Start Free Trial
πŸ”’ COPPA & GDPR Compliant

Privacy Policy

Sprouza β€” Holistic Child Development Platform

Last Updated: 4 June 2026 Effective Immediately

Sprouza ("Sprouza", "we", "us", or "our") provides an ad-free, gamified learning application designed for the holistic development of children aged 2 and above ("App" and "Services"). This Privacy Policy explains what personal information we collect, how we use and protect it, the legal bases on which we process it, and the rights available to you and your child.

Built for children, controlled by parents.

Sprouza is ad-free. We do not show third-party advertising to children and we do not sell personal information. Child profiles are created and managed by a parent or guardian aged 18 or older, who is in full control of the data at all times. We collect only what is necessary to deliver personalised, age-appropriate learning.

1. Who This Policy Covers

This Privacy Policy applies to all individuals and organisations that use Sprouza's educational platform, mobile applications, website, AI-powered learning services and related features.

  • Parents / guardians (18+) who create and manage a Sprouza account on behalf of their child.
  • Children whose learning profiles are created by their parent or guardian. Children do not register directly β€” a parent account is always required first.
  • School staff and teachers who use the School Edition under an institutional account approved by their school administration.
  • School administrators who manage teacher, classroom and student access within participating schools and institutions.

2. COPPA Compliance (US β€” Children Under 13)

COPPA

Sprouza complies with the Children's Online Privacy Protection Act (COPPA), which protects the personal information of children under 13 in the United States.

  • Parent-first account model: Only adults (parents or guardians aged 18+) may register a Sprouza account. Registration requires explicit confirmation that the registrant is 18 or older and agrees to this Privacy Policy before any data is collected.
  • Verifiable parental consent: By completing the registration process (entering email, phone, password and ticking the 18+ consent checkbox), the parent or guardian provides the consent required under COPPA for the collection of their child's information in connection with the App's educational services.
  • Minimum data collection: We ask only for the child's first name or nickname, age, and grade/interests β€” the minimum needed to personalise learning. We do not ask for a child's full name, home address, telephone number, or Social Security number.
  • No behavioural advertising to children: We do not serve targeted or behavioural advertising to children and we do not share child data with ad networks.
  • Parental review and deletion rights: Parents may review, correct, or delete their child's profile and data at any time from within the App (Parents hub β†’ Privacy & Data) or by contacting privacy@sprouza.com.
  • No conditioning on data disclosure: Access to educational content is not conditioned on a child disclosing more personal information than is reasonably necessary.

3. GDPR Compliance (EEA / UK Users)

GDPR

For users in the European Economic Area (EEA) and the United Kingdom, Sprouza complies with the General Data Protection Regulation (GDPR) and the UK GDPR. The age of digital consent for processing children's data in most EEA member states is 16 (some states permit 13–15 with parental consent). Sprouza requires adult (18+) consent for all child accounts.

Legal Bases For Processing

Processing Activity Legal Basis
Creating and maintaining parent and child accounts Contract performance (Art. 6(1)(b) GDPR)
Personalising the child's learning path (AI content, progress tracking, gamification) Contract performance (Art. 6(1)(b) GDPR)
Processing subscription payments Contract performance (Art. 6(1)(b) GDPR)
Sending essential service emails (password reset, subscription, assignments) Legitimate interests (Art. 6(1)(f) GDPR) β€” necessary for the safe operation of the service
Safety monitoring and kid-safety content moderation Legitimate interests (Art. 6(1)(f) GDPR) β€” to protect children using the App
Compliance with legal obligations Legal obligation (Art. 6(1)(c) GDPR)

Your GDPR Rights

EEA and UK users have the following rights, which you can exercise free of charge:

  • Right of Access: request a copy of the personal data we hold about you. Use the Export My Data feature in the app (Parents hub β†’ Privacy & Data) or email privacy@sprouza.com.
  • Right to Rectification: correct inaccurate data from within the app or by contacting us.
  • Right to Erasure ("Right to be Forgotten"): permanently delete your account and all associated data using the Delete My Account button in the app (Parents hub β†’ Privacy & Data β†’ Delete My Account), or by submitting a request at sprouza.com/delete-account if you cannot access the app. Deletion is immediate and irreversible β€” your account, all child profiles, and all learning history are erased on confirmation.
  • Right to Restriction: request that we limit processing in certain circumstances β€” contact us at privacy@sprouza.com.
  • Right to Data Portability: receive your data in a structured, machine-readable format via Export My Data in the app.
  • Right to Object: object to processing based on legitimate interests β€” contact us at privacy@sprouza.com.
  • Right to Lodge a Complaint: you have the right to complain to your local data protection authority (e.g. the ICO in the UK, or your national DPA in the EEA).
GDPR Response Time

We will respond to rights requests within 30 days (extendable by a further 60 days for complex requests).

4. Information We Collect

Information You Provide To Us

  • Parent / Account Holder: email address and/or phone number (for account recovery), password (stored only as a bcrypt hash β€” never in plaintext), display name (optional), and country.
  • Child Profile Information: first name or nickname, age, grade/educational stage, avatar colour, and interests (e.g. animals, space, music). We ask only for what is needed to personalise learning. We do not ask for a child's date of birth, address, or government ID.
  • School Edition Information: school name, class, teacher names and contact details, and student admission numbers provided by the institution. Schools are responsible for obtaining appropriate consent from staff before providing their details.
  • Support & Communications: messages you send us, parent–teacher notes, and feedback submitted in-app.

Information Generated Through Use Of The App

  • Learning activity, questions answered, correct/incorrect responses, XP, levels, streaks, badges, and mastery data β€” used exclusively to personalise and improve the child's learning path.
  • Mood check-ins and activity selections the child makes during sessions.
  • Device and diagnostic data (app version, platform, and basic error logs) used solely to keep the App reliable and secure. We do not use device fingerprinting for advertising.

Payment Information

Subscription payments are processed by Razorpay (India) or our designated payment partner. We do not store full card or banking details on our servers; all payment data is handled directly by the payment processor under their own PCI-DSS security standards. We retain only a subscription reference ID and status.

5. How We Use Information

  • To create, manage, and personalise each child's learning experience, recommendations, and AI-generated content.
  • To operate gamification features (XP, levels, streaks, badges) and produce progress reports for parents and teachers.
  • To generate age-appropriate educational content using AI β€” every AI output is routed through our kid-safety moderation system before it reaches a child, blocking harmful, inappropriate, or profane content.
  • To manage accounts, subscriptions, free trials, and school enrolment.
  • To send essential service messages (password reset, subscription confirmation, assignment notifications). We do not send marketing emails without your explicit opt-in.
  • To keep the App safe, secure, and working correctly, and to comply with legal obligations.
  • We do not use children's data to build advertising profiles, sell data to third parties, or for any purpose unrelated to providing the educational service.

6. Children's Privacy & Safety

Sprouza is designed to be set up and supervised by a parent, guardian, or authorised school. Every child-facing AI surface passes through automated kid-safety moderation (profanity/harm blocklist + OpenAI content moderation) before content reaches the child. Blocked content is logged in an internal audit trail reviewed by our team.

  • No behavioural advertising and no third-party ad networks of any kind.
  • Minimum data collection β€” we ask only for what is needed for age-appropriate personalisation.
  • Voice and conversational AI features are automatically disabled for children under 4 years old.
  • Parents can review, edit, or delete any child profile and all associated data at any time from within the App.
  • A Parent PIN can be set to prevent children from accessing parent-only controls (billing, sign-out, profile deletion).

7. How We Share Information

We do not sell personal information. We share data only with the following service providers who help us run Sprouza, under contractual data processing agreements (DPAs) and security obligations:

Provider Purpose Data Shared
Amazon Web Services (AWS) Cloud hosting, database, and file storage All app data (encrypted at rest and in transit)
OpenAI / OpenRouter AI content generation and kid-safety moderation Learning prompts (no child name or PII in prompts)
Razorpay Payment processing (India) Payment details (handled under Razorpay's PCI-DSS environment)
Resend / SendGrid Transactional email delivery Parent email address and email content
Expo (Expo Push Notifications) Push notification delivery Device push token (no PII)

We may also disclose information if required by applicable law, court order, or to protect the rights, safety, and security of our users and the public.

8. Data Retention

We retain personal information only for as long as needed to provide the Services and for legitimate legal, accounting, or safety purposes:

  • Active Accounts: data is retained while the account is active.
  • Deleted Child Profiles: removed immediately upon deletion in the App; CASCADE deletion removes all associated learning history.
  • Deleted Parent Accounts: the account and all child profiles, progress, and history are permanently and irreversibly deleted immediately. No backup retention of personal data occurs after deletion.
  • Payment Records: we retain minimal subscription reference data (no card details) for 7 years to meet legal accounting obligations.
  • Content moderation logs: AI moderation audit logs (no child PII, only flagged content patterns) retained for 12 months for safety review.

9. Data Security

All personal data is encrypted in transit and at rest.

Every connection between the Sprouza app and our servers uses TLS 1.2 or higher (HTTPS), so data cannot be read or tampered with while it travels over the network. Data stored on our servers and database is encrypted at rest using AES-256, the same standard used by financial institutions, so raw data files are unreadable without the decryption keys β€” even if storage media were physically accessed.

Additional safeguards we apply:

  • Passwords: stored only as a one-way bcrypt hash β€” we never store or have access to your plaintext password.
  • Session tokens: generated server-side, stored in HTTP-only cookies, and invalidated immediately on sign-out.
  • Database access controls: the database is not publicly accessible; only the application server can connect to it via private networking.
  • Infrastructure: hosted on AWS with encrypted EBS volumes and S3 server-side encryption (SSE-S3) for uploaded files.
  • API keys and secrets: stored as environment variables, never in source code or logs.

No method of transmission or storage is completely immune to risk, but we apply defence-in-depth and we will notify affected users of any data breach as required by applicable law (e.g. within 72 hours under GDPR).

10. International Data Transfers

Sprouza is operated from India and may process and store information in countries other than your own, including the United States (AWS) and other locations where our service providers operate. Where we transfer EEA/UK data internationally, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms to ensure the data remains protected in accordance with GDPR requirements.

11. Your Rights & How To Exercise Them

Self-service in the app:

The fastest way to exercise your rights is directly in the Sprouza app β€” go to Parents hub β†’ Privacy & Data to:

  • Export My Data: download a JSON file of all data we hold for your account and children (GDPR right of access / portability).
  • Delete My Account: permanently and immediately delete your account and all associated data (GDPR right to erasure / COPPA deletion right).

For all other rights requests or questions, contact us at privacy@sprouza.com. We will respond within 30 days.

12. Cookies and tracking

The Sprouza mobile app does not use third-party tracking cookies or advertising SDKs. The App uses a secure, server-side session token (HTTP-only cookie on web) solely to maintain your login session. No cross-site tracking or device fingerprinting is performed.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and notify you within the App or by email at least 14 days before the changes take effect. Continued use of the App after the effective date constitutes acceptance of the updated policy.

14. Contact us & Data Controller

Sprouza is the data controller for personal information collected through the App. If you have questions, rights requests, or concerns about your privacy or your child's data, please contact our Privacy team:

Email

privacy@sprouza.com

Website

www.sprouza.com

Support

Parent & School Support Team

EEA/UK users who are not satisfied with our response have the right to lodge a complaint with their national data protection authority (e.g. the UK Information Commissioner's Office at ico.org.uk, or the relevant EEA supervisory authority).

πŸš€ Free Trial πŸ“ž Contact