Privacy Policy
Last updated: April 2026
1. Introduction
Thinkee ("we", "us", "our") is committed to protecting the privacy of our users, particularly children. This policy explains how we collect, use, and protect personal data in compliance with the UK GDPR, the Data Protection Act 2018, and COPPA regulations.
2. Data We Collect
Parent accounts:
- Name and email address (for account creation and login)
- Hashed password (we never store plain-text passwords)
Child profiles (created by parents):
- Display name (chosen by parent — need not be real name)
- Age (to determine appropriate content difficulty)
- Avatar selection
- Quiz scores and activity data
3. Children's Privacy
Children do not create accounts independently. All child data is stored under the parent's account. We do not collect personal information directly from children. Children's profiles contain only a display name, age, and learning activity data.
We design our service in line with the UK Age Appropriate Design Code to ensure a high level of privacy protection for children.
4. How We Use Data
- To provide the educational quiz service
- To track learning progress and award badges
- To display progress reports to parents
- To provide age-appropriate question content
4.1 Legal Basis for Processing
We process personal data under the following legal bases:
- Contract: to provide the Thinkee service
- Consent: for processing children's data via parent account holders
- Legitimate interests: to improve and secure the platform
We rely on parental consent for processing children's personal data. Parents can withdraw consent at any time by deleting their account.
5. Data Sharing
We do not sell personal data. We share data only with trusted service providers (such as payment processors and hosting providers) who process data on our behalf. We do not use advertising or tracking technologies in the child-facing interface.
6. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration.
We use industry-standard security measures including encrypted passwords (bcrypt), HTTPS encryption, secure HTTP-only cookies, and rate-limited authentication endpoints.
7. Parental Rights
Parents can at any time:
- View all data associated with their child's profile
- Edit or delete child profiles
- Request deletion of their account and associated personal data (subject to limited retention required by law or regulation)
- Export their child's progress data
8. Data Retention
We retain data for as long as the account is active. When a parent deletes a child profile or parent account, we delete personal data where possible, but may retain limited information where required for legal, regulatory, or legitimate business purposes.
9. Cookies
We use essential cookies only for authentication. We do not use tracking, advertising, or analytics cookies.
These cookies are necessary to keep you logged in and ensure the platform functions securely.
10. No External Content in Child Interface
The child-facing interface contains no advertisements, external links, social media integration, chat features, or user-generated content.
11. Contact
For privacy-related enquiries, please contact us at contact@thinkee.app.