Privacy policy
Alphamingo is used by young children, so this policy is written to be read by their parents rather than by lawyers. It describes what the app really does today — not what we might do later.
Last updated: 9 August 2026
1. Who this policy is from
Alphamingo is a small independent project — an alphabet picture-book app for children roughly aged three to six, plus this website and a private admin tool used to write the books.
The data controller is Yurii Tyvodar, an individual developer, who can be reached at support@alphamingo.com. That address is read by the person who builds the app, not by a support desk.
2. Children’s privacy
This is the section that matters most, because the people using this app are under 13.
We do not knowingly collect personal information from children, and the app is built so that there is nothing to collect. This is intended to satisfy the United States Children’s Online Privacy Protection Act (COPPA), Article 8 of the UK and EU GDPR, and the UK Age Appropriate Design Code.
Concretely, in the children’s app there is:
- No sign-up, sign-in, or user profile. The app opens directly onto the books.
- No field anywhere that asks for a name, an age, a birthday, a photograph, or an email address.
- No advertising, no ad networks, and no behavioural or contextual ad targeting.
- No third-party analytics SDK, no crash-reporting SDK, no attribution SDK, and no social-media SDK. The app does send anonymous counts of which stories are read to our own database — section 3 says exactly what they contain.
- No profiling, no personalisation, and no recommendations based on a child’s behaviour.
- No chat, no comments, no sharing, no user-generated content, and no way for a child to be contacted by anyone.
- No links out of the reading experience, so a child cannot tap their way into a browser, a store, or a social network.
- No access to the microphone, camera, photo library, contacts, or location. The app never asks for these permissions, because it has no use for them.
- No push notifications.
Because we hold no personal information about any child, there is no profile to sell, no profile to leak, and nothing for a parent to request or delete. If you believe a child has somehow provided us with personal information — for example by writing to our support address — email support@alphamingo.com and we will delete it.
3. What we actually collect
From children using the app: nothing
No personal data is collected from, or about, a child using Alphamingo. The app stores your child’s progress, if anything, on your own device; it is never uploaded, and deleting the app removes it.
Anonymous counts of what is read
So we can tell which stories children enjoy and where they lose interest, the app sends a small count when the shelf of letters is opened, when a story is opened, when a page is reached, when the “Read to me” voice is used, and when a story is finished. A count contains only these things: which of those five events it was, the story’s short name (for example letter-d-duke), the page number, whether the device runs iOS or Android, the app’s version number, and the time our database received it.
It contains no identifier whatsoever — no device identifier, no advertising identifier, no account, no location, and no session identifier, not even a random one that lasts a single session. We therefore do not tell one reader from another, do not count how many children use the app, and do not follow anyone from one page to the next. We know that page 6 of a story was reached four hundred times; we do not know by whom, or that any two of those four hundred were the same child.
One honest detail rather than a flat “impossible”: counts are sent in small batches, so a handful of rows that arrive in the same instant came from the same phone. That is the only thread that exists in this data, it says nothing about who is holding the phone, and we do not pull it.
These counts go to our own database in Ireland. No third-party analytics company is involved, and there is no analytics or advertising SDK in the app. Under the UK and EU GDPR our lawful basis is legitimate interests — understanding which stories work so we can make better ones. Because the counts identify nobody, there is nothing here to request or delete; if you would still rather the app did not send them, email support@alphamingo.com and we will tell you how to turn them off in the next release.
Server request logs
Stories, illustrations and narration audio are downloaded from our hosting provider’s servers. Making that request unavoidably reveals your device’s IP address and general technical details such as the time of the request and the type of device — exactly as it would for any website or app that loads anything from the internet.
Our provider keeps these standard operational logs to run and secure the service. We do not use them to build a profile, we do not link them to any person, we do not use them for advertising or analytics, and we do not attempt to identify anyone from them. Under the UK and EU GDPR our lawful basis for this is legitimate interests — namely keeping the service running and defending it from abuse.
If you email us
We receive your email address and whatever you choose to write. We use it to answer you and for nothing else. Under the UK and EU GDPR our lawful basis is legitimate interests — replying to someone who has written to us. Please do not include your child’s personal details — we do not need them to help you.
From the administrator
The adults who write the books have accounts, each with an email address and a password. See section 6.
4. What we do not do
Plainly, and without exceptions hidden in other sections:
- We do not sell personal information. We never have and there is nothing to sell.
- We do not share or disclose personal information to third parties for their own purposes.
- We do not show advertising of any kind, and we do not work with advertising networks or data brokers.
- We do not use third-party analytics in the app. The counts described in section 3 go to our own database, carry no identifier, and are never shared.
- We do not track users across other apps or websites.
- We do not use cookies or similar technologies in the children’s app.
- We do not build advertising profiles, and we do not make automated decisions that have any effect on anyone.
5. Pictures, stories and narration
Illustrations are original drawings. Most are simple flat shapes stored inside the story itself; painted books are ordinary picture files the app downloads from our own storage, the same one-way download as the audio below. There are no photographs of real people anywhere in the app.
The “Read to me” button works one of two ways:
- A recorded audio file. Where a book has narration, the app downloads an ordinary audio file from our storage and plays it. This is a one-way download; nothing about your child is sent with the request beyond what section 3 describes.
- Your device’s own built-in voice. Where a page has no recorded narration yet, the app asks your phone or tablet’s operating system to speak the sentence, using the same speech feature the device already provides. We hand the sentence to the device; we do not send it to us. How your operating system performs that speech is governed by Apple’s or Google’s own privacy policy.
The app never records audio and never requests microphone access. Narration only ever comes out of the speaker.
6. The administrator accounts
The books are written and edited through a private page on this website. Only the adults on our allowlist can use it — today there are two. Each account holds an email address, a password stored in hashed form by our authentication provider, and the times the account signed in.
There is no public sign-up. A visitor who finds the admin page sees a sign-in form and cannot create an account. Children have no account, never see this page, and are not affected by it in any way.
7. The companies that help run this
We keep the list of outside companies as short as we can. Today it is:
- Supabase — stores the books, the narration audio files, and the single administrator account. Supabase acts as our data processor and does not use any of it for its own purposes.
- Our website host — serves this website and the admin page, and keeps standard access logs.
- Our email provider — carries messages you send to our support address.
To be specific about where things sit: the books, the narration audio and the administrator account live in a Supabase project hosted in the EU (Ireland). This website and the admin page run on Cloudflare Workers, which serves requests from whichever of its locations is nearest the visitor, so a request made outside Europe is handled outside Europe. Where personal data is transferred internationally we rely on the safeguards those providers put in place, such as standard contractual clauses. Write to support@alphamingo.com if you would like the current specifics.
We will also disclose information if the law genuinely requires it — for example a valid court order — and we will resist requests that go further than the law requires.
8. How long anything is kept
- Data about children: none is kept, because none is collected.
- Anonymous counts of what is read: kept for up to 18 months and then deleted automatically, so we can compare one season with the next. They identify nobody, so this is a housekeeping limit rather than a privacy one.
- Server request logs, which contain your device’s IP address: kept so we can keep the service running and safe, and deleted automatically by our providers — Cloudflare keeps them at most 7 days, Supabase 1 day on our current plan. We do not copy them anywhere else, so nothing survives that window on our side.
- Administrator accounts: kept while that person is still writing books, so they can sign in, and deleted on request.
- Support emails: kept while we are helping you and for up to 12 months afterwards, in case you write again about the same thing, then deleted.
9. Your rights, and deleting data
Depending on where you live — including under the UK and EU GDPR, and under California law — you have the right to ask what personal data is held about you, to get a copy, to have it corrected or deleted, to restrict how it is used while a question about it is settled, to object to how it is used, and to complain to a regulator.
In practice, the honest answer for almost everyone reading this is that we hold nothing about you or your child, so there is nothing to retrieve or erase. If you would like to be certain, email support@alphamingo.com and we will tell you exactly what we do and do not hold.
To remove everything on your side, delete the app. That removes the books and any progress stored on your device. Nothing about your child remains on our servers, because nothing was ever put there.
If you are in the UK or EEA and think we have handled data badly, you may complain to your national data protection authority. We would rather you told us first at support@alphamingo.com so we can fix it.
10. This website
The public pages of this website — this one, the home page and the support page — carry no advertising, no third-party analytics, no tracking pixels, and no cookie banner, because there is nothing to consent to. The only cookies this site sets are the ones strictly necessary to keep the administrator signed in to the private admin page, and you will never receive one unless you sign in there.
11. Changes to this policy
If this policy changes, the date at the top changes with it. If a change ever meaningfully affects what we collect — which we do not intend — we will say so clearly on this page rather than quietly editing a sentence.
12. Contact
Questions, corrections, or anything at all about this policy: email support@alphamingo.com. A real person reads it.
Last updated: 9 August 2026.