← Back

Privacy & Cookie Policy

Last updated: 30 July 2026

Phonics Path teaches early reading to children aged roughly 4–7. Accounts are created and controlled by a parent or legal guardian, who is the person we deal with for all privacy matters. Children never create accounts themselves and we never ask a child for personal details.

Who is responsible for your data

AEJ Language Academy is the data controller for Phonics Path. You can reach us at ae.jlanguageacademy@gmail.com.

What we collect and why

  • Parent email and password — to create and secure the account. Passwords are stored only as salted hashes by our authentication provider; we never see them. Lawful basis: performance of a contract.
  • Child's first name or nickname — used only to greet the child in the app. A nickname is perfectly fine, and we encourage it. Lawful basis: parental consent, given when you create the account.
  • Lesson progress — which lessons are complete, stars earned and attempt counts, so learning continues across devices. Lawful basis: contract.
  • Subscription status — whether the account is free, trialling or subscribed, plus the identifiers our payment provider gives us. Lawful basis: contract and legal obligation (tax records).
  • Technical logs — error and security logs containing the request time and a truncated identifier. Lawful basis: legitimate interest in keeping the service safe.

Voice and microphone

When a lesson asks the child to say a sound, the browser captures a short audio clip (usually a few seconds). That clip is sent over an encrypted connection to a speech service purely to check whether the sound was produced, and is discarded immediately after the check. We do not store, replay, sell or train models on your child's voice, and no audio is kept on our servers or in our database.

The microphone is only ever activated by tapping the record button, and you can refuse or revoke microphone permission in your browser at any time — the rest of the app keeps working.

Children's privacy (COPPA, GDPR Art. 8)

We do not knowingly collect personal information directly from children. The only child-related data we hold is the nickname and progress a parent chooses to create. A parent can review, correct or delete that data at any time from the Me page or our data deletion page. There is no chat, no user-to-user contact, no public profile, no behavioural advertising and no third-party ad tracking anywhere in the app.

Cookies and similar technology

We use as few as possible, and none for advertising:

  • Strictly necessary — a session token that keeps you signed in, and a cookie remembering your cookie choices. These cannot be switched off.
  • Payment — our payment provider sets cookies inside its own secure checkout window so a purchase can be completed safely.
  • Embedded video — lesson videos are embedded in privacy-enhanced mode so the video provider does not track viewing for advertising.

You can change your consent at any time using the cookie banner control at the bottom of the page.

Who we share data with

Only processors who help us run the service: our hosting and database provider, our speech-checking provider (audio only, not retained), our video provider for lesson playback, and our payment provider. We never sell personal data.

Payments: Paddle acts as the Merchant of Record for subscriptions. When you subscribe, Paddle processes your payment, billing, tax, and invoice details. You can read their privacy notice at paddle.com/legal/privacy.

Some processors are outside the UK/EEA; transfers rely on Standard Contractual Clauses or an adequacy decision.

How long we keep it

  • Account and progress data: while the account is open, then erased on request.
  • Inactive accounts: deleted after 24 months without a sign-in.
  • Voice audio: not retained at all.
  • Invoices and tax records: as long as tax law requires (typically 6–7 years).
  • Security logs: up to 90 days.

How we protect it

All traffic is encrypted with HTTPS/TLS. Data is stored in an encrypted, access- controlled database where row-level security rules mean one family can never read another family's records. Administrative actions are logged. Payments are handled entirely by our payment provider — we never see or store card numbers.

Your rights

You can request access, correction, deletion, restriction, objection, or a portable copy of your data, and you can withdraw consent at any time. Use the data deletion page or email us; we respond within 30 days. If you are unhappy with our response, you may complain to your local data protection authority (in the UK, the ICO).

Changes

If we make a material change we will update the date above and, where required, tell you by email or an in-app notice.

See also our Terms & refunds.