Privacy Policy
Zupzi is a family app: a parent sets missions, a child completes them, earns Stars and talks to Zuzi, a voice companion. This page says exactly what we keep about your family, why, for how long, and how you delete it.
Who this covers
This policy covers the Zupzi app for iPhone and iPad and our website, zupzi.io. It is written for the parent or legal guardian who holds the account — children never create an account; a child profile only exists inside a parent’s family.
Children come first
Zupzi is used by children under 13, always through an account their parent or guardian created. When you add a child you confirm that you are that child’s parent or legal guardian and that you agree to this policy for the information we keep about her. We record when you agreed. This is how we meet the parental-consent requirements of COPPA (United States) and article 14 of the LGPD (Brazil).
You can see everything we hold about a child inside the app, change it, and delete it — the child alone or the whole family. We never show a child advertising, never let a child talk to another person through Zupzi, and never sell or share a child’s information for marketing.
What we collect, and why
About you, the parent
- E-mail address and a way to sign in — a password, your Google account or your Apple account (Sign in with Apple, including Apple’s Hide My Email relay). Used to run your account and to send you the e-mails described below.
- Your first name (optional) and your family’s name, so the app can address you and your children.
- Your time zone, sent by your phone, so quiet hours and daily limits follow your clock.
- The phones and tablets you paired for your children, with the label you gave each one (“Manu’s tablet”). You can turn any of them off at any time.
- Messages you send us from Help & feedback in the app: what you write, whether it is a problem or an idea, the app and iOS versions and whether it is an iPhone or an iPad (the screen shows these and your account before you send), and your family’s internal id. It reaches our support inbox by e-mail, with your sign-in e-mail as the reply address, and we use it only to answer you and to fix problems.
About each child
- First name or nickname and date of birth. The birth date is used to show the child’s age to you and to keep Zuzi’s tone right for her age. It is never shown to anyone else.
- A portrait: either a drawing from our gallery or a photo you choose. Photos are kept in private storage that only your family can reach.
- A four-digit PIN the child uses to open her side of the app. We do not store the digits — only a salted, one-way hash the app can check.
- What she does in Zupzi: missions completed, Stars earned and spent, rewards asked for, streaks, level, and the clothes and items she unlocked for her avatar.
- Mission photos (“photo proof”): when a mission asks for a picture, the child takes one and it goes to you for approval. Photos live in a private bucket, isolated per family, and are only ever shown through short-lived links. They are kept for one month unless you choose another period in the Safety Center (one week, one month, three months or one year); after that the image is deleted and only the record that the mission was done remains. They are deleted with the account.
- The photo coach — off until you turn it on in the Safety Center. When it is on, a mission photo is sent to Alibaba Cloud’s Qwen service, in Singapore, together with the mission’s name and its steps — never the child’s name or any identifier — so an AI model can answer with a word of encouragement and a tip. Alibaba Cloud’s terms say it does not use this data to develop or improve its models; it does not publish a fixed retention period, so we do not promise that nothing is kept there. The coach keeps no copy of the photo on our side, it can be wrong, and it never decides Stars: a parent still approves. We keep one short sentence of what it said, for the parent’s approval screen.
- Conversations with Zuzi — see the next section.
- When you consented to this policy for that child.
Zuzi, the voice companion
Zuzi is a voice companion the child talks to. Here is exactly what happens to her voice:
- Zuzi only listens after a parent allows it. In the Safety Center, “Where Zuzi listens” starts as Not yet. Until you choose Allowed, Zuzi stays asleep and no voice leaves the device. (App versions before 1.3.0 talk to a server we run ourselves instead, and have no such switch.)
- When you allow it, the child’s voice is processed by Alibaba Cloud. Zuzi listens, understands and answers through Qwen, the real-time voice model of Alibaba Cloud Model Studio, in its Singapore region: the child’s voice is streamed there, understood, answered, and turned back into speech, and the child’s words are transcribed there so that we can send you the transcript. The short summary in that e-mail is written by a Qwen text model in the same place. Alibaba Cloud’s terms say it does not use this data to develop or improve its models. Alibaba Cloud does not publish a fixed period for how long it keeps request data, so we do not promise that nothing is kept there. We do not keep the audio, and we send Alibaba Cloud only the child’s first name, as Zuzi uses it in the conversation — never an e-mail, a photo or the family’s identity.
- We follow COPPA and the LGPD. The parent holds the account, creates the child profile, gives every permission, and can delete the whole family from the app at any time.
- After every conversation, the whole transcript and a short summary are e-mailed to you. Everything Zuzi says to your child stays visible to you, always. The transcript itself is not stored on our servers beyond the time it takes to send that e-mail; what we keep is a short record — when the conversation happened, how many minutes and turns — and the summary in your in-app notices.
- Zuzi has limits you control. Each family has 10 minutes of Zuzi a month (20 with an invitation code), and you can set a daily limit, down to zero, in the Safety Center. Zuzi only opens with a ticket our server issues for a paired device.
- You can report any conversation from its notice in the app. A person reads every report and replies to you.
- Zuzi is guided to talk like a kind tutor and to steer away from topics a child should not hear. She is software and can still make mistakes; the transcript in your inbox is there so nothing is hidden from you.
The Funny Mirror
The Funny Mirror puts playful effects — ears, silly faces, backgrounds — on the picture from the front camera. It all happens on the device. The camera picture and the points our code finds on a face stay inside the app on that phone or tablet: they are never sent to us or to anyone else, and never used to recognize who someone is. No picture is saved, there is no button to share one, and the camera is only on while the mirror is open, after iOS asks for your permission.
E-mails we send
We send e-mail only about your own family: when your family is created, after every Zuzi conversation, and when you report one. We do not send newsletters or marketing e-mail, and we do not e-mail children.
What we do not do
- No advertising, in the app or anywhere else.
- No third-party analytics or tracking software in the app, and no advertising identifiers.
- No selling, renting or sharing of personal information for marketing.
- No chat or messaging between users — a child can only ever talk to Zuzi.
- No purchases inside the app; the app never asks a child, or you, for money.
We do keep a first-party log of events (which family did what, and when) to run the service and fix problems. It carries internal ids, never a child’s name, photo or words.
Who processes data for us
These companies store or move data on our behalf, under their own security commitments. None of them may use it for anything else.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in and private photo storage | United States (us-east-1) |
| Vercel | Runs our server | United States |
| Resend | Delivers our e-mails | United States |
| Apple, Google | Sign-in, if you choose them; they tell us only your e-mail and name | Their own regions |
| Alibaba Cloud (Model Studio, Qwen) | Zuzi’s voice, answers, transcript and summary; and the photo coach — each only after a parent allows it | Singapore |
| Fly.io | Relays the Zuzi conversation between the app and Alibaba Cloud; keeps nothing | United States |
| Our own server | Zuzi, in app versions before 1.3.0 | Hardware we operate |
If you are outside the United States, your data is transferred there to be processed by these providers. Zuzi conversations, when a parent allows them, are also processed in Singapore. We may also disclose information when the law requires it.
How long we keep things
- Your account and your children’s profiles: for as long as the account exists.
- Mission photos: one month, or the period you chose in the Safety Center, and never past the account.
- Zuzi transcripts: only in the e-mail we sent you. The short event record stays with the account.
- When you delete the account, everything above is deleted from our systems, photos included. E-mails already delivered to your inbox are yours and stay there.
Your rights, and where the buttons are
- See and correct: every child’s details are in the app, under Family. Your own e-mail is what you sign in with.
- Delete a child: Family → the child → Remove.
- Delete the whole family account: Settings → Delete family account. The app asks you to type a word first. It removes your children, their missions, Stars, rewards, photos and your login. If another adult shares the family, only your own login is removed. This cannot be undone.
- Withdraw consent for a child at any time by removing the child. Zupzi cannot keep a child profile without it.
- Ask us for a copy of your data, or for anything you cannot do in the app, at support@zupzi.io. Residents of Brazil have the rights of the LGPD (access, correction, portability, deletion, information about sharing) and may also contact the ANPD; residents of the European Economic Area and the United Kingdom have the equivalent GDPR rights and may contact their supervisory authority.
Security
Everything travels over HTTPS. Photos sit in private storage behind signed, short-lived links. PINs are stored only as one-way hashes. A child’s device holds a token your family can revoke, and Zuzi only opens with a ticket our server signs for that device. No system is perfect; if we ever learn of a breach that affects you, we will tell you.
Changes
If this policy changes in a way that matters to you, we will say so in the app or by e-mail before it takes effect. The date at the top is always the current version.
Contact
Write to support@zupzi.io. A person reads it. We answer privacy requests within 30 days, and usually much sooner.