For parents
Direct Notice to Parents
Last updated: September 13, 2026
This is the direct notice Rusty gives you, in plain language, before child information is uploaded to Rusty’s cloud service or live child voice is processed. You will also see the same information inside the app before the authorization and consent steps.
Who Is Asking
FOUR STAR GROUP INC, which operates Rusty — a voice-based learning app for children ages 4–12.
Tracking Choice and Install Attribution
On the first active screen, before Meta initializes or transmits, iOS asks whether you allow Rusty to track activity across other companies’ apps and websites. After that choice, Meta App Events sends a one-time App Install event and a minimal app-activation/session attribution signal. Later cold launches may send another minimal activation/session signal, but do not resend the App Install event. This tracking choice is separate from the child-data authorization and consent choices below.
- What Meta may receive. The Meta app identifier, Rusty’s bundle and version information, an anonymous app-install identifier, device and operating-system details, network information such as IP address, event time, and the device’s limited-ad-tracking status.
- How your choice is enforced. Advertiser tracking and IDFA collection are enabled only after Allow and remain disabled after Ask App Not to Track. Automatic event and purchase logging remain disabled for everyone.
- What Rusty does not intentionally send. A Meta user ID, custom events, account details, names, ages, interests, child or family profile identifiers, lesson activity, answers, voice or transcripts, safety records, purchase details, receipts, or subscription information.
The Meta SDK’s install and activation behavior is treated as tracking, so Rusty uses Apple’s App Tracking Transparency framework. For people who decline, Meta’s configured SKAdNetwork and Aggregated Event Measurement paths provide delayed, aggregated campaign measurement without enabling advertiser tracking or IDFA collection. Rusty does not keep a separate copy of the events. Meta controls its retention and deletion practices.
What We Want to Collect From Your Child
- Their first name or a nickname, so Rusty can talk to them naturally.
- Their age and optional grade, so activities can start at an appropriate level.
- Their voice, while a session is running, so Rusty can hear their answers and reply out loud.
- What they practice — which activities they did and how they answered structured questions.
- Optional interests and learning preferences, only if you turn personalization on.
A child’s voice is personal information under COPPA, which is why we ask about it explicitly rather than burying it.
How We Will Use It
- To run the tutoring conversation and the activities inside it.
- To decide what to teach next, based on what your child actually demonstrated.
- To give you plain-language summaries of each session.
- To show a parent handoff and keep a short non-verbatim safety record if a narrow safety rule fires. Optional safety email is used only when enabled and is not emergency monitoring.
- To keep the service secure and working.
We do not use your child’s information for advertising of any kind, and we do not sell it.
Who Else Receives It, and Why
We use service providers to run Rusty. They may use this information only to provide services to us, under contracts that require them to protect it.
Google (Gemini on Google Cloud) — the AI tutor
Your child’s live speech, their name/age/grade, and (if enabled) their interests are sent to Google so the AI can understand them, speak back, and notice safety concerns. Google states it does not use this content to train its AI models.
Apple and RevenueCat — adult purchase and entitlement
The default route uses an Apple App Store purchase selected by the adult. Apple processes payment and RevenueCat reports purchase or subscription entitlement information to Rusty. They do not receive the child’s profile or learning record from Rusty. Rusty does not receive a full payment-card number.
Kids Web Services (Epic Games) — alternate route only
If the app specifically shows the alternate KWS route, KWS receives the adult’s email and related verification metadata to run the check. It receives no child profile or learning information. Rusty receives the result, not the private identity details used on KWS’s pages.
Supabase — secure hosting and storage
Stores the family account, child profiles, and learning records in the United States.
The complete list is on our Service Providers page.
What We Will Not Collect
- No saved recordings of your child’s voice.
- No saved transcripts of what your child said.
- No free-text writing typed by a child.
- No photos, homework images, or camera access.
- No home address, phone number, school name, or precise location.
- No IDFA collection unless the device user first chooses Allow in Apple’s tracking prompt, and no child-profile, learning, voice, or safety information intentionally sent to Meta. The separate install and cold-launch activation signals are described in Section 2.
How to Give Your Consent
- 1. Read this notice. The app requires the full direct notice to be opened before the adult can continue to a purchase.
- 2. Complete the adult account setup. The adult signs in, sets a parent PIN, reviews the required notices, and completes the authorization step shown in the app. Free includes one cloud learner and 10 shared voice minutes per local week. Premium and Family are optional monthly subscriptions processed by Apple; Family supports up to four learner profiles. If the app instead displays the alternate KWS route, follow the independent link it sends.
- 3. Make the child-data choices. The app shows the required uses plainly before a cloud profile is created and before voice can start.
Optional personalization is a separate choice. If you do not authorize and consent to voice, live spoken tutoring will not run; activity-only practice can still be used.
If You Do Not Consent
Rusty does not create the learner profile or start live child voice until the required adult setup and consent choices are complete. If voice consent is declined, the parent-managed learner can still use activity-only practice. Pending, failed, or expired authorization metadata is deleted from Rusty’s server within 30 days.
Changing Your Mind
You can review, correct, export, or delete your child’s information, and withdraw any consent, at any time in Parent Settings → Account and the selected child’s privacy controls, or by emailing privacy@userusty.com. Withdrawing consent stops the affected processing going forward. See our Contact & Privacy Rights page.
If we make a material change to what we collect or how we use it, we will send you a new direct notice and ask for your consent again.
Full Details
The complete description of our practices is in our Privacy Policy, and the deletion timetable is on our Child Data Retention page.
