Privacy Policy
Effective date: 31 August 2026
Apps: Nupo for iOS (bundle com.app.nupo) and Nupo for Android (package app.nupo.kid)
Provided by: InternSpirit Private Limited (India)
Contact: vishnu@internspirit.com
Nupo is a daily learning app for children aged 5–12, set up and controlled entirely by a parent or guardian. This policy explains what we collect, why, and the choices you have. It covers both the iOS and Android versions of Nupo; where the two differ, we say so explicitly. We wrote it to be read, not skimmed — it's short because we collect very little.
The short version
- The parent creates the account. On Android that means Sign in with Google or an email address and password; on iOS it means Sign in with Apple or Sign in with Google. Either way we get an email address for the parent.
- Children never create accounts, enter personal information, or see ads.
- Almost everything Nupo does — knowing which app was opened, showing lessons, counting minutes — happens entirely on the device and is never uploaded.
- We show no ads and use no advertising or marketing SDKs. We do use product analytics to see where parents get stuck setting Nupo up and whether families keep using it — never to profile anyone and never for advertising. No advertising identifier is collected, and nothing your child types or answers is ever sent. See Product analytics below.
- We never sell or share data with anyone except the infrastructure providers listed below.
Information we collect (parent account)
When a parent signs in and uses Nupo, we store the following in our cloud database (Google Firebase, operated by Google LLC):
| Data | Platform | Purpose |
|---|---|---|
| Your saved setup: your child's first name, their age range, and the owl's nickname | Android and iOS | So that signing in on a new phone, or after reinstalling, restores what you already set up |
| Parent's email address | Android and iOS | Account sign-in and, occasionally, to contact you about Nupo |
| Parent's name, if the sign-in provider supplies one | iOS | Addressing you correctly in the app |
| Which sign-in method was used (Apple or Google) | iOS | Signing you back into the right account |
| Account created / last active timestamps | Both | Understanding whether Nupo is being used |
| App version, device model, and OS version | Both | Debugging and support |
| Child's age band (a coarse range, never a birth date or name) | Both | Understanding which age groups use Nupo |
| Number of apps selected for lessons (a count only — not which apps) | Both | Understanding how Nupo is configured |
| Whether setup was completed | Both | Support, and knowing where people get stuck |
| How you heard about Nupo, if you told us during setup | Both | Understanding how people find us |
A note on Sign in with Apple. Apple lets you hide your real email address. If you choose that, we receive a relay address ending in @privaterelay.appleid.com and never see your actual email. That works perfectly well — you can use Nupo entirely through the relay.
Subscriptions. Nupo for iOS is a paid app; Nupo for Android is currently free and offers no purchases. On iOS, purchases are processed by Apple and we use RevenueCat to confirm whether a subscription is active. The RevenueCat SDK is also present in the Android app, ready for a future paid plan: it receives an account identifier so a subscription could follow your account, but no purchase is currently possible there. Neither we nor RevenueCat ever see your payment card, billing address, or Apple Account password — Apple handles all of that. RevenueCat holds only your purchase history and an account identifier so that your subscription follows you across devices and reinstalls. We have deliberately disabled RevenueCat's optional device-identifier and advertising-attribution collection.
We do not collect: your child's birth date or exact age, photos, contacts, messages, location, browsing history, the list of apps installed on the device, or any answer your child gives. The child's first name, their age range, and the owl's nickname are saved to your account — and only your account — purely so that signing in on a new phone restores your setup, as described in the table above.
Information that stays on the device
The following is stored only on the device and is never transmitted to us or anyone else:
- The parent PIN (stored as a salted cryptographic hash — we cannot read it, and it is never uploaded, so it has to be set again on a new phone)
- Daily usage and earned-time counters
- Everything about the child's learning session — every question shown, every answer given, progress and streaks. None of this is ever transmitted.
- Which app is in the foreground at any moment. This is read on the device to decide when to show a lesson, used in that instant, and never uploaded or logged.
Your child's first name and the owl's nickname used to live only on the device. Since 25 August 2026 they are also saved to your account so that a new phone or a reinstall restores your setup instead of making you answer every setup question again. They are readable only by your account and are deleted with it.
The permissions Nupo asks for, and why
On Android, Nupo uses the Usage Access permission to detect, on-device, when a chosen app comes to the foreground, and the Display over other apps permission solely to show the lesson screen. This information is processed in the moment and is never uploaded, logged, or shared.
On iOS, Nupo uses Apple's Screen Time framework (Family Controls, Managed Settings, and Device Activity) to pause and resume the apps you chose. This works differently from Android in a way that is worth understanding:
- You choose the apps in Apple's own picker, not ours. Apple hands Nupo an opaque token for each app — a meaningless identifier that we cannot decode. Nupo cannot see what apps are installed on the device, cannot read their names, and cannot see their contents.
- Nupo asks iOS to tell it when the earned minutes have been used up. iOS reports only that a threshold was reached — never what your child did.
- Nupo sends local notifications (generated on the device, not from our servers) when a session is nearly over.
- Screen Time authorization is requested by the parent, on their own device, for their own child.
On neither platform does Nupo request SMS, contacts, camera, microphone, or location permissions.
We never ask for permission to track you across other companies' apps and websites, because we never do it. Nupo contains no advertising identifier (IDFA), no App Tracking Transparency prompt, and no attribution SDK. The product analytics described below measure how our own app is used and never follow you anywhere else.
Children's privacy
Nupo is used by children under parental control, and we take that seriously:
- The account and all settings belong to the parent. The information about a child that reaches our servers is limited to three things the parent enters during setup: the first name (or nickname), the age range, and the owl's nickname, stored so the setup can be restored. We ask for nothing else about the child: no birth date, no photo, no contact details, and never their answers.
- The child-facing screens contain no ads, no external links, no purchases, and no data entry beyond answering learning questions, which are processed on-device and never stored on our servers or transmitted.
If you believe we have inadvertently collected personal information from a child, contact vishnu@internspirit.com and we will delete it promptly.
Where your data lives, and who processes it
| Processor | What they handle |
|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, and Firebase Analytics) | The parent account record and saved setup described above, plus the product-analytics events listed under Product analytics. Google also handles Sign in with Google on both platforms, and email/password sign-in on Android. |
| Apple Inc. (iOS only) | Sign in with Apple, and all payment processing for subscriptions. |
| RevenueCat, Inc. (iOS purchases; the SDK also ships on Android) | Confirming whether a subscription is active. Purchase history and an account identifier only. Android is currently free, so RevenueCat holds only an account identifier there. |
| PostHog, Inc. (iOS only) | The product-analytics events listed under Product analytics. Hosted in PostHog's US region. No session replay and no automatic capture — only the events we write ourselves. |
All data is encrypted in transit (TLS), and database access rules ensure each account can only ever read or write its own record.
We use no advertising SDKs, no crash-reporting SDKs, and no data brokers. We do not sell, rent, or share your personal information with third parties for their own purposes.
Product analytics
Nupo uses product analytics so we can tell where the app is failing parents. Before we added it we had no way of knowing that a parent had installed Nupo, tried to sign in, and been blocked. We use two tools:
- Firebase Analytics (Google LLC) — on Android and iOS.
- PostHog (PostHog, Inc.) — on iOS only.
Both are configured to record only the events we deliberately write into the app. We do not use session replay, screen recording, or automatic capture of taps and gestures. Nothing is recorded from the screens your child sees beyond the fact that a lesson happened.
What we record:
- Which setup step was reached, and where a parent stopped.
- Whether each permission was granted or skipped (Android), or whether Screen Time access was granted (iOS).
- Whether signing in succeeded or failed, and a short technical reason code when it fails (for example
invalid-credential). We never record what was typed. - That a lesson was shown on the device, that it was completed, or that a parent used their PIN to skip it — plus a once-a-day marker that Nupo was used.
- The child's age band (such as 7–8), the chosen subject, and how many apps are gated.
What we never record:
- Your child's name, the owl's name, your name, or anything else typed into the app.
- Any question your child saw, or any answer they gave. Those never leave the device.
- Screen recordings, screenshots, or a general log of what was tapped.
- Your advertising ID. Because Nupo is for children, there is no advertising identifier in either app — on Android it is removed from the app entirely and ad personalisation and ad-user-data signals are switched off; on iOS there is no IDFA and no App Tracking Transparency prompt, because we never track you across other companies' apps. Analytics data is tied only to a random, app-specific identifier that is destroyed when you uninstall Nupo.
PostHog is configured to discard IP addresses, so they are never stored with our analytics events. Firebase Analytics uses the network address to derive an approximate country, which is why a country breakdown appears in our reports. Neither is precise location: we cannot tell what city, area or address anyone is in.
This data is used solely to improve Nupo. It is never used for advertising, never sold, and never shared with anyone other than Google and PostHog as the processors running the service on our behalf.
Where your data is processed
Our processors — Google, Apple, RevenueCat and PostHog — are United States companies, and your data is processed on their infrastructure, which may be in the United States or in other countries where they operate. Our PostHog project is hosted in PostHog's US region. Where the law requires a safeguard for such transfers (for example the GDPR), we rely on our processors' standard contractual clauses and equivalent data-protection terms. All data is encrypted in transit.
How long we keep data
We keep your account record for as long as your account exists. When you delete your account (see below), your account and profile record are permanently deleted from our systems. Data stored only on your device is yours: it is removed when you clear Nupo's storage or uninstall the app.
Note that Apple and Google keep their own records of purchases and refunds under their own retention policies, which we do not control.
Your rights and choices
You can, at any time:
- View what we hold about you — email us and we'll send you a copy.
- Delete your account and all associated data:
- iOS: Parent settings → Delete account
- Android: Settings → Account → Delete account
- or by emailing us. See our Data Deletion page.
- Correct your details by deleting the account and signing up again.
- Cancel a subscription at any time in Settings → Apple Account → Subscriptions on iOS. Deleting your Nupo account does not cancel an Apple subscription; you must cancel it with Apple separately. (Nupo for Android is currently free, so there is nothing to cancel.)
We respond to all requests within 30 days. Depending on where you live, you may have additional rights under laws such as the GDPR or India's DPDP Act; we honour reasonable requests regardless of jurisdiction.
Changes to this policy
If we change what we collect or how we use it, we will update this policy and its effective date, and — for material changes — inform you in the app before the change applies.
Contact
Questions, requests, or concerns: vishnu@internspirit.com
