Privacy Policy
Effective Date: 15 October 2025
Lukkids (the "Service") is operated by MyCTOfriend, a company located at 190 Rue Topaze, 13510 Eguilles, France. We are committed to protecting the privacy of both parents and children who use Lukkids. This Privacy Policy explains what information we collect through our website and app, how we use and share that information, and your rights as a user or parent. This policy is designed to comply with the European Union's General Data Protection Regulation (GDPR) and the United States Children's Online Privacy Protection Act (COPPA). By using Lukkids, you agree to the practices described in this Privacy Policy.
Information We Collect
We collect only the personal information necessary to provide and improve the Lukkids experience. This includes:
- Parent Account Information: When you create a Lukkids account, we collect the parent or guardian's email address and a password. We may also collect a parent's name or other contact details if you choose to provide them (for example, if you contact support). This information is used to set up and secure your account, and to communicate with you about the Service.
- Child Profile Information: We ask you (the parent) to provide your child's first name and birth date (or age). We use this information to personalize your child's experience (e.g. addressing the child by their first name) and to ensure content is suitable for their age group. Note: Children do not create their own accounts or provide personal details directly – the child's profile is managed under the parent's account. We do not ask for or collect a child's last name, address, phone number, or other contact information. The app is designed so that your child can use it safely without sharing personal identifying details.
- Usage Data and Content: Lukkids may collect information about how the app is used and any content created or provided during use. For example, if your child interacts with Lukkids (such as by asking questions, chatting with our educational AI, or using other features), we will process and store those interactions. This usage data helps us operate the Service and monitor for appropriate use. We may log certain events or safety flags (for instance, if the system detects potentially inappropriate or concerning content in a child's interaction) so that we can review it and, if necessary, notify you or take action to keep the experience safe. This information is used internally to improve our AI and ensure a safe learning environment.
- Device and Technical Information: When you use our website or app, we may collect technical information such as your device type, operating system version, browser type, IP address, and general location (e.g. city or country). We collect this data to help diagnose technical issues, keep the Service secure, and understand how users access our Service. For example, an IP address can help us approximate your region to load the app faster or choose the right language, and it can also be used for security and fraud prevention.
- Cookies and Tracking Technologies: Our website uses cookies and similar technologies to enhance user experience and analyze usage. For instance, we might use cookies to remember your login session or preferences. We also use third-party analytics and tools (described in Cookies & Tracking below) that may set cookies to collect information about website visitors. These cookies can provide us with insights on how many people visit our site, which pages are popular, and how our marketing campaigns are performing. You can control or disable cookies through your browser settings, and we will obtain consent for non-essential cookies where required by law.
We do not collect any sensitive personal information such as financial information, government ID numbers, or any health-related data. We also do not intentionally collect any personal information from children beyond the limited details noted above. If we discover that a child has inadvertently provided personal information beyond what we request (for example, by typing a phone number or full name into the app), we will delete that information from our records.
How We Use Your Information
We use the collected information for the following purposes:
- Providing the Service: We use personal data to operate Lukkids and provide its features. For example, the parent's credentials allow you to log in and secure the app, and the child's first name and age allow us to tailor the educational content to be age-appropriate and personalized. The content of your child's interactions (questions, chat messages, etc.) is used to generate relevant educational responses and activities.
- Personalization and Experience: Children learn best when content is relevant to them. We might use your child's profile info (like age) to customize the difficulty of content or topics presented. We also may address the child by name within the app to create a friendly, personalized learning environment.
- Safety and Monitoring: Ensuring a safe experience is a core part of Lukkids. We monitor in-app interactions for safety and appropriateness. This means the system may automatically check the content of your child's questions or messages for things like harassment, explicit language, or personal data. If potentially inappropriate content is detected, we may take steps such as filtering the response, alerting our moderation team, or logging a safety flag in your account. These safety measures allow us to notify you (the parent) about any concerning behavior or incidents and to take action to protect your child. For example, if a child were to ask something that raises a red flag (like sharing personal contact information or experiencing bullying), we may record that event and inform you via the parent dashboard or contact you so you are aware. Our goal is to involve parents and keep children safe.
- Communicating with You: We use the parent's email address and contact info to communicate about account management and updates. This includes sending you necessary administrative emails (for example, to verify your account, confirm subscription or purchases if any, password resets, or important notices about security or privacy). We may also send educational content and updates about Lukkids to your email. For instance, we might send newsletters, tips for using the app with your child, new feature announcements, or special content offers. We consider these communications part of our service to keep you informed and help you and your child get the most from Lukkids. If at any time you prefer not to receive non-essential emails (like newsletters or tips), you will have the option to unsubscribe or opt out by following the instructions in those emails.
- Service Improvement and Analytics: The information about how you and your child use Lukkids helps us understand what is working well and what could be improved. We analyze usage data (in aggregated or anonymized form when possible) to debug issues, improve our AI models, enhance content, and develop new features. For example, if we see that a particular activity is very popular or that users are having difficulty with a certain section, we can focus our efforts accordingly. We also use analytics to measure the effectiveness of our educational content and our outreach efforts (like how people find our website).
- Compliance and Legal Reasons: Finally, we may use or disclose your information as necessary to comply with applicable laws and regulations, to respond to lawful requests by public authorities (e.g., child protection agencies or law enforcement), or to enforce our Terms of Service and other agreements. For example, we will use information to prevent fraud, protect the security of our website and app, and to ensure we are complying with parental consent requirements under COPPA and data protection laws under GDPR.
We will not use personal information for purposes that are incompatible with those above without obtaining your consent. If we ever need to process your data for a new purpose, we will update this Privacy Policy and notify you as required.
How We Share Information
We understand that your information and your child's information are sensitive, and we handle sharing with great care. We do not sell your personal information or your child's personal information to third parties for their own marketing or any other purposes. We only share data in the following circumstances:
- Service Providers: We use trusted third-party companies to help us run Lukkids. These service providers only receive the information necessary for them to perform specific services on our behalf. They are contractually obligated to protect personal information and use it only for the agreed-upon purpose. Key service providers we work with include:
- Cloud Hosting and Data Storage: We store our application data on secure servers in Europe (currently in Paris, France). Our hosting provider manages the physical infrastructure and database where your information is stored. They do not use your data for any purpose except maintaining and safeguarding our storage.
- Artificial Intelligence Processing (OpenAI): Lukkids uses AI technology to power some educational and interactive features. When your child interacts with our AI features (for example, asks a question or engages in a dialogue), the content of those messages may be sent to OpenAI, our third-party AI service provider, for processing and generating a response. OpenAI's servers are primarily located in the United States, so this means the data from those interactions might be transmitted and processed in the U.S. OpenAI acts as our processor – they are not permitted to use the information except to provide the service to us. We have agreements in place to protect the data shared with OpenAI. (For instance, OpenAI is bound by terms that limit how they can store or use the data we send, and we do not allow them to use it for training their public models.) The sole purpose of sharing this data is to provide your child with AI-driven educational responses and to monitor content for safety.
- Analytics and Tracking Tools: We may use third-party analytics services such as Google Analytics to collect information about how adults (parents) use our website and how you found us. Analytics providers set their own cookies or identifiers to gather usage data (e.g., which pages are visited, for how long, IP address, device information). This helps us understand website traffic and improve our outreach. We may also use marketing tools like the Facebook Pixel or Google advertising cookies on our website to help us reach interested parents on other platforms and measure the effectiveness of our ads. These tools allow us to know, for example, if a Facebook/Google ad led you to sign up for Lukkids. The information collected through these trackers may be combined with other data those providers have about you, depending on your settings with those services. Please note, these analytics and marketing tools are used only on our marketing website for parents, not within the children's app environment. We do not show third-party ads in the Lukkids app or use advertising trackers in the app interface that children use.
- Email and Communications: If we send emails or notifications, we might use an email delivery service (for example, a service like SendGrid, Mailchimp, or similar) to manage our mailing lists and send messages. Those services would have access to your email address and the content of the message, solely for the purpose of sending emails on our behalf. They are not allowed to use your email for anything else.
- Business Transfers: If MyCTOfriend (the company operating Lukkids) is involved in a merger, acquisition, investment, or sale of all or a portion of its assets, your information may be transferred to the new owner or partner as part of that transaction. If such a change in ownership happens, we will ensure that the successor entity is bound to respect the provisions of this Privacy Policy regarding your personal information, and we will provide notice to you (for example, via email or a prominent notice on our site) of the change and any choices you may have as a result.
- Legal Requirements and Safety: We may disclose personal information if we believe in good faith that such action is necessary to comply with a legal obligation or government request; to enforce our Terms of Service or other agreements; or to protect the rights, safety, or property of MyCTOfriend, our users, or the public. For instance, if required by law enforcement with the proper documentation, we might have to provide information. Or, if a disclosure could prevent an emergency involving a child's safety, we may share information with the appropriate authorities or the child's parent.
Aside from the situations above, we do not share or transfer your or your child's personal information to any third parties. Where we do share information with service providers, we remain responsible for how they handle your data under our instructions. We require all third parties to implement appropriate data protection measures.
Cookies and Tracking Technologies
Cookies are small text files stored on your device that help websites remember information about your visit. Lukkids uses cookies and similar technologies on our website (not the core children's app interface) for several reasons:
- Essential Cookies: These are cookies necessary for our site to function. For example, if our site has a login for the parent dashboard, a cookie may keep you logged in as you navigate. These cookies do not collect personal data for marketing, but simply keep the site working (e.g., session cookies).
- Preference Cookies: We might use cookies to remember your preferences (such as language selection or any customization on our site) so that you have a better experience on return visits.
- Analytics Cookies: As mentioned, we use third-party analytics (like Google Analytics) that set cookies to collect information about site traffic and user interactions. This data is aggregated and helps us see general usage patterns (for example, number of visitors, most viewed pages, how users find the site). Google Analytics may collect information such as your IP address, but we have configured it, where possible, to anonymize IPs and not share other identifying data. This analysis helps us improve the content and structure of our website.
- Advertising and Tracking Pixels: On our marketing pages, we may utilize pixels or cookies from services like Facebook or Google Ads. These trackers help us with interest-based advertising – meaning, they can inform us if someone who visited our site later signs up, or they can allow us to show ads about Lukkids to people who have visited our site or shown interest. For example, if you visited our site, we might later show you a Lukkids advertisement on Facebook to remind you of our service. The data collected through these trackers can include things like which pages you visited on our site and certain actions you took (like clicking a signup button). This information is used to measure our marketing effectiveness and to reach parents who might be interested in Lukkids. Importantly, none of these advertising or tracking cookies are used in the children's portion of the app. They are only present on parent-facing web pages (such as our homepage, info pages, or blog).
We will ask for your consent to use any non-essential cookies when you first visit our website, in accordance with applicable laws. You have choices when it comes to cookies and tracking:
- You can refuse or withdraw consent for non-essential cookies using the cookie banner or settings on our site (if available).
- You can also disable or clear cookies through your browser settings. Most browsers allow you to block cookies or delete them. Keep in mind, disabling cookies may affect certain functionality (for instance, if you block all cookies, the parent login session might not persist).
- To opt-out of Google Analytics, you can use Google's opt-out browser add-on, and for interest-based ads, services like Facebook and Google provide opt-out mechanisms through your account settings or via industry sites like the Network Advertising Initiative's opt-out page.
By using our site with cookies enabled, you are agreeing to our use of cookies as described here. We update our cookie practices as needed and will reflect changes in this Privacy Policy or in our Cookie notice if we maintain a separate one.
Children's Privacy and Parental Controls
Protecting children's privacy is at the heart of our policy:
- Parental Account and Consent: Lukkids is intended for use by children only with a parent or guardian's involvement and consent. We require a parent or legal guardian to create the account, provide the child's profile information, and set up the app for the child. By creating your child's profile on Lukkids and agreeing to this Privacy Policy, you (the parent) are providing consent for us to collect and use your child's personal information as described. We do not knowingly allow a child under 13 to sign up for Lukkids or provide personal information directly; all personal data (like name and age) must be submitted by a parent or guardian. This approach ensures compliance with COPPA and similar child data protection laws.
- No Additional Child Data Collection: Aside from the child's first name and age (provided by the parent), Lukkids does not ask children to input personal details. Children using the app interface are not asked for their contact information, last name, address, or any other identifying information. We strongly discourage children from trying to share any personal information about themselves or their family while using Lukkids. The interactive features in Lukkids are designed to educate and engage without collecting personal data. If at any point your child attempts to enter personal information into the app (for example, typing an address or full name in a chat), our system is designed to ignore or redact such information, and/or our moderators will remove it upon discovery to protect your child's privacy.
- Parent Dashboard and Controls: As a parent, you have control over your child's use of Lukkids. The app may include a Parent Dashboard or settings area that is accessible only with the parent's password or login. We encourage you to use these controls to supervise and guide your child's experience. For example, you might be able to review your child's activity history, see any flagged content, adjust content settings, or limit certain features according to what you feel is appropriate. We lock the parent settings behind your account login so that your child cannot access or change them. When your child is using Lukkids in "child mode," they will not be able to leave the app or access external links without parental input (where applicable), ensuring a contained and safe environment. To return to the parent Dashboard or make changes, your parent password is required.
- Parental Access and Rights (COPPA Requirements): As the parent or guardian of a child using Lukkids, you have the right to know what information we have collected about your child, to see that information, and to request that it be deleted. You also have the right to tell us to stop collecting or using your child's information. We are committed to honoring these rights. If you would like to review the personal information we have about your child (such as their profile and any stored usage content), or if you want us to delete your child's information, you can contact us at any time (see the Contact Us section below). For your child's safety and privacy, we may take steps to verify your identity as the parent or guardian before fulfilling such requests. For example, we might require you to contact us from the email associated with the account or provide some account identifying information. Once verified, we will provide you with the information we have, or carry out the deletion or cessation of data collection as you've requested. Please note, if you ask us to delete your child's data or to stop collecting it, we may have to close or limit the child's access to Lukkids, since certain data is necessary for providing the service (e.g., without age or an account, the app may not function as intended for your child). However, we will always comply with a parent's deletion request and will not refuse you based on your choice to exercise your rights.
- No Conditioning: In compliance with COPPA, we do not condition a child's participation in Lukkids (or any of its activities) on the child providing more personal information than is reasonably necessary. This means we only ask for the bare minimum information we need (first name and age to personalize the experience). Your child can fully enjoy the educational features of Lukkids without needing to divulge extra personal details. We also do not offer features that would allow your child to make personal information publicly visible to others. There are no public profiles for children within Lukkids, and children cannot communicate with unapproved external parties through our app.
If you ever have any concerns about your child's privacy or safety on Lukkids, please contact us. We value the involvement of parents in managing their children's online experiences and will work with you to ensure Lukkids remains a safe, trusted space for learning.
Data Security and Retention
We take the security of you and your child's personal information seriously. We implement a variety of administrative, technical, and physical safeguards to protect against unauthorized access, alteration, disclosure, or destruction of personal data. Here are some key measures we take:
- Secure Transmission: All communication between your device and Lukkids servers is encrypted using industry-standard encryption (HTTPS/TLS). This means that personal information (like login credentials or any content transmitted) is encoded in transit and cannot be easily intercepted by third parties.
- Access Controls: The personal data we store (such as account information and child profile data) is accessible only by authorized personnel who need it to operate and develop the service. MyCTOfriend staff and contractors who have access to personal data are bound by confidentiality obligations and are trained on privacy and security best practices. Internally, we limit access to sensitive data – for example, an employee assisting with a support request will only access the specific information needed to help you, and nothing more.
- Password Protection: Your account password is stored in a secure, hashed form (not in plain text) in our database. This means even our team cannot read your actual password. Always choose a strong, unique password for Lukkids and keep it confidential. If you suspect any unauthorized access to your account, let us know immediately so we can help you secure it.
- Infrastructure Security: Our servers are protected by firewalls and monitoring systems to guard against intrusions. We keep our software and systems updated to patch vulnerabilities. Regular backups are performed to prevent data loss, and those backups are secured as well. Additionally, any sensitive data at rest is stored securely (for example, we may use encryption at rest for certain types of data where appropriate).
- Testing and Reviews: We periodically review our security practices and may run security assessments or tests (sometimes called penetration testing) to identify and address potential weaknesses. While no system can be guaranteed 100% secure, we strive to use industry best practices and take prompt action if we discover any issues.
Data Retention: We retain personal information only for as long as it is necessary to fulfill the purposes described in this policy, or as required by law:
- Account Data: We will keep your account information (and your child's profile information) for as long as your account is active. This allows us to provide the service to you and your child continuously. If you decide to delete your Lukkids account or if we close the service, we will delete or anonymize personal information associated with your account (unless we are required to keep it longer for legal reasons). For example, if you delete your account, we will remove your and your child's personal details from our primary systems. However, data might persist temporarily in secure backups; if so, we will continue to protect it and delete it according to our backup retention schedule.
- Usage Data: Data such as logs and analytics may be kept in aggregate form to help us analyze and improve our service. Aggregated data (which does not identify individuals) may be retained longer than personal data, as it does not contain personal information. Any personally identifiable usage data will either be deleted or de-identified when it's no longer needed for our legitimate business purposes (for instance, if we have stored chat transcripts for safety review, we might delete or anonymize them after a certain period unless needed to investigate ongoing issues).
- Legal Obligations: In some cases, we may need to retain certain information to comply with legal obligations or resolve disputes. For example, we might keep records of financial transactions (if any) for accounting/tax purposes as required by law, or keep information if needed to enforce our agreements or to handle a legal claim.
We also follow a "data minimization" principle: we try not to collect or keep more data than we actually need. When personal information is no longer required, we ensure it is safely deleted or anonymized. If you have specific questions about our data retention practices, feel free to contact us.
International Data Transfers
Your data may be processed outside of your home country. MyCTOfriend is based in France, and our primary servers are located in the European Union. However, as noted earlier, we use certain service providers (such as OpenAI, Google, and Facebook) that are located in or have servers in other countries, including the United States. This means that when you or your child use Lukkids, some personal information might be transferred to and processed on servers in a country that may have different data protection laws than your country (for instance, the U.S. may not provide the same level of legal data protection as the EU does).
Whenever we transfer personal data out of the European Economic Area (EEA), we take steps to ensure that appropriate safeguards are in place to protect that data in accordance with GDPR requirements. These safeguards may include:
- Standard Contractual Clauses: We have agreements in place with our service providers (such as OpenAI) that incorporate the European Commission's Standard Contractual Clauses, which are legal contracts designed to ensure that your personal data receives the same protection as it would inside the EU. These clauses bind the service provider to protect your data and give you rights to enforce if needed.
- Data Processing Agreements: For each third-party processor we use, we establish Data Processing Agreements that outline how they can process the data and require them to maintain strict confidentiality and security standards.
- Additional Protections: We also assess our providers' security measures and privacy practices. For example, OpenAI and our other processors implement robust security controls. In cases where our providers offer it, we enable additional privacy features (such as disabling data use for AI model training, as we do with OpenAI). We only transfer the minimum data necessary for the service to function.
By using Lukkids, you understand that your personal information and your child's information may be transferred to our servers and authorized third parties in countries other than your own. However, this will always be done in line with the protections described above. We will always treat your data securely and in accordance with this Privacy Policy, no matter where it is processed.
If you would like more information about international data transfers or the specific safeguards we have in place, you can contact us using the information at the end of this policy. We'd be happy to provide more details upon request.
Your Rights and Choices
We want you to feel in control of your and your child's personal information. As a user or parent, you have several rights regarding personal data that we collect and hold. These rights allow you to access, modify, or control what happens with your data. Below is a summary of your key rights and how you can exercise them:
- Access Your Information: You have the right to request a copy of the personal information we hold about you and your child. This includes your account information and any data associated with your child's profile or usage. We can provide this in a common digital format. For example, you may request to see what profile information and chat logs we have for your child.
- Correct or Update Your Information: If any of the personal information we have is incorrect or out-of-date, you have the right to request a correction. For instance, if you change your email address or realize the birth date on your child's profile is wrong, you can update this through the parent settings or ask us to update it. We encourage you to keep your information current to ensure your child's experience is appropriate for their age.
- Delete Your Information (Right to Erasure): You can ask us to delete the personal information we have about you and/or your child. As noted in the Children's Privacy section, parents can request deletion of a child's information at any time. You can also request deletion of your entire account. We will honor such requests, provided we don't have a specific legal obligation to retain the data. Deletion means we will remove your personal and profile information from our active databases. (As mentioned, residual information might remain in secure backups for a short period, but will be purged according to our backup policy.) Once deleted, the information cannot be recovered, so please be sure when you make this request. If you ever decide to come back to Lukkids after deletion, you would need to create a new account.
- Withdraw Consent / Object to Processing: Where we rely on your consent to process data (for example, for optional features or for sending newsletters), you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the legality of any processing we did prior to your withdrawal. Additionally, in certain cases, you may have the right to object to processing based on legitimate interests. For example, you can object to any direct marketing uses of your information. If you object, we will reconsider our reasons for processing your data and will stop or restrict processing unless we have a compelling legitimate ground or a legal requirement to continue.
- Restrict Processing: You can ask us to restrict or pause the processing of your data in certain circumstances. For instance, if you contest the accuracy of the information we hold or you want to ensure we no longer process data while you are in the process of exercising another right (like a deletion request), you can request a temporary restriction.
- Data Portability: For data that you have provided to us and that we process by automated means based on consent or contract, you have the right to request a copy in a portable format (e.g., a common machine-readable format like JSON or CSV). In plain terms, if you wanted to take the data you gave us (like profile info or certain content) and use it elsewhere or keep a copy, we will provide it to you when applicable.
- Lodge a Complaint: If you believe your privacy rights have been infringed or you are dissatisfied with our handling of any request you make, you have the right to lodge a complaint with a supervisory authority. As MyCTOfriend is based in France, our lead supervisory authority is the CNIL (France's data protection authority). You can contact the CNIL or your local data protection authority in the EU/EEA. We would, however, appreciate the chance to address your concerns directly first, and we are committed to resolving any issues in good faith. Please feel free to reach out to us with any concerns, and we will do our best to help.
- Opt-Out of Marketing Communications: As mentioned, if you no longer wish to receive our newsletter or other non-essential communications, you can opt out at any time. The easiest way is by clicking the "unsubscribe" link in any marketing email we send. You can also contact us directly to be removed from our mailing list. Note that even if you opt out of marketing or educational emails, we may still send you important administrative messages (for example, updates about your account, security alerts, or changes to our policies), as those are not promotional in nature.
To exercise any of your rights, you can contact us at any time (see Contact Us below). We will respond to your requests as soon as possible, and in any case within the timeframe required by law (GDPR typically requires within one month). There is no fee for making a request, though if a request is repetitive or excessive, the law permits us to charge a reasonable fee or refuse – but we have not had to do that, and we will always explain our reasoning if we ever were to refuse a request. We may ask you for information to verify your identity (especially for sensitive requests like data access or deletion concerning a child) to ensure that we do not give out personal data to an unauthorized person.
Your trust is extremely important to us, and we believe that honoring your privacy rights is a crucial part of maintaining that trust.
Changes to This Privacy Policy
We may update or modify this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. If we make any significant changes, we will let you know by appropriate means so that you can review the changes before they take effect. For instance, we might notify you by email (sent to the address associated with your account) or by posting a prominent notice within the Lukkids app or on our website if the changes are substantial.
Some changes might be minor (for example, improving wording for clarity or updating our contact information). In those cases, we may simply update the "Effective Date" at the top of this policy. Significant changes (such as any changes in what data we collect, how we use it, or if we ever were to change our data sharing practices) will be clearly communicated to you.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of Lukkids after any update to this policy will be considered acceptance of the changes, to the extent permitted by law. If you do not agree with any changes to the policy, you have the choice to stop using the Service and, if you wish, delete your account as described above.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or any aspect of your privacy while using Lukkids, please do not hesitate to contact us. We are here to help and address any issues.
Operator: MyCTOfriend (operator of Lukkids)
Address: 190 Rue Topaze, 13510 Eguilles, France
Contact Form: You can reach us by using the contact form on our website: lukkids.com/contact
We will gladly answer your questions or assist you in exercising any of your rights. Your and your child's privacy is important to us, and we appreciate you entrusting Lukkids with your child's education and safety. Thank you for reading our Privacy Policy.