🔒 Privacy draft

Privacy Policy

This policy describes the V4 Founder Beta as built. The beta is intentionally local-first and does not operate a cloud child account system.

V4 Founder Beta draft • Last reviewed 27 July 2026 • Requires operator/legal review before commercial launch

1. Who operates LumiQuest

Before public launch, replace: [Operator legal name], [registered address], [privacy contact email], and where required [EU/UK representative or DPO contact]. V4 does not invent those details.

2. What the V4 beta stores

Learning progress, a nickname, age number, settings, routine tasks, room-plan notes and garden observations are stored in the browser on the device using local storage. The service worker may cache site files for offline use. The beta does not transmit those records to a LumiQuest server because no backend is connected.

3. What we deliberately do not collect

  • No exact date of birth, child email, phone number or postal address.
  • No child photo, video, voice recording or biometric identifier.
  • No precise geolocation.
  • No school name or public child profile.
  • No child-to-child messages.
  • No behavioral advertising identifier or third-party analytics profile.
  • No payment-card data.

4. Parent and child controls

A parent can edit the local nickname/age and clear the browser data. Production accounts must add authenticated access, correction, deletion, export, consent withdrawal and regional rights workflows before they are enabled.

5. Children and consent

The Founder Beta is designed so children can use content without a cloud account. If production features later process child personal data, LumiQuest must apply the relevant regional age and parental-consent rules instead of using one worldwide age threshold.

6. Sharing and advertising

V4 contains no third-party ad network, behavioral advertising or data brokerage. Production vendors must be documented, contractually restricted and reviewed for child-data use before activation.

7. Retention and deletion

Browser-local data remains until it is cleared by the user/browser or the site storage is removed. A production backend must adopt purpose-based retention limits rather than indefinite child-data retention.

8. International transfers

There are no LumiQuest cloud transfers in this static beta. Production hosting, support, analytics and processors must be assessed for GDPR/UK GDPR, Korean PIPA, China PIPL and other applicable transfer rules before launch.

9. Security

The beta avoids server-side child data. Production requires authenticated parent access, encryption in transit and at rest, access controls, secrets management, audit logs, breach response, backups and vendor-security review.

10. Contact and complaints

Before launch, publish a real privacy contact and regulator/complaint information appropriate to each offered region.