No ads, ever.
The game shows no ads and runs no ad tracking. Nothing a student touches carries a marketing pixel, and there is no targeted advertising anywhere.
Security at Infinilearn
Infinilearn is played by thousands of kids, so the bar is simple: guard every player like they were ours. Here is how we do it, in plain English.
No ads. No selling data. No open chat. No student emails.
The short version · The rest of this page is the proofThe oath
The game shows no ads and runs no ad tracking. Nothing a student touches carries a marketing pixel, and there is no targeted advertising anywhere.
Not to brokers, not to partners, not anonymized, not ever. Our revenue is memberships, so families are the customer, never the product.
Kids sign in with a username and a six-digit PIN. Even our Google sign-in option only proves identity; the email behind it is never stored.
Players talk through preset phrases and emotes only. Parents and teachers can switch multiplayer off entirely, and it applies within a minute.
Defense in depth
For school IT teams
The NIST Cybersecurity Framework is what we name on district data sharing agreements. Here is what each function looks like in practice, and we are happy to walk your team through the full mapping.
Security has one accountable owner, written policies, and a signed data sharing agreement with every school that asks for one.
We keep a full inventory of what student data exists, where it lives, and who can reach it. Our DSA data schedules are filled out from that inventory, not from memory.
Encryption everywhere, deny-by-default access rules, least privilege, and server-only writes for anything sensitive.
Production errors and anomalies are exported and reviewed every day, not once a quarter.
Reported issues get triaged, fixed, and written up with a root cause. Every security finding ever reported to us has been resolved.
Continuous backups, point-in-time restore, and Git-driven deploys that can roll back in minutes.
Proof, not promises
Independent security researchers have tested Infinilearn from the outside, and we run recurring audits of our own code from the inside. Every real finding, from either direction, has been fixed. Not filed in a backlog. Fixed.
Our access rules ship with automated test suites that run against a real database emulator: over a hundred cases proving that the right people get in and, just as deliberately, that everyone else stays out.
Classrooms are why we exist, so the legal side is built in, not bolted on. Students can play without ever providing contact information, which is how we approach COPPA. When schools use Infinilearn, they own their students' records and we act as a school official under FERPA, bound by the data sharing agreements we sign. When a school or parent asks us to delete data, we delete it and confirm in writing.
Found a vulnerability? Email adrian@infinilearn.com. Reports go straight to the person who can fix them, usually the same day.
Questions about security?