Privacy Policy
Last updated: 1 August 2026
1. Our promise
GENALF is built for children, so privacy is the default: no ads, no trackers, no selling of personal data — ever. This policy explains what we collect and why, in line with the GDPR and its child-protection requirements (“GDPR-K”).
2. What we collect
- Grown-up accounts: email address, display name, and billing data processed by Stripe. We never see full card numbers.
- Child profiles: a first name or nickname, avatar, and creative progress. No email, no phone number, no precise location.
- Technical data: the minimum server logs needed for security and reliability.
3. Parental consent and control
- A child profile exists only after a parent or guardian creates it and verifiably consents.
- Grown-ups see their child’s activity, approve every purchase, and can export or delete the child’s data at any time.
4. Who processes data
We use a small number of processors under data-processing agreements: Stripe (payments) and Amazon Web Services (hosting, EU region). We do not embed third-party advertising or analytics scripts.
5. Retention and your rights
We keep personal data only as long as the account exists or the law requires. You can request access, correction, export, or deletion at any time — from account settings or by writing to support@genalf.com. You may also complain to your local data protection authority.