Sprouza ("Sprouza", "we", "us", or "our") provides an ad-free,
gamified learning application designed for the holistic
development of children aged 2 and above ("App" and "Services").
This Privacy Policy explains what personal information we collect,
how we use and protect it, the legal bases on which we process it,
and the rights available to you and your child.
Built for children, controlled by parents.
Sprouza is ad-free. We do not show third-party advertising
to children and we do not sell personal information.
Child profiles are created and managed by a parent or
guardian aged 18 or older, who is in full control of the
data at all times.
We collect only what is necessary to deliver personalised,
age-appropriate learning.
1. Who This Policy Covers
This Privacy Policy applies to all individuals and organisations
that use Sprouza's educational platform, mobile applications,
website, AI-powered learning services and related features.
-
Parents / guardians (18+)
who create and manage a Sprouza account on behalf
of their child.
-
Children
whose learning profiles are created by their parent
or guardian. Children do not register directly β
a parent account is always required first.
-
School staff and teachers
who use the School Edition under an institutional
account approved by their school administration.
-
School administrators
who manage teacher, classroom and student access
within participating schools and institutions.
2. COPPA Compliance (US β Children Under 13)
COPPA
Sprouza complies with the Children's Online Privacy
Protection Act (COPPA), which protects the personal
information of children under 13 in the United States.
-
Parent-first account model:
Only adults (parents or guardians aged 18+) may register a Sprouza account. Registration requires explicit confirmation that the registrant is 18 or older and agrees to this Privacy Policy before any data is collected.
-
Verifiable parental consent:
By completing the registration process (entering email, phone, password and ticking the 18+ consent checkbox), the parent or guardian provides the consent required under COPPA for the collection of their child's information in connection with the App's educational services.
-
Minimum data collection:
We ask only for the child's first name or nickname, age, and grade/interests β the minimum needed to personalise learning. We do not ask for a child's full name, home address, telephone number, or Social Security number.
-
No behavioural advertising to children:
We do not serve targeted or behavioural advertising to children and we do not share child data with ad networks.
-
Parental review and deletion rights:
Parents may review, correct, or delete their child's profile and data at any time from within the App (Parents hub β Privacy & Data) or by contacting privacy@sprouza.com.
-
No conditioning on data disclosure:
Access to educational content is not conditioned on a child disclosing more personal information than is reasonably necessary.
3. GDPR Compliance (EEA / UK Users)
GDPR
For users in the European Economic Area (EEA) and the United Kingdom, Sprouza complies with the General Data Protection Regulation (GDPR) and the UK GDPR. The age of digital consent for processing children's data in most EEA member states is 16 (some states permit 13β15 with parental consent). Sprouza requires adult (18+) consent for all child accounts.
Legal Bases For Processing
| Processing Activity |
Legal Basis |
| Creating and maintaining parent and child accounts |
Contract performance (Art. 6(1)(b) GDPR) |
| Personalising the child's learning path (AI content, progress tracking, gamification) |
Contract performance (Art. 6(1)(b) GDPR) |
| Processing subscription payments |
Contract performance (Art. 6(1)(b) GDPR) |
| Sending essential service emails (password reset, subscription, assignments) |
Legitimate interests (Art. 6(1)(f) GDPR) β necessary for the safe operation of the service |
| Safety monitoring and kid-safety content moderation |
Legitimate interests (Art. 6(1)(f) GDPR) β to protect children using the App |
| Compliance with legal obligations |
Legal obligation (Art. 6(1)(c) GDPR) |
Your GDPR Rights
EEA and UK users have the following rights, which you can exercise free of charge:
-
Right of Access:
request a copy of the personal data we hold about you. Use the Export My Data feature in the app (Parents hub β Privacy & Data) or email privacy@sprouza.com.
-
Right to Rectification:
correct inaccurate data from within the app or by contacting us.
-
Right to Erasure ("Right to be Forgotten"):
permanently delete your account and all associated data using the Delete My Account button in the app (Parents hub β Privacy & Data β Delete My Account), or by submitting a request at sprouza.com/delete-account if you cannot access the app. Deletion is immediate and irreversible β your account, all child profiles, and all learning history are erased on confirmation.
-
Right to Restriction:
request that we limit processing in certain circumstances β contact us at privacy@sprouza.com.
-
Right to Data Portability:
receive your data in a structured, machine-readable format via Export My Data in the app.
-
Right to Object:
object to processing based on legitimate interests β contact us at privacy@sprouza.com.
-
Right to Lodge a Complaint:
you have the right to complain to your local data protection authority (e.g. the ICO in the UK, or your national DPA in the EEA).
GDPR Response Time
We will respond to rights requests within 30 days (extendable by a further 60 days for complex requests).
4. Information We Collect
Information You Provide To Us
-
Parent / Account Holder:
email address and/or phone number (for account recovery), password (stored only as a bcrypt hash β never in plaintext), display name (optional), and country.
-
Child Profile Information:
first name or nickname, age, grade/educational stage, avatar colour, and interests (e.g. animals, space, music). We ask only for what is needed to personalise learning. We do not ask for a child's date of birth, address, or government ID.
-
School Edition Information:
school name, class, teacher names and contact details, and student admission numbers provided by the institution. Schools are responsible for obtaining appropriate consent from staff before providing their details.
-
Support & Communications:
messages you send us, parentβteacher notes, and feedback submitted in-app.
Information Generated Through Use Of The App
-
Learning activity, questions answered, correct/incorrect responses, XP, levels, streaks, badges, and mastery data β used exclusively to personalise and improve the child's learning path.
-
Mood check-ins and activity selections the child makes during sessions.
-
Device and diagnostic data (app version, platform, and basic error logs) used solely to keep the App reliable and secure. We do not use device fingerprinting for advertising.
Payment Information
Subscription payments are processed by Razorpay (India) or our designated payment partner. We do not store full card or banking details on our servers; all payment data is handled directly by the payment processor under their own PCI-DSS security standards. We retain only a subscription reference ID and status.
5. How We Use Information
-
To create, manage, and personalise each child's learning experience, recommendations, and AI-generated content.
-
To operate gamification features (XP, levels, streaks, badges) and produce progress reports for parents and teachers.
-
To generate age-appropriate educational content using AI β every AI output is routed through our kid-safety moderation system before it reaches a child, blocking harmful, inappropriate, or profane content.
-
To manage accounts, subscriptions, free trials, and school enrolment.
-
To send essential service messages (password reset, subscription confirmation, assignment notifications). We do not send marketing emails without your explicit opt-in.
-
To keep the App safe, secure, and working correctly, and to comply with legal obligations.
We do not use children's data to build advertising profiles, sell data to third parties, or for any purpose unrelated to providing the educational service.
6. Children's Privacy & Safety
Sprouza is designed to be set up and supervised by a parent, guardian, or authorised school. Every child-facing AI surface passes through automated kid-safety moderation (profanity/harm blocklist + OpenAI content moderation) before content reaches the child. Blocked content is logged in an internal audit trail reviewed by our team.
-
No behavioural advertising and no third-party ad networks of any kind.
-
Minimum data collection β we ask only for what is needed for age-appropriate personalisation.
-
Voice and conversational AI features are automatically disabled for children under 4 years old.
-
Parents can review, edit, or delete any child profile and all associated data at any time from within the App.
-
A Parent PIN can be set to prevent children from accessing parent-only controls (billing, sign-out, profile deletion).
7. How We Share Information
We do not sell personal information. We share data only with the following service providers who help us run Sprouza, under contractual data processing agreements (DPAs) and security obligations:
| Provider |
Purpose |
Data Shared |
| Amazon Web Services (AWS) |
Cloud hosting, database, and file storage |
All app data (encrypted at rest and in transit) |
| OpenAI / OpenRouter |
AI content generation and kid-safety moderation |
Learning prompts (no child name or PII in prompts) |
| Razorpay |
Payment processing (India) |
Payment details (handled under Razorpay's PCI-DSS environment) |
| Resend / SendGrid |
Transactional email delivery |
Parent email address and email content |
| Expo (Expo Push Notifications) |
Push notification delivery |
Device push token (no PII) |
We may also disclose information if required by applicable law, court order, or to protect the rights, safety, and security of our users and the public.
8. Data Retention
We retain personal information only for as long as needed to provide the Services and for legitimate legal, accounting, or safety purposes:
-
Active Accounts:
data is retained while the account is active.
-
Deleted Child Profiles:
removed immediately upon deletion in the App; CASCADE deletion removes all associated learning history.
-
Deleted Parent Accounts:
the account and all child profiles, progress, and history are permanently and irreversibly deleted immediately. No backup retention of personal data occurs after deletion.
-
Payment Records:
we retain minimal subscription reference data (no card details) for 7 years to meet legal accounting obligations.
-
Content moderation logs:
AI moderation audit logs (no child PII, only flagged content patterns) retained for 12 months for safety review.
9. Data Security
All personal data is encrypted in transit and at rest.
Every connection between the Sprouza app and our servers uses TLS 1.2 or higher (HTTPS), so data cannot be read or tampered with while it travels over the network. Data stored on our servers and database is encrypted at rest using AES-256, the same standard used by financial institutions, so raw data files are unreadable without the decryption keys β even if storage media were physically accessed.
Additional safeguards we apply:
-
Passwords:
stored only as a one-way bcrypt hash β we never store or have access to your plaintext password.
-
Session tokens:
generated server-side, stored in HTTP-only cookies, and invalidated immediately on sign-out.
-
Database access controls:
the database is not publicly accessible; only the application server can connect to it via private networking.
-
Infrastructure:
hosted on AWS with encrypted EBS volumes and S3 server-side encryption (SSE-S3) for uploaded files.
-
API keys and secrets:
stored as environment variables, never in source code or logs.
No method of transmission or storage is completely immune to risk, but we apply defence-in-depth and we will notify affected users of any data breach as required by applicable law (e.g. within 72 hours under GDPR).
10. International Data Transfers
Sprouza is operated from India and may process and store information in countries other than your own, including the United States (AWS) and other locations where our service providers operate. Where we transfer EEA/UK data internationally, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms to ensure the data remains protected in accordance with GDPR requirements.
11. Your Rights & How To Exercise Them
Self-service in the app:
The fastest way to exercise your rights is directly in the Sprouza app β go to Parents hub β Privacy & Data to:
-
Export My Data:
download a JSON file of all data we hold for your account and children (GDPR right of access / portability).
-
Delete My Account:
permanently and immediately delete your account and all associated data (GDPR right to erasure / COPPA deletion right).
For all other rights requests or questions, contact us at privacy@sprouza.com. We will respond within 30 days.
12. Cookies and tracking
The Sprouza mobile app does not use third-party tracking cookies or advertising SDKs. The App uses a secure, server-side session token (HTTP-only cookie on web) solely to maintain your login session. No cross-site tracking or device fingerprinting is performed.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and notify you within the App or by email at least 14 days before the changes take effect. Continued use of the App after the effective date constitutes acceptance of the updated policy.
14. Contact us & Data Controller
Sprouza is the data controller for personal information collected through the App. If you have questions, rights requests, or concerns about your privacy or your child's data, please contact our Privacy team:
EEA/UK users who are not satisfied with our response have the right to lodge a complaint with their national data protection authority (e.g. the UK Information Commissioner's Office at ico.org.uk, or the relevant EEA supervisory authority).