Privacy policy
Last updated: 7 August 2026
Cosmos: Space Quiz for Kids is a learning app for children about space and the cosmos. This policy explains, in plain language, what the app does and does not do with data. It is written to be read by a parent.
The short version: we collect no personal information from children, children never sign in, and there are no ads and no third-party tracking anywhere in the child experience — ever.
The short version
- We do not collect any personal information from children. No name, no email, no birthday, no photo, no location, no contacts, no device identifiers used for tracking.
- Children never sign in. There is no child account and no login anywhere in the child-facing app. A child opens the app and starts learning.
- There are no ads and no analytics in the child experience. No ad networks, no behavioural advertising, no tracking, ever.
- The parents’ area is measured. Once the parental gate is passed we record which parent screen was opened, which setting was changed, and how a purchase or restore ended, using Firebase Analytics. It is switched off until the gate is passed and switched off again when you leave, so it never runs while your child is using the app. Advertising identifiers are disabled, and no event describes your child. What Firebase attaches to those events, and why it is not tracking, is set out in full below.
- A parent may optionally create an account, behind a parental gate, solely to back up their child’s learning progress so it survives a lost or replaced device. The app is fully functional without it.
What is stored on the device
All learning content ships inside the app and works fully offline. Unless a parent turns on backup (below), the app stores the following only on the device:
- Learning progress: which questions have been answered, whether each was answered correctly or marked “I don’t know yet”, how many slides were seen, and the resulting star counts.
- Preferences: reduce-motion, sound on/off, and read-aloud toggles.
None of this describes the child as a person. It is anonymous learning state.
What the parents’ area measures
This is the one place the app measures anything, and it is worth being precise rather than reassuring.
When. Never at launch, and never while a child is using the app. Firebase Analytics is switched off before any of our code runs, stays off through the whole child experience, and is switched on only at the moment the parental gate is passed — a two-digit sum that a young child cannot do. It is switched off again the moment you leave the parents’ area. Everything below therefore happens only while an adult is holding the phone.
What we send. Which parent screen was opened (dashboard, settings, backup, purchase); which control was used; which plan was selected; and how a purchase or restore attempt ended. Event values are limited to yes/no flags, counts and a short fixed list of names — there is no free text, and no field in this app for a child to type into.
What Firebase attaches on its own. Being honest about a third-party SDK means naming what it adds, not only what we ask for:
- An app-instance ID — a random identifier Firebase generates for this installation. It is not your Apple or Google account, not your device’s advertising identifier, and not shared with anyone. Deleting the app ends it.
- Approximate location, meaning the country or region Google derives from the IP address the events arrive on. Not GPS, not a street, not a city block.
- Ordinary technical context: app version, operating system version, device model, language.
What is switched off at the build level, so it cannot be collected even while measurement is on: the advertising identifier (IDFA on iOS, the advertising ID on Android), the Android device ID, the iOS vendor identifier, ad personalisation, ad storage, ad-network attribution, and Firebase’s automatic screen tracking. There is no Google Ads link and no Google Signals. Nothing here is used to advertise to you, and nothing follows you into another app or website.
What is never measured. The onboarding, the learning slides, the question map, the quiz and the results screen are not instrumented at all — not even anonymously. One consequence we accept: because measurement only begins once the gate is passed, we cannot tell how many people start the gate and give up.
The optional parent account (backup only)
A parent can sign in — only from behind a parental gate — to back up the child’s progress to the cloud. This is optional and off by default.
- Sign-in is provider-only: Sign in with Apple or Google. We never create, store, or reset a password, because there is no password.
- What the backup stores: an opaque account identifier, the parent’s email address (provided by Apple or Google as the account holder), the same anonymous learning-progress blob described above — including the reduce-motion, sound and read-aloud preference toggles, so a restored device comes back set up the way your child had it — a mirror of purchase status, and timestamps.
- What the backup never stores: the child’s name, age, birthday, photo, voice, location, device tracking identifiers, or anything the child typed — there is nothing in this app for a child to type.
- The parent’s email is account-holder contact information, which is permitted. It is never used for advertising and is never associated with any child.
Each account can only ever read or write its own backup row. This is enforced at the database level (Row Level Security), not merely in the app.
The optional purchase
The app is unlocked by a purchase — either a monthly plan that opens with a 3-day free trial and renews until cancelled, or a lifetime unlock paid once. Purchases are handled by the App Store and Google Play through RevenueCat, which validates receipts and restores purchases. Every route into a purchase passes through a parental gate first, and the price, the billing period and the renewal terms are shown in plain language before any purchase.
Deleting your data
- Delete the app: removes all on-device progress and preferences.
- Delete your account (Backup & account screen, behind the parental gate): permanently erases your cloud backup and account. On-device progress is kept. Deletion cascades — removing the account removes the backup row.
You can also ask us to delete a backup by writing to cosmos@ripeseed.io from the account’s email address.
Who we share data with
We do not sell data and we do not share data for advertising. The only third parties involved are the infrastructure providers that make backup and purchases work:
- Supabase — stores the parent account and the progress backup (only if a parent signs in).
- RevenueCat / Apple App Store / Google Play — process purchases and validate receipts.
- Google (Firebase Analytics) — receives the parents’-area events described above, and only those. Google acts as our data processor for them; they are not used for advertising, not linked to a Google Ads account, and not combined with anything else about you.
Nothing about the child is transmitted to any of them.
Children’s privacy (COPPA / GDPR-K)
This app is designed for children and complies with COPPA and equivalent children’s privacy rules. We do not knowingly collect personal information from children. The only personal datum in the system is the parent’s email, and only when the parent chooses to sign in.
Contact
Questions about this policy: cosmos@ripeseed.io