Privacy Policy

In short

This policy explains what we do with your family’s data. The whole document is below, but the essentials fit in five lines:

  • We keep your child’s conversations because the supervision this product promises depends on it — and you can read every one of them.
  • We do not sell any data, we show no advertising, we build no marketing profiles, and we do not use conversations to train artificial intelligence models.
  • There is no analytics, tracking or advertising SDK inside the app. None.
  • Microphone audio never leaves the device: speech is transcribed on the iPhone itself and only the text is sent.
  • You can delete everything whenever you want, and deleting means deleting — no recovery window, no retained copy.

This is version 2026-09-06, in force since September 6, 2026.

Who is responsible for your data

This policy covers the Ludea Mentor app, called “Ludea” throughout this text. The controller of your data under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) is Tutor Seguro Desenvolvimento de Software Customizável Ltda. (trading as Tutor Seguro), a company registered in Brazil under company number (CNPJ) 66.845.407/0001-28, with its registered office at Rua Pais Leme, 215, conj. 1713, São Paulo/SP, CEP 05424-150, Brasil.

For anything to do with privacy, write to contato@ludea.com.br. Use that address to exercise any of the rights listed in the “Your rights” section.

What we collect

We collect what is listed below, and nothing beyond it. Each row says what it is for and what allows us to process it.

From you, the parent or guardian:

DataWhat forLegal basis
Email addressSigning in, resetting your password, receiving alerts and service noticesPerformance of a contract (art. 6(1)(b))
PasswordAuthentication. Stored only as a hash, never in readable formPerformance of a contract (art. 6(1)(b))
Parent-area PINKeeping the adult area separate from the child area. Also stored as a hashPerformance of a contract (art. 6(1)(b))
Country and languageAdjusting text, currency and time zone — and deciding which legal documents apply to your accountPerformance of a contract (art. 6(1)(b))
Subscription status, plan and expiry dateUnlocking the allowance you paid forPerformance of a contract (art. 6(1)(b))
Apple purchase identifierLinking an App Store payment to your accountPerformance of a contract (art. 6(1)(b))
Alert preferences (channel and severity)Sending only what you asked for, the way you asked for itPerformance of a contract (art. 6(1)(b))
Date, time and version of your acceptance of the termsProving which text you accepted and whenLegal obligation (art. 6(1)(c))
Application access logsSecurity and fraud investigationLegal obligation (art. 6(1)(c))

For each child profile, entered by you:

DataWhat forLegal basis
Name or nicknameAddressing the child by name in the conversationParental consent (art. 6(1)(a) with art. 8)
Date of birthAdapting language and content to the child’s age — this is what stops the tutor from answering a 6-year-old the way it would answer a 16-year-oldParental consent (art. 6(1)(a) with art. 8)
School yearMatching explanations to the curriculumParental consent (art. 6(1)(a) with art. 8)
AvatarIdentifying the profile in the listParental consent (art. 6(1)(a) with art. 8)
Scope, method and sensitive topicsDeciding what the tutor talks about and how it explainsParental consent (art. 6(1)(a) with art. 8)
Words blocked by the familyAdding blocks that apply only in your householdParental consent (art. 6(1)(a) with art. 8)
Quiet hours, time zone and session limitTelling you when the child uses the app out of hours or for too longParental consent (art. 6(1)(a) with art. 8)

Generated by use:

DataWhat forLegal basis
Messages written by the child and the tutor’s repliesProviding the service, keeping the thread of the conversation, and letting you supervise itParental consent (art. 6(1)(a) with art. 8)
Photos sent by the childReading the photographed exercise. Kept in private storage, readable only through a temporary link generated for youParental consent (art. 6(1)(a) with art. 8)
Safety screening flagsRecording why a message was blocked or raised an alertSee the “Health data” section
Alerts raised, their severity and whether they were readNotifying you, and not repeating the same noticeSee the “Health data” section
Model used and token count per replyMeasuring cost and applying the plan’s allowanceLegitimate interests (art. 6(1)(f))
Registered devices, platform, install identifier and notification tokenSending each notification to the right device, and knowing which device is the child’s and which is yoursPerformance of a contract (art. 6(1)(b))

Health data: signs of crisis

Ludea’s second screening layer looks, in the text of the messages, for signs of psychological distress, suicidal ideation, self-harm, eating disorders and indications of violence suffered. When it finds one, it raises an alert for you and records the flag alongside the message.

Information about a person’s mental health is sensitive data. We process it on two grounds that stand together:

  • Your explicit consent (art. 9(2)(a)), given at sign-up in a box of its own, separate from the others.
  • Protection of vital interests (art. 9(2)(c)) — this is what allows the screening to keep working while the account exists, even if consent is withdrawn.

This data is used exclusively to raise the alert for you and to record why it was raised. It is not shared with anyone, does not feed statistics, is not used to improve the product, and never leaves your account. It is deleted with the account.

The screening runs by text comparison inside our own server, not through an external artificial intelligence model. A message flagged as a crisis is never sent to the AI provider: the response the child sees is fixed text, written by people.

What we use the data for

  • Providing the service: answering the child’s questions, adapting language, subject and limits to the profile you configured.
  • Keeping supervision possible: storing the history so you can read it, and raising the alerts you chose to receive.
  • Protecting the child: blocking inappropriate content and identifying signs of crisis.
  • Billing and plan control: applying the monthly allowance and recognising your subscription.
  • Communicating: sending welcome, password reset, alert and relevant service emails.
  • Security and legal duties: keeping access logs, investigating fraud and complying with lawful requests.

Who we share it with

To work, Ludea uses providers that act as processors on our behalf and may only handle the data on our instructions. This is all of them:

ProviderWhat it receivesWhat for
Anthropic (Claude)The text of the question, the recent conversation history, the photo when there is one, and the profile’s age and scope instructionsGenerating the tutor’s reply
SupabaseAll account data and uploaded imagesDatabase and file storage
VercelServer requests and access logsApplication hosting
ResendYour email address and the content of the message sentSending welcome, password reset and alert emails
ApplePurchase identifier and subscription statusBilling, renewal and subscription event notifications

The child’s name is not sent to the AI provider as an identified field; what goes is the age, the school year and the profile preferences, along with the text of the question. If the child writes their own name in the conversation, that text travels as part of the message.

We may also share data where there is a court order, a lawful request from a competent authority, or a need to protect someone’s rights, life or safety. Where the law allows us to tell you, we will.

Sending data across borders

Transfers outside the European Economic Area rely on the European Commission’s Standard Contractual Clauses (GDPR art. 46(2)(c)), signed with each provider, together with the supplementary measures described in the Security section. Where a provider is covered by an adequacy decision, we rely on that decision instead (art. 45).

How long we keep it

  • Account data, profiles, conversations, messages, images and alerts: for as long as the account exists. We do not delete history for inactivity or for non-payment.
  • All of the above, when you delete the account: erased immediately and permanently, with no recovery window.
  • Password reset codes: 15 minutes, invalidated on use or after five wrong attempts.
  • Temporary links to view images: 30 minutes.
  • Application access logs: 6 months, kept for security, fraud investigation and to respond to lawful requests.
  • Record of your acceptance of the terms and billing records: for the statutory retention period, even after the account is deleted, to meet tax obligations and to prove consent.

Database backups may retain already-deleted records for up to 30 days, until they are overwritten by the hosting provider’s normal retention cycle. They are not consulted to operate the service.

Security

  • Traffic encrypted in transit (HTTPS/TLS) between the app, the server and the providers.
  • Password and PIN stored only as bcrypt hashes — we cannot read or recover the originals.
  • Images in private storage: the stored URL opens for nobody, and reading requires a signed, temporary link generated for you.
  • Progressive lockout on the PIN after wrong attempts, because the most likely risk in this product is not a remote attacker: it is the child holding the device.
  • Sessions can be invalidated in bulk when the password changes, so whoever already had access loses it.
  • The device handed to the child gets a credential that can only chat — it cannot read alerts, change settings or reach the account.

No system is impenetrable. If a security incident occurs that is likely to result in a risk to you or your child, we will notify you and the competent authority without undue delay.

Your rights

Under the GDPR, you — and your child through you — have the right at any time to:

  • Access the personal data we hold, and receive a copy of it (art. 15).
  • Have inaccurate or incomplete data corrected (art. 16).
  • Have data erased — the “right to be forgotten” (art. 17).
  • Restrict processing while a dispute about accuracy or lawfulness is resolved (art. 18).
  • Receive your data in a portable, machine-readable format and have it sent to another provider (art. 20).
  • Object to processing based on our legitimate interests (art. 21).
  • Withdraw consent at any time, without affecting what was lawful before the withdrawal (art. 7(3)).
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (art. 22) — see the Automated decisions section.

Much of this you can do yourself, immediately, inside the app: read every conversation, correct a profile’s details, remove a profile, and delete the whole account. For anything not in the app, write to contato@ludea.com.br — we answer within 30 days.

You may lodge a complaint with the supervisory authority of the country where you live, where you work, or where the alleged infringement took place (GDPR art. 77). The list of national authorities is published at edpb.europa.eu.

Children

Ludea processes children’s data as its main activity, not by accident. That processing must always serve the child’s best interests. In this product, that means:

  • The age below which consent must come from the parent or guardian is 16 — or the lower age set by your country, which may be 13, 14 or 15 (GDPR art. 8(1)). Every Ludea profile is created by an adult, inside an adult’s account.
  • Where the child is below the age of consent set by your country, processing is based on your consent as the holder of parental responsibility, and we make reasonable efforts to verify it (art. 8(2)).
  • No child’s data is used for profiling or for marketing of any kind, in line with Recital 38.
  • We ask the child for nothing beyond what the tutor needs to work, and we do not make use conditional on giving more than that.
  • There is no sign-up by the child and no login for the child: the profile lives inside your account and only you create it.
  • The child sees no advertising, is not tracked, and is never asked for personal data inside the app.
  • We collect no contact details for the child — no email, no phone — and the app does not let them talk to another person. There is no user-to-user chat.
  • The device handed to the child cannot reach the parent area, which is protected by a PIN.
  • The app tells the child, in words they understand, that the person who looks after them can read the conversations — including the ones the child deletes.

We make reasonable efforts to verify that consent was given by the parent or legal guardian, using the technology available: the account requires a verifiable email address, a password, an express declaration of legal responsibility, and a PIN set before any profile can be created.

Automated decisions

Two things in Ludea are decided automatically: whether a message is blocked or flagged as a sign of crisis, and whether a photo is accepted. Neither produces a legal effect or affects your child in any way beyond the use of the app itself — blocking a question and telling you about it is what the product exists to do.

You can still ask for a human review. If a block or an alert looks wrong to you, write to contato@ludea.com.br with the context: we review it and adjust the lists where warranted.

Cookies and tracking

The app uses no cookies, no advertising identifier, and does no cross-app tracking. The session is held by a token stored in the device’s own secure storage.

The public pages on this site use only what is needed to deliver the page. There is no analytics or advertising cookie.

Changes to this policy

Every version carries an identifier and a date, and the version in force when you accepted is recorded on your account. If a change widens the processing of your child’s data, we will ask for fresh consent inside the app before applying it — we do not treat silence as agreement in that case.

Contact

Privacy and data rights: contato@ludea.com.br.

Tutor Seguro Desenvolvimento de Software Customizável Ltda. (trading as Tutor Seguro), a company registered in Brazil under company number (CNPJ) 66.845.407/0001-28, Rua Pais Leme, 215, conj. 1713, São Paulo/SP, CEP 05424-150, Brasil.