Akidy

Estes documentos legais são atualmente mantidos em inglês e turco. Para este idioma, faz fé a versão inglesa apresentada abaixo.

Akidy Privacy Policy

Version 2026-07-04.1 — Effective 4 July 2026

Akidy ("we", "us") is a learning application for children aged 2–6, operated for their parents and guardians. Protecting children is the reason this product exists, and it is the first rule of how we handle data. This policy explains what we collect, why, and the rights you have. It is written for the adult who manages the account.

1. Who the account belongs to

Only an adult parent or legal guardian may create an Akidy account. During registration you confirm that you are the child's parent or guardian and you verify your email address with a one-time code. This email verification is how we obtain verifiable parental consent before any child profile can be created (COPPA "email plus" method; GDPR-K Art. 8 consent by the holder of parental responsibility).

2. What we collect

About you (the parent):

  • Email address, full name, chosen password (stored only as a salted bcrypt hash)
  • App language, country (optional), timezone (optional)
  • Consent records: which policy version you accepted, when, and from which IP address

About your child — only what learning requires, nothing more:

  • A display name or nickname you choose (it does not need to be a real name)
  • Birth date (used only to select age-appropriate content)
  • Optional gender selection, avatar choice, preferred language
  • Learning activity: which activities were completed, stars, streaks, minutes spent, answers to learning questions, favorites and earned badges

We never collect from children: no photos, no audio or video recordings, no free-text input, no location, no contacts, no advertising identifiers.

Technical data: request logs with pseudonymous request IDs for security and debugging; crash reports (only if crash reporting is enabled for the build, containing device model and stack trace, never child data).

3. What we do NOT do

  • No advertising, and no advertising SDKs — the app contains no third-party ad tracking of any kind.
  • No sale or rental of personal data, ever.
  • No behavioural profiling beyond the learning recommendations visible in the app.
  • No public sharing of child data. Child profiles are visible only inside your family account.
  • No push messages to children — notifications go to the parent's device and can be disabled in system settings.

4. Why we process data (legal bases)

PurposeLegal basis (GDPR)
Providing the learning service, progress, streaks and badgesContract (Art. 6(1)(b))
Child profile dataParental consent (Art. 6(1)(a), Art. 8)
Security, abuse prevention, rate limitingLegitimate interest (Art. 6(1)(f))
Payment/subscription stateContract (Art. 6(1)(b))
Legal obligations (accounting, requests by authorities)Legal obligation (Art. 6(1)(c))

5. Where your data lives and who processes it

Data is stored in a PostgreSQL database operated by our hosting provider inside the EU/EEA where technically feasible. Depending on the features enabled for your build, the following categories of processors may be used, each bound by data-processing agreements: cloud hosting, email delivery (verification and password-reset codes), push notification delivery (Google Firebase Cloud Messaging, receiving only an anonymous device token), subscription management (app-store billing and RevenueCat, receiving only your account identifier — never child data), and crash reporting. We do not transfer child learning data to any processor that does not need it for the service.

6. Payments

Subscriptions are purchased exclusively through Apple App Store or Google Play. We never see your card details. We store only your plan, its validity period and the store transaction identifiers required to grant access.

7. Retention

  • Account and family data: kept while the account exists.
  • Verification and reset codes: expire after 15 minutes, purged on use.
  • Sign-in refresh tokens: expire after 30 days or on sign-out.
  • If you delete your account, everything in section 8 is removed immediately and irreversibly.

8. Your rights (and how to use them in the app)

  • Access / portability: Settings → Privacy & Data → *Export my data* returns a complete machine-readable copy (account, family, children, learning history, consents).
  • Erasure: Settings → Privacy & Data → *Delete account* permanently deletes your account, your family, every child profile and all their learning history, device tokens, consents and subscription records. This action is password-confirmed and cannot be undone.
  • Rectification: names, languages and child details are editable in the app.
  • Withdrawal of consent: deleting the account withdraws consent entirely; you may also delete an individual child profile at any time.
  • Complaint: you may lodge a complaint with your local data-protection authority.

We answer privacy requests at privacy@akidy.com within 30 days.

9. Security

Passwords are hashed with bcrypt. Sessions use short-lived signed tokens plus rotating refresh tokens that are revocable and stored only as SHA-256 hashes. Verification codes are hashed, single-use, attempt-limited and short-lived. Anonymous endpoints are rate limited. Production systems boot only with real secrets, all traffic is TLS, and backups are encrypted at rest by the storage provider.

10. Changes

If this policy changes in a way that affects children's data, we will require renewed parental consent (the policy version you accepted is stored with your account). The current version is always available in the app under Settings → Privacy & Data.

11. Contact

Akidy — privacy@akidy.com

Voltar à página inicial