Version 1.8 · Effective 26 September 2026

Children's Privacy

Wundaloom is designed for children aged 2–10. This is the short, plain-English guide for parents. The full Privacy Policy has the legal detail.

Your child never has their own account

You hold the account. Under it, you create a small profile for each child — a name (a nickname is fine), and optionally a year of birth so we can pitch stories at the right reading level. That's all your child needs. They never sign in, enter an email, or contract with anyone.

What Wundaloom knows about your child

  • The name you chose for them and, if you added it, their year of birth
  • Which stories they've opened, finished, or come back to
  • Quiz answers and stars earned
  • Words they've met that they might not have seen before
  • Books they've favourited, sorted, or given a thumbs-up / thumbs-down to
  • Reading streak days
  • Any personalised story or narration you choose to create for them

What Wundaloom does not know

  • Their email or phone (they don't have one in the app)
  • Where they are — we never ask for location and never use GPS. Like any website, our servers see the device's IP address on each request, which gives only a rough area, and we don't use it to work out where anyone is
  • What's in their photos, contacts, or files
  • Their voice or camera (we never ask for those permissions)
  • Any advertising identifier — we don't track for ads
  • Anything the child writes about themselves — there is nowhere to write a message, a profile or a comment. The one place text can be typed is the story name on the personalisation screen, which is a name for the story, and we ask you not to use a child's real name there

Who receives their information

The child data listed above is stored by Supabase(database, UK/EU region) and Cloudflare (audio storage on global R2 infrastructure), and processed by Vercel, which runs our servers. Expo delivers app updates. The full list, including RevenueCat for purchases, is in the Privacy Policy.

When youchoose to create a personalised story, the way your child's identity is used depends on what you order:

  • Personalised text — we send an anonymous placeholder to OpenAI (US) along with the pronoun you chose, and swap in the story name you chose on our own server. For that step OpenAI receives the placeholder, never the name.
  • Personalised narration audio — optional. The narrator has to say the story name out loud, so the story text containing that name is sent to OpenAI's voice service — only when you add narration, and only after you have accepted our in-app AI disclosure. We ask you not to use a child's real name or other identifying information. If you withdraw that consent, no new narration is made; narration already created stays in the edition until you delete it.

We don't send reading history, quiz results, or anything from the child's profile. The narration instructions do tell the narrator which age version of the story to read.

No behavioural advertising. No tracking pixels. No selling. Ever.

Personalisation is off by default

Personalised stories exist as an option — a story carrying a name you choose — but they only happen when you explicitly create one with Dream Keys (buying Dream Keys is behind the Parent PIN). Every curated story your child reads by default sends nothing about them to any AI.

How to change or delete a child's data

  • Change a child's name or birth details: Parent Zone → tap the profile.
  • Delete one child's data:Open the “Who's reading?” screen → tap the small trash icon on that child. You'll be asked for the Parent PIN. Their profile, reading history, quiz results, favourites, vocabulary, and any personalised stories or narration audio created for them are permanently deleted; the account and other children remain.
  • Delete the whole account and everything under it: Parent Zone → Account → Delete account. Or visit wundaloom.com/delete-account.
  • Ask for a copy: email support@wundaloom.com from the email on your account.

How long we keep it

While your account is active, we keep everything above. When you delete a child, we permanently delete that child's profile and all their reading data straight away; personalised audio files are removed from storage within 30 days. When you delete the whole account, we permanently erase your account, every child, every reading record, every personalised story and audio file within 30 days.

The full retention schedule — category by category, with purpose and deletion timeframe — is published at wundaloom.com/child-data-retention.

How parents authorise a child profile

Before a child profile is created, we explain how Wundaloom uses the child's information and ask the adult to confirm that they are the parent or authorised guardian. For our core reading features, our UK GDPR lawful basis is legitimate interests, as explained in our Privacy Policy. Optional personalised features have their own separate parent choice. For US families, our COPPA parental- verification process applies before covered child information is collected.

You can stop the processing at any time by deleting the child profile or the whole account (Parent Zone → Privacy choices), or by objecting under UK GDPR — email support@wundaloom.com from the account address.

A note you can read to your child

“Wundaloom is your reading room. It remembers which stories you've read and which ones you loved, so your reading room feels like yours. We don't use what you read for adverts, and we don't show it to other families. If you or your grown-up want Wundaloom to forget your reading history, your grown-up can ask us to delete it.”

Contact

support@wundaloom.com. You can also complain to the UK Information Commissioner's Office at ico.org.uk.