Privacy Policy
What Ludea collects, what for, who it is shared with, how long it is kept, and how you delete all of it.
Versão intl-2026-09-06 · em vigor desde September 6, 2026 · Demais países, em inglês
In short
This policy explains what we do with your family’s data. The whole document is below, but the essentials fit in five lines:
- We keep your child’s conversations because the supervision this product promises depends on it — and you can read every one of them.
- We do not sell any data, we show no advertising, we build no marketing profiles, and we do not use conversations to train artificial intelligence models.
- There is no analytics, tracking or advertising SDK inside the app. None.
- Microphone audio never leaves the device: speech is transcribed on the iPhone itself and only the text is sent.
- You can delete everything whenever you want, and deleting means deleting — no recovery window, no retained copy.
This is version 2026-09-06, in force since September 6, 2026.
Who is responsible for your data
This policy covers the Ludea Mentor app, called “Ludea” throughout this text. The controller of your data under applicable data protection law is Tutor Seguro Desenvolvimento de Software Customizável Ltda. (trading as Tutor Seguro), a company registered in Brazil under company number (CNPJ) 66.845.407/0001-28, with its registered office at Rua Pais Leme, 215, conj. 1713, São Paulo/SP, CEP 05424-150, Brasil.
For anything to do with privacy, write to contato@ludea.com.br. Use that address to exercise any of the rights listed in the “Your rights” section.
What we collect
We collect what is listed below, and nothing beyond it. Each row says what it is for and what allows us to process it.
From you, the parent or guardian:
| Data | What for | Legal basis |
|---|---|---|
| Email address | Signing in, resetting your password, receiving alerts and service notices | Performance of a contract |
| Password | Authentication. Stored only as a hash, never in readable form | Performance of a contract |
| Parent-area PIN | Keeping the adult area separate from the child area. Also stored as a hash | Performance of a contract |
| Country and language | Adjusting text, currency and time zone — and deciding which legal documents apply to your account | Performance of a contract |
| Subscription status, plan and expiry date | Unlocking the allowance you paid for | Performance of a contract |
| Apple purchase identifier | Linking an App Store payment to your account | Performance of a contract |
| Alert preferences (channel and severity) | Sending only what you asked for, the way you asked for it | Performance of a contract |
| Date, time and version of your acceptance of the terms | Proving which text you accepted and when | Legal obligation |
| Application access logs | Security and fraud investigation | Legal obligation |
For each child profile, entered by you:
| Data | What for | Legal basis |
|---|---|---|
| Name or nickname | Addressing the child by name in the conversation | Consent of the parent or legal guardian |
| Date of birth | Adapting language and content to the child’s age — this is what stops the tutor from answering a 6-year-old the way it would answer a 16-year-old | Consent of the parent or legal guardian |
| School year | Matching explanations to the curriculum | Consent of the parent or legal guardian |
| Avatar | Identifying the profile in the list | Consent of the parent or legal guardian |
| Scope, method and sensitive topics | Deciding what the tutor talks about and how it explains | Consent of the parent or legal guardian |
| Words blocked by the family | Adding blocks that apply only in your household | Consent of the parent or legal guardian |
| Quiet hours, time zone and session limit | Telling you when the child uses the app out of hours or for too long | Consent of the parent or legal guardian |
Generated by use:
| Data | What for | Legal basis |
|---|---|---|
| Messages written by the child and the tutor’s replies | Providing the service, keeping the thread of the conversation, and letting you supervise it | Consent of the parent or legal guardian |
| Photos sent by the child | Reading the photographed exercise. Kept in private storage, readable only through a temporary link generated for you | Consent of the parent or legal guardian |
| Safety screening flags | Recording why a message was blocked or raised an alert | See the “Health data” section |
| Alerts raised, their severity and whether they were read | Notifying you, and not repeating the same notice | See the “Health data” section |
| Model used and token count per reply | Measuring cost and applying the plan’s allowance | Legitimate interests |
| Registered devices, platform, install identifier and notification token | Sending each notification to the right device, and knowing which device is the child’s and which is yours | Performance of a contract |
Health data: signs of crisis
Ludea’s second screening layer looks, in the text of the messages, for signs of psychological distress, suicidal ideation, self-harm, eating disorders and indications of violence suffered. When it finds one, it raises an alert for you and records the flag alongside the message.
Information about a person’s mental health is sensitive data. We process it on two grounds that stand together:
- Your explicit consent, given separately at sign-up, given at sign-up in a box of its own, separate from the others.
- Protection of the child’s life and physical safety — this is what allows the screening to keep working while the account exists, even if consent is withdrawn.
This data is used exclusively to raise the alert for you and to record why it was raised. It is not shared with anyone, does not feed statistics, is not used to improve the product, and never leaves your account. It is deleted with the account.
The screening runs by text comparison inside our own server, not through an external artificial intelligence model. A message flagged as a crisis is never sent to the AI provider: the response the child sees is fixed text, written by people.
What we use the data for
- Providing the service: answering the child’s questions, adapting language, subject and limits to the profile you configured.
- Keeping supervision possible: storing the history so you can read it, and raising the alerts you chose to receive.
- Protecting the child: blocking inappropriate content and identifying signs of crisis.
- Billing and plan control: applying the monthly allowance and recognising your subscription.
- Communicating: sending welcome, password reset, alert and relevant service emails.
- Security and legal duties: keeping access logs, investigating fraud and complying with lawful requests.
Who we share it with
To work, Ludea uses providers that act as processors on our behalf and may only handle the data on our instructions. This is all of them:
| Provider | What it receives | What for |
|---|---|---|
| Anthropic (Claude) | The text of the question, the recent conversation history, the photo when there is one, and the profile’s age and scope instructions | Generating the tutor’s reply |
| Supabase | All account data and uploaded images | Database and file storage |
| Vercel | Server requests and access logs | Application hosting |
| Resend | Your email address and the content of the message sent | Sending welcome, password reset and alert emails |
| Apple | Purchase identifier and subscription status | Billing, renewal and subscription event notifications |
The child’s name is not sent to the AI provider as an identified field; what goes is the age, the school year and the profile preferences, along with the text of the question. If the child writes their own name in the conversation, that text travels as part of the message.
We may also share data where there is a court order, a lawful request from a competent authority, or a need to protect someone’s rights, life or safety. Where the law allows us to tell you, we will.
Sending data across borders
Ludea is operated from Brazil, and the providers listed above run servers in other countries, mainly the United States. Your family’s data — including the content of conversations — is transferred across borders. We sign data processing terms, including the European Commission’s Standard Contractual Clauses where the provider offers them, requiring every provider to use the data only on our instructions.
How long we keep it
- Account data, profiles, conversations, messages, images and alerts: for as long as the account exists. We do not delete history for inactivity or for non-payment.
- All of the above, when you delete the account: erased immediately and permanently, with no recovery window.
- Password reset codes: 15 minutes, invalidated on use or after five wrong attempts.
- Temporary links to view images: 30 minutes.
- Application access logs: 6 months, kept for security, fraud investigation and to respond to lawful requests.
- Record of your acceptance of the terms and billing records: for the statutory retention period, even after the account is deleted, to meet tax obligations and to prove consent.
Database backups may retain already-deleted records for up to 30 days, until they are overwritten by the hosting provider’s normal retention cycle. They are not consulted to operate the service.
Security
- Traffic encrypted in transit (HTTPS/TLS) between the app, the server and the providers.
- Password and PIN stored only as bcrypt hashes — we cannot read or recover the originals.
- Images in private storage: the stored URL opens for nobody, and reading requires a signed, temporary link generated for you.
- Progressive lockout on the PIN after wrong attempts, because the most likely risk in this product is not a remote attacker: it is the child holding the device.
- Sessions can be invalidated in bulk when the password changes, so whoever already had access loses it.
- The device handed to the child gets a credential that can only chat — it cannot read alerts, change settings or reach the account.
No system is impenetrable. If a security incident occurs that is likely to result in a risk to you or your child, we will notify you and the competent authority without undue delay.
Your rights
Under applicable data protection law, you — and your child through you — have the right at any time to:
- Confirm whether we process your data, and access it.
- Correct data that is inaccurate, incomplete or out of date.
- Delete your data, including your child’s.
- Receive your data in a portable format.
- Object to or restrict processing.
- Withdraw consent at any time.
- Know who we share data with.
- Be told what happens if you refuse consent — the answer is in the Your rights section.
Much of this you can do yourself, immediately, inside the app: read every conversation, correct a profile’s details, remove a profile, and delete the whole account. For anything not in the app, write to contato@ludea.com.br — we answer within 30 days.
If your country has a data protection authority, you may complain to it. If you are not sure whether it does, write to us first and we will help you find out.
Children
Ludea processes children’s data as its main activity, not by accident. That processing must always serve the child’s best interests. In this product, that means:
- The age below which consent must come from the parent or guardian is 16, or a lower age where your local law sets one. Every Ludea profile is created by an adult, inside an adult’s account.
- Processing of a child’s data is based on your consent as the parent or legal guardian, and we make reasonable efforts to verify that it was you who gave it.
- We ask the child for nothing beyond what the tutor needs to work, and we do not make use conditional on giving more than that.
- There is no sign-up by the child and no login for the child: the profile lives inside your account and only you create it.
- The child sees no advertising, is not tracked, and is never asked for personal data inside the app.
- We collect no contact details for the child — no email, no phone — and the app does not let them talk to another person. There is no user-to-user chat.
- The device handed to the child cannot reach the parent area, which is protected by a PIN.
- The app tells the child, in words they understand, that the person who looks after them can read the conversations — including the ones the child deletes.
We make reasonable efforts to verify that consent was given by the parent or legal guardian, using the technology available: the account requires a verifiable email address, a password, an express declaration of legal responsibility, and a PIN set before any profile can be created.
Automated decisions
Two things in Ludea are decided automatically: whether a message is blocked or flagged as a sign of crisis, and whether a photo is accepted. Neither produces a legal effect or affects your child in any way beyond the use of the app itself — blocking a question and telling you about it is what the product exists to do.
You can still ask for a human review. If a block or an alert looks wrong to you, write to contato@ludea.com.br with the context: we review it and adjust the lists where warranted.
Cookies and tracking
The app uses no cookies, no advertising identifier, and does no cross-app tracking. The session is held by a token stored in the device’s own secure storage.
The public pages on this site use only what is needed to deliver the page. There is no analytics or advertising cookie.
Changes to this policy
Every version carries an identifier and a date, and the version in force when you accepted is recorded on your account. If a change widens the processing of your child’s data, we will ask for fresh consent inside the app before applying it — we do not treat silence as agreement in that case.
Contact
Privacy and data rights: contato@ludea.com.br.
Tutor Seguro Desenvolvimento de Software Customizável Ltda. (trading as Tutor Seguro), a company registered in Brazil under company number (CNPJ) 66.845.407/0001-28, Rua Pais Leme, 215, conj. 1713, São Paulo/SP, CEP 05424-150, Brasil.