Privacy Policy
Last updated: August 28, 2026
Pip is built around a simple promise: children’s data is not a business model. This policy explains what we collect, why, and the control you have over it.
1. Who is responsible
The data controller for Pip is Sumlane UG (haftungsbeschränkt), Marie-Curie-Str. 33, 40721 Hilden, Germany (managing director: Felix Kerlin). You can reach us at any time at support@guidedaiforkids.com.
2. What we collect
We only collect what Pip and this website need to work:
- Parent account: email address and sign-in method (email, Apple, or Google), plus your parental-consent confirmation.
- Child profiles: first name or nickname and birth date, entered by the parent. Children never create accounts and we never ask them for personal data.
- Chat content: the conversations between your child and Pip, stored so you can review them and so Pip can continue a conversation.
- Safety events: when a chat touches a blocked topic, we record a moderation event (reason, category) for the parent’s Issues view.
- Device link: a technical device identifier and session tokens used to keep a child’s device paired. No advertising identifiers.
- Subscription status: whether your family’s subscription is active, provided by the app stores via RevenueCat. We never see or store payment card details.
- This website: pages viewed and App Store / Google Play button clicks, measured with cookieless analytics. We do not identify visitors, set advertising cookies, or profile children.
- Parent app analytics: setup and paywall events from the parent account, so we can see where families get stuck. Child devices are not tracked. Events never include a child’s name, birth date, pairing code, or chat content.
3. What we never do
- No advertising and no tracking for advertising.
- No selling or sharing of personal data with data brokers.
- No profiling of children for marketing purposes.
- Chat content is not used to train AI models by us.
4. Why we process data (legal bases)
- Providing the service (Art. 6(1)(b) GDPR): accounts, pairing, chat delivery, parental controls, subscription checks.
- Safety of children (Art. 6(1)(f) GDPR, legitimate interest): content moderation and the parent’s Issues view.
- Consent (Art. 6(1)(a) GDPR): the parental consent given during registration for processing a child’s profile and chat data. You can withdraw it by deleting the child profile or your account.
- Website analytics (Art. 6(1)(f) GDPR, legitimate interest): measuring visits and store-button clicks on this website so we can understand reach.
- Parent product analytics (Art. 6(1)(f) GDPR, legitimate interest): understanding how parents complete setup and subscribe. This does not apply to child sessions.
5. Children’s data and parental consent
Pip is designed so that the parent account is the only real account. A parent or legal guardian creates and manages every child profile and gives consent for the child’s use during registration. Children authenticate only with a short join code on their device. They cannot enter personal data, make purchases, or change safety settings themselves.
Parents can review all of their child’s conversations in the app and can request deletion of a child profile and its data at any time (see “Your rights”).
6. Who processes data for us
We use a small number of processors to run the service:
- Supabase: database and authentication (parent accounts, profiles, chat content).
- OpenRouter: routes chat messages to AI models that generate Pip’s answers and safety classifications. Message content is processed to produce a reply; per our configuration it is not used for model training.
- RevenueCat: subscription status and entitlements on behalf of the app stores. RevenueCat receives an app user ID and purchase receipts, not chat content or child profiles.
- Vercel: hosting of our API and this website.
- PostHog: cookieless website analytics and parent-app product analytics (setup and paywall events identified to the parent account only) on PostHog Cloud EU. No session recordings, no advertising cookies, and no child or chat data.
- Apple / Google: app distribution and payment processing under their own privacy policies.
Some of these providers process data outside the EU/EEA (in particular in the USA). Where they do, transfers rely on adequacy decisions or Standard Contractual Clauses.
7. How long we keep data
- Parent account and child profiles: until you delete them or your account.
- Chat content and moderation events: until you delete them or your account.
- Join codes and device links: until they expire, are redeemed, or are revoked.
- Website and parent-app analytics events: up to 12 months.
- Subscription records: as required by tax and accounting law (in Germany generally up to 10 years for transaction records).
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and to withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, including deleting your family’s data, email support@guidedaiforkids.com from your account address. We respond within 30 days.
9. Security
Access to your family’s data is protected by authentication, row-level access rules in our database, and encrypted transport. Child devices hold only a scoped session that parents can revoke at any time from the parent app.
10. Changes to this policy
If we change this policy in a way that affects your family, we’ll say so in the app before it takes effect and update the date above.