Privacy Policy

Famzo Learn · last updated 27 August 2026

The short version

Who we are

Famzo Learn (“we”) makes a learning app for children aged 2–8. For data-protection purposes we are the controller (UK/EU GDPR) and the Data Fiduciary (India’s DPDP Act) for the data described below. You can reach us at privacy@famzolearn.com.

This policy covers all three places you can meet us: the mobile apps for iPhone and Android, the web app that runs in a browser at famzolearn.com/app, and the rest of this website. The web app is the same product signed in to the same account — a browser simply has different plumbing, and where that changes something it is called out below rather than left for you to work out.

What stays on the device

The following is written to storage on the phone or tablet and is never transmitted to us. It is removed when the app is deleted.

WhatWhy
The child’s nicknameTo greet them in the app. We ask for a nickname rather than a real name on purpose, and the app says so at the point of asking.
Age band (2–5 or 5–8)To pick story length and difficulty.
The parent’s email as typed at set-upKept locally so the app remembers who set it up. It is also used to create the sign-in account — see below.
Friends list, reading theme, reminder times, cached lessons Preferences and offline use. The friends feature is entirely local — nothing about it reaches a server.

The same thing, in a browser

The web app writes exactly this list to your browser’s own local storage, under the same names, on your own machine. It is not a tracking cookie, it is not read by anyone else, and it is never transmitted to us. Firebase also stores your sign-in token there so you are not asked to log in on every visit.

Clearing site data for famzolearn.com in your browser removes all of it, exactly as deleting the app does on a phone. Using a private or incognito window means it is discarded when you close the window.

What is sent, and to whom

We use Google Firebase, and nothing else, as our back end. Google processes this data on our instructions.

WhatWhereWhy
Parent’s email address and passwordFirebase Authentication So the account can be signed in to. The password is stored hashed by Google; we never see it. Sessions that never complete set-up use an anonymous account with no email at all.
Learning progress — chapters read, streak count, difficulty level, which daily items are doneCloud Firestore So progress survives reinstalling. It is stored against the random account identifier, not against your child’s name or age.
Requests for lesson picturesFirebase Storage Downloading illustrations. Read-only — the app never uploads anything.
Whether a subscription is active, and when it expires Cloud Firestore So the app knows whether to show today’s content. Held against the same random account identifier. No card number, no billing address, no payment history.

Security rules on our database restrict every progress record to the single account that created it. One family cannot read another’s.

The web app talks to the same Firebase project, over the same rules, with the same account. Nothing about it is a separate database and nothing extra is collected because you happen to be in a browser. Your browser sends its IP address and user-agent to Google when it makes those requests, as it must for any request to reach a server at all; Google holds those in its own operational logs under its privacy terms. We do not read them, keep them, or use them to work out where you are.

If you open your browser’s network inspector on the web app you will see three hosts, and no others: identitytoolkit.googleapis.com (signing in), firestore.googleapis.com (the progress and the lessons) and storage.googleapis.com (the pictures). You may also see a request to www.google.com/images/cleardot.gif — that is Google’s own connection check inside the Firebase library, a one-pixel image with no content, and we neither add it nor see its result. We would rather name it here than have you find it and wonder. The Firebase code itself is served from famzolearn.com, not from Google’s CDN, so nothing is requested from anyone before you sign in.

What we never collect

The app reads text aloud using the device’s own built-in speech, so nothing your child hears or says is sent anywhere. In the web app this is the browser’s own speech synthesis, which behaves the same way — and the microphone is never asked for, because reading aloud does not need one. Reminders are generated on the device; we do not operate push notifications.

Payments and subscriptions

The app is free to download and includes a free trial. There are two ways to subscribe, and they are handled by different people.

Bought inside the app

The purchase is handled entirely by Apple or Google under their own terms. We never see or store your card details. What we receive back from the store is whether a subscription is active and when it expires, held against the same random account identifier as your progress.

Your country for pricing and trial length is read from your App Store or Google Play storefront — the country your account is billed in. We do not use your IP address or your device location to work out where you are.

Bought on this website

The payment is taken by [PAYMENT PROCESSOR], a licensed payment processor acting on our behalf. You enter your card details on their page, not ours, and they never reach our servers — we still never see or store a card number. They hold your name, email address, billing country and the payment record as their own controller, under their privacy policy and under the card-network rules they are bound by; we receive back only the fact that a payment succeeded, the plan you bought, and when it renews.

We keep an invoice for each website purchase — your name, email address, billing country, the amount and the tax — because Indian tax law requires us to. That is the one record here that survives a deletion request, and only for as long as the law says. It is not linked to anything your child did in the app.

For a website purchase, the country used for pricing is the billing country you enter yourself. We do not geolocate you.

Children, and how a parent consents

This app is for children, so a parent or guardian sets it up and consents on the child’s behalf. Set-up asks for a parent’s email address and a password, and the child’s section is reached only after that.

Different countries define a child differently, and we apply the strictest rule that applies to you:

We do not show advertising to children, we do not profile them, and we do not use their data to decide what to sell them. There is nothing to sell.

Why we are allowed to hold it

In the UK and EU we rely on consent given by the holder of parental responsibility (GDPR Art. 6(1)(a) and Art. 8), on the necessity of processing to perform the contract where you have bought a subscription, and on our legitimate interest in keeping the service working and secure. In India we rely on the verifiable consent of the parent. You can withdraw consent at any time by asking us to delete the account.

How long we keep it

Progress data stays until you ask us to delete it, or until the account has been inactive for 24 months, whichever comes first. On-device data goes the moment the app is deleted. Backups are cleared within 90 days of a deletion. Records of a purchase may be kept longer where tax law requires it — in India that is 8 years for an invoice, and it is the invoice we keep, not the account.

Deleting everything

Email privacy@famzolearn.com from the address the account was created with and we will delete the account and all associated progress within 30 days, then confirm. Deleting the app from the device removes everything held locally straight away.

Where the data goes

Google’s Firebase infrastructure may process data outside your country. For transfers out of the UK or EEA we rely on the Standard Contractual Clauses in Google’s data processing terms. For India, transfers are made only to countries not restricted by the Government under the DPDP Act.

Your rights

Depending on where you live you may ask us to give you a copy of the data, correct it, delete it, restrict what we do with it, or object to it. In India you may also nominate someone to exercise these rights on your behalf. Write to privacy@famzolearn.com.

If you are unhappy with our answer you can complain to your data protection regulator — the ICO in the UK, your national authority in the EU, or the Data Protection Board in India.

This website

The public pages — the home page, the pricing page, this one — set no cookies, run no analytics and embed nothing from anyone else. No tag manager, no pixel, no font from someone else’s server. The example photographs are served from our own storage. If you email us, we keep that email so we can reply to it.

Two pages are necessarily different, and both only after you choose to use them:

We do not use cookies for advertising or measurement anywhere, on any page, so there is no consent banner to dismiss.

Changes

If we change how any of this works we will update this page and change the date at the top. If a change is significant we will tell you in the app, in the web app, and by email before it takes effect.

Contact

The Terms of Service sit alongside this policy and cover what you may do with the app, what a subscription costs and how to get a refund.

Privacy: privacy@famzolearn.com
Anything else: support@famzolearn.com