Privacy and child safety
Privacy notice
Last updated: 14 July 2026
1. Who this notice is for
This notice explains how Gem Glow Academy handles information when a parent creates an account, creates a child profile, pays for membership, contacts support or allows a child to use the activities and palace. The parent is responsible for deciding whether the service is appropriate for their child and for supervising its use.
2. Information we handle
| Parent account | Email address, optional display name, Supabase account identifier, family access code and account settings. |
|---|---|
| Child profile | A first name or nickname, age band, avatar, securely hashed PIN, profile status and last sign-in time. We do not require a child email address. |
| Activity and palace data | Activities completed, completion time, room category, gems earned and spent, streak totals, owned palace items and saved item positions. |
| Billing | Subscription status, plan, Stripe customer and subscription identifiers and renewal date. Payment card details are handled by Stripe and are not stored in Gem Glow’s database. |
| Support and security | Messages sent to support, limited anti-abuse fingerprints, login attempts, technical logs and security events. |
3. Why we use it
- To create and secure parent and child access.
- To save progress, gems, purchases and palace layouts across devices.
- To provide subscriptions, billing support and payment recovery.
- To answer support requests and investigate faults or misuse.
- To protect children, families and the service from unauthorised access.
- To meet legal, accounting and safeguarding responsibilities.
4. Child accounts and PINs
Only a parent account can create, edit, archive or restore a child profile and reset its PIN. PINs are stored as one-way hashes. Resetting a PIN invalidates existing child sessions. A family code is a household login identifier and should only be shared with the children and trusted adults in that household.
5. Providers
We use carefully selected providers to operate the service: Supabase for authentication and database hosting, Vercel for website and server hosting, Stripe for subscriptions and payment management, and Resend for support email delivery. These providers process information only for the services they provide to us and under their own security and data-protection obligations.
6. Cookies and local storage
Essential browser storage is used to keep parent authentication active, hold a signed child session cookie, remember short-lived interface choices and provide a display-only cache when a page loads. Security-sensitive balances, item ownership and access rights are always checked on the server. We do not currently load advertising trackers or behavioural analytics within child activity, dashboard or palace pages.
7. How long information is kept
Account and progress information is normally kept while the membership or account remains active and for a limited period afterwards so that the parent can recover or export it and so that we can meet legal and accounting requirements. Short-lived login-attempt and contact anti-abuse records are intended to be deleted on a rolling schedule. A parent may ask for a child profile or family account to be deleted, subject to information we must retain by law.
8. Security
Security controls include server-side entitlement checks, row-level database security, restricted service credentials, signed HTTP-only child sessions, hashed PINs, rate limits, atomic gem and purchase transactions, Stripe webhook verification and security headers. No online service can guarantee absolute security, so parents should use a strong parent password and keep family codes and PINs private.
9. Parent choices and rights
A parent can update profile details, reset a PIN, archive a child profile and manage billing from the parent account. Depending on applicable law, the parent may also ask to access, correct, export, restrict or delete personal information, or object to certain processing. Contact support using the support page and include the parent account email so the request can be verified.
10. Automated decisions and sensitive information
Gem Glow does not use child activity data to make medical, educational or legal decisions. The service is not a diagnostic, counselling or therapy service. Children should not enter health information, private family information or other sensitive details into free-text fields.
11. Changes
We may update this notice when the product, providers or legal requirements change. Material changes will be highlighted to parent account holders before they take effect where appropriate.
12. Contact
Questions or privacy requests can be sent through the support page. Before public launch, the business should add its full legal entity name, registered address and dedicated privacy contact here.
