โ† Back to PocketPals

COPPA Compliance Notice

Children's Online Privacy Protection Act โ€” How PocketPals complies

๐Ÿ”’ COPPA Compliant from Day One

What is COPPA?

The Children's Online Privacy Protection Act (COPPA) is a U.S. federal law that protects the privacy of children under 13. It requires operators of websites and apps directed to children to obtain verifiable parental consent before collecting personal information from children.

PocketPals is an app designed for children ages 3โ€“12. We take COPPA seriously โ€” not as a compliance checkbox, but as a core design principle. Children's privacy is baked into every feature we build.

How PocketPals Complies with COPPA

What We Do NOT Collect from Children

Identity

  • Full name
  • Exact birthdate
  • Photo or video
  • Physical address

Contact

  • Phone number
  • Email address
  • Social media handles
  • School name

Behavioral

  • Location data
  • Behavioral ad profiles
  • Cross-app tracking data
  • Stored voice audio

We collect only: first name, age range (3โ€“4, 5โ€“7, or 8โ€“12), conversation transcripts (text only), and learning progress. Voice audio is processed in real time and never stored.

Subprocessors โ€” Who We Share Data With

PocketPals is built by NuStack Digital Ventures LLC (Wyoming). To operate the service, your child's data passes through the following subprocessors. Each has a signed Data Processing Agreement (DPA) with us requiring COPPA-compliant handling:

Subprocessor Purpose Child Data
Anthropic, PBCBuddy LLM responses (Claude)Yes โ€” conversation text. Does not train on PocketPals data.
OpenAI, LLCSpeech-to-text (Whisper STT)Yes โ€” voice audio chunks, immediately discarded post-transcription
ElevenLabs, Inc.Buddy voice synthesis (TTS)Indirect โ€” Buddy reply text only, no child voice input
Supabase, Inc.Database + storage (us-east-1)Yes โ€” profiles, transcripts, memory facts
Vercel, Inc.Application hosting, edge computeIn transit only
Stripe, Inc.Web pathway parent payment + COPPA verificationNo child data โ€” parent billing only
RevenueCat, Inc.Native pathway subscription managementNo child data โ€” parent subscription only
Apple Inc.iOS in-app billingNo child data โ€” parent App Store account only
Google LLCAndroid in-app billingNo child data โ€” parent Play Store account only
ResendTransactional email (parents)Indirect โ€” parent email + child first name in digest only
PostHog Inc.Product analyticsYes โ€” UUID + event names only. Never first names or transcripts.
Sentry, Inc.Error monitoringIndirect โ€” scrubbed payloads only, no child PII
Clerk, Inc.Operator surface authenticationNo child data at launch โ€” ops surface only
Inngest, Inc.Background job processingYes โ€” UUIDs and operation types only
Doppler, Inc.Secrets managementNo user data
Cloudflare, Inc.DNS, edge securityIn transit only

AI Safeguards (Anthropic)

PocketPals uses Anthropic's Claude model to power Buddy's responses. The following safeguards are in place per our agreement with Anthropic:

Data Retention

Voice transcripts are retained for 90 days, then converted to summaries. Summaries are retained while the account is active plus 30 days. Moderation and safety events are retained for 24 months. Parental consent records are retained for 7 years. Audit logs are retained indefinitely. Upon account deletion, all child data is deleted within 30 days and you will receive a confirmation email with a deletion certificate ID.

Your Rights as a Parent

How to Exercise Your Rights

You can exercise any of the rights above by:

We will confirm the action by email and complete it within 30 days of receiving your request.

Data Deletion Requests

To request deletion of all data associated with your child's account:

Request Data Deletion โ†’

Include your account email in the message. We will complete deletion within 14 days and send a confirmation email with a deletion certificate ID. What is preserved: parental consent records (7-year legal hold) and anonymized aggregate statistics (no child PII). What is deleted: all transcripts, summaries, memory facts, child profile, and usage data.

Questions about our COPPA compliance?

coppa@pocketpals.app

Read our full Privacy Policy โ†’

NuStack Digital Ventures LLC ยท Wyoming ยท We respond within 30 days.

COPPA Compliance Notice v3 โ€” 2026-04-25 ยท NuStack Digital Ventures LLC ยท Wyoming