Privacy Policy
What Ludea collects, what for, who it is shared with, how long it is kept, and how you delete all of it.
Versão us-2026-09-06 · em vigor desde September 6, 2026 · Estados Unidos, em inglês
In short
This policy explains what we do with your family’s data. The whole document is below, but the essentials fit in five lines:
- We keep your child’s conversations because the supervision this product promises depends on it — and you can read every one of them.
- We do not sell any data, we show no advertising, we build no marketing profiles, and we do not use conversations to train artificial intelligence models.
- There is no analytics, tracking or advertising SDK inside the app. None.
- Microphone audio never leaves the device: speech is transcribed on the iPhone itself and only the text is sent.
- You can delete everything whenever you want, and deleting means deleting — no recovery window, no retained copy.
This is version 2026-09-06, in force since September 6, 2026.
Who is responsible for your data
This policy covers the Ludea Mentor app, called “Ludea” throughout this text. The controller of your data under the Children’s Online Privacy Protection Act (15 U.S.C. §§ 6501–6506) and its rule (16 CFR Part 312) (“COPPA”), together with applicable state privacy laws is Tutor Seguro Desenvolvimento de Software Customizável Ltda. (trading as Tutor Seguro), a company registered in Brazil under company number (CNPJ) 66.845.407/0001-28, with its registered office at Rua Pais Leme, 215, conj. 1713, São Paulo/SP, CEP 05424-150, Brasil.
For anything to do with privacy, write to contato@ludea.com.br. Use that address to exercise any of the rights listed in the “Your rights” section.
What we collect
We collect what is listed below, and nothing beyond it. Each row says what it is for and what allows us to process it.
From you, the parent or guardian:
| Data | What for | Legal basis |
|---|---|---|
| Email address | Signing in, resetting your password, receiving alerts and service notices | Necessary to provide the service you signed up for |
| Password | Authentication. Stored only as a hash, never in readable form | Necessary to provide the service you signed up for |
| Parent-area PIN | Keeping the adult area separate from the child area. Also stored as a hash | Necessary to provide the service you signed up for |
| Country and language | Adjusting text, currency and time zone — and deciding which legal documents apply to your account | Necessary to provide the service you signed up for |
| Subscription status, plan and expiry date | Unlocking the allowance you paid for | Necessary to provide the service you signed up for |
| Apple purchase identifier | Linking an App Store payment to your account | Necessary to provide the service you signed up for |
| Alert preferences (channel and severity) | Sending only what you asked for, the way you asked for it | Necessary to provide the service you signed up for |
| Date, time and version of your acceptance of the terms | Proving which text you accepted and when | Required by law |
| Application access logs | Security and fraud investigation | Required by law |
For each child profile, entered by you:
| Data | What for | Legal basis |
|---|---|---|
| Name or nickname | Addressing the child by name in the conversation | Verifiable parental consent (16 CFR 312.5) |
| Date of birth | Adapting language and content to the child’s age — this is what stops the tutor from answering a 6-year-old the way it would answer a 16-year-old | Verifiable parental consent (16 CFR 312.5) |
| School year | Matching explanations to the curriculum | Verifiable parental consent (16 CFR 312.5) |
| Avatar | Identifying the profile in the list | Verifiable parental consent (16 CFR 312.5) |
| Scope, method and sensitive topics | Deciding what the tutor talks about and how it explains | Verifiable parental consent (16 CFR 312.5) |
| Words blocked by the family | Adding blocks that apply only in your household | Verifiable parental consent (16 CFR 312.5) |
| Quiet hours, time zone and session limit | Telling you when the child uses the app out of hours or for too long | Verifiable parental consent (16 CFR 312.5) |
Generated by use:
| Data | What for | Legal basis |
|---|---|---|
| Messages written by the child and the tutor’s replies | Providing the service, keeping the thread of the conversation, and letting you supervise it | Verifiable parental consent (16 CFR 312.5) |
| Photos sent by the child | Reading the photographed exercise. Kept in private storage, readable only through a temporary link generated for you | Verifiable parental consent (16 CFR 312.5) |
| Safety screening flags | Recording why a message was blocked or raised an alert | See the “Health data” section |
| Alerts raised, their severity and whether they were read | Notifying you, and not repeating the same notice | See the “Health data” section |
| Model used and token count per reply | Measuring cost and applying the plan’s allowance | Our legitimate business interest in operating the service |
| Registered devices, platform, install identifier and notification token | Sending each notification to the right device, and knowing which device is the child’s and which is yours | Necessary to provide the service you signed up for |
Health data: signs of crisis
Ludea’s second screening layer looks, in the text of the messages, for signs of psychological distress, suicidal ideation, self-harm, eating disorders and indications of violence suffered. When it finds one, it raises an alert for you and records the flag alongside the message.
Information about a person’s mental health is sensitive data. We process it on two grounds that stand together:
- Your opt-in consent, given separately at sign-up, given at sign-up in a box of its own, separate from the others.
- Protection of the child’s life and physical safety — this is what allows the screening to keep working while the account exists, even if consent is withdrawn.
This data is used exclusively to raise the alert for you and to record why it was raised. It is not shared with anyone, does not feed statistics, is not used to improve the product, and never leaves your account. It is deleted with the account.
The screening runs by text comparison inside our own server, not through an external artificial intelligence model. A message flagged as a crisis is never sent to the AI provider: the response the child sees is fixed text, written by people.
What we use the data for
- Providing the service: answering the child’s questions, adapting language, subject and limits to the profile you configured.
- Keeping supervision possible: storing the history so you can read it, and raising the alerts you chose to receive.
- Protecting the child: blocking inappropriate content and identifying signs of crisis.
- Billing and plan control: applying the monthly allowance and recognising your subscription.
- Communicating: sending welcome, password reset, alert and relevant service emails.
- Security and legal duties: keeping access logs, investigating fraud and complying with lawful requests.
Who we share it with
To work, Ludea uses providers that act as processors on our behalf and may only handle the data on our instructions. This is all of them:
| Provider | What it receives | What for |
|---|---|---|
| Anthropic (Claude) | The text of the question, the recent conversation history, the photo when there is one, and the profile’s age and scope instructions | Generating the tutor’s reply |
| Supabase | All account data and uploaded images | Database and file storage |
| Vercel | Server requests and access logs | Application hosting |
| Resend | Your email address and the content of the message sent | Sending welcome, password reset and alert emails |
| Apple | Purchase identifier and subscription status | Billing, renewal and subscription event notifications |
The child’s name is not sent to the AI provider as an identified field; what goes is the age, the school year and the profile preferences, along with the text of the question. If the child writes their own name in the conversation, that text travels as part of the message.
We may also share data where there is a court order, a lawful request from a competent authority, or a need to protect someone’s rights, life or safety. Where the law allows us to tell you, we will.
Sending data across borders
Ludea is operated from Brazil, and the providers listed above run servers in the United States and other countries. Your family’s data — including the content of conversations — is processed outside the United States. We sign data processing terms with every provider requiring them to use the data only on our instructions.
How long we keep it
- Account data, profiles, conversations, messages, images and alerts: for as long as the account exists. We do not delete history for inactivity or for non-payment.
- All of the above, when you delete the account: erased immediately and permanently, with no recovery window.
- Password reset codes: 15 minutes, invalidated on use or after five wrong attempts.
- Temporary links to view images: 30 minutes.
- Application access logs: 6 months, kept for security, fraud investigation and to respond to lawful requests.
- Record of your acceptance of the terms and billing records: for the statutory retention period, even after the account is deleted, to meet tax obligations and to prove consent.
Database backups may retain already-deleted records for up to 30 days, until they are overwritten by the hosting provider’s normal retention cycle. They are not consulted to operate the service.
Security
- Traffic encrypted in transit (HTTPS/TLS) between the app, the server and the providers.
- Password and PIN stored only as bcrypt hashes — we cannot read or recover the originals.
- Images in private storage: the stored URL opens for nobody, and reading requires a signed, temporary link generated for you.
- Progressive lockout on the PIN after wrong attempts, because the most likely risk in this product is not a remote attacker: it is the child holding the device.
- Sessions can be invalidated in bulk when the password changes, so whoever already had access loses it.
- The device handed to the child gets a credential that can only chat — it cannot read alerts, change settings or reach the account.
No system is impenetrable. If a security incident occurs that is likely to result in a risk to you or your child, we will notify you and the competent authority without undue delay.
Your rights
Under COPPA and applicable state privacy laws, you — and your child through you — have the right at any time to:
- Know what personal information we collect, use and disclose, and get a copy of it.
- Correct inaccurate personal information.
- Delete personal information, including your child’s.
- Review your child’s personal information and refuse to permit its further collection or use, at any time (16 CFR 312.6).
- Opt out of the sale or sharing of personal information — we do not sell or share personal information, and never have.
- Opt out of targeted advertising — there is no advertising in Ludea.
- Not be discriminated against for exercising any of these rights.
Much of this you can do yourself, immediately, inside the app: read every conversation, correct a profile’s details, remove a profile, and delete the whole account. For anything not in the app, write to contato@ludea.com.br — we answer within 30 days.
You may file a complaint with the Federal Trade Commission at reportfraud.ftc.gov, and with the attorney general of your state. California residents may also contact the California Privacy Protection Agency at cppa.ca.gov.
Children
Ludea processes children’s data as its main activity, not by accident. That processing must always serve the child’s best interests. In this product, that means:
- The age below which consent must come from the parent or guardian is 13 (COPPA). Every Ludea profile is created by an adult, inside an adult’s account.
- We give you direct notice of what we collect from your child before collecting it, and we obtain your consent before the child’s first conversation (16 CFR 312.4 and 312.5).
- We do not condition your child’s participation on disclosing more information than is reasonably necessary for the tutor to work (16 CFR 312.7).
- You may review the information collected from your child, refuse to allow its further use, and have it deleted, at any time and without giving a reason (16 CFR 312.6). Reading every conversation and deleting a profile are available inside the app, without contacting us.
- We do not disclose a child’s personal information to third parties other than the service providers listed in this policy, who are contractually bound to use it only to run Ludea.
- We ask the child for nothing beyond what the tutor needs to work, and we do not make use conditional on giving more than that.
- There is no sign-up by the child and no login for the child: the profile lives inside your account and only you create it.
- The child sees no advertising, is not tracked, and is never asked for personal data inside the app.
- We collect no contact details for the child — no email, no phone — and the app does not let them talk to another person. There is no user-to-user chat.
- The device handed to the child cannot reach the parent area, which is protected by a PIN.
- The app tells the child, in words they understand, that the person who looks after them can read the conversations — including the ones the child deletes.
We make reasonable efforts to verify that consent was given by the parent or legal guardian, using the technology available: the account requires a verifiable email address, a password, an express declaration of legal responsibility, and a PIN set before any profile can be created.
Automated decisions
Two things in Ludea are decided automatically: whether a message is blocked or flagged as a sign of crisis, and whether a photo is accepted. Neither produces a legal effect or affects your child in any way beyond the use of the app itself — blocking a question and telling you about it is what the product exists to do.
You can still ask for a human review. If a block or an alert looks wrong to you, write to contato@ludea.com.br with the context: we review it and adjust the lists where warranted.
Cookies and tracking
The app uses no cookies, no advertising identifier, and does no cross-app tracking. The session is held by a token stored in the device’s own secure storage.
The public pages on this site use only what is needed to deliver the page. There is no analytics or advertising cookie.
Changes to this policy
Every version carries an identifier and a date, and the version in force when you accepted is recorded on your account. If a change widens the processing of your child’s data, we will ask for fresh consent inside the app before applying it — we do not treat silence as agreement in that case.
Contact
Privacy and data rights: contato@ludea.com.br.
Tutor Seguro Desenvolvimento de Software Customizável Ltda. (trading as Tutor Seguro), a company registered in Brazil under company number (CNPJ) 66.845.407/0001-28, Rua Pais Leme, 215, conj. 1713, São Paulo/SP, CEP 05424-150, Brasil.