Privacy policy
ClueStep is a parent-managed homework coaching service operated by Steady Steps Parenting LLC, which is responsible for the information described in this policy. We collect only the information needed to run family accounts, respond to homework questions, and show learning history.
Who creates an account
A parent or legal guardian creates and owns the family account. Learner profiles sit underneath that account and do not require a child’s email address or password. Children under 13 should use ClueStep only through a parent-managed family account and with their parent’s permission.
Signing in with Google or Facebook
Signing in with a provider is optional. Creating the account with an email address and password involves neither Google nor Meta. Learner profiles never sign in with a provider.
If you choose Continue with Google, your browser goes to Google, and Google learns that you are signing in to ClueStep. Google returns your Google account identifier, name, email address, whether Google has confirmed that address, and a link to your profile picture. We request only the sign-in scopes openid, email and profile. We cannot read your Gmail, Drive, contacts, or calendar.
If you choose Continue with Facebook, Meta learns that you are signing in to ClueStep. Facebook returns your Facebook user identifier, name, the email address on your Facebook account, and a link to your profile picture. We request only the email and public_profile permissions. We cannot see your friends, posts, photos, messages or page activity, and we never post anything to your account. Facebook does not tell us whether that address is confirmed, so we email you a verification link before the family account can be used.
From either provider we store the provider name, the account identifier it issued, the sign-in tokens needed to complete and maintain your session, and the name, email address and profile picture link on your parent account. We do not receive or store your provider password. We do not share learner profiles, homework questions, coaching conversations or usage with Google or Meta, and we do not use provider sign-in data for advertising.
Removing ClueStep from your Google account or Facebook settings stops future sign-ins; it does not by itself delete the family data already in ClueStep. To delete that, use the steps under Deleting your data.
Information we handle
We store the parent’s name and email, learner profile names, school-level bands and optional exact grades, optional parent-provided interests and learning preferences, text from coaching conversations (including writing excerpts), saved flashcard decks, linked practice worksheets, topic summaries, feedback, conversation stars and parent review status, account usage, and billing status. Stripe processes payment card details; ClueStep does not receive or store full card numbers.
Homework photos and drawings are sent to the selected coaching model so it can respond. The application does not add the image itself to conversation history. Students should avoid including faces, school IDs, addresses, or other personal details in homework photos.
How a coaching request is handled. To answer a question, what your learner typed, the recent conversation and any photo they attached are sent to the selected coaching model. For the models we use through OpenRouter, every request requires a provider with a zero-data-retention policy and denies data collection, so the provider may not keep that work or use it to train models; if no eligible provider is available, the request fails rather than quietly relaxing that rule. Coaching conversations are private to your family account: they are not published, not sold, not shared with other families, and never sent to an advertising or analytics service. Two narrow exceptions, stated so the sentence above is exact rather than merely reassuring: our support team can read a trimmed excerpt of a reply that has been flagged or rated, in order to review incorrect or confusing help, and our safety check can email a parent when a message suggests a child may need support — that notice deliberately does not include what the child wrote. When a message suggests possible harm at home or by a caregiver, we avoid automatically emailing a parent who could be involved. We still record the concern for review and encourage the learner to reach an adult they feel safe with. These automated text checks can be wrong or miss concerns and are not an emergency service.
Why we use it
School inquiries include your contact details, school or district, role, approximate enrollment and classroom counts, and any optional planning details you provide. We use them to discuss school access and pricing. Inquiries are stored in our private support queue and follow the support-ticket retention schedule below. Please do not include student names or records in a sales inquiry.
We use this information to provide guided homework help, preserve conversations, prepare parent recaps, secure accounts, process purchases, prevent abuse, and operate the service. We do not sell personal information or use it for behavioral advertising.
Grade level, optional interests and learning preferences may be sent to the selected coaching model to personalize examples. Parents can edit or clear them in the family dashboard. Please use light interests such as hobbies, not medical information, school names, or addresses. Stars record a checked answer or parent review of a conversation; they are not a diagnosis or an assessment of mastery.
Service providers
We use service providers for hosting and network security, model inference, email delivery, payment processing, and database operations. They receive only the information needed to perform their role and handle it under their own contractual and privacy obligations.
Google and Meta act as identity providers only for parents who choose provider sign-in, and receive only what that sign-in requires, as described above. Their handling of your Google or Facebook account is covered by their own privacy policies, not this one.
To judge whether our public pages help families find Clue, we keep a short, first-party note of where a new parent account or free trial started (the referring site or a site-provided campaign name, or “direct”). It is aggregate attribution only: no name, email, IP address or ad identifier is attached to it, it is never used for advertising or targeting, and it is deleted with the account or trial. When you arrive from a link that names a campaign, that campaign name alone is kept in one small first-party cookie for 90 days — only the name of the channel, such as “library flyer”, never an identifier for you, your visit or your browsing — so that if you read a lesson first and start a free trial afterwards, the trial is still credited to the place that told you about us.
First-party visit counting on the public pages. Our public pages count visits with our own first-party counters rather than a third-party analytics service. We record a running total per day for: the page (from a fixed list — the home page, /learn and its lessons, /for-parents, /for-schools, /school, /support, /privacy, /terms, /pricing, /compare, /homework-routine, /methods and its guides), the channel that brought the visit (a campaign label or referring site), the country (from our network provider’s country header; your IP address itself is never stored), the referring website’s domain name only (never the full link), and whether the visit was the first from that browser that day or a later one. A first-party cookie that expires after one day helps tell those two apart; it holds a random value with no personal information and is never combined with your name, email or account. Counting also happens on /try. It never happens inside a signed-in family account, no learner-specific address can ever be recorded, and there is no row per person anywhere in this data. We previously described a Google Analytics tag here; that tag never actually collected data (our security policy blocked it), and it was removed entirely on September 16, 2026.
Page-view counts. To know whether anyone is reaching the site at all, each public page keeps a daily running total of page views: one number per day, per channel and per page, with nothing recorded about the visitor. There is no row for a visit or a visitor, no cookie and no identifier of any kind, no IP address, browser or session detail, and no time finer than the day. The page is stored as one of a fixed list of names (the home page, /learn and its lessons, /try, /for-parents, /for-schools, /school, /support, /privacy, /terms, /pricing, /compare, /homework-routine, /methods and its guides) rather than the address you visited, so a page specific to you or your learner can never be recorded. Signed-in pages and the administrator workspace are not counted. Those totals cannot be used to tell who visited, how often, from where, or what else they read, and they are not used for advertising or targeting. The free trial at /try keeps the same kind of daily totals for five of its steps (a subject picked, an example question used, a question typed, a question sent, and a send stopped by the security check), counting each step at most once per page load and only before a trial has started, again with nothing recorded about the visitor: no row, cookie, identifier, IP address, browser detail or time finer than the day.
Referral links. A family can invite another family with a personal link such as cluestep.com/?ref=ABCD1234, and clubs, teachers or newsletters can be given a code of their own. Opening such a link stores one small first-party cookie that holds only that code, for 90 days, and adds one to a daily total for that code — a count, with nothing about you attached to it. The code records who referred a family — it is not an identifier for you, it is not shared with anyone, and it tells the referrer nothing about you. A referral link holds no identifier for you, and no third-party pixel, ad tag or tracking script is involved. If a free trial or a family account is later created in that browser, the code is stored with that trial or family so a referral reward or a partner payment can be worked out, and it is deleted with them. No learner profile or homework content is ever attached to a referral.
Abuse prevention. Two public pages that create a record and then spend money on our side — parent sign-up and the no-account free trial at /try — run a Cloudflare Turnstile check to tell a person from an automated script. Your browser loads Turnstile from challenges.cloudflare.com, and our server sends Cloudflare the resulting one-time token and the connecting IP address to confirm it. Cloudflare acts as our network-security provider for that check. Turnstile is not analytics or advertising: it receives no name, email, learner profile or homework content, and its result is used only to allow or refuse that one request. Turnstile is not used anywhere inside a signed-in family account.
Quick Clues, rewards and classrooms
Quick Clues stores challenge attempts, first-answer correctness, hint use, completion dates, kudos entries, sharing preferences and custom reward goals. These are participation records, not an assessment of intelligence or mastery. The curated challenge bank does not send these answers to an AI provider.
A parent can enroll their own learner in a private classroom using a teacher-provided code; a learner with an eligible self-managed account can enroll themselves. Enrollment shares the selected classroom nickname and kudos earned since joining with that classroom's teacher. It does not give the teacher access to family billing, homework conversations, or unrelated family rewards. Other students are shown group progress rather than classmates' individual difficulties. Do not put sensitive personal information in nicknames or custom reward descriptions.
Score sharing is optional. Family learners need a parent to enable it. The share action includes a kudos total and a general ClueStep link, not public student profiles, learner identifiers, school details or a list of answers. Once someone chooses another app to share through, that app handles the shared text under its own policies.
A parent can authorize a separate challenge-only device with a short-lived, single-use pairing code. A hashed device token and an HttpOnly cookie allow that device to return to the selected learner's challenges without granting family-management or billing access. Parents can revoke paired devices.
Reminders are off unless enabled. We store the selected schedule and, for push delivery, a push subscription containing a delivery endpoint and encryption keys. Your browser's push provider handles delivery. Notifications contain generic challenge invitations, not grades, names, answers or reward amounts. Family-child email reminders go to an authorized verified parent address; eligible self-managed learners can use their own verified address. You can disable reminders in Quick Clues. A teacher cannot subscribe a class member to reminders on their behalf.
Challenge records remain with the learner until the linked profile or account is permanently deleted. Removing a learner or pausing a family blocks challenge access and reminder delivery during the existing recovery window. Classroom membership can be ended without deleting earned personal kudos. Contact support for help exporting or deleting records associated with a self-managed learner or educator account.
The lesson newsletter
At the end of each free lesson there is a single field offering one email a week. It is entirely optional, it is not part of any account, and nothing on the lesson pages requires it.
Adults only. This list is written for parents and teachers. We ask for one email address and nothing else — no name, no age, no grade, no child’s address — and we do not knowingly sign up children. If a child has entered an address, use the unsubscribe link in any email, or write to [email protected] and we will delete the record.
Double opt-in. Submitting the form sends exactly one email: a confirmation link. Nothing else is ever sent unless you click it. If you do not, the address is deleted within seven days. This means a mistyped or maliciously submitted address never receives the newsletter.
What is stored. The email address itself, whether it is pending, confirmed or unsubscribed, the dates of those events, how far through the four-email welcome sequence it has got, the slug of the lesson page the form was used on, and the same aggregate acquisition label described above (“direct”, a campaign name, or a referring site). The confirmation and unsubscribe tokens are stored only as one-way hashes. No name, IP address, learner profile, homework, or family account is linked to a subscription, and a family account and a newsletter subscription are separate records even when they use the same address.
One-click unsubscribe. Every email carries an unsubscribe link that works in one click, with no sign-in, no password and no “are you sure” step, and the standard mail headers that let Gmail, Apple Mail and Outlook show their own unsubscribe button. Unsubscribing takes effect immediately; the record is then deleted after thirty days.
No tracking, never shared. The emails contain no tracking pixel, no open tracking, no read receipt and no click-through redirector — links go directly to cluestep.com and carry only a plain campaign name in the address bar so we can see which email brought someone back. We do not sell, rent, share or swap this list, we do not upload it to any advertising platform, and we do not use it to build a profile of you. Resend delivers the mail on our behalf as a service provider.
Deleting your data
Sign in as the parent who owns the family account and open Family → Privacy controls. Download a student’s saved content as a ZIP containing readable pages, structured records and saved picture files, download family account records, remove a student, or request deletion of the whole family account. If your account has a password, confirm it first. If you only sign in with Google, Facebook or your school, sign out and sign back in, then return to the panel within five minutes; there is no password to enter.
Removing a student immediately takes them off the active family plan and blocks access to their study tools. Their profile and saved content remain available to the family owner for download or restoration for 60 days from removal. The panel shows the deadline. After that deadline, restoration and student downloads stop, and the next scheduled cleanup permanently deletes their profile and saved content from the active database. Removing a student does not cancel your subscription or refund used clues.
If you cannot sign in, email [email protected] from the address on the account, or from the email address held by the provider you signed in with, and ask us to delete your family account. We may need to verify that the requester is the family account owner. We aim to confirm within 30 days.
Parent choices and retention
An account-deletion request pauses new clues, learner creation, purchases, and recaps while support checks billing. It does not itself cancel a Stripe subscription. You can still manage billing and export your data. The family owner can withdraw the request in Privacy controls within 60 days of the original request. Permanent account deletion is support-assisted and cannot happen before those 60 days have elapsed and billing has been checked. Restoring access does not restart a canceled subscription.
Routine expiry and picture storage limits do not erase retained student content during a student’s 60-day recovery window or the family account’s 60-day recovery window. Restored conversations and writing receive a fresh 365-day retention period; restored pictures receive at least 180 days and response records and ratings receive 30 days. Previously expired or permanently deleted content and original homework photos cannot be recovered or exported. Encrypted backups expire separately, normally within 14 days; earlier copies may still contain deleted records until they expire, and completed deletions must be reapplied before restoring a backup into service.
AI study aids are saved for the selected learner and accessible only through their family account. If enabled, generation uses bounded excerpts from that learner’s recent chats in the selected subject. Saved study aids remain until deleted or the learner or family account is removed. Family exports include saved study aids. Deleting an aid clears its content and keeps a billing receipt to prevent duplicate charges.
Saved clues are removed after 365 days without an update. Resolved or closed support tickets are removed after 180 days without an update. Safety-review excerpts and diagnostic details are cleared after 30 days; reviewed or dismissed events and recap delivery logs are removed after 90 days. Open reports remain available for investigation and are reviewed by support. These limits apply to our active database; existing emails, payment-provider records, and separately maintained backups need separate handling.
Reply ratings are linked to the rated response so the team can review incorrect or confusing help. Response retry records, ratings and request timing records are retained for 30 days. They contain response text and identifiers, not original photos. Saved writing revisions, assignment goals and optional rubric excerpts are removed after 365 days without an update, or with their linked conversation, learner or family. Saved deck recall choices are self-reported and remain with the deck. These records are included in family exports.
Unsent photos and scratch work stay in the current page memory and are not recovered after closing it. Read-aloud uses an available English voice marked as local by your browser. We do not send your clue to a separate speech service. The public scripted demonstration does not save or transmit your answers.
The no-account free trial. You can ask up to five questions, follow-ups included, without creating an account. To let that same browser continue an unfinished free journey, ClueStep sets one small cookie that is used only to resume the trial; it is never used for advertising, analytics identifiers, or any other purpose, the value is stored as a one-way hash and never combined with a name or email, and it expires automatically after 90 days. A parent account that starts in the same browser takes the trial over: the remaining free questions then count toward the family plan, and the cookie stops working. The text of trial questions is kept with the trial record so they can be reopened after a refresh, is removed with the trial after 90 days, and is not saved to any family profile unless the parent creates a family account; images and photos are never saved from a free trial.
Sending a journey to a parent. At the end of a free trial, a child may ask us to email a parent or guardian a link to continue. The email address is typed by the child, is stored only as a one-way hash, is used to send at most three short emails for that trial, and is deleted when the link is used or after 14 days — never added to a mailing list, never used for marketing, and never combined with anything else. The email carries only a sign-up link and a general explanation of ClueStep; it includes no homework, conversation text, learner name, or tracking. Saved trial work is attached only after the recipient verifies the invited email address. When a parent verifies that email address while creating an account, the child’s free trial is attached to that family so the questions count toward the household allowance, exactly as if the parent had signed up on the child’s browser.
Flashcard decks remain until you delete the deck, learner, or family account. Writing uploaded as plain text is placed in the message draft for review before sending; sent text follows conversation retention. Original text files are not stored.
We do not load Google Ads tags, and we do not send sign-up or purchase events to advertising services. Earlier versions used Google Ads conversion measurement on public pages; that integration was removed on September 8, 2026. The Google Analytics tag this policy once described was removed entirely on September 16, 2026; visit counting is first-party only. Homework photos are not saved in our database. An annotated photo is an in-session preview only. Diagrams that Clue draws at a learner’s request contain no homework photo; each is saved with that clue for 180 days so reopening the clue shows it again without drawing it twice, counts toward a per-family storage limit, appears by title in family exports, and is deleted with its conversation or family. OpenRouter coaching requests require providers with a zero-data-retention policy; if no eligible provider is available, the request fails rather than silently relaxing that restriction.
Optional voice controls
Free and paid parent-managed accounts can choose to hear Clue’s replies. We send the selected clue’s observation and next step to Microsoft MAI-Voice-2 through OpenRouter to generate speech. We require zero-data-retention routing and deny data collection for training; if an eligible route is unavailable, read-aloud fails without relaxing those settings. We do not send the learner’s microphone recording, homework photo, or full conversation to the speech service. Generated audio stays temporarily in the browser and is not saved in our database.
Microphone dictation is optional and starts only when the learner taps Speak. We enable it only when the browser supports on-device recognition; we do not fall back to remote browser transcription. ClueStep does not upload or store microphone recordings. Recognized words appear in an editable draft and are handled like typed homework only after the learner presses Send. Dictation support and language packs depend on the browser. Read-aloud can mispronounce mathematical notation; the written clue stays available.
Contact us
For a privacy question or a request involving a child’s information, email [email protected]. We may need to verify that the requester is the family account owner.
