Children's Privacy Policy
This Children's Privacy Policy (the "Policy") explains how Nevzat Atilla Ozder ("Developer", "we", "us", or "our") handles information in connection with our kid-focused iOS app(s) (each a "Kids App", and together the "Kids Apps"). Our Kids Apps are designed for young children and the parents and guardians who provide the apps to them.
This Policy applies to all of our Kids Apps. It does not apply to our general (non-kids) apps; for those, please use the general Privacy Policy linked on their App Store listings or on our website. This Policy forms part of, and should be read together with, our Terms of Use. If there is a conflict between this Policy and the Terms of Use on a matter of privacy, this Policy controls.
This version is effective as of the "Last updated" date shown above and replaces any earlier version.
1) Who operates the Kids App (Data Controller)
- Data Controller / Operator: Nevzat Atilla Ozder
- Address: Cavus Mah. Muhtesem Sk. 6B/16 Sile / Istanbul, Turkiye
- Email: support@atillaozder.com
- Data Protection Officer: Not required; none appointed. Privacy enquiries go to the email above.
We are the "operator" of the Kids Apps for the purposes of the U.S. Children's Online Privacy Protection Act ("COPPA") and the "controller" for the purposes of the EU/UK General Data Protection Regulation ("GDPR") and Turkiye's Personal Data Protection Law No. 6698 ("KVKK").
2) Our privacy-by-design approach
We design our Kids Apps to collect as little information as possible from children. A Kids App runs on the device and does not require an account or login to use. We apply a high standard of protection appropriate to children, by design and by default, consistent with applicable children's privacy frameworks (including COPPA, as amended, and the UK Age Appropriate Design Code).
A) Information the Kids App does NOT collect
- No advertising and no advertising identifiers (IDFA).
- No advertising, behavioural analytics, or cross-app tracking SDKs. Where a Kids App offers a subscription (currently Kid Doodle), one measurement service receives a record of that purchase and nothing else — see section 2(C).
- No third-party tracking, profiling, or behavioral advertising.
- No push-notification token collection.
- No user accounts, login, email capture, or registration.
- No user-generated content shared with us (no chat, no profile, no uploads).
- No precise location (GPS), contacts, photos, camera, microphone, or health data.
- No biometric identifiers (such as fingerprints, faceprints, or voiceprints).
- No government-issued identifiers.
- No identifier that recognizes a user across apps, services or websites, and no profile built about anyone. There is one narrow exception, described in section 2(C): a random identifier created on the device when an app is installed, attached to subscription purchases so that we can measure our own advertising. It is not shared onward, is never used to target advertising, and can be reset by deleting and reinstalling the app.
No SDK of ours ever sees a child. Our Kids Apps integrate no advertising, social, behavioural-analytics or cross-app tracking software development kits (SDKs). Where a Kids App offers a subscription (currently Kid Doodle), it uses one service, RevenueCat, solely to measure those purchases — see section 2(C). It is not given a name, a birthdate, an email address, a location, a device identifier, or anything a child does in the app.
B) Information processed by Apple (App Store / In-App Purchases / Diagnostics)
A Kids App uses Apple's App Store and, where offered, Apple's In-App Purchase system (StoreKit), including for any optional auto-renewing subscription. We do not receive your payment card information. Apple may process personal data when you download the app, make a purchase, or start, renew or cancel a subscription (for example, account, purchase, subscription and renewal information) under Apple's own policies, as an independent controller. Whether a subscription is active is decided on the device by StoreKit, so a Kids App continues to work normally with no internet connection, and we never receive your billing details.
Apple diagnostics (optional): If the device owner has opted in to share technical diagnostics with app developers in iOS settings, Apple may provide us with anonymized or aggregated crash and performance information to help us fix bugs. This information is provided through Apple's developer tools and is not used to track users.
Apple policies:
C) Subscription measurement (RevenueCat)
This section concerns a purchase made by an adult, not anything a child does. A subscription can only be started from a paywall that sits behind a parental gate, and is completed through Apple's own payment sheet; nothing a child draws, taps or spends time on is measured, recorded or sent anywhere. Where a Kids App offers an auto-renewing subscription (currently Kid Doodle), we send a record of each purchase to RevenueCat, Inc. (United States), which acts as our processor. We do this for one reason: to learn which of our own Apple Search Ads campaigns led to a subscription, so we can tell whether our advertising pays for itself. RevenueCat does not decide what an app unlocks — that is settled on the device by Apple's StoreKit — and the app never asks RevenueCat about you.
What is sent is the purchase itself: the product identifier, its price, and the date. It is labelled with a random identifier generated on the device at install, which is not linked to a name, an email address, an account, or any other app. We also send Apple's own AdServices attribution token, which identifies the advertising campaign, ad group and search keyword — it identifies the advert, not the person, and it is the standard token that requires no tracking permission.
What is never sent: no advertising identifier (IDFA) — the app does not include Apple's AdSupport framework at all — no name, birthdate or email address, no location, no contacts, photos, camera or microphone data, no device identifier, and nothing a child draws or does inside the app. The app shows no tracking-permission prompt because there is no cross-app tracking to ask about.
RevenueCat's own privacy policy is available at revenuecat.com/privacy.
D) Information you choose to send us (optional)
If a parent or guardian contacts us for support by email, we receive the information contained in that email (for example, the sender's email address and the message content). We do not ask children to submit personal information in a Kids App, and we do not require any personal information as a condition of using a Kids App's features.
Unsolicited information: If we learn that we have received personal information from a child without a parent's or guardian's involvement (for example, an unsolicited email), we will delete it as soon as reasonably possible and will not use or disclose it except as necessary to respond or to comply with law.
3) How we use information, and our legal bases
Because our Kids Apps use no advertising SDKs and no behavioural analytics, our use of personal information is limited to:
- responding to parent/guardian support requests sent to support@atillaozder.com;
- maintaining, securing, and improving the Kids Apps based on our own testing and on feedback you choose to send us (with no in-app behavioural analytics and no tracking);
- where a Kids App offers a subscription, measuring whether our own Apple Search Ads advertising leads to subscriptions, using purchase records that are not linked to a person (see section 2(C)); and
- complying with our legal obligations and exercising or defending legal claims.
We do not use information for behavioral advertising, profiling, or tracking, and we do not sell or rent personal information.
Legal bases (GDPR/UK GDPR): where the GDPR applies, we rely on our legitimate interests in operating, securing, and improving the Kids Apps, in understanding whether our own advertising to parents works, and in responding to your enquiries (balanced against your rights), on compliance with a legal obligation, and, where required, on your consent, which you may withdraw at any time. Because we direct the Kids Apps to children, we minimize processing and rely on parent/guardian-initiated contact rather than on collecting information from children.
Automated decision-making: we do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on children or parents.
4) How we share information
We do not sell or rent personal information. We share information only in these limited situations:
- With Apple: to process downloads, any in-app purchases, and any subscription (including renewals and cancellations) via the App Store.
- RevenueCat, Inc. (United States): our processor for subscription measurement, as described in section 2(C). It receives the purchase record and Apple's advertising attribution token, and no personal information about a child. It is bound by contract to act only on our instructions and may not use the information for its own purposes.
- Service providers: if we ever engage a processor to act strictly on our instructions (for example, email handling for support), they are bound by confidentiality and data-protection obligations and may not use the information for their own purposes.
- Legal and safety reasons: where required to comply with applicable law, lawful requests, or to establish, exercise, or defend legal claims, or to protect the rights, safety, and integrity of users, the public, or our services.
- Business transfer: in connection with a merger, acquisition, or sale of assets, subject to this Policy and applicable law.
5) Data retention
Consistent with the amended COPPA Rule, we keep personal information only for as long as is reasonably necessary to fulfill the specific purpose for which it was collected; we do not retain it for any secondary purpose and we do not retain it indefinitely. When it is no longer needed, we delete or anonymize it.
- In-app data: we operate no user-account database and hold no profile of any child. Where a Kids App offers a subscription, the purchase records described in section 2(C) are held by our processor for as long as we use the service to measure advertising, and are deleted on request (see section 8).
- Support emails: if you email us, we retain the correspondence only as long as reasonably necessary to respond and for legitimate recordkeeping, dispute-resolution, and legal-compliance purposes, after which we delete or anonymize it. You can request deletion at any time (see Section 8).
6) International transfers
We are located in Turkiye. RevenueCat, Inc. processes the subscription-measurement data described in section 2(C) in the United States. Apple and its service providers may process App Store, purchase, subscription, and optional diagnostics data in the United States and other countries under Apple's policies. Where we transfer personal information across borders and the GDPR/UK GDPR or KVKK applies, we rely on a lawful transfer mechanism — such as an adequacy decision or appropriate safeguards (including standard contractual clauses, binding corporate rules, or, under the KVKK as amended in 2024, a written undertaking authorized by the Turkish Data Protection Board) — to protect that information.
7) Security
We use reasonable administrative, technical, and organizational measures appropriate to the limited information we control (such as support emails) to protect it against unauthorized access, loss, misuse, or alteration. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8) Your rights (parents/guardians) and how to contact us
A) United States — COPPA
Our Kids Apps are directed to children, so COPPA applies. Consistent with COPPA, we do not knowingly collect personal information from children in the Kids Apps, and we do not condition a child's participation on disclosing more personal information than is reasonably necessary. Where a parent or guardian voluntarily emails us, we rely on COPPA's limited exceptions that permit collecting online contact information solely to respond to a specific request, after which we delete it.
As a parent or guardian, you may review any personal information we have received from or about your child, direct us to delete it, and refuse to permit its further use or collection, by contacting us at the email below. We will take reasonable steps to verify that you are the child's parent or guardian before acting on a request. Because the subscription record described in section 2(C) is labelled with a random per-install identifier and not with any detail about a person, we cannot look it up from a name or an email address; tell us the approximate purchase date and the Apple receipt, or simply ask us to delete it, and we will remove the record and stop the measurement.
No third-party disclosure for advertising: consistent with the amended COPPA Rule, we do not disclose children's personal information to third parties for targeted advertising or other unrelated purposes. We would obtain separate verifiable parental consent before making any such disclosure, which we do not currently make.
California & other U.S. state laws (incl. CPRA): we do not "sell" or "share" (for cross-context behavioral advertising) the personal information of children or of consumers of any age, we do not use sensitive personal information to infer characteristics, and we do not offer financial incentives in exchange for personal information.
To learn more about COPPA and children's privacy, you can visit the U.S. Federal Trade Commission's website.
B) GDPR / UK GDPR (EEA/UK)
If you are in the EEA or UK, you may have rights to access, rectify, erase, restrict, or object to processing of personal information, to data portability, and to withdraw consent where processing is based on consent.
If you are in the UK, we also take into account the heightened protections for children under the UK GDPR (as updated by the Data (Use and Access) Act 2025) and the ICO's Age Appropriate Design Code (the Children's Code).
Right to complain: you also have the right to lodge a complaint with your local data protection supervisory authority. We would, however, appreciate the chance to address your concerns first.
C) Turkiye KVKK (Law No. 6698)
For users in Turkiye, you have rights under Article 11 of the KVKK, including (among others) the right to:
- learn whether your personal data is processed;
- request information if it is processed;
- learn the purpose of processing and whether it is used in accordance with that purpose;
- know the third parties to whom personal data is transferred (domestically or abroad);
- request correction of incomplete or inaccurate data;
- request deletion or destruction under the applicable conditions;
- request that correction, deletion, or destruction be notified to third parties to whom data was transferred;
- object to a result against you arising exclusively from automated analysis; and
- request compensation for damages arising from unlawful processing.
How to exercise your rights (email)
Email: support@atillaozder.com
Please include the Kids App name, the type of request (access, deletion, etc.), and enough detail for us to locate
the relevant communication. We will respond within the timeframe required by applicable law. We do not charge for
exercising your rights except where permitted by law for manifestly unfounded or excessive requests.
9) Third-party links and Parental Gates
Our Kids Apps are designed to provide a safe environment for children.
Parental Gates: where a Kids App includes any link that leads outside the app (such as a link to our support email, website, this Policy, or other apps), that link is intended to be protected by a "parental gate" — a challenge designed to help ensure the user is an adult — to prevent children from accessing external content without supervision.
Third parties: if a parent or guardian chooses to navigate to a third-party website or service, that third party's privacy practices apply, and we are not responsible for them.
10) Apple Kids Category and child-directed requirements
To the extent a Kids App is offered in Apple's Kids Category or is otherwise treated as directed to children, we design it to comply with the additional requirements that apply. Our Kids Apps carry no behavioural advertising and no advertising SDKs, and transmit no personally identifiable information about a child and no device identifier to any third party. Where a Kids App offers a subscription, the single third-party service it uses (section 2(C)) receives a record of a parent's purchase, labelled with a random per-install identifier, and Apple's own advertising attribution token, which identifies an advert rather than a person. Neither is used to track a user across apps or services, which is why our Kids Apps show no tracking-permission prompt and collect no advertising identifier.
11) Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date, and, where a change is material, we will take additional reasonable steps to notify you (for example, in the app or on the store listing) where feasible. Your continued use of a Kids App after an update takes effect indicates your awareness of the updated Policy.
12) Contact
- Nevzat Atilla Ozder
- Cavus Mah. Muhtesem Sk. 6B/16 Sile / Istanbul, Turkiye
- Email: support@atillaozder.com