← Back to Wonderkit

Privacy Policy

1. Introduction

Wonderkit (“Wonderkit,” “we,” “us,” or “our”) is operated by Mesmeraiz Inc. This Privacy Policy applies to the Wonderkit website and service at wonderkit.dev (the “Service”). It describes the personal information we collect from the parent or guardian who creates a Wonderkit account, and the limited information collected about that parent's children as part of using the Service, and how that information is used, shared, retained, and protected.

This policy is written for a US audience and addresses the Children's Online Privacy Protection Act (COPPA) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). It does not address the EU/UK GDPR or other non-US privacy regimes.

By creating a Wonderkit account and adding a child profile, a parent or guardian agrees to the practices described in this Privacy Policy and in our Terms of Service.

2. Who we are

Wonderkit is a product of Mesmeraiz Inc, a Delaware C-Corporation, operating the Service at wonderkit.dev. Mesmeraiz Inc is the entity responsible for the collection and use of information described in this Privacy Policy.

For any question, concern, or request relating to privacy or this policy, contact us at privacy@wonderkit.dev.

3. The parent–child model

Wonderkit is designed to be used by children under the supervision of a parent or legal guardian (“parent”). Only a parent can create a Wonderkit account, and the parent remains the account holder for every child profile added to that account. Children do not register independently, do not have their own credentials, and cannot access Wonderkit without a parent first creating the family account.

Because the parent is the account holder, the parent is responsible for reviewing this Privacy Policy, deciding what information to add for each child profile, and controlling settings such as sharing and visibility on the child's behalf. See Section 6 for how this relates to parental consent under COPPA.

4. Information we collect

4.1 Information from the parent

4.2 Information about the child

All child information is entered or generated under the parent's control, when the parent adds a child profile and while the child uses the Service under that profile. We collect:

4.3 Information collected automatically

Our servers automatically log standard technical and security information necessary to operate and protect the Service (e.g., request metadata, error logs, and security-relevant events). Wonderkit does not use any third-party analytics services or advertising trackers — we do not run tools like ad pixels, cross-site tracking scripts, or third-party behavioral-analytics SDKs anywhere on the Service.

Device information: if you use the Wonderkit mobile app and allow notifications, we collect a push-notification token for your device so we can send you notifications (for example, when a child's creation is ready). This token is a device identifier; we use it only to deliver notifications and share it with our push-delivery provider (see Section 7). Alongside the token we also store your device's time zone (as reported by the device, e.g. “America/Los_Angeles”) so that notifications only arrive at a reasonable hour where you are, and never in the middle of the night. We use the time zone only for that timing decision; it is not shared with our push-delivery provider and is not used to locate you.

5. How we use information

We use the information described above to:

We do not use child information, or parent information, to serve targeted advertising, and we do not sell personal information. See Section 7.

6. Children's privacy & COPPA

6.1 How parental consent works today

Because Wonderkit is directed in part to children, we design the sign-up and account model around the parent as the point of consent and control. A parent gives consent for the collection of their child's information when they: (a) create a verified Wonderkit account — either by a magic-link sign-in to the parent's own email, or by signing in with an existing Google or Apple account — (b) add a child profile themselves, providing whatever name, avatar, and optional age they choose to enter, and (c) for paid plans, complete a payment-card transaction through Stripe, which serves as an additional signal that an adult is establishing and controlling the account.

We are continually strengthening our parental-consent process, and we may add further verification steps over time. If you have questions about how we obtain and verify parental consent, contact us at privacy@wonderkit.dev.

6.2 What we collect from children, and why

We limit the information collected about children to what is needed to operate the profile and the creative/chat experience described in Section 4.2: a name, an avatar, an optional age, the child's creations, chat transcripts with the guardian AI, safety-moderation flags, and usage telemetry tied to that child's profile. We do not collect a child's precise location, government ID numbers, or other sensitive identifiers, and we do not require a child to provide their own contact information (email, phone) to use the Service.

6.3 No behavioral advertising to children

We do not show advertising to children on Wonderkit, and we do not use a child's information to build advertising profiles or to serve them targeted or behavioral ads.

6.4 Parental rights

A parent may at any time:

To exercise any of these rights, or if you have any question about your child's information, contact us at privacy@wonderkit.dev, or use the in-app deletion controls described in Section 8.

7. How we share information / subprocessors

7.1 Subprocessors

We use the following service providers to operate Wonderkit. Each is contractually bound to use information only to provide services to us.

ProviderRole
SupabaseAuthentication, database, and file storage
AnthropicPowers the guardian chat companion and the AI builder that generates creations
OpenAIGenerates images used in creations
StripePayment processing and subscription billing
Resend (via Supabase Auth)Sends authentication and transactional email (e.g., magic-link sign-in)
Fly.ioHosts the Wonderkit application
Expo (Expo Application Services)Delivers push notifications to a parent's device; transmits the notification and the device's push token via Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM)
Google & AppleOptional "Sign in with Google/Apple" identity providers, used only if a parent chooses social sign-in (handled through Supabase Auth)
CloudflareDNS for wonderkit.dev; may process visitors' IP addresses when routing requests

We do not use content you or your child submit to Wonderkit to train AI models, and we do not permit our AI providers to use content submitted through their commercial APIs to train their general-purpose models. Our AI providers process this content only to generate the responses and creations you request.

7.2 We do not sell personal information, and we run no third-party advertising

Wonderkit does not sell personal information to anyone, and we do not run third-party advertising or ad-tracking on the Service.

7.3 Sharing creations

Wonderkit's Community Feed and creation-sharing features are off by default. A creation is only shared beyond the family's own account — whether via a direct share link or the Community Feed — if the parent affirmatively turns sharing on for that creation or for the account.

8. Data retention & deletion

We retain parent and child information for as long as the Wonderkit account is active, in order to provide the Service. A parent can delete an individual child's profile (and that child's creations, chat transcripts, and usage data) from the parent portal at any time. To delete an entire family account, contact us at privacy@wonderkit.dev.

When you delete data, we remove it from our active systems promptly and purge it from routine backups within 30 days. If an account becomes inactive, we may delete its data after an extended period of inactivity. We retain a child's personal information only as long as reasonably necessary to provide the Service.

We do not currently offer a self-service data export tool. If you would like a copy of your or your child's information, you may request it by contacting privacy@wonderkit.dev, and we will respond within 45 days.

9. Security

We use technical and organizational measures designed to protect information on Wonderkit, including:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account's security has been compromised, contact us immediately at privacy@wonderkit.dev.

10. California privacy rights (CCPA/CPRA)

This section applies to California residents and supplements the rest of this Privacy Policy, under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).

10.1 Categories of information collected and disclosed

The categories of personal information we collect are described in Section 4 (identifiers such as name and email; commercial information such as billing/subscription status; internet or other electronic activity such as usage telemetry; and, for child profiles, the profile, creation, chat, and safety-flag information described in Section 4.2). We disclose these categories only to the service providers listed in Section 7.1, for the business purposes described in Section 5.

10.2 Your rights

We do not offer financial incentive programs in exchange for personal information. Because we do not sell or share personal information, the CCPA's opt-in requirement for the sale or sharing of information belonging to consumers under 16 does not apply to Wonderkit's practices.

To exercise any of these rights, contact us at privacy@wonderkit.dev. We may need to verify your identity (and your relationship to a child's account) before completing certain requests.

11. Where data is stored

Wonderkit's database, storage, and hosting providers (Supabase and Fly.io) operate the infrastructure that stores Wonderkit data. That infrastructure is currently located in the Singapore (Asia Pacific) region. Because Wonderkit is a US company, your information — including information relating to children — is transferred to and stored outside the United States. Wherever data is processed, Wonderkit remains responsible for it and requires its providers, by contract, to protect it consistent with this policy.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change to how we collect, use, or share information — especially information about children — we will notify parents (for example, by email or an in-app notice) before the change takes effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.

13. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or your (or your child's) information, contact:

Mesmeraiz Inc
privacy@wonderkit.dev