v1.1.0 · updated 2026-08-15
⚠️ Working template pending attorney review. Do not treat as final legal text. See LAUNCH_CHECKLIST for owner actions.
Privacy Policy — With My Little EYE
Version 1.1.0 · Last updated 2026-08-15
⚠️ TEMPLATE PENDING LEGAL REVIEW. This document is a working template
tailored to how the app currently collects and uses data. It has NOT been
reviewed by an attorney. Do NOT rely on it for production compliance until
a qualified privacy lawyer has signed off. See LAUNCH_CHECKLIST.md.
In plain words
We built With My Little EYE to help kids learn to spell and grow their
vocabulary through a hidden-object game. Parents purchase a one-time family
unlock before their child can play, and we collect the minimum information
we need to run the account, save progress, and keep the experience safe.
We do not collect photos, real names, birthdates, location, microphone,
camera, or contacts from children. We do not show ads. We do not sell data.
1. Who we are
With My Little EYE ("we", "us", "the App") is operated by the owner named on
the LAUNCH_CHECKLIST. For privacy questions email
privacy@wmleye.example.com (replace before launch) or submit a request
via the in-app Help form.
2. Information we collect from parents
- Account credentials — email, password (stored only as a bcrypt hash),
parent PIN (stored only as a bcrypt hash).
- Preferences — preferred language, analytics-opt-in status.
- Subscription record — a flag that says whether the family unlock has
been purchased (sandbox at launch; real Stripe once enabled), plus a
reference to the Stripe customer id when payment is live.
- Timestamps — account created, last login, deletion request (if any).
3. Information we collect for each child profile
Each child profile is created and controlled by a parent. We collect:
- Optional nickname (parent-chosen, no legal name required).
- Avatar (one of six cartoon animals).
- Age band (2-4, 4-6, or 6-8 — a range, never a precise birthdate).
- Difficulty and narration speed preferences.
- Accessibility settings (reduced motion, high contrast, streak counter
visibility).
- Progress — token balance, total stars, current world/level.
4. Gameplay analytics per child profile
Tied to the pseudonymous child-profile ID only — never to a real name:
- Levels attempted and completed
- Objects found, incorrect taps, hint usage
- Time to find each object, replay-pronunciation counts
- Word Book vocabulary tracking (words encountered vs. mastered)
- Session length and count
This lets us tune difficulty, surface adaptive support, and generate the
parent dashboard summary. It is not used for advertising.
5. What we DO NOT collect
- No photos or images of children.
- No microphone or camera access.
- No precise location (no GPS, no IP-based geolocation for children).
- No real names or birthdates (age band only).
- No contact lists.
- No behavioural advertising or ad-network SDKs.
- No cross-site or cross-service tracking.
- No social-media sharing from child mode.
6. How we use the information
- Deliver and secure the account (authenticate parents, save child progress).
- Improve the learning experience (adjust difficulty, present the right
vocabulary for the child's age band and current world).
- Provide the parent dashboard (weekly activity, mastered words, session
length).
- Respond to support requests.
- Detect and prevent abuse (rate limiting, brute-force protection).
- Process the one-time family unlock payment via Stripe (parents only —
we never expose payment surfaces to children).
7. Legal bases (GDPR)
- Contract — to deliver the service the parent signed up for and paid for.
- Legitimate interest — to secure the account, prevent abuse, run
aggregated analytics that are strictly non-advertising.
- Consent (for children) — the parent gives verifiable consent when
creating each child profile.
8. Sharing with third parties
We share the minimum data needed with the following processors:
| Processor | Purpose | Data shared |
|---|---|---|
| OpenAI (via Emergent LLM Key) | Text-to-speech audio generation | Small text snippets (word/spelling/mission phrases). No child identifiers. |
| Google Gemini (Nano Banana, 2.5 Pro Vision) | Cartoon thumbnail generation & content-authoring vision audits | Text prompts + scene images we author. No child data. |
| Stripe | Family unlock payments (currently sandbox — will flip to live after review) | Parent email + billing details entered on Stripe's own form. We never see the card number. |
| SendGrid | Transactional email (currently dev-log mode) | Parent email + template variables (name, reset link). |
We do not share data with advertising networks, brokers, or analytics
providers beyond first-party in-app analytics.
9. Children's Privacy (COPPA / GDPR-K style)
- The App is designed for children as young as age 2, always with
parent oversight.
- Only a parent can create an account and purchase the unlock.
Children cannot register, purchase, or view billing surfaces.
- We collect no direct identifiers from children: no photos, no location,
no contact info, no birthdate.
- Parents can at any time: review their child's data via the parent
dashboard, correct the nickname/avatar/settings, delete the child profile
entirely (Settings → Delete profile), or request full account deletion.
- We do not knowingly collect information from a child without a parent
account.
10. Data retention
Proposal — attorney to confirm: We keep parent-account and child-profile
data for 24 months after the last recorded child activity. After that we
either anonymise (strip email + nickname, keep aggregate learning stats
for research) or delete on request. Audit logs of admin content edits are
kept for 24 months and then rotated out.
11. Security measures
- Passwords and PINs stored only as bcrypt hashes.
- Session cookies are HttpOnly, SameSite=None, Secure.
- All admin actions are recorded in an audit log.
- Rate limiting on login and PIN endpoints protects against brute force.
- Access to production data is limited to the minimum-necessary staff.
12. Your rights
Parents may:
- Access any data we hold about their account or child profiles.
- Correct account details, child nicknames, avatars, and settings.
- Delete individual child profiles or the entire account.
- Export account and child-profile data as JSON (Privacy → Export).
- Opt out of optional analytics tracking (Settings → Analytics consent).
To exercise any right email the address in section 1 or use the in-app
Help form. We aim to respond within 30 days.
13. Data location
Proposal — operator to confirm before launch. Data is stored on
Emergent-managed MongoDB infrastructure. Region (EU or US) is set by the
operator; the choice is disclosed here once finalised.
14. Changes to this Policy
We may update this Policy from time to time. When we do we bump the version
number at the top of this page and require every existing parent to
re-consent on next login. Historic versions are available on request.
15. Contact
- Privacy: privacy@wmleye.example.com (placeholder — set before launch)
- In-app: Settings → Help → Submit a request
End of Privacy Policy · Version 1.1.0.
← Back to home