WimziPal Privacy Policy
WimziPal (“we”, “us”, “the app”) is an AI companion app designed for children aged 3–9, used only with parental supervision and consent. This policy explains what information we collect, how we use it, and the choices you have. Questions: privacy@wimzipal.com.
1. Who controls the data
The data controller is ROIDS Software, the maker of WimziPal. Contact us at privacy@wimzipal.com for any privacy-related question, request, or complaint, including a request for our postal address.
2. What we collect
From the parent (account holder)
- Email address: sign-in, account recovery, safety alerts, and support replies.
- Password: stored only as a one-way bcrypt hash; we can never read it. Not collected when you use Sign in with Apple or Google.
- Apple / Google sign-in identifier: when used, only the opaque user ID and the email returned by Apple or Google are stored.
- Subscription state: whether you have an active premium plan, fetched from RevenueCat. We do not store card or payment details.
About each child (entered by the parent)
- First name and date of birth: personalises replies and determines age-appropriate content.
- Interests, gender, notes: optional fields the parent enters to make replies more relevant.
- Selected avatar, character, and companion preferences: the parent picks from built-in options; no photo or image is uploaded or stored.
From each conversation
- Voice recordings: sent to the speech-to-text service for transcription and then discarded immediately. We do not store the audio.
- Text transcripts: the transcribed input and the AI's reply are stored for up to 90 days so the parent can review sessions. Older transcripts are deleted.
- Photos shared with the “Show your buddy” feature: sent to the vision service for description and then discarded immediately. We do not store photos.
- Moderation flags: when the safety layer flags content, the category is recorded with the turn so parents can be alerted and review what happened.
Device and technical data
- Device identifier: used to enforce usage limits, and to make the free trial one-per-device rather than one-per-install. On iOS this is a random value we generate and keep in the system keychain; on Android it is the operating system’s per-app device ID. Because it is meant to identify a device that has already had its free trial, it survives deleting and reinstalling the app. It is sent only to our own servers, which store a one-way cryptographic hash of it rather than the value itself, and it identifies a device, never a child. It is not an advertising identifier and is never shared with anyone.
- Crash logs: via Firebase Crashlytics, used solely to fix bugs. Collected only after the parent gives explicit consent during sign-up. Firebase Analytics has been removed from the app, and we do not collect app-usage analytics events.
- App version, OS version, locale, screen size, language: captured when you send a Contact-Us message so we can reproduce issues.
This website
The app and this website are separate, and we treat them differently on purpose. Your child uses the app; you use the website. So the app is the strict one.
- The app collects no usage analytics. Firebase Analytics was removed. Nothing counts what your child taps, how long they play, or which buddy they pick.
- This website counts visits, without cookies. We use Cloudflare’s privacy-first analytics to see roughly how many people arrive, which pages they read and which country they came from. It sets no cookies, it does not fingerprint your browser, and it cannot follow you to any other site. We deliberately do not use Google Analytics here.
- None of it touches your child or your account. Website analytics is anonymous traffic measurement. It is never joined to a WimziPal account, a child profile, or anything from inside the app, and no conversation ever leaves the app to reach it.
3. What we never collect
- Precise or coarse location
- Phone numbers or postal addresses
- Payment card numbers: handled entirely by Apple, Google, and RevenueCat
- Advertising identifiers (IDFA / GAID)
- Contacts, calendars, or photo library beyond the single photo the parent chooses to share
- Anything you do not provide voluntarily
4. How we use the data
- To run the app: sign in, render the right character, keep your child's session personal, and enforce parental controls.
- To keep your child safe: every AI reply passes through a moderation layer before being spoken; flagged content can trigger a parent alert.
- To improve reliability: anonymised crash data helps us find and fix bugs.
- To respond to support requests: only when you contact us.
We never sell personal information, share it for cross-context behavioural advertising, or train third-party AI models on your child's conversations. We do not show advertisements. We do not build commercial or advertising profiles of your child, and we do not track your child across other apps, websites, or services.
Legal basis (EU/UK). Where the GDPR or UK GDPR applies, we process this data to perform our contract with you (running the service you signed up for), on the basis of the parent's consent (for AI processing and optional crash reporting, which you can withdraw at any time by emailing privacy@wimzipal.com, and we will disable it on your account), and for our legitimate interest in keeping the service secure and reliable. Because WimziPal is for children, we rely on the account-holding parent's consent, never on the child's own.
5. AI services we use
WimziPal's conversations are powered by two AI services. Each is bound by its own privacy policy and processes data only for the purpose listed:
- OpenAI (USA): speech-to-text, chat replies, vision descriptions. Receives the child's typed or spoken message, short voice recordings, camera photos, and the child's first name and age. Not retained for model training.
- ElevenLabs (USA): text-to-speech. Receives the reply text only, never the child's voice recording or name.
On iPhone and iPad, before any of this data is shared with the AI services above, the app shows the parent a clear in-app disclosure that names each service and what is sent, and asks for the parent's explicit permission. Each provider is contractually required to safeguard the data with protections that are the same as, or equivalent to, those described in this policy, and to use it only to deliver the service listed, never to train its own AI models on your child's conversations.
6. Children's privacy (COPPA)
WimziPal is designed for children under 13 with parental supervision. We comply with the U.S. Children's Online Privacy Protection Act (COPPA) and equivalent rules elsewhere:
- A parent or legal guardian must register the account. There is no path for a child to create an account independently.
- All child-profile data is entered, controlled, and deleted by the parent.
- We do not collect more child information than is needed to deliver the service.
- We do not condition a child's participation on disclosing more information than is reasonably necessary.
- We do not enable behavioural advertising, third-party tracking, or user-to-user contact features.
If you believe we have collected information from a child without verifiable parental consent, contact privacy@wimzipal.com and we will delete it promptly.
7. Your rights
- Access the data we hold about you and your child.
- Correct any inaccurate data via in-app settings or by emailing us.
- Delete your account from Settings → Delete account, or by emailing us. Your data is removed from the app right away and fully purged from our systems within 30 days.
- Export a copy of your data: email us and we will send it within 30 days.
- Object to processing, though the only processing we do is operating the service you signed up for.
- Complain to your local data protection authority (in the EU/UK) if you believe we have mishandled your data.
8. Retention
- Conversation transcripts: up to 90 days, then deleted.
- Voice recordings and photos: not stored.
- Account and child-profile data: retained while the account is active, deleted within 30 days of account deletion.
- Free-trial sessions (used without creating an account): the child profile and transcripts are deleted after 7 days. The hashed device identifier and a count of what the trial used are kept after that, so the same device is not offered the free trial again; they contain nothing that describes a child.
- Crash logs: up to 90 days per Firebase Crashlytics defaults.
- Contact-Us messages: retained until resolved, then deleted.
9. Security
All traffic between the app and our servers is encrypted via HTTPS (TLS 1.2+). Passwords are stored as bcrypt hashes. Every AI route requires a verified parent JWT, and each child's data is access-controlled so one parent account cannot access another family's data. Conversation transcripts are accessible only to the authenticated parent who owns the child profile.
10. International transfers
Our backend and service providers operate primarily in the United States and the European Union. Where data moves from the EU or UK to the United States, that transfer is covered by the European Commission's Standard Contractual Clauses (or an equivalent approved safeguard) with each provider. By using the app you consent to the transfer of your data to those jurisdictions for the purposes described in this policy.
11. Changes to this policy
If we update this policy we will update the effective date at the top of the page. Material changes will also be announced in the app. Continued use after a change means you accept the updated policy.
12. Contact
Privacy questions, requests, complaints: privacy@wimzipal.com
Support: support@wimzipal.com
