Version 2.3 · Effective 14 August 2026
Privacy Policy
Wundaloom is a curated children's reading app. Because it's made for children, we collect as little as we can, we tell you exactly where it goes, and we never sell it or use it for advertising.
If you'd rather read the short child-focused version, see our Children's Privacy Notice.
1. Who we are
The data controller is Wundaloom Ltd, a company registered in England and Wales.
- Company No. [pending Companies House confirmation]
- Registered office: [pending — registered office address on the Companies House register at submission]
- Email: support@wundaloom.com
- Telephone: [pending business number]
This policy is written in the UK context; if you are outside the UK your local law may add rights on top — nothing here removes them.
2. What we collect from parents
- Email address (for sign-in, account recovery, and transactional messages)
- Password (stored as a one-way hash; we cannot read it)
- Session tokens (so you stay signed in)
- Parent PIN (a 4-digit code, stored hashed, used to gate adult actions like subscribing or removing a child)
- Language and reading-preference settings
- Subscription status, purchase history, and Dream Key balance
3. What we collect for each child
You create a child profile; the child does not have their own account. For each profile we store:
- The display name you chose (a first name or nickname — no full legal name required)
- Optional birth month + year (used only to pitch stories at the right reading level; we never store a full date of birth)
- Which stories they opened, completed, abandoned, or replayed, with timestamps
- Quiz answers and star grades
- Vocabulary words met while reading
- Favourites, custom shelves, and thumbs-up/thumbs-down reviews
- Reading streak days and earned badges
- Any personalised story or narration you choose to create (see §5)
We do not collect emails, phone numbers, contacts, photos, location, biometrics, microphone or camera data, free-text messages, or advertising identifiers from your child.
4. Technical information
- Your device IP address (seen by our servers on every request)
- Device model, operating system version, app version, locale (sent by the RevenueCat billing SDK when a subscription action is happening)
- Install identifier and app runtime version (used to deliver over-the-air JavaScript updates via Expo Updates)
We do not use analytics SDKs, crash reporters, marketing pixels, tracking pixels, the Android advertising ID, the iOS IDFA (we do not trigger App Tracking Transparency), or any social-media tag.
5. Personalised stories and narration
When you choose to create a personalised edition of a story (with your child as the hero), our server contacts OpenAI, L.L.C. to rewrite the text and, optionally, to narrate it aloud.
For the personalised text, we do NOT send your child's real name to OpenAI. Instead we send an anonymous placeholder token (for example, {{CHILD_NAME}}), the pronoun family you selected (he/him, she/her, they/them), and the source story text (published by us). Our server substitutes the real name into the personalised text after OpenAI returns it.
Personalised narration audiorequires the narrator to pronounce the story name you have chosen. To produce it, our server sends OpenAI's text-to-speech service the story text (which contains the story name), the narration instructions for the chosen age band, and the voice selection. Our server does not send OpenAI your account identifier, your child's profile identifier, your email address, device identifiers, location, or any other account metadata. OpenAI receives the story name and story text; it does not receive information capable of telling it which child or which household "Alex" belongs to.
Before this feature runs, the parent account holder must explicitly review and accept a short in-app disclosure that names OpenAI as the provider and lists exactly what is transmitted. That consent is versioned and revocable: if we update the disclosure text, the previous acceptance stops applying and we ask again. Consent is stored per parent account, is required before any story name reaches OpenAI (enforced at the database layer regardless of how the Dream Keys used were obtained), and can be withdrawn.
OpenAI's current default retention arrangement for API calls involves temporary abuse-monitoring log retention. Zero Data Retention is an enhanced arrangement Wundaloom is separately pursuing with OpenAI; this policy will be updated if and when that arrangement is contractually in force. Until then, we describe the current position accurately: OpenAI is a processor operating under its published API terms and its data-processing addendum, and personalised narration only runs where you have granted the explicit consent above.
The finished personalised edition (text) is stored in our database and the audio file in Cloudflare R2 storage; both are deleted when you delete your account or the associated child profile.
You control this feature entirely — no personalisation happens without you explicitly choosing to create an edition. Curated stories (which every child reads unless they choose otherwise) never send anything about your child to any AI provider.
6. Who we share with
We use service providers to perform specified services for us, each subject to their applicable contracts, data-processing terms and privacy obligations.
- Supabase Inc. — hosts our database, authentication, and storage. UK/EU region.
- Vercel Inc. — hosts our website and serverless functions. UK/EU deployment.
- RevenueCat Inc. (United States) — validates subscriptions and Dream Key purchases. Receives your Wundaloom user identifier and the device information the SDK sends automatically (model, OS, app version, IP address, installation identifiers) during purchase actions. We do not send your child's name, age, or reading activity.
- Apple Inc. and Google LLC — process in-app purchases through their respective stores. Their own privacy terms apply.
- OpenAI, L.L.C. (United States) — text personalisation and text-to-speech narration when narration is available. See §5 for what is actually transmitted.
- Cloudflare Inc. (global infrastructure) — stores story images and narration audio. Storage-only; no analysis of content.
- Expo Inc. — delivers app updates and receives technical update information such as installation identifiers, runtime version and update channel.
We do not sell personal data and we do not share for advertising.
7. Lawful bases (UK GDPR)
We rely on:
- Contract — to provide the account, sign-in, subscriptions, and purchase history.
- Legitimate interest — for security logs, product improvement based on aggregated reading signals, and delivering the child their own reading experience under the parent-managed profile.
- Consent — for personalised editions and narration (§5), collected explicitly from the parent at the moment of purchase.
8. How long we keep your data
While your account is active, we keep the data described above. When you delete your account (Parent Zone → Delete account, or by emailing us), we permanently remove the account, all child profiles, all reading and quiz data, favourites, personalised editions, and narration audio within 30 days.
We retain the following residue for legal, accounting, and fraud-prevention reasons:
- A salted one-way hash of your email address (we cannot recover the address from it), so we can honour deletion and reconcile any late-arriving refunds
- Pseudonymous subscription reconciliation records (product identifier, dates, no personal details)
- The minimum accounting records required by UK tax and audit rules, per the retention schedule we maintain internally
Your RevenueCat billing customer record is also deleted when your Wundaloom account is deleted. Purchase receipts held by Apple or Google are retained under their own policies.
The full retention schedule — category by category, with purpose + business need + deletion timeframe — is set out in our published Child Data Retention & Deletion Schedule.
9. Your rights
Under UK GDPR you have the right to access, correct, delete, and export your personal data, to object to processing, and to withdraw any consent you gave. To exercise any of these, email support@wundaloom.com. We aim to respond within one calendar month.
You can also lodge a complaint with the UK Information Commissioner's Office at ico.org.uk.
10. Children's rights, and your rights as their parent
Wundaloom is a child-directed service. You, the parent or guardian with an account, act on your child's behalf. You can, at any time:
- See what we hold about your child (email us or view directly in the app)
- Correct or delete anything
- Delete a child profile and everything under it (Parent Zone → tap the trash icon on the profile)
- Delete the whole account (see §11 and the deletion page)
- Withdraw consent for personalisation (stop purchasing personalised editions; existing editions remain until you delete them or your account)
Wundaloom is designed with children's privacy and high-privacy defaults at its core. We have built our approach with the UK Age-Appropriate Design Code (Children's Code) and US COPPA requirements in mind, and we review it as the service and applicable requirements evolve.
11. Deleting your account
From the app: Parent Zone → Account → Delete account. You will re-enter your password and type the word DELETE to confirm.
From the web: visit wundaloom.com/delete-account. Or email us at support@wundaloom.com from the address on your account.
Deleting the Wundaloom account does not cancel your App Store or Google Play subscription automatically — you also need to manage that in your device's subscription settings.
12. Cookies
The wundaloom.com website sets only strictly-necessary cookies for authentication (Supabase session). It does not set any analytics or advertising cookies. The Wundaloom mobile app does not use cookies.
13. International transfers
Some of our service providers are outside the UK. Where personal data is transferred internationally we rely on the relevant UK GDPR safeguards — for example, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — as set out in the provider's data- processing terms and any supplementary safeguards.
14. Security
All traffic between the app and our servers uses TLS. Passwords and PINs are stored as one-way hashes. Database access is scoped per user via row-level security. Narration audio is stored in a private object bucket accessed only via short-lived signed URLs.
15. Changes to this policy
If we make a material change we'll increment the version number above and, for logged-in users, tell you in-app before the change takes effect. The previous version remains available on request.
16. Contact
Questions or requests: support@wundaloom.com.