Privacy Policy
Version 1.0 · Effective · This policy is also our direct notice to parents under the Children's Online Privacy Protection Act (COPPA).
If you are the kid — here it is in normal words
- I am a computer program. I am not a person, and I am not your friend pretending to be one.
- I remember things your grown-up told me about you, so I can be helpful. Nobody else sees them.
- Your grown-up can read everything you say to me. I am not a secret diary. If you are older, I remind you of that every time you start.
- If you tell me something that makes me worried you are not safe, I will tell your grown-up. I will also show you people who can help right away. I will not keep that quiet.
- If you show me a photo or a file, I look at it, write down what was in it, and then the photo is deleted straight away. I never keep a picture — not of you, not of your homework, not of anything. Your grown-up sees what I wrote down, not the picture.
- Nobody buys anything about you. There are no adverts here. I am never trained on your words.
- There are no other kids here. Nothing you make can be seen by strangers.
- You can ask your grown-up to delete everything, and it really goes.
On this page
- Who we are
- Notice to parents
- What we collect
- Parental consent
- The sensitive profile
- Voice, photos and files
- How we use information
- Who else sees it
- What we never do
- How long we keep it
- Your rights
- Security
- Europe and the UK
- US state rights
- Child safety reporting
- If something goes wrong
- This website
- Changes
- Contact us
1. Who we are
Gnappo is operated by Valadier Ventures, [registered address] (“we”, “us”). We are the controller of the personal information described here. For anything in this policy, write to privacy@gnappo.app.
Gnappo is a child-directed service. We do not attempt to argue that it is a mixed-audience service, and we assume every child user is under 13 unless a parent has told us otherwise.
2. Notice to parents
A child never creates an account here. A parent or legal guardian creates the account, adds each child, and controls everything in it. Before we collect anything from your child, we tell you what we will collect, what we will do with it, and that you can review it, delete it, or refuse to let us collect any more of it at any time.
Refusing further collection means we close that child's profile and delete what we hold for them. Gnappo cannot function without a conversation record — that record is the product you are being shown — so there is no reduced mode we can honestly offer instead.
3. What we collect
From you, the parent
| What | Why |
|---|---|
| Email address and password | To create and secure your account, and to send you digests and alerts. |
| Payment confirmation from our payment processor | To take a subscription, and — for paid accounts — as our method of verifying you are an adult (§4). |
| Mobile number, where you use SMS verification | Only for free accounts, to verify you are an adult. |
| The state or country you declare | To show your child an age percentile without ever locating their device. |
| The rules you set per child | What is allowed, session length, which topics raise an alert. |
From your child
| What | Why |
|---|---|
| First name or nickname, and date of birth | To address them, and to set the age band that governs how Gnappo answers. |
| Everything they type or say to Gnappo, and everything Gnappo says back | It is the conversation. It is also what your daily summary and any alert are built from. |
| What they make — stories, drawings, quiz answers | To show it back to them and to you. It is never shown to anybody else. |
| Interests, dislikes, favourites | To make answers land. Ordinary personal information, and you can edit or clear it. |
| A photo, PDF or text file they send, where you have switched that on | To read it and answer the question about it — a worksheet, a page of sums, a drawing. The file itself is deleted within the same request and is never stored; what is kept is the text of what was in it. See §6. |
| Anything they volunteer mid-conversation | We cannot stop a child mentioning their school or their street. We do not ask for it, we do not use it to build a profile, and you can delete any conversation. |
Automatically
| What | Why |
|---|---|
| IP address, browser and device type, timestamps | To keep the service running and secure, and to spot abuse. Not used to profile a child or to target anything at them. |
| An audit record of every safety decision and every time a parent opens a conversation | Required of us, and it is the evidence that a guardrail actually fired. It cannot be edited or deleted below the retention floor in §10 — including by us. |
4. Parental consent
We obtain verifiable parental consent before collecting personal information from a child, by one of:
- A payment-card transaction — the same act as subscribing, which produces a record we can point to. This is our primary method.
- SMS to your mobile number, followed by a confirming step. Available to free accounts. We are permitted to use this method precisely because we do not disclose children's personal information to third parties for their own purposes.
- Government photo ID, or ID plus a selfie match, used only where consent is disputed or the methods above fail. Both images are deleted promptly after the match, and never used for anything else.
Consent is recorded per purpose and per child, not as a single checkbox, and each one can be withdrawn on its own from your account.
5. The sensitive profile
You may tell Gnappo things about your child that make it dramatically more useful and are, in law, among the most sensitive categories there are: a diagnosis, a bereavement, an anxiety, a thing that must be handled gently. This is entirely optional and Gnappo works without it. Five rules govern it, and they are built into the software rather than promised in this document:
- Separate, per-field consent, with its own record and its own withdrawal.
- Its own encryption key, in a per-child encrypted store. Withdrawing consent destroys that key, which makes the data unrecoverable rather than merely marked deleted.
- It is never sent to a model as you wrote it. Gnappo derives behavioural directions from it — “prefer literal language, avoid idioms, be gentle about fathers and car journeys” — and only those directions reach the model. The diagnosis itself never leaves our database.
- It is never in an email. Your daily digest says there is a summary and links to it; it does not put your child's diagnosis in a plaintext inbox.
- We never infer it. Gnappo does not diagnose, screen, or score your child for any condition. Only you can assert something, in your own words, and we store your words.
Where you are in a place that treats this as consumer health data or special-category data — Washington's My Health My Data Act, Nevada's SB 370, the GDPR's Article 9 — we rely on your explicit, separate consent, and honouring its withdrawal is the deletion described above.
6. Voice, photos and files
Two things a child can send us are not text: what they say, and what they show us. We treat both the same way, and it is the shortest rule in this policy — we read it, we keep what it said, and we destroy the recording or the file inside the same request. There is no library of a child's photographs here, because there is nowhere for one to be.
Voice
Where your child speaks instead of typing, the audio is turned into text and the audio is destroyed within the request. We do not store recordings, we do not create a voiceprint or any other voice embedding, and we never use a voice to identify anybody. A voiceprint is personal information under COPPA and biometric information under Illinois, Texas and Washington law, and the simplest way to hold none is to build none.
One honest caveat about your browser. Where speech is handled by your browser's own recogniser, some browsers do that on your device and some send the audio to their own servers — Google's, in Chrome's case — under the browser's terms rather than ours. Gnappo asks for on-device recognition wherever the browser offers it, and only claims “stays on this device” when the browser has confirmed it. Where it cannot be confirmed, the browser vendor is a recipient of that audio and we say so here rather than implying otherwise.
Photos, PDFs and text files
This is off until you turn it on, per child, on that child's settings page. With it on, your child can take a photograph or attach a PDF or a text file — a worksheet, a page of sums, a drawing they want help with.
What happens then, in order:
- The file is uploaded, encrypted, into your child's own area.
- It is read once — by a model under the zero-retention, no-training terms in §8 — which produces the text of what was in it and a safety judgement on the image itself.
- The file is deleted before that request finishes. Not on a schedule, not overnight, not when a job next runs: inside the same request, including when the reading fails.
- What remains on the conversation is the text. That is what Gnappo answers from, and it is what you see in the thread.
You will not be able to see the picture, and neither will we. That is the trade, and it is deliberate: a photograph of a child, kept anywhere, is the single most sensitive thing this product could hold, and the only way to be certain it is not misused is not to have it. What you get instead is the full text of what Gnappo read, in the conversation, alongside your child's message. If a picture triggers a safety alert, we keep no description of it at all — the alert is the record — because deleting an image and keeping a paragraph about it would not be deleting it.
We ask the reader not to describe people. If someone appears in a picture, the text records only that a person appeared — no age, no appearance, no clothing, nothing about them. A child's photograph should not become a written description of a child.
Files are limited to 8 MB and to pictures, PDFs and plain text. Anything else is refused.
7. How we use information
- To run the conversation, and to shape it to your child's age and to what you have told us.
- To apply the safety guardrails, and to raise an alert to you when one fires.
- To produce your daily digest and the summaries you can take to a clinician.
- To keep the service secure, prevent abuse, and meet our legal obligations.
- To bill you, where you are on a paid plan.
Under the GDPR our legal bases are: contract for running the service you asked for; legitimate interests for security and abuse prevention; legal obligation for the audit and reporting duties in §15; and explicit consent for §5 and §6. Consent for a child under the applicable age of digital consent is given or authorised by you.
8. Who else sees it
We use a small number of processors, each under a contract that binds them to our instructions:
| Who | What they receive | Terms |
|---|---|---|
| OpenAI and Google — our two model vendors, and the only two | The text of a turn, plus the behavioural directions derived from §5 — never the sensitive profile itself, and never your child's date of birth or contact details. Where your child sends a photo or a file under §6, the file is passed once for reading and is deleted by us immediately afterwards. | Zero retention, and no training on the content. Contracted, not merely intended. |
| Our hosting and email providers | What is needed to serve the application and deliver your digests and alerts. | Processors only; no independent use. |
| Our payment processor | Your payment details, which they hold and we do not. | Independent controller for payment; PCI-compliant. |
| Your browser's speech vendor, where §6 applies | The audio of what your child said. | Under that browser's own terms, not ours. See the caveat in §6. |
We may also disclose information where the law requires it, to protect a child from harm, or as part of a merger or acquisition — in which case the buyer is bound to this policy, and you are told before anything about your child moves, with the chance to delete it first.
9. What we never do
- We never sell or rent personal information. Not a child's, not a parent's, not ever.
- We never train AI on children's data, and we contract our vendors not to either.
- We never store a photograph or a file a child sends. It is read and destroyed inside the same request — there is no album, no thumbnail, no backup and no way for us to produce one later. See §6.
- We never show advertising and we run no third-party analytics anywhere a child can reach.
- We never send push notifications to a child and we build no streaks, no loss mechanics and no re-engagement nudges. Anything that pulls a child back is aimed at you instead, if at all.
- We never let a child reach another child. No sharing, no galleries, no friend lists, no user-made bots.
- We never publish a ranking of identified children. Percentiles are shown only to that child and to you.
- We never condition a child's participation on giving us more information than the service needs.
10. How long we keep it
We do not keep children's information indefinitely. These are ceilings, not targets, and you can shorten any of them in your account.
| What | Kept for |
|---|---|
| Raw conversation transcripts | 12 months |
| Daily and weekly summaries | 24 months |
| Safety alert records | 24 months |
| The sensitive profile (§5) | Until you withdraw it — then destroyed with its key |
| Voice audio | Not kept at all (§6) |
| Photos, PDFs and text files a child sends | Not kept at all — destroyed inside the request that read them (§6). The text of what was read is kept with the conversation, on the row above. |
| Account and billing records | As long as the account is open, then as tax and accounting law requires |
| The safety audit trail | The retention floor above; it cannot be pruned below it, by anyone |
When you close an account, we delete it and everything under it, subject only to the last two rows.
11. Your rights
As the parent, at any time, you may:
- See everything we hold about your child, including every conversation.
- Export it in a portable format.
- Correct anything that is wrong.
- Delete any conversation, any part of the profile, a whole child, or the whole account.
- Refuse any further collection from your child, which closes their profile.
- Withdraw a consent without withdrawing the others.
Most of these are buttons in your account. Anything that is not, we will do within 30 days of an email to privacy@gnappo.app. We will not charge you, and we will not make you argue for it.
Teenagers. Where a child is 14 or older, we tell them, in their own words and at the start of every session, that a parent can read their conversations. We are not willing to run covert surveillance of a teenager on a parent's behalf.
12. Security
- Each family's data is isolated, and each child's private material is encrypted with a key of its own.
- Deleting sensitive material destroys its key, so deletion is not a promise we would have to prove.
- Passwords are stored as modern salted hashes, never in a readable form.
- Every safety decision and every parent access is written to an append-only, hash-chained audit log.
- Access by our staff is limited to what is needed to run the service, and is itself audited.
13. Europe and the UK
- Where a child is below the age of digital consent — 16 unless the country sets it lower — consent is given or authorised by you. We gate to 16 and relax it per country.
- Information in §5 is special category data and rests on your explicit consent.
- We complete a Data Protection Impact Assessment before launching a feature that touches children's data, and keep it on file.
- No decision with a legal or similarly significant effect is made about your child by automated means alone. A safety alert is a message to you; you decide what happens next.
- You may complain to your national supervisory authority. We would rather you told us first.
- Our representative in the EU/UK is [EU/UK representative].
14. US state rights
Depending on where you live, you may have rights to know, access, correct, delete, and to limit the use of sensitive information, plus a right not to be discriminated against for exercising them. We honour these for every US resident rather than checking your state first. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing for you to opt out of — and no child's information has ever been in scope of such a sale.
15. Child safety reporting
Where we detect apparent child sexual abuse or exploitation material, or the grooming of a child, we preserve the evidence and report it to the appropriate authority — the National Center for Missing & Exploited Children in the United States, the National Crime Agency in the United Kingdom, or the equivalent where you live. This is not something a setting can turn off.
16. If something goes wrong
We maintain an incident response plan with a named person on call. If a breach affects your child's information, we will tell you within 24 hours of confirming it — what happened, what was involved, and what we are doing — and we will notify regulators within the time the law allows.
17. This website
This marketing website sets no cookies, runs no analytics, and loads nothing from any other server — no fonts, no tag managers, no embedded video, no social buttons. Our server keeps ordinary web logs, briefly, to keep the site up. The Gnappo application itself is a separate site at app.gnappo.app, which stores your sign-in session in your own browser and uses no advertising or analytics cookies either.
18. Changes
If we change how we handle a child's information in a way that matters, we will ask you again rather than assume the consent you already gave covers it — that is what the law requires and it is also the only honest reading of consent. Lesser changes are posted here with a new version and date, and we email you.
19. Contact us
Privacy: privacy@gnappo.app
Anything else: support@gnappo.app
Post: [registered address]
If you are worried about your child's safety right now, do not wait for us. Contact your local emergency number, or in the United States call or text 988 for the Suicide & Crisis Lifeline.