ProsperReader is a reading companion for one conversation about one story, and it is built to stay there. The instruction sent with every turn tells it that it is not the reader's friend, teacher or parent; that it may talk only about the story on the screen; and that it must never ask about the reader's life, family, school or home, or repeat anything identifying if the reader says it. If a reader brings up their own life anyway, ProsperReader steers back to the story and nothing is written down.
The consequence, stated plainly: if a reader says something worrying, ProsperAI will not tell anyone — not a parent, not a teacher, not us. It does not judge what a reader says, does not keep it, and has no way to raise it. There is no record to disclose, and none to subpoena. A reader who needs to be heard needs a person, and the app says so on the reader's own screen every time a conversation is open.
5. The camera and nearby devices
The Android app can use the camera to read a pairing QR square, and Bluetooth and local Wi-Fi to pass a request between two devices in the same room. No photograph is stored or transmitted; the camera is a barcode reader and nothing else. Nearby pairing is device-to-device and reaches no network. Location permissions appear in the Android manifest only because older versions of Android required them for a Bluetooth scan; the app never reads your position.
6. Children
ProsperAI is designed to be set up by a parent, guardian or teacher and used by children. We take the same position for a child as for anyone else, which is that we hold nothing:
- We collect no personal information from a child — not a name, not an age, not an email address, not a photograph, not a location.
- A child's name and age are typed in by their guardian and stay on the device. A name is never sent anywhere. An age is sent to Anthropic as part of the editing instruction, because it is what the editing is for.
- There is no sign-up, no profile, no messaging with strangers, no user-to-user chat, and no advertising.
- The AI is instructed never to ask a child for their name, age, where they live, or anything else identifying, and never to repeat such a thing if it is said.
- Any adult can review everything the app holds, and erase all of it, on the device itself — see section 8.
Because we collect nothing, there is no data about a child for us to disclose, sell, or delete on request. If you believe otherwise, please contact us and we will investigate.
7. AI-generated content, and how to report it
Text in this app is edited, and sometimes written, by an AI model. Models make mistakes. Editions are produced against the standards a guardian set, and a guardian can always compare an edited version with the original.
Both the Android app and the web app have a “Something here is wrong” button on the reading screen and in every conversation. Tapping it flags the exact text to the guardian on their own device, where it appears on the first screen they see. Nothing is sent to ProsperAI, because there is nowhere to send it — the guardian is the person who can act, and they can re-edit the story, change the reader's standards, or switch the feature off.
What that flag carries is bounded on purpose: it quotes what the app displayed, and never what the reader typed or said. A report is not allowed to become the transcript this product refuses to keep.
If you want to tell us about AI output, please email the address at the foot of this page. Doing so is entirely your choice and sends us only what you write in that email.
8. Keeping, and deleting, your information
Your data stays until you remove it. Because it lives only on your device, you remove it yourself and it is gone:
- Android: Settings → “Erase everything on this device”, or uninstall the app. Uninstalling deletes the app's private storage, and because Auto Backup is off there is no cloud copy to survive it.
- Web apps: the reset control in Settings, or clearing site data for the domain in your browser.
There is no account to close and no request to send us, because we hold nothing to erase.
9. Optional features that change this
ReaderRelay is an experimental, off-by-default feature of the web apps only. It is not present in the Android app. When a person deliberately turns it on, messages between a guardian's device and a reader's device pass through a third-party message host, and both apps display a permanent on-screen banner for as long as it is running. Those messages are encrypted on your device with a key derived from your pairing secret, which never leaves your devices, so the host cannot read them — but it can see that messages are passing, how large they are and when. While it is on, the honest sentence is “nothing readable leaves your device”, and the banner exists so that this can never be true without your knowing it.
10. Security
Keeping everything on one device removes whole categories of risk — there is no central database to breach. It also means the security of your information depends on the security of your device. We recommend a device lock, and the app supports a guardian PIN so a reader cannot reach the control surface. The PIN is a gate rather than a boundary: an adult with full access to the device can reach the underlying files, and we would rather say so than imply otherwise.
11. For schools and districts
The usual student-data-privacy question is "what will you do with our students' data, and what will you sign?" The honest answer here is unusual enough to be worth stating plainly.
There may be nothing for us to sign
A data privacy agreement governs what a vendor does with student data it receives. We receive none. ProsperAI operates no servers, so a district adopting it is not sending student information to a third party at all — it is installing software that runs on district devices and keeps everything there. If your process requires an agreement regardless, we are glad to sign one; what it will say is that we hold nothing.
FERPA and COPPA
- FERPA. No education record is disclosed to us. Rosters, names, grades and reading levels are typed in locally by a teacher and stay in that device's private storage. We are not a "school official" with access to records, because there is no access to grant.
- COPPA. We collect no personal information from children of any age — see section 6. There is no account, no sign-up, no advertising, no persistent identifier, and no user-to-user contact.
- No rostering integration. There is deliberately no Clever, ClassLink or OneRoster sync, because each of those is a server relationship. Class lists are entered on the device.
Mandated reporting — what this app is and is not
A teacher reviewing "Talk about it" asked the question that matters: if a student tells the AI something about what is happening at home, and the teacher never sees it, where does that leave a mandated reporter?
The answer is that ProsperAI is not a disclosure channel and must not be treated as one. It is fenced to the story on the screen (see section 4), it keeps no transcript, and it makes no judgement about what a student says. It will never surface a concern to a teacher, an administrator or a parent, because it does not detect one and does not retain the words.
We considered building a narrow safety signal — a model deciding that a student's answer crossed a threshold, and writing one line so an adult knew it had happened, with no quote. It is deliberately not built. It would put a model in the position of judging children's disclosures, it would be wrong in both directions, and an adult who came to rely on it would be relying on something that misses things. Saying clearly that the app is not watching is more honest than a signal that watches badly.
Practically, for a school: this changes nothing about a reporter's duties, and it removes nothing from their view. A student's disclosure to a person is the path it has always been. What a school should not do is deploy this believing that an adult will be alerted — and that is exactly why this paragraph exists rather than being left unsaid.
Anthropic is the one subprocessor, and the district holds that relationship directly
In Live mode the device sends the text being edited to Anthropic. This is the one place a third party is involved, and a district evaluating us should evaluate that relationship on its own terms — not through us, because we are not a party to it. The API key is the district's own, the account is the district's own, and the billing and the terms are between the district and Anthropic.
Two specifics worth putting in front of counsel:
- No student is named. The editing instruction carries an age and the reading standards a teacher chose. It does not carry a name, a student ID, a school, a class, or a reading level history. This is a property of how the prompt is built, not a policy we are asking you to trust.
- But the text itself is whatever was put in. If a teacher pastes a student's own writing in to be leveled, that writing goes to Anthropic like any other text. That is the one path by which student work could reach a subprocessor, it is entirely under the teacher's control, and a district with a retention requirement should settle it in its own agreement with Anthropic. We would rather say this than let "no names are sent" be heard as "nothing identifying can ever be sent."
What a district cannot get from us, and why
These are consequences of the design rather than features not yet built, so no roadmap will deliver them:
- No district-wide dashboard. Aggregating usage across schools requires a server that receives it, which is the one thing this product does not have. Per-device records can be exported by the person holding the device.
- No central spend visibility. Same reason. Each device shows and can export its own.
- No remote configuration or remote wipe. A device is administered by the person holding it, through the app, or through whatever MDM already manages the hardware.
12. Accessibility
Stated the way we would want a vendor to state it to us — what has been done, and what has not been checked.
There is no VPAT for this product, and no third-party accessibility audit has been carried out. A VPAT is a conformance claim, and a conformance claim that has not been audited is not worth the page it is on. We would rather tell a district that up front than hand over a document we filled in about ourselves.
What the apps do today:
- The reading surface is ordinary semantic HTML on the web and standard Android text on the phone, so a screen reader, a system font-size setting and a browser zoom all work on it.
- Read-aloud is built in on both platforms, using a voice already installed on the device. It needs no permission and no network, and it works offline and in Demo mode.
- Reading level, tone and simplification are the product itself — which is to say a reader who needs a plainer text is served by the main feature and not by an accessibility mode bolted to the side.
- Controls are buttons and links rather than gestures, and no meaning is carried by colour alone.
- On the web a reader answers a question by typing. This is a deliberate privacy decision (section 4) and we recognise it is also a barrier for some readers; on Android the same reader can answer by speaking, on-device.
What has not been verified: contrast ratios across every theme and state, focus order and visible focus on every control, screen-reader labelling of the icon-only buttons, and behaviour at very large text sizes. If any of these blocks a reader in your district, write to the address below and tell us which one — that is more useful to us than a checklist, and we will fix it.
13. Changes to this policy
If what leaves your device ever changes, this page changes in the same release — not afterwards. The date at the top is the date of the last change.
14. Contact
ProsperAI · prosper.ai.xu@gmail.com
Questions about this policy, about what the apps do, or about anything you believe contradicts what is written here, are all welcome at that address.
