Privacy Policy

Effective July 2, 2026

bMotion Technologies Corp (operating as Poppins Learning), a Delaware corporation. This Policy covers both the School path and the direct-to-parent Family path — see “How This Policy Works” below for which parts apply to you.

Privacy Policy

This Privacy Policy explains how bMotion Technologies Corp, a Delaware corporation doing business as Poppins Learning (“Poppins,” “we,” “us”), collects, uses, and discloses personal information in connection with the Poppins reading and literacy application and related websites, software, and services (collectively, the “Services”). Poppins is a reading tool that supports children, including children with dyslexia and related learning differences, in building reading and pronunciation skills.

How This Policy Works: Our Two Kinds of Users

Poppins is offered in two ways, and the way you use the Services affects how this Policy applies to you.

Schools (our primary path). Schools, school districts, and other educational institutions (each, a “School”) license the Services for their students. When a School uses Poppins, the School directs the collection and use of student information for educational purposes, and Poppins acts on the School’s behalf as described in the section “Schools and Student Data” below. In this path, the School is our customer, and students and their families use the Services through the School.

Families (direct path). A parent or legal guardian (“Parent”) may also create an account directly and allow their child to use the Services outside of a School. In this path, the Parent is our customer, and we collect and use information as described in the section “Children’s Privacy” below, including obtaining verifiable parental consent where required.

Where a section of this Policy applies to only one path, we say so. Where it applies to both, it applies to both.

Our core commitments. We do not sell personal information. We do not use personal information to serve behavioral or targeted advertising. We do not display third-party advertising to children in the Services. We collect only the information reasonably needed to provide the Services, and we handle student information in accordance with the Family Educational Rights and Privacy Act (“FERPA”), the Children’s Online Privacy Protection Act (“COPPA”), and applicable state student-data-privacy laws.

Personal Information We Collect

We collect only the categories of information described below. The specific fields collected depend on how the Services are used and, in the School path, on what the School chooses to provide.

Account and roster identifiers. First and last name, a Poppins-assigned student identifier, a username, and, where a School provides them, an optional local or district-assigned student identifier, grade level, and school or organization membership, and the person’s role (student or teacher).

Home-language information. Where a School or Parent provides it, information about a child’s home language, used to support language-appropriate instruction. We do not collect other demographic categories.

Learning and usage data. Reading progress, exercise scores, skill-mastery levels, session activity such as time spent and exercises completed, and derived recommendations for a child’s next exercise.

Voice recordings. Short voice recordings captured during pronunciation exercises, used to provide feedback within the Services. These recordings are automatically deleted within ninety (90) days, or within seven (7) days of a verified deletion request. See “Voice Recordings” below.

Device and technical data. Limited device and operating-system information used to run the application on a device. We do not collect precise geolocation and we do not collect advertising identifiers in the Services.

Communications. Information you provide when you contact us for support or otherwise communicate with us.

What we do not collect. Through the Services we do not collect health diagnoses, IEP or 504 records, Social Security numbers or similar government identifiers, precise geolocation, or payment-card numbers from children. Any subscription payment in the direct Family path is processed by a third-party payment processor, and we do not store full card numbers.

How We Use Personal Information

We use personal information to:

  • provide, maintain, and support the Services and each child’s learning experience;
  • create and administer accounts and rosters and authenticate users;
  • generate progress information for educators and, in the Family path, for Parents;
  • secure the Services and detect and prevent fraud, abuse, and misuse;
  • respond to support requests and communicate with Schools and Parents about the Services; and
  • comply with our legal obligations.

De-identified data. We may create and use de-identified data, which cannot reasonably be used to identify any individual, to operate, research, and improve the Services and to measure and describe their educational effectiveness. We do not attempt to re-identify de-identified data.

No advertising use; no model training on identifiable student data. We do not use personal information for behavioral or targeted advertising, and we do not use identifiable student information to train artificial-intelligence or machine-learning models except to provide the Services.

How We Disclose Personal Information

We disclose personal information only as follows:

  • Service providers. We share information with vendors that process it on our behalf to provide the Services, under contracts that limit their use of the information to that purpose. Our current service providers with access to student information are our cloud-infrastructure provider (Amazon Web Services, in the United States), our self-hosted data layer operating on that infrastructure, and our rostering and single-sign-on provider (Ednition).
  • At the direction of the School or Parent. In the School path, we share information as the School directs. In the Family path, we act on the Parent’s direction.
  • Legal and safety. We may disclose information where required by law or legal process, or to protect the rights, safety, or security of users, the public, or Poppins. Where permitted, we will notify the School before disclosing student information in response to legal process.
  • Business transfers. If Poppins is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to the commitments in this Policy and applicable law.

No sale; no sharing for targeted advertising. We do not sell personal information, and we do not share it for cross-context behavioral or targeted advertising. We do not knowingly do so with respect to any user, and never with respect to a child.

Children’s Privacy

Protecting children’s privacy is central to how we operate. Since the Services are intended for children, we design them to collect only what is needed for the educational experience, and we do not condition a child’s participation on disclosing more information than is reasonably necessary.

In the School path

Where a child uses the Services through a School, we rely on the School to provide the consent required under COPPA on behalf of Parents, for the collection and use of student information for the educational purpose of the Services. COPPA permits a School to authorize the collection of a student’s personal information in the educational context in lieu of individual parental consent, and we limit our use of that information to providing the Services to the School. The School is responsible for providing any notices to, and obtaining any consents from, Parents that applicable law requires.

In the Family path

Where a Parent creates an account directly, we obtain verifiable parental consent before collecting personal information from a child under 13, consistent with COPPA, and the Parent may review the child’s information, direct us to delete it, and refuse to permit further collection. A child’s account in this path is created and managed under the consent and supervision of a Parent.

What we do not do with children’s information

We do not use children’s personal information to serve behavioral or targeted advertising, we do not integrate third-party advertising software-development kits into the Services, and we do not use tracking technologies in the Services to build advertising profiles of children. If we learn that we have collected personal information from a child in a manner inconsistent with this Policy or applicable law, we will delete it.

Schools and Student Data (FERPA and State Student-Privacy Law)

When a School uses the Services, the student information we handle may include education records subject to FERPA and to state student-data-privacy laws. In that role:

  • We act as a “school official” with a legitimate educational interest under, performing an institutional service the School would otherwise perform itself.
  • Student information remains under the control of, and is used only for the benefit of, the School. We do not use it for any purpose other than providing the Services and the limited purposes described in this Policy.
  • We do not re-disclose student information except as the School directs or as law permits, and we require our service providers to protect it under obligations no less protective than ours.
  • We do not sell student data, do not use it for targeted advertising, and do not use it to build non-educational profiles, consistent with applicable state student-privacy laws.
  • On the School’s direction or at the end of the engagement, we return or delete student information as described under “Retention” and in our data processing and student data privacy agreement with the School.

Parental rights in the School path. Parents who wish to access, review, correct, or request deletion of their child’s education records should contact the School, which we will support. We will refer Parent requests we receive directly to the School.

State Student Data Privacy Laws

In addition to FERPA and COPPA, many states have adopted student-data-privacy laws that apply to companies like Poppins that provide online services to schools. Where our School users are located in a state with such a law, we comply with it. These laws differ in detail but share a common core, modeled largely on the California Student Online Personal Information Protection Act, and we align our practices to that core.

Key regimes we align with include: the California Student Online Personal Information Protection Act (SOPIPA) and the school-contract requirements of California Education Code section 49073.1; New York Education Law section 2-d and its Parents’ Bill of Rights for Data Privacy and Security; the Illinois Student Online Personal Protection Act (SOPPA); the Colorado Student Data Transparency and Security Act; Connecticut’s student-data-privacy law; Virginia Code section 22.1-289.01; and North Carolina General Statute section 115C-401.2. This list is illustrative, and many other states have comparable laws with which we comply where they apply.

Consistent with these laws, when we handle student information on behalf of a School we commit that we:

  • do not sell or rent student data;
  • do not use or disclose student data for targeted advertising, and do not present targeted advertising to students;
  • do not use student data to create a profile of a student except in furtherance of the educational purpose of the Services;
  • use student data only for the authorized educational purposes for which the School provides it and as our agreement with the School permits;
  • maintain reasonable administrative, technical, and physical security for student data;
  • delete or return student data at the School’s direction or when it is no longer needed to provide the Services;
  • provide notice of a data breach affecting student data as required by law and our agreement with the School; and
  • require our service providers to protect student data under obligations no less protective than ours.

State-specific mechanisms. Some states require specific contract terms, parent-facing disclosures, or breach-notice timelines, such as a New York parents’ bill of rights and supplemental information, an Illinois written agreement and breach-notice timeline, or a North Carolina data confidentiality and security agreement. We implement these through the data processing or student data privacy agreement, or the state-mandated agreement, that we sign with the applicable School.

Voice Recordings

The Services capture short voice recordings when a child completes pronunciation exercises, so the Services can provide reading feedback. We use these recordings only to provide and improve the reading experience, we do not use them for advertising, and we do not sell them. Voice recordings are automatically deleted within ninety (90) days, or within seven (7) days after a verified deletion request from a School or Parent.

Retention of Personal Information

We keep personal information only as long as reasonably necessary to provide the Services and to meet our legal and contractual obligations. In the School path, we return or delete student information at the School’s direction and in accordance with our agreement with the School, which may require deletion within a set period after the engagement ends; those School-directed and contractual deletion requirements govern. Voice recordings follow the schedule described above. In the Family path, we retain a child’s information for no longer than reasonably necessary and delete it promptly on a Parent’s verified request. De-identified data, which does not identify any individual, may be retained.

Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, appropriate to its nature. These include (i) hosting of student information on United States infrastructure, with encryption in transit and at rest; (ii) access limited to authorized personnel and service providers on a least-privilege, need-to-know basis; (iii) no advertising software-development kits in the Services, and no behavioral or targeted advertising or advertising cookies; (iv) privacy and security training for personnel with access to student information; and (v) a written incident-response process for handling any security incident.

No method of transmission or storage is completely secure, so while we work to protect personal information, we cannot guarantee absolute security.

Cookies and Similar Technologies

The Services are designed for use by children and do not use advertising or cross-context tracking cookies. We use only the technologies necessary to operate the Services and to understand general, aggregated usage so we can maintain and improve them. Our public marketing website may use basic analytics that do not access student information. We do not use these technologies to serve behavioral or targeted advertising, and because we do not sell or share personal information for advertising, we honor recognized opt-out preference signals to the extent they apply to any non-student website analytics.

Your Rights Under State Consumer Privacy Laws

Depending on where you live, you may have rights under a state consumer-privacy law, such as the laws of California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia. Subject to that law’s conditions and exceptions, these rights may include the right to access, correct, or delete your personal information, to obtain a copy of it, and to opt out of targeted advertising, the sale of personal information, or certain profiling. Since we do not sell personal information and do not use it for targeted advertising, there is nothing to opt out of for those purposes.

Student information and these state laws. Most state consumer-privacy laws do not apply to information governed by FERPA or handled by a service provider on behalf of a School. For student information in the School path, Parents and eligible students exercise their rights through the School, as described above.

How to exercise your rights. To make a request, email us at privacy@poppins.io. We currently accept privacy requests by email; we may ask for information reasonably necessary to verify your identity or authority before acting on a request. You have the right not to be treated differently for exercising your rights.

California Notice

Notice at Collection. The categories of personal information we collect are described under “Personal Information We Collect,” and we use them for the purposes described under “How We Use Personal Information.” We do not sell personal information and do not share it for cross-context behavioral advertising, and we do not do so with respect to consumers under 16.

Shine the Light. California residents may ask whether we disclose personal information to third parties for those third parties’ direct-marketing purposes. We do not, but you may contact us at privacy@poppins.io with any such request.

Contact Us

If you have questions about this Policy or our privacy practices, contact us at:

Poppins Learning (bMotion Technologies Corp)

185 Alewife Brook Parkway, Cambridge, Massachusetts 02138

Privacy: privacy@poppins.io

Legal and copyright notices: legal@poppins.io

Updates to This Policy

We may update this Policy from time to time. We will post the updated Policy with a new “Last Updated” date and, where required by law or our agreements, provide notice to Schools or Parents and obtain any renewed consent needed before applying a material change to the collection or use of a child’s information.