Privacy Policy

Effective 16 September 2026 · Policy version 1.2

About this notice

Conkerly (“we”, “us”) builds short daily practice for children in Years 1–6, used by a parent or carer on their child's behalf. This notice explains what personal data we collect, why, and what rights you and your child have over it.

If you have any question about this notice, or want to exercise any of the rights below, email us at [email protected]. That address reaches the people who handle data protection directly; [email protected] is for everything else.

Who is responsible for your data

Conkerly is the data controller for the personal data described in this notice — we decide what's collected and why. We're a small team; every request that comes to our contact address is read and actioned by a real person.

Data about you (the parent or carer)

  • Your email address — to identify your account and let you sign in.
  • A password, if you choose to sign in with email and password — we never store your actual password, only a one-way, irreversible scrambled version of it (a “hash”) that can't be turned back into your password, even by us.
  • A short-lived verification code or link, if you're confirming your email address or resetting your password — it stops working after a few minutes or a single use.
  • Your display name.
  • If you sign in with Google or Microsoft instead: those providers confirm your identity to us and pass us your email and name. Your social sign-in never sees, and is never told, anything about your child.
  • A record of the device your family uses Conkerly on, so your child can be recognised on a trusted tablet without you signing in every time — we store a scrambled version of the device's login token, never the token itself.
  • Whether you've opted in to marketing emails — off unless you actively turn it on.
  • Sign-in and security records: your session and device history, plus a note of each sign-in that failed, each time the account was locked, each device you marked as trusted, and each time your password changed. These notes include the internet (IP) address the request came from — that's how we can tell your own sign-in from someone else trying to guess their way into your account. We use them only to keep your account secure, and we never record what was typed in a failed attempt.

Data about your child

  • A first name or nickname you choose for them — never a surname.
  • An avatar (a picture they pick from a set we provide) — never a photo of them.
  • Their year group (Year 1–Year 6-ish) — this is the only age-related detail we ever collect; we never ask for or store a date of birth.
  • A 4-digit PIN, if they sign in on a shared family device — stored the same one-way, scrambled way as a password, never as the plain PIN.
  • If you choose to set one up, a username and password so your child can sign in on a device that isn't the family tablet (e.g. a school computer). You choose the username; we reject anything that looks like a real name, email address or phone number, and it's stored the same one-way, scrambled way as any other password.
  • Their answers to practice questions, and how they're getting on — which questions they got right, how long they took, and their progress by subject and topic. This is what lets the app choose sensible next questions and lets you see their progress.
  • If someone gets your child's PIN or password wrong, we record that it happened and the internet (IP) address it came from — usually your home broadband. A 4-digit PIN is quick to guess at, so knowing that someone has been trying is most of how we protect their profile. We never record what was typed, and we never record the username that was guessed at.

What we deliberately never collect about your child

This isn't just a policy promise — it's built into the database itself, so this data can't be added later without a deliberate, reviewed change:

  • No surname or full legal name.
  • No date of birth — only the year group.
  • No home address, postcode or other location.
  • No child email address or phone number.
  • No health, biometric or other special category data.
  • No photo of your child, and no free-text messages or open chat with anyone.

Why we process this data, and our legal basis

  • Running your account, your child's profile(s), and delivering practice and progress reporting. Performance of our contract with you (UK GDPR Article 6(1)(b)) — you're the account holder, and this is the service you've signed up for.
  • Keeping the service secure — preventing fraud and abuse, rate-limiting, and audit. Our legitimate interests (Article 6(1)(f)), balanced against your rights — this is low-intrusion and what you'd reasonably expect from any online service.
  • Sending you marketing emails. Your consent (Article 6(1)(a)), which is off by default and only used if you actively opt in. You can withdraw it at any time.

A note on children and consent: in the UK, the digital age of consent is 13, and Conkerly's children are younger than that. We don't rely on a child's own consent for the core service — you, the parent, are the contracting party, and we process your child's data to deliver the service you've asked for on their behalf.

For children: what we know about you

  • What we know about you: your first name (or a nickname), the avatar picture you chose, what year group you're in, and how you get on with your practice questions.
  • What we never know: your surname, your birthday, where you live, your email address, or your phone number.
  • Who can see how you're doing: your grown-up can see your progress. No one else can — there's no chat, no messaging, and nobody outside your family can contact you through Conkerly.
  • How the app picks your questions: Conkerly picks questions that are just right for you — not too easy, not too hard — based on how you've been getting on.

Extra protections for children's data

  • High-privacy settings by default — a child is never ranked or scored against other children unless a parent actively opts them in. That covers leaderboards and the standardised scores on your progress dashboard: with it off, your child's readiness is measured against a fixed reference rather than against other children. The setting lives on your child's details in the parent portal, it is off until you turn it on, only a parent can change it, and you can turn it off again at any time.
  • No advertising, and no advertising or tracking SDKs of any kind on the parts of Conkerly your child uses.
  • No marketing is ever directed at children — the only marketing preference in the whole system belongs to the parent account, and it's off unless a parent turns it on.
  • No open chat, messaging, or any way for another person — child or adult — to contact your child through Conkerly.
  • We never sell personal data, to anyone, for any reason.

Who else handles this data

We use a small number of specialist companies (“processors”) to run Conkerly. Each only sees the data it needs to do its specific job, and none of them are permitted to use your family's data for their own purposes. Your family's account and your child's practice data are stored in the EU (Frankfurt).

  • Auth0 (an Okta company), EU region. Verifies a parent's identity when you sign in with Google or Microsoft. Auth0 only ever sees a parent's email, name and social-account identifier — it never sees any data about your child.
  • Render, EU (Frankfurt). Hosts our database and servers. This is where all parent and child personal data is stored.
  • Cloudflare. Delivers public, non-personal assets (question graphics, app files) quickly to your device. No personal data passes through Cloudflare.
  • Google Workspace (email delivery). Sends account emails on our behalf — email verification codes and password-reset links — to a parent's own email address. It never sends anything to or about a child (children don't have an email address on Conkerly). These emails are delivered through Google's mail infrastructure, which may route them outside the EU; each one contains only a parent's own email address and a sign-in code or link.

How long we keep your data

We keep your family's account and progress data for as long as your account is open, so the app can keep working the way it's supposed to — remembering your child's progress between sessions, for instance.

If your subscription ends, we keep your child's practice history for a further 90 days before deleting it. That grace period is there on purpose: a lapse is usually just a card that expired, and if you come back within three months your child picks up exactly where they left off, streak and all. After 90 days the answer-by-answer history is removed.

The security records described above are kept for 12 months and then deleted. They exist to let us spot someone trying to break into an account, and a sign-in attempt from two years ago cannot help with that.

You can ask us to delete some or all of your family's data at any time, free of charge, by emailing [email protected]. Deleting a child's profile, or your whole family account, removes every piece of linked data in one action — their profile, their practice answers, their progress, and their sign-in records.

One deliberate exception, so this page doesn't overstate what deletion does: the security records described above aren't thrown away, they're stripped of everything that points at you. The internet address is erased and the link to your family is removed, leaving an anonymous note that a sign-in failed at a particular time — something nobody can trace back to you or your child. We keep that because it's how we'd still see an attack in progress against other families.

Your rights (and your child's)

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you or your child.
  • Have inaccurate data corrected (rectification).
  • Ask us to delete your or your child's data (erasure).
  • Ask us to restrict how we use your data (restriction).
  • Receive your data in a portable format, or ask us to send it to someone else (portability).
  • Object to processing that's based on our legitimate interests (objection).
  • Withdraw consent at any time, where we rely on consent (e.g. marketing emails).

To exercise any of these rights, for yourself or on your child's behalf, email [email protected]. It's free of charge, and we respond to every request personally.

Complaining to the regulator

If you're unhappy with how we've handled your data, we'd like the chance to put it right — email us first. You also have the right to complain directly to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk (opens in a new tab).