ADR-009: Children's data
Status: Accepted Date: 2026-10-10
Context
Every student is aged 5 to 10. The pilot agreement forbids releasing materials, curricula or any information about students. Vietnam's personal data protection law applies to data processed here, and expansion abroad will bring rules such as COPPA and the UK Children's Code.
Decision
- Data minimization. No email and no password for students. Collect only what an exercise or a teacher needs.
- Pseudonymous analytics. Names live in one place; interaction data and AI calls use IDs only.
- Nothing in logs. No names, answers, free text, tokens or cookies in logs (
LOG_REDACT_PATHS). - No trackers. No third-party analytics, ads or font/CDN requests on student-facing pages. Fonts are self-hosted.
- AI through one door. AI calls go only through the API's AI module, never from the browser, never with names, and only to providers with zero data retention and no training on inputs.
- Synthetic everywhere else. No real student or school data in code, seeds, staging, screenshots, issues, PRs, docs or prompts. These docs don't name the pilot school.
- Encrypted at rest. Full-disk encryption on every node; backups encrypted before they leave.
- Subprocessors are listed. Cloudflare, Vercel, the AI provider and email providers are recorded so the school can be told.
Alternatives considered
- Treating compliance as a later phase: retrofitting minimization and redaction is far harder than starting with them.
Consequences
- Some debugging is harder, by design.
- Webcam proctoring is out. Monitoring means the teacher's live view of the class.