← WonderED

Privacy Policy

WonderED is a child-development platform, which means privacy is not a compliance annex — it is the product's spine. This policy explains, in plain language, exactly what we collect, why, and what control you have. It is written to satisfy and exceed COPPA (US), GDPR/GDPR-K (EU), and the UK Age-Appropriate Design Code, applied to all users regardless of location.

1. Who is responsible

WonderED (development-phase operator; interim contact [email protected]) is the data controller for the Service.

2. Our privacy commitments, up front

3. What we collect

About you (the Guardian): email address, display name, password (stored only as an argon2 hash), parent-zone PIN (hashed), locale/region, consent records, subscription status, and an audit trail of account-level actions.

About each child profile: nickname, birth year-month, avatar choice, optional interests, accessibility preferences, and the derived age band.

From play: which activities were attempted and at what difficulty; play events (correct/incorrect responses, hints, retries, saved reflections, completion times); the skill-level estimates derived from them; and the observations you record.

Technical: transient server logs (including IP addresses) for security and abuse prevention, and first-party usage events stored in our own database.

What we deliberately do not collect: children's real names, precise birthdates, photos or camera access, contact lists, location, voice recordings (on-device only), or data from third-party brokers.

4. Why we process it

We do not use children's data for marketing, profiling beyond the app's educational personalization, or automated decisions with legal effect.

5. Parental consent, verifiably

Creating a child profile requires ticking an explicit consent statement tied to a policy version; the consent event is stored with your account and shown in your consent history. You can withdraw consent per child at any time; withdrawal stops collection for that profile and unlocks export and deletion.

6. Where data lives and who processes it

All application data is stored on our own server infrastructure (a European data-center server we operate), in our own PostgreSQL database. Infrastructure processors:

No processor receives child play data. If we ever add one that would, we will update this policy and re-request consent first.

7. Retention and deletion

8. Your rights (and where the buttons are)

Requests received by email are verified against the account email and answered within 30 days.

9. Security

Passwords and PINs are hashed with argon2; sessions use short-lived tokens with rotating refresh tokens and theft detection; every child-scoped request is checked against guardian ownership on the server; consent changes and data-rights actions are audit-logged; the database is not exposed to the internet; transport is HTTPS everywhere. If a breach affects your data, we will notify you and the relevant authority without undue delay and within legal deadlines.

10. Age-appropriate design

The child surface contains no ads, no external links, no chat with strangers, no public profiles, no dark patterns, no infinite feeds, and no purchase surfaces; purchases and settings live behind the parent PIN. Session-length guidance is built in with gentle wind-downs. Reward design is mastery-oriented, not engagement-maximizing.

11. Development preview note

While the Service is in its development phase: sign-in codes may be shown in-app instead of emailed (until the email provider is enabled), and premium purchases may be simulated with no payment collected. These conveniences never weaken the child-data protections above and will be removed at commercial launch.

12. Changes to this policy

Material changes are announced in-app at least 14 days in advance with a new version number. Changes that expand processing of child data require fresh parental consent before they apply to any child profile.

13. Contact

Privacy questions and rights requests: [email protected] (interim development-phase contact).