Naven’s notice to parents under COPPA: what happens before a parent consents, what Naven collects from a child with consent, who sees it, how long it is kept, and how a parent reviews it or has it deleted.
Last updated 25 September 2026This is Naven’s notice under the US Children’s Online Privacy Protection Act (COPPA) and the FTC’s COPPA Rule (16 C.F.R. Part 312, as amended in 2025). It applies to every Naven account whose owner gave an age under 13, and to the parents and legal guardians of those children. The general Privacy Policy applies to every account as well; where the two differ for a child under 13, this notice is the one that applies.
Operator: Naven, operated by its developer, Shervin Shapoury.
Email: shervin@shapoury.com
Postal address: given on request by email
Telephone: given on request by email
Naven has no other operator. No other company collects personal information from children through Naven.
Naven asks for a birth year when an account is created, without suggesting an answer or saying what any answer leads to, and keeps only the age band it falls in. If the age given is under 13, the account is paused before it can do anything that collects or shares a child’s information: it cannot send messages, post, upload, call, invite anybody, choose a public username or use Naven AI. It can read what others send it.
If consent does not arrive within 14 days, Naven deletes the child’s account, everything it holds about them, and the parent’s email address. This runs automatically every day.
Schools. A school may consent on a parent’s behalf, but only for an account the school creates for its own student, for the school’s educational purposes, under a signed agreement with Naven (see student data). Naven then uses that student’s information only for those purposes, and the school can review and delete it.
None of it is used for advertising, sold, or shown to anybody. All of it is deleted if consent does not arrive.
| Information | How it is collected | Why |
|---|---|---|
| Messages, photos, voice notes, files, channel posts and reactions | The child sends them | To deliver them to the people the child chooses; to screen them before they are sent |
| Display name, age band (never the birth year), optional profile photo and username | The child enters them | So people know who they are talking to; to apply the rules for their age |
| Who they talk to and call, when, and for how long | Recorded as they use Naven | To show their conversations and call history; for the parent controls |
| Browser and device type, country, time zone, language, days Naven was opened | Automatically, from the browser | Security alerts, showing times correctly, keeping the service working |
| A notification token (only if notifications are turned on) | From the browser, with permission | To deliver notifications |
| Messages Naven refused to send, and why | Recorded by the screen | Safety, and to tell the parent the category and time (never the content) |
| Questions asked of Naven AI — only with the parent’s separate consent | The child types them | To answer them |
Naven does not require a child to share more than a feature needs. It does not ask for a child’s home address, phone number, school or photograph, and its screen stops an account under 13 from sending a home address or phone number to anybody. It never collects a child’s location: sharing a location is switched off for accounts under 13.
At any time, a parent or guardian can:
Naven checks that a request comes from the parent — through the parent controls, which need the parent’s emailed link and PIN, or by replying from the address that gave consent.
Naven keeps a child’s information only as long as it is needed for the purpose it was collected for, then deletes it:
| What | Kept for |
|---|---|
| Anything collected before consent | Deleted after 14 days if consent is not verified |
| Messages and uploads | Until deleted by the child or parent, or the account is deleted; uploads expire after two years |
| The signed consent form and the record of consent | While the account exists — it is the proof consent was given — and deleted with it |
| Device and country records | 180 days after last use |
| Days Naven was opened | 60 days |
| Everything else | Until the account is deleted |
Naven keeps a written information security program for children’s information, as the COPPA Rule requires: access is limited to the developer, credentials are kept in a secret store, traffic is encrypted in transit, and service providers are chosen for the protections they offer. It is reviewed at least once a year.
That is a description, not a promise. Naven makes no promise that information is or will stay secure — see section 2 of the Terms. Naven is not end-to-end encrypted: its software reads messages in order to screen them.
If Naven changes what it collects from children, how it uses it, or who it shares it with, it asks the parent for new consent before doing so. The date at the top of this page is always the current version.