Naven Open Naven
Legal · Compliance

Compliance

How Naven meets the rules for children, students, schools and the app stores — each requirement set against what Naven actually does.

Last updated 25 September 2026
COPPA
Verified parental consent by signed form
FERPA
School official, under a signed agreement
California (SOPIPA)
No ads, no profiling, no sale
Canada (FIPPA)
Supports a school’s privacy assessment
App stores
Deletion, reporting, child-safety standards
Certification
None claimed — see below

About certification

No government agency certifies compliance with COPPA, FERPA or FIPPA, and Naven displays no seal. COPPA practices can be independently certified by one of the Safe Harbor programs the FTC has approved; Naven has not yet been certified by one. Everything on this page is a description of what Naven actually does, set against the rule it names — not a badge, and not legal advice to anybody.

Naven does not make a change that would contradict this page without first changing this page, and telling the schools and parents it affects.

COPPA — children under 13 (United States)

The Children’s Online Privacy Protection Act and the FTC’s COPPA Rule, 16 C.F.R. Part 312, as amended in 2025.

What the rule requiresWhat Naven does
Notice on the website of how children’s information is handled, with the operator’s contact details (§ 312.4(d))The Children’s Privacy Notice, linked from the home page, the sign-in screen where the age is asked, the parent pages and every legal page
Direct notice to the parent before collecting (§ 312.4(b)–(c))Emailed to the parent the child names, saying what would be collected, who could see it, how to consent, and that data is deleted without consent
Verifiable parental consent before collection, use or disclosure (§ 312.5)A signed consent form returned by scan — a method the Rule lists — checked by a person before the account can send, post, upload, call or use AI
Separate consent for disclosure to third parties that is not integral to the service (2025 amendments)Naven AI, which sends questions to an outside AI company, has its own box on the form and stays off without it
Delete information collected to seek consent if consent is not given (§ 312.5(c)(1))An unconsented under-13 account and everything about it is deleted after 14 days, automatically, every day
Parents can review, refuse further collection, and have data deleted (§ 312.6)Parent controls show contacts, refusals and usage; the parent can pause the account or delete it; or email the operator
Do not require more information than an activity needs (§ 312.7)No address, phone, school or photo asked of a child; location sharing is off for under-13 accounts; the screen blocks a child sending an address or phone number
A written information security program (§ 312.8, as amended)In place, naming the person responsible, reviewed at least yearly; described in the notice without promising security
A written data retention policy, published, and deletion when no longer needed (§ 312.10)Published in the notice and the Privacy Policy
No behavioural advertising to childrenNaven shows no advertising to anybody, and Google Analytics never runs once someone is signed in

FERPA — education records (United States)

FERPA binds schools, not Naven directly. Naven meets its side through a signed agreement with the school.

What the rule requiresWhat Naven does
A school may share education records with a “school official” under its direct control (34 C.F.R. § 99.31(a)(1)(i)(B))Naven accepts that designation in a signed agreement
Records used only for the purpose they were shared for, and not re-disclosed (§ 99.33)Used only to provide the service; disclosed only to the named sub-processors or as the law requires
Parents and eligible students can inspect and correct records (§§ 99.10–99.22)Requests go through the school; Naven helps it respond within 10 business days
Records returned or destroyed when no longer neededDeleted on request and within 60 days after an agreement ends

California — SOPIPA, Education Code 49073.1, CCPA and CalOPPA

What the rule requiresWhat Naven does
No targeted advertising to studentsNo advertising at all
No profiling of a student except for school purposesNone, except running the service
No sale of student informationNever
Reasonable security procedures, and deletion when the school asksDescribed in the agreement’s Exhibit A; deletion on request
Contract terms required by Education Code § 49073.1In Naven’s agreement, or the California Student Data Privacy Agreement a district already uses

CCPA and CPRA. Naven does not meet the thresholds that make a business subject to the California Consumer Privacy Act, and it gives everybody the rights that law describes anyway: to know, to delete, to correct, and not to have data sold or shared — Naven sells and shares nothing, so there is nothing to opt out of. CalOPPA. The Privacy Policy is linked from every page, says how Naven responds to Do Not Track and Global Privacy Control signals, and is dated.

Canada — FIPPA, MFIPPA and PIPEDA

British Columbia’s and Ontario’s public-sector privacy laws bind schools and boards rather than Naven. Naven supports a school’s privacy impact assessment, limits its use of the school’s data by agreement, helps answer access and correction requests, and states plainly that data is stored in the United States. For members in Canada generally, Naven’s Privacy Policy covers the principles in PIPEDA: consent, limited collection and use, access, and a contact who is accountable.

A province or school that requires data to be stored inside Canada cannot use Naven today.

The App Store and Google Play

What the stores requireWhat Naven does
In-app account deletion, and a web page to request it (Apple 5.1.1(v); Google Play)Settings → Delete account; the delete-account page; the parent controls for a child
Report objectionable content and abusive users; block users (Apple 1.2; Google Play UGC)Report and Block in every conversation’s menu, reviewed by a person
Published standards against child sexual abuse and exploitation, with a contact (Google Play)The Child Safety Standards page
A privacy policyThe Privacy Policy, the children’s notice and the student data page

Who is responsible

Operator: Naven, operated by its developer, Shervin Shapoury, who is also responsible for its information security program.
Email: shervin@shapoury.com
Postal address: given on request by email
Telephone: given on request by email