Privacy Policy
The short version. Sprouzy is built to keep as little about you as possible.
• We do not use advertising, tracking pixels, analytics SDKs or social-media plug-ins — on the website or in the app.
• You can use the app without an account. Then everything — the child's plan, levels and progress — is stored only on your device and never leaves it.
• If you choose to create an account (so the plan follows you to another phone or the TV), we keep the minimum needed to make that work: your e-mail, a password hash and the child's plan and progress. We never sell or share it for marketing.
• You can delete the account and everything with it at any time, from inside the app or by e-mail.
1. Who is responsible for your data
The data controller is:
GROW THROUGH PLAY SRL
Registered office: [street, number, city, county, postcode], Romania
Trade Register no.: J__/____/____ · Tax ID (CUI): RO________
E-mail for anything about your data: contact@sprouzy.com
We are established in Romania, a member state of the European Union. The EU General Data Protection Regulation (GDPR) and Romanian Law no. 190/2018 apply to everything we do with personal data. We have not appointed a Data Protection Officer because our processing is small in scale and not our core business; the address above reaches the people who make decisions about data.
2. What this policy covers
This policy covers the website sprouzy.com, the Sprouzy web app, the Sprouzy apps for phones and tablets, and the Sprouzy app for Android TV. It also covers e-mails we exchange with you and orders for printed materials placed with us. It does not cover the app stores (Google Play, App Store) or any third-party site we link to — they have their own policies.
3. Children
Sprouzy is made for children aged 3 to 10, but it is operated by parents and guardians. Only an adult may create an account, and the app is designed so that a child never has to type anything about themselves.
- We do not knowingly collect personal data directly from children. The account belongs to the adult; the child is a profile inside it.
- A child profile contains a first name or nickname chosen by the parent, an age band, the answers the parent gave to a short starting questionnaire (about attention and activity, three questions), and the plan and progress that follow from it. It never contains a surname, photo, date of birth, school, location or contact details, and there is no field for any of them.
- The app has no chat, no user-generated content, no comments, no sharing with other users and no links out to social networks. There is no advertising.
- If you believe a child has given us personal data without a parent's involvement, write to contact@sprouzy.com and we will delete it.
Where local law sets a higher standard for children's data (for example the UK Age-Appropriate Design Code or the US Children's Online Privacy Protection Act, COPPA), we follow it: verifiable parental consent is built into the account flow — the account is the parent's, is confirmed by e-mail, and the child profile is created by the parent.
4. Using Sprouzy without an account
You can open the app and use it in “try it” mode without giving us anything. In that mode:
- The child's plan, chosen language, game levels and daily progress are stored only on your device (in the app's private storage on a phone or TV, or in the browser's local storage on the web).
- Nothing about the child is sent to our servers. The app only downloads the content it needs (tasks, games, cards, tales, sounds) from our server — the same way a browser downloads a web page. Those downloads reveal your IP address and app version to our server, which is unavoidable for any internet service; we do not use them to identify you and they are kept only in short-lived technical logs (see section 10).
- If you later create an account, the app offers to move that local progress into the account so nothing is lost. Until you do, it stays where it is, and uninstalling the app or clearing browser data removes it completely.
5. What we collect if you create an account
An account exists for one reason: so the same plan and progress can be opened on a second device — a tablet, the other parent's phone, the TV. If you create one, we store:
| Data | Why | Required? |
|---|---|---|
| Your e-mail address | To sign you in, to confirm the account is yours (activation link), to reset a forgotten password, and to reach you about the service | Yes |
| Your password | Stored only as a one-way hash; we cannot read it | Yes |
| Your first name | Shown in the app as a greeting | No |
| App language | To send you e-mails in your language | Set automatically |
| Child profile: nickname, age band, the three questionnaire answers, the generated plan, game levels and daily progress | This is the service — it is what gets synchronised between your devices | Yes, for a plan to exist |
| Device type (phone / web / TV), operating system and app version, and a random device identifier generated by the app | To keep each device signed in and to know which app version you have when something breaks | Set automatically |
| Sign-in sessions (a random token, stored hashed) | So you do not have to type the password every time | Set automatically |
We deliberately do not collect: precise or approximate location, contacts, photos, microphone or camera input, the child's surname or date of birth, advertising identifiers, or anything from other apps on the device. The app requests no device permissions beyond what is needed to play sound.
6. The website sprouzy.com
The website is static. It sets no cookies, loads no analytics, and contains no third-party tracking. Fonts are served from Google Fonts, which means Google's servers see the IP address of the browser requesting the font file; Google states it does not use these requests for tracking. When you press “Get access” and leave your e-mail, we store that e-mail with the date and the language of the page, only to write to you when the app is available for you (section 7, legitimate interest / your request). You can ask us to delete it at any time.
7. Why we are allowed to process it (legal bases)
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing the app, the account, synchronisation between devices, activation and password-reset e-mails | Performance of a contract with you (art. 6(1)(b)) |
| Answering your e-mails and access requests | Performance of a contract / steps before a contract (art. 6(1)(b)) |
| Keeping the service secure: rate limits, blocking abuse, short technical logs | Our legitimate interest in running a safe service (art. 6(1)(f)) |
| Telling you about important changes to the service or these terms | Legitimate interest and, where required, legal obligation (art. 6(1)(c), (f)) |
| Sending any marketing e-mail | Only with your consent (art. 6(1)(a)), which you can withdraw from any e-mail — we currently send none |
| Fulfilling an order for printed materials, invoicing, tax records | Contract (art. 6(1)(b)) and legal obligation (art. 6(1)(c)) |
We do not carry out automated decision-making with legal or similarly significant effects. The plan the app builds for a child is adjusted by simple rules from the child's own results (which level was passed), and a parent can change or reset it at any time.
8. Who we share it with
We do not sell personal data, do not share it with advertisers, data brokers or “partners”, and do not use it to build profiles for anyone else. The only recipients are service providers who act on our instructions under a data-processing agreement, and only as far as needed:
| Provider | What for | Where |
|---|---|---|
| Hostinger International Ltd. (61 Lordou Vironos Street, 6023 Larnaca, Cyprus) | Hosting the server and database | European Union — Hostinger data centre within the EU |
| Hostinger International Ltd. (e-mail service of the same hosting account) | Sending activation, password-reset and PDF e-mails | European Union |
| Google Play / Apple App Store | Distributing the apps and, if you buy through them, processing the payment — we never see your card details | Per their policies |
| Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin 2, Ireland) — only if you buy from us directly, outside the app stores | Taking the payment; we receive only a confirmation, the amount and the last four digits of the card. Stripe is an independent controller for the payment itself — see stripe.com/privacy | Ireland / EU (Stripe may transfer data to the US under the EU–US Data Privacy Framework and Standard Contractual Clauses) |
| The postal or courier company named at checkout — only if you order a printed product | Delivering it: name, delivery address, phone number for the courier | Your country |
We may also disclose data if the law requires it (for example a binding request from a court or authority), or to establish or defend a legal claim.
9. Where it is stored
Our servers and database are located in the European Union. We do not transfer personal data outside the EU/EEA in the normal running of the service. If a provider we use ever processes data outside the EU/EEA, we rely on an adequacy decision of the European Commission (for example for the United Kingdom, or the EU–US Data Privacy Framework for certified US companies such as Stripe) or on the Commission's Standard Contractual Clauses, and we say so in the table above.
10. How long we keep it
| Data | Kept for |
|---|---|
| Account and child profiles | Until you delete the account. Accounts not opened for 24 months receive a reminder and are deleted 60 days later if still unused. |
| Activation and password-reset links | Until used, or 7 days (activation) / 1 hour (reset) — then removed. |
| Sign-in sessions | Until you sign out, or 90 days of inactivity. |
| Rate-limit counters (IP address, one hour window) | 1 hour. |
| Server access logs (IP address, requested URL, time) | 14 days, then deleted automatically. |
| “Get access” e-mail list | Until we have written to you and you have either created an account or asked to be removed — at most 12 months. |
| E-mails you send us | As long as needed to help you; at most 24 months. |
| Invoices and order records | As long as Romanian tax and accounting law requires (currently 5–10 years), then deleted. |
11. Security
- All traffic between the app or website and our server is encrypted (HTTPS/TLS).
- Passwords are stored only as salted one-way hashes. Session, activation and reset tokens are stored hashed; the plain token exists only on your device or in the e-mail sent to you.
- Sign-in, registration and e-mail sending are rate-limited to stop guessing and abuse.
- Access to the server and database is limited to the people who run the service, with individual credentials.
- Backups are encrypted and kept within the EU; they are overwritten on a rolling basis and deleted data disappears from backups within 30 days.
- If a breach ever affects your data, we will notify the supervisory authority within 72 hours as the GDPR requires and tell you directly if the risk to you is high.
12. Your rights
Under the GDPR you may, at any time and free of charge:
- Access — get a copy of what we hold about you and your child's profile.
- Rectify — correct anything that is wrong (most of it you can edit inside the app).
- Erase — delete the account and everything in it. There is a “Delete account” button in the app's settings; you can also e-mail us. Deletion is immediate in the live database and complete within 30 days including backups.
- Port — receive the child's plan and progress in a machine-readable file (JSON).
- Restrict or object — ask us to stop a particular processing based on legitimate interest.
- Withdraw consent — where processing is based on consent, at any time, without affecting what was done before.
- Complain — to the Romanian supervisory authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral Gheorghe Magheru 28–30, Bucharest, dataprotection.ro, or to the authority in the EU country where you live. We would rather hear from you first, but it is your right.
Write to contact@sprouzy.com from the e-mail address on the account so we know it is you. We answer within one month; if a request is complex we may take up to two more months and will tell you why.
13. Cookies and local storage
Website: no cookies at all — no analytics, no consent banner needed.
Web app: no cookies either. It uses the browser's local storage to keep the child's progress and, if you signed in, your session token, so the app opens where you left it. This is strictly necessary for the app to work and is not used for tracking. Clearing site data in your browser removes it.
Phone and TV apps: the same information is kept in the app's private storage; the session token is kept in the device's secure keychain / keystore.
14. E-mails we send
With an account you receive only service e-mails: the activation link, a password-reset link when you ask for one, a PDF you asked the app to send you, and rare notices about important changes. We send no newsletter and no marketing unless you have separately asked for it, and every such e-mail would carry a one-click unsubscribe.
15. Printed products and payments
If we offer a printed version of a plan or activity cards and you order one, we additionally process your name, delivery address, phone number (for the courier) and the order itself, and keep the invoice as tax law requires. Card details are entered directly with the payment provider and never reach our servers. Purchases inside the apps through Google Play or the App Store are handled entirely by the store; we receive a receipt identifier, not your payment details.
16. If you are in the United Kingdom or outside the EU
UK: the UK GDPR and Data Protection Act 2018 give you the same rights as above. You may complain to the Information Commissioner's Office (ico.org.uk). Data flows from the UK to our EU servers under the UK adequacy regulations for the EEA.
United States: we do not sell or “share” personal information as defined in US state privacy laws, and we do not knowingly collect personal information from children under 13 except through a parent's account as described in section 3.
Elsewhere: we apply this policy to everyone, wherever they are.
17. Changes to this policy
When we change this policy we update the version and date at the top and keep previous versions available on request. If a change affects what we collect or why, we tell account holders by e-mail and inside the app before it takes effect.
18. Contact
GROW THROUGH PLAY SRL · [registered address], Romania