Legal

Privacy Policy

Last updated: May 2026

Our commitment to your family's privacy

EduPlayHub is built for children and their caregivers. We collect only the minimum data necessary to deliver the Service, we never sell personal data, and we comply fully with COPPA and applicable international children's privacy laws.

1. Who We Are

EduPlayHub ("we", "us", "our") operates the educational platform at eduplayhub.kids. We act as the data controller for personal data collected through the Service. For any privacy enquiries, contact us at eduplayhub.kids@outlook.com.

2. Information We Collect

We collect only what is strictly necessary to provide the Service. This includes: (a) your email address and hashed password for account creation and authentication; (b) your display name and role (parent, teacher, or student) to personalise the experience; (c) your child's age range and grade level to serve appropriate content; (d) game progress data — scores, streaks, and badges — to track learning milestones and surface achievements; and (e) anonymised, aggregated usage analytics (page views, session lengths) to improve the platform. We do not collect financial card data — all payment processing is handled exclusively by Lemon Squeezy's PCI-DSS certified infrastructure.

3. How We Use Your Data

Your data is used solely to provide and improve EduPlayHub. Specifically: to authenticate you and maintain a secure session; to save and display your child's learning progress across devices; to send transactional emails (account verification, password resets, subscription receipts); and to generate aggregate, non-identifiable analytics about platform usage. We never sell, rent, or share personal data with advertisers or data brokers. We do not use your data to serve targeted advertising of any kind.

4. Children's Privacy (COPPA & GDPR-K)

EduPlayHub respects children's privacy and fully complies with the Children's Online Privacy Protection Act (COPPA) and equivalent laws, including GDPR-K for users in the European Union. We do not knowingly collect personal information directly from children under 13 without verifiable parental or guardian consent. All child profiles are created and managed by a parent, guardian, or teacher. If you believe a child under 13 has submitted personal information without appropriate consent, please contact us immediately at eduplayhub.kids@outlook.com and we will delete it within 48 hours.

5. Data Storage & Security

Data is stored in Supabase's managed PostgreSQL infrastructure, hosted on secure cloud servers with AES-256 encryption at rest and TLS 1.3 encryption in transit. Row-level security (RLS) policies are enforced at the database level, ensuring each user account can only access its own data. We conduct regular security reviews, apply patches promptly, and monitor for unauthorised access.

6. Cookies & Local Storage

We use browser local storage to remember your theme preference (light or dark mode) and to persist your authentication session token between visits. We do not use third-party tracking cookies, advertising cookies, or cross-site tracking technologies of any kind. Our platform is completely ad-free.

7. Data Sharing & Third Parties

We share data only with the following third parties, each bound by data protection agreements equivalent to this policy: (a) Supabase — our database and authentication infrastructure provider; (b) Lemon Squeezy — our payment processor, which handles subscription billing and stores payment method data on our behalf under PCI-DSS compliance. We do not share data with any other third parties except as required by applicable law, court order, or to protect the safety of our users.

8. Your Rights

Depending on your location, you may have the right to: access a copy of the personal data we hold about you; request correction of inaccurate or incomplete data; request deletion of your account and all associated personal data; object to or restrict certain types of processing; and receive your data in a portable, machine-readable format. To exercise any of these rights, contact us at eduplayhub.kids@outlook.com. We will respond within 30 days. Account deletion can also be initiated directly from Account Settings.

9. Data Retention

We retain account and progress data for the duration of your active subscription plus up to 90 days after cancellation or account closure, to allow for recovery. After that window, all personal data is permanently and irreversibly deleted. Anonymised, aggregated analytics data from which no individual can be identified may be retained indefinitely for platform improvement purposes.

10. Changes to This Policy

We will notify you of any material changes to this Privacy Policy by email to your registered address at least 14 days before they take effect. We will also display a notice within the platform. Continued use of the Service after the effective date constitutes your acceptance of the updated policy.

11. Contact & Data Controller

Data Controller: EduPlayHub  ·  eduplayhub.kids@outlook.com
For COPPA or GDPR-related requests, please mark your subject line "Privacy Request" and include the registered email address associated with the account.