← Back to Derive

Children and Students

In force from 7 September 2026

For parents, guardians, teachers and schools. The minimum age for a Derive account, what happens to a student’s work, what we do not yet do, and what a parent can ask us for.

This notice is published by Derive Notes Pty Ltd (ACN 696 859 597), 2/290 Boundary Street, Spring Hill QLD 4000, Australia. It sits under the Privacy Policy and the Terms of Service. Questions and requests go to matt@derivenotes.com.

Who this is for

This notice is for parents, guardians, teachers and schools. It explains the minimum age for a Derive account, what happens to a student's work, and what a parent can ask us to do. It also says plainly where our controls are still manual, because a notice for parents that hides that is worth nothing.

Who may hold an account

These are eligibility requirements. They are conditions of the Terms of Service, and you are responsible for meeting them. Derive does not verify them.

  • You must be at least 13 everywhere.
  • Where the law of your country sets a higher age for using an online service without a parent's consent, you must be at least that age. In the European Economic Area and the United Kingdom we apply 16.
  • You must be 18 or over to use Derive from India, South Africa, Japan or the Republic of Korea.
  • Derive may not be used from mainland China.

There is no version of Derive for children under 13, and there is no way for a parent to consent on a child's behalf.

How we ask about age, and where we do not

When the setup flow asks, it asks for a date of birth on a neutral screen. We do not ask "are you over 13", because that teaches the answer. We store only the band your answer falls into, one of under 13, 13 to 15, 16 to 17, or 18 and over, together with how we worked it out and when. We do not store the date itself.

The age question is not currently asked of every account. Some setup variants do not include a date of birth step, and choosing "University" or "Teacher" during setup records the account as 18 or over without asking for a date. So there are accounts whose age band we do not know. We treat an unknown band as too young for anything where age matters, such as marketing email, but not for use of the product itself.

If an account answers under 13, we lock it and sign the person out. We do not currently delete it automatically. The lock is applied on the device and in the account's settings record. It is not yet enforced by our servers. If you are a parent and want the account removed, email us and we will delete it by hand.

What a student's work is used for

A page of maths in Derive is used for four things.

  1. To give you the product. We store your pages so they sync across your devices and so you can search them.
  2. To read your handwriting. An image of the part of the page you wrote on, plus the recognised text around it, is sent to the AI providers listed on the Subprocessors page so they can turn it into text and check the working. This is how Derive works. It cannot be turned off, because there is no version of Derive that keeps your writing on the device.
  3. To improve our own handwriting recognition. We keep some of the recognised text and stroke geometry and use it to train and evaluate our own recognition models. See "Model training, and how to object" below.
  4. To keep the service running and safe. Diagnostics, error reports and usage counts.

We do not sell student data. We do not show advertising in Derive, and we do not build an advertising profile of anyone. Nothing a student writes is ever used for advertising.

There is one thing we do share with an advertising company, and it can never be about a child. On the Derive web app, for accounts created since section 13.6 of the Privacy Policy came into force, held by someone 18 or over who has accepted analytics, we tell Meta that a sign up, a trial or a payment happened, so that we can measure whether our own adverts work. Nothing at all is sent about a user under 18 or of unknown age. Nothing at all is sent about an account that existed before that section came into force. No page, no handwriting and no recognised text is ever involved.

AI providers do receive a student's handwriting

Yes. An image of the region of the page and the surrounding recognised text go to OpenRouter (and from there to Relace, Modal or DeepInfra), to Google and to OpenAI. Code a student writes and runs goes to Judge0. All of those are in the United States, or, in Google's case, at a global endpoint that is not pinned to a country. The full list, with each provider's own privacy terms, is on the Subprocessors page and the AI disclosure explains which feature sends what.

No account name, email address or Derive account id is sent to any AI provider.

There is currently no age condition on this. A 13 year old's page goes to the same providers as an adult's, in the same way.

Model training, and how to object

We use content students create to train and evaluate our own handwriting and mathematics recognition models. This is a first party activity. We do not send anyone's work to another company for that company to train on.

Four things are collected for this purpose: a frozen copy of the page's stroke geometry when a student uses the lasso and taps Recognise, the recognised text of nearby lines on the page, the recognised text of each attempt at a step, and the record of a student telling the tutor it got a verdict wrong.

This is opt out. It is on by default for every account. You can object at any time by emailing matt@derivenotes.com and we will stop using that account's work for training. This is a manual process on our side: there is no switch in the product to do it yourself, and objecting does not require us to retrain or discard a model or dataset we have already produced.

Deleting a page does not currently remove everything derived from it. If a student deletes a page, the page and its recognised text are removed on the next scheduled purge. Some training records keyed to the student's account, rather than to the page, are kept until the account itself is deleted.

Human review

A person on our team looks at real pages of handwriting in order to label them correctly for training. This is done on a workstation, by the founder, on pages sampled across accounts. It is how a recognition model gets accurate. Labelled records committed to our code contain only stroke identifiers and the grouping, not the handwriting itself or any text.

Analytics and screen recording for younger users

  • Usage analytics are always off for an account that has told us it is under 13.
  • In the European Economic Area and the United Kingdom, analytics are off for anyone under 16 and we do not offer the choice.
  • Outside those places, analytics are on by default, including for an account whose age we do not know. They can be turned off at any time in Settings, Account.
  • Screen recording, which would capture the canvas and therefore handwriting, is off for everyone, with no way to turn it on today. It is separate from usage analytics, so turning analytics on does not start it. If we ever turn it on it will be opt in, and we will update these documents first.

Details are in the Cookies notice.

Marketing email to young people

Marketing email is age gated per country. We hold a minimum age for each of 245 territories, from 13 to 20, and we apply the one that matches the account's country. If we do not know an account's age band, we treat it as too young and send nothing. In India we send no marketing to anyone under 18 at all, and no permission from a parent changes that.

Click tracking in email is applied only to accounts recorded as 18 or over, worldwide.

Push notifications: the iPhone and iPad app asks for notification permission, but no device token is stored and there is no way for us to send a push message to anyone today.

What we collect about school and university

  • If you tell us you are at high school and you are 16 or over, we ask which school. In Australia we offer a list; elsewhere the box accepts free text.
  • If you tell us you are at university, we ask which institution and which degree.
  • If your age band is under 16, we do not show either question, and we clear any answer you had already given.

Parents and guardians

If you are a parent or guardian and you believe your child has an account, email matt@derivenotes.com. We will:

  • tell you what we hold about the account,
  • correct it if it is wrong,
  • delete the account and its notebooks, and
  • stop using its content for model training.

We answer within the time the law where you live allows, and never more than 30 days.

We do not currently have a way to verify a parent's identity or relationship, and there is no mechanism in the product to obtain a parent's permission for a child to use Derive. We handle every request by hand, by email, and we may ask you for enough information to be satisfied that you are who you say you are before we disclose anything about an account.

Schools, teachers and districts

Derive is licensed for individual personal study. It is not designed, sold or supported for use by a school, a district or a teacher directing a class.

  • There are no seats, no administrator role, no class or roster, and no way for a teacher or a school to see a student's work.
  • We are not a "school official" under the United States Family Educational Rights and Privacy Act, and we do not accept student records from an institution.
  • We do not offer a student data privacy agreement, and we have not signed one with anyone. The Data processing addendum is a draft for institutions to start from, not an executed agreement.

If a school wishes to adopt Derive, contact matt@derivenotes.com first. We will not knowingly accept an institutional deployment without a written agreement in place.

Sharing

There is no sharing, collaboration, class or teacher visibility feature in Derive today. Notebooks are private to the account. No student's work is disclosed to a teacher or a school by the product.

Privacy Policy, Terms of Service, Cookies, Subprocessors, AI disclosure, Data processing addendum.