Legal
Privacy Policy — Their First Words
Last updated: September 7, 2026
Plain-language summary
- Their First Words is a flashcard app that helps parents teach early words and useful phrases to their children. The parent is the user; the child is the end-user.
- The app works without an account. Without one, the child’s profile and saved learning data (word and phrase progress, favorites, milestone state, and session history) stay only on your device and never reach our servers. Technical data, first-party analytics where enabled, and storefront purchase state may still be processed as described in §§3.4–3.5 and 4.3.
- An account is optional and created by signing in with Apple or Google — typically after purchasing the one-time Pro unlock — to save the child’s progress to the cloud and across devices. Only then are the child profile and saved learning data described below stored on our servers.
- We do not sell data. We do not share it with advertisers. There are no ads in the app. We do not track you across other apps or websites. Firebase derives an approximate country/region from request metadata for app configuration and first-party analytics; we never request GPS or precise location.
- The app uses Firebase (Google) for accounts, data storage, and first-party analytics. Apple or Google handles an in-app purchase directly for the version of the app downloaded from its store; the app sends them no child-profile or learning data for that purchase.
- On Android, a Google Play referral link may supply a creator affiliate ID. We keep only that ID—not the full referrer—and may associate it with a later new-purchase marker to attribute purchases to creator promotions and help determine affiliate compensation. It never changes price, access, or the purchase flow.
- You can delete your account and associated cloud profile data from inside the app at any time (Account → Delete account). Processor-held technical data follows the limited retention rules in §7.
This summary is informational. The full policy follows.
1. Who we are
This Privacy Policy describes how Their First Words LLC, a California limited liability company (“we,” “us,” “our”), collects, uses, and shares information through the Their First Words mobile application (the “App”), available on the Apple App Store and Google Play.
Contact:
- Email:
privacy@theirfirstwords.org - Postal address: Their First Words LLC, 2108 N St, Ste N, Sacramento, CA 95816, United States
We are the data controller for purposes of GDPR. For users in the United Kingdom, we act as data controller under UK GDPR.
2. Scope
This policy applies to information collected through the App itself. It does not apply to the App Store listing pages (governed by Apple’s and Google’s policies), or to any third-party website you may navigate to from the App.
3. What we collect
Using the App without an account: sections 3.1–3.3 describe what we store for a signed-in account. Without an account, the child profile (§3.2) and learning data (§3.3) exist only on your device — none of it reaches our servers. (§3.5’s technical data and §3.4’s purchase/referral state still apply as described there.)
3.1 Account information (created only when you sign in)
Accounts are created by signing in with Apple or Google (there is no App-specific password). When you do, we collect:
| Data | Source | Why we collect it |
|---|---|---|
| Email address | Your Apple or Google account (Apple users may share Apple’s private relay address instead of their real one) | Account identification |
| Firebase User ID (UID) | Generated by Firebase on first sign-in | Internal identifier for your account |
3.2 Child profile information
For each child profile, we store:
| Data | Source | Why we store it |
|---|---|---|
| Child’s first name | You type it | Personalized greeting; display in Progress |
| Child’s age range | You pick a range (0–24 months, 2–3 years, 3–5 years) | Serves age-appropriate word content |
| Character / avatar gender | You pick Boy or Girl | Sets the avatar’s art variant |
| Selected character (avatar) | You select it from a catalog | Display in the app’s top bar and flashcard screens |
| Accessory selection (optional) | You select it from a catalog | Display on the character avatar |
| Character avatar (generated image) | Created by the app from your character and accessory choices | Displays the personalized avatar |
| Content language | An app setting (default English); the parent changes it in-app, and it syncs across their devices | Selects the language of flashcard text and audio |
| Display & playback preferences | You set these in-app (e.g. voice, optional reference language, auto-advance, sound on/off, show/hide card text, image style, and the Progress chart / language views) | Remembered across your devices |
We do not collect: the child’s last name, the child’s email, the child’s date of birth (we use an age range only), the child’s photo, the child’s voice recordings, the child’s precise location, or any biometric data.
3.3 Learning data (generated as you use the App)
As the parent and child use the App together, we generate and store:
| Data | What it is |
|---|---|
| Word and phrase progress | For each word or phrase catalog ID, per language: whether it is in progress, learned (word), or said (phrase); a first-seen timestamp where present; and the relevant completion timestamp (learnedAt for words or saidItAt for phrases) |
| Favorites | Catalog content IDs the parent has marked as favorites (word slugs or TFP-### phrase IDs), and the date each favorite was added |
| Session events | Timestamps of completed practice sessions, the content language, and the library practiced (Words or Phrases) |
| Word and phrase milestone events | A timestamp recording when each Words or Phrases learned/said or practice-days milestone celebration was acknowledged. Words use w:<number> / d:<number> keys; Phrases use the separate p:w:<number> / p:d:<number> namespace so both ladders remain independent |
This data is tied to the parent’s account and the relevant child profile. It is used to display the Progress screen, populate the Words or Phrases selection on Today, and power each library’s in-app milestone celebrations.
Child profile deletion record. Created when you delete an individual child profile. It stores only childId, requestedAt, completedAt. Prevents an offline or stale device from recreating the deleted profile or its learning data. Retention: Kept until you delete the parent account.
3.4 Purchase state and Android referral attribution (from Google Play)
Pro is a one-time purchase handled directly by Apple or Google. The app asks the storefront on your device whether the current store account owns tfw_lifetime and uses that result only to unlock Pro. We do not link purchase ownership to your Firebase UID, keep a Firebase receipt or entitlement ledger, or transfer ownership between Apple and Google. The storefront keeps its transaction record under its own terms. Consent-gated Firebase Analytics may receive the product-interaction events described in §4.3, but never your payment-card details or child-profile data.
On Android only, when you install from a direct Google Play referral link, the App reads the first-party Play Install Referrer once for a new installation. We keep only a validated lowercase creator affiliate ID, the source (google_play_install_referrer), and capture time; the full referrer is discarded. If that installation later receives an explicit new tfw_lifetime purchase callback, we may add the product ID, observation time, and a one-way SHA-256 fingerprint of the Play purchase token. We never store the raw token, price, payment details, or a revenue/commission amount, and restored or historical purchases are not converted into new referrals.
This referral record is saved locally first. If you later use optional Apple/Google sign-in, the first signed-in Firebase UID on that installation may claim one owner-only record at users/{UID}/referrals/googlePlayInstall; a different account cannot overwrite or inherit it. We use this metadata to measure creator promotions, attribute referred purchases, and help determine compensation for our affiliate partners. The record itself does not calculate commissions or verify proceeds; compensation must be reconciled with actual storefront transactions. It cannot grant, deny, restore, or verify Pro and is not a claim that a transaction produced revenue (for example, Play license-test purchases can also produce store callbacks).
We never see your credit card number, expiration date, CVV, or any other payment information. Those are handled entirely by Apple or Google.
3.5 Technical data (collected automatically)
| Data | Source | Purpose |
|---|---|---|
| Firebase installation ID | Firebase SDK | Crash diagnostics; first-party analytics |
| Device language | Device | Future localization fallback (currently unused at launch) |
| Time zone | Device (Intl.DateTimeFormat) |
Scheduling optional, time-appropriate features |
| App version | App | Diagnostics |
| Approximate country/region | Firebase Analytics and Remote Config derive it from request IP metadata | App configuration; first-party analytics |
| First-party analytics events | Firebase Analytics in restricted mode | App usage analysis (see §4.3) |
| Crash report (device model, OS version, app version, stack trace) | Firebase Crashlytics | Diagnose + fix app crashes — no child data (see below) |
| Android creator affiliate ID + optional one-way new-purchase fingerprint | Google Play referral/purchase callback; stored locally and, after optional sign-in, Firebase | Attribute purchases to creator promotions and support affiliate compensation without an ad ID or third-party attribution service |
Crash diagnostics: if the App crashes we collect a crash report — device model, OS version, app version, and a technical stack trace (no child names, ages, or learning data) — via Firebase Crashlytics (Google), a processor under our Firebase Data Processing Addendum, to diagnose and fix stability problems.
App configuration: the App fetches remote configuration from Firebase Remote Config (Google) to check whether your installed app version is still supported, to display a maintenance notice during planned downtime, and to turn specific features on or off. This request includes your Firebase installation ID, the app version, and basic device information (operating system, language, and time zone). Firebase automatically derives and collects a country code from request IP metadata. It does not send your account, child-profile, or learning data. Firebase Remote Config is a processor under our Firebase Data Processing Addendum.
3.6 Feedback you send us (you give us this)
If you choose to send feedback through the App (Account → Send feedback), we store the message you write, together with your account’s user ID, the app version, your platform (iOS or Android), the active flashcard language, and the time you sent it. We use this to read and act on your feedback. The in-App channel does not promise a direct reply; contact support@theirfirstwords.org when you need one.
The legal basis is performance of a contract / handling the request you initiated (GDPR Article 6(1)(b)) — the same basis as your account data.
We ask you not to include your child’s name or other personal details in your message, and we never attach any child profile data to it. If personal details slip in, we remove them when we act on the feedback. Feedback is private — it is sent only to us and is never shown to other users. It is deleted when you delete your account (see §7 and §8).
3.7 What we explicitly do not collect
- Push-notification tokens — the App does not send phone (push) notifications, so it does not request push permission or store a device push token
- Advertising ID (IDFA on iOS, AAID on Android) — disabled by configuration in Firebase Analytics
- GPS, precise location, and device Location Services — not requested. Firebase derives approximate country/region from request metadata as disclosed in §3.5; this requires no location permission.
- Contacts list — not requested
- Photos or camera roll — not requested
- Microphone — not requested
- Audio recordings of you or your child — the App plays audio TO the child; it never records
- Browsing history across other apps or websites — not collected
- Social media identifiers — not collected
- Full Google Play referrer strings and raw purchase tokens — parsed or hashed in memory, then discarded
4. How we use information
4.1 To provide the App
To create and maintain your account, store and display child profiles, track word and phrase progress, present the Today, Words, and Phrases libraries, manage favorites, and run flashcard sessions.
4.2 Purchase management and creator referrals
To ask Apple or Google on the device whether the current storefront account owns the one-time Pro unlock, so paid content is available. On Android, we also use the first-party Play Install Referrer to measure which creator referral link led to a new installation and may associate that minimized referral record with a later new-purchase callback. This helps us measure affiliate marketing and determine compensation for creators who promote the App. Referral processing is optional metadata and never affects billing or access. We do not display ads in the App or use referral records to target ads or send marketing messages to users.
4.3 First-party analytics (Firebase Analytics, restricted mode)
We use Firebase Analytics in “restricted” configuration:
google_analytics_adid_collection_enabled: false— advertising ID collection is disabledgoogle_analytics_default_allow_ad_storage: falsegoogle_analytics_default_allow_ad_user_data: falsegoogle_analytics_default_allow_ad_personalization_signals: false- Google Signals are disabled at the Firebase project level
- No Audiences are exported to Google Ads or other advertising platforms
We track in-app events — for example session_started and session_completed (including the session’s content language and playback settings, such as the voice and auto-advance mode used), word_learned, phrase_said_it, and word_favorited (the relevant catalog content ID), category_opened, paywall_viewed, language_changed, audio_failed (so we can tell when word or phrase audio fails to play on a device), and purchase events — to understand how the App is used in aggregate.
Firebase Analytics assigns an app-instance identifier and derives approximate country/region from request IP metadata. We do not assign your Firebase account UID as the Analytics User-ID. We also do not send child names, age ranges, avatar selections, profile identifiers, child counts, or child-added/switched/deleted events to Analytics. The request IP is discarded by Google Analytics before an event is logged; the derived approximate geography may remain with the event. We do not collect GPS or precise location.
For completed sessions we also record the content language (for example, how many sessions were in Spanish) so we can see which languages families use in aggregate. This is installation-scoped usage data, not a child-profile field.
We do not collect a date of birth. We also do not send the child’s name, age or age range, avatar selection, or profile identifier as an Analytics user property or event parameter. The parameters we record are product-usage dimensions — for example a catalog word, phrase, or category identifier, the content language, and playback settings.
You control analytics with an in-app privacy setting. Analytics is off unless you turn it on, in every region. You can turn it off at any time; turning it off stops collection going forward. Voluntary sign-out and account deletion reset the device-scoped Analytics app-instance data before the auth boundary, but previously collected events may remain under the retention rule in §7 and are not keyed to your account UID. This restricted-mode analytics supports only the App’s internal operations — we do not use it for advertising, and we share no analytics data with any third party for their own purposes.
4.4 Communications
- We currently send no marketing, digest, or automated operational account email because no outbound email provider is connected. Material notices use the App and the hosted policy unless another legally permitted channel is available. Adding outbound email requires this policy and the processor inventory to be updated first.
4.5 Legal compliance and safety
To comply with legal obligations, respond to lawful requests from public authorities, and detect, prevent, or address fraud or abuse.
4.6 App configuration and version support
We use Firebase Remote Config to check whether your installed app version is still supported (and prompt you to update if it is not), show a maintenance message during planned downtime, and enable or disable specific features. This relies only on your app version, installation identifier, basic device information, and approximate country derived from request metadata; it does not read or transmit any account, child-profile, or learning data.
5. Who we share information with
We do not sell your data. We do not share it with advertising networks. Firebase acts as our contracted processor; Apple or Google acts as the storefront for a purchase you choose to make:
| Processor | What they receive | Purpose | Contractual basis |
|---|---|---|---|
| Google (Firebase) | All account data, child profile data, learning data, optional Android creator-referral metadata, first-party analytics events, crash/session diagnostics (Crashlytics/Firebase Sessions), installation/app-instance identifiers, and remote-configuration request metadata (app version, device information, approximate country) | Authentication; database; creator-referral measurement; analytics; crash reporting (Crashlytics); remote configuration (Remote Config) | Firebase Data Processing and Security Terms |
| Apple / Google (store purchases) | Payment information you provide directly to the storefront; its transaction record; the app’s request to buy or check ownership of tfw_lifetime |
In-app purchase processing and same-store restore | Apple Privacy Policy / Google Play Terms |
Our processors are bound by contract to use the data only to provide the specific service we engage them for, not for their own purposes, and not to combine it with data from other sources for profiling. Store purchases are also governed by the Apple or Google terms linked above.
We do not engage advertising networks, third-party attribution SDKs (Branch, Adjust, AppsFlyer, etc.), third-party analytics services (Mixpanel, Amplitude, PostHog, etc.), session replay tools (FullStory, LogRocket), or any other data-broker-adjacent service. Android referral measurement uses only Google Play’s first-party Install Referrer through Expo Application.
6. Children’s privacy
Their First Words is parent-led: the App is intended for parents to use with their child. The child does not create an account, sign in, type, or make any choices that send data to us — every piece of information about the child is entered by the parent.
We design and operate as if the Children’s Online Privacy Protection Act (COPPA), the GDPR’s protections for children (Article 8 / GDPR-K), and the UK Children’s Code (Age Appropriate Design Code) all apply, because the data we hold is about an identifiable child.
6.1 United States (COPPA)
Verifiable Parental Consent (VPC). No child data reaches our servers before consent — without an account, the child’s profile and learning data live only on the parent’s device. When the parent chooses to save that data to the cloud, they create an account by signing in with their own Apple or Google account. At that sign-in the parent agrees to our Terms of Service — which include confirming that they are the child’s parent or legal guardian (see Terms §2) — and to this Privacy Policy, and consents to our collection and use of their child’s profile and learning data as described in this policy. This authenticated, parent-agreed account creation is the consent transaction; child data is stored server-side only under that account, and the parent’s email address is already verified by Apple or Google.
No third-party disclosures of child data. As noted in §5, every processor that handles child-related data is bound by a data processing agreement to act only on our behalf. We disclose no child data to third parties for their own use. Because our collection supports only the App’s internal operations and involves no such disclosure, COPPA permits us to obtain parental consent through an email-based method (16 CFR §312.5(b)(2)(viii)); we are not required to obtain a separate, more rigorous form of consent such as a credit-card transaction, government-ID check, or video call.
Retention. See §7.
Parental rights. Parents may, at any time:
- Review the child’s information stored under their account (visible in-App on the Progress screen and Account → Personalize)
- Refuse further collection by deleting the child profile or the entire account in-App (see §8)
- Receive a copy of all child data on request (email
privacy@theirfirstwords.org)
6.2 European Union and United Kingdom (GDPR / UK GDPR / Children’s Code)
Legal basis. Processing of parent account data is under contract (GDPR Article 6(1)(b)). Processing of child profile data is under the parent’s verified parental consent (Article 6(1)(a) and Article 8 for the child’s data) given via account creation. Optional analytics is processed under the parent’s separate, granular consent settings managed in-App.
Android creator-referral processing described in §§3.4 and 4.2 relies on our legitimate interests (Article 6(1)(f)) in attributing purchases to creator promotions and determining affiliate compensation. We limit this processing to the referral and purchase metadata described above, without advertising IDs, child-profile data, or cross-app tracking. This processing is separate from the optional Firebase Analytics setting. You can object to this use of your information by contacting privacy@theirfirstwords.org (see §8.2).
Child’s age threshold. We treat every account as if the most restrictive EU member-state threshold (age 16) applied. Because the parent is always the account holder and always provides consent on the child’s behalf, the per-country variance does not change our flow.
UK Children’s Code. We have completed a Data Protection Impact Assessment (DPIA) covering all 15 standards; the DPIA is available on request to privacy@theirfirstwords.org. Notable defaults:
- Geolocation: no GPS, precise location, or device Location Services. Firebase derives only approximate country/region from request metadata for app configuration and first-party analytics.
- Profiling: none. We do not infer behaviour or build advertising profiles of children.
- Nudge techniques: we explicitly avoid them. There are no streak guilt prompts, no manipulative reminders, no rewards for engagement.
- Default privacy settings: we send no marketing, digest, or automated operational account email. There is no email a parent must opt out of.
- Connected toys / devices: not applicable.
Data Protection Officer. We have not appointed a Data Protection Officer because we do not meet the GDPR Article 37 thresholds (no large-scale systematic monitoring; no large-scale special-category data). Privacy inquiries are handled by our privacy contact at privacy@theirfirstwords.org.
7. How long we keep information
| Category | Retention |
|---|---|
| Active accounts (signed in within the last 24 months) | For as long as the account is active. |
| Android referral record on the device | Until App data is cleared or the App is uninstalled. A reinstall may receive a new Play referrer. |
| Android referral record linked to an account | While the account exists; removed by account deletion. |
| Inactive accounts (no sign-in for 24 months) | A 30-day grace period begins, then we automatically delete all child profile data (name, age range, character/avatar gender, progress, favorites). The parent’s Firebase Auth record remains so the parent can sign back in to a fresh slate — and the Pro purchase is unaffected: it belongs to the parent’s Apple/Google account and restores on a compatible device using that same storefront account. We do not promise an email warning because no outbound email provider is connected. |
| Feedback you send us (§3.6) | Stored while your account is active; deleted when you delete your account (in-App or via the 24-month inactive-account deletion). |
| Parent-initiated deletion | Active account data is removed when the in-App deletion cascade succeeds. Residual processor backup/replication copies follow the limited deletion cycle below. See §8. |
| First-party analytics events | Up to 14 months under Firebase Analytics’ available event-data retention settings. Our configured target is 2 months; the live console setting is external state. |
| Server-side logs | Application logs normally follow Google Cloud Logging’s 30-day _Default retention, while audit logs and custom-routed buckets can retain longer (including 400 days for _Required logs). Live routing and retention are console-controlled. |
We do not create a separate application backup of deleted user data. Google may retain residual copies in backups or replication systems during its deletion cycle for up to 180 days, unless law requires longer retention. Those residual copies are not available to the active App and are deleted under Google’s processor terms.
8. Your rights and how to exercise them
8.1 In-App account deletion (recommended)
Inside the App: Account → Delete account. A confirmation modal will ask you to type “DELETE” to proceed. After re-authentication, the App will:
- Delete your account record (
users/{your UID}), all child profiles, progress, milestone events, any linked Android referral record, and any feedback you sent us from our database - Delete any per-user content in Storage
- Delete your Firebase Authentication record
Your one-time Pro purchase is not part of the App account or deletion cascade. It stays with your Apple/Google store account; deleting your App account neither refunds nor removes it, and there is no ongoing billing (see §9).
When the deletion cascade succeeds, the account and active application data are removed immediately and cannot be restored through the App. There is no application soft-delete, grace period, or undelete option. Residual processor backup/replication copies follow the limited retention described in §7.
8.2 Other rights
You may also exercise the following rights by emailing privacy@theirfirstwords.org:
- Access. Request a copy of the personal data we hold about you and your child.
- Rectification. Ask us to correct inaccurate data. (Most child profile data can be edited in-App via Account → Personalize.)
- Erasure (“right to be forgotten”). Same effect as in-App deletion; we provide this manual route in case in-App deletion is for some reason unavailable.
- Restriction. Ask us to temporarily stop processing your data while a dispute is resolved.
- Portability. Request a copy of your data in a machine-readable format (JSON).
- Objection. Object to processing based on legitimate interests, including Android creator-referral attribution and affiliate compensation, by emailing
privacy@theirfirstwords.org. - Withdraw consent. To withdraw consent for the underlying account and all associated processing, use account deletion (Account → Delete account).
We will respond within 30 days. If we need to extend that window for complex requests, we will tell you why.
8.3 Right to lodge a complaint
If you are in the EU/UK and believe we have mishandled your data, you may complain to your national data protection authority. The UK’s authority is the Information Commissioner’s Office (https://ico.org.uk). A list of EU authorities is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
9. Purchases and billing
The Pro unlock is a one-time in-app purchase processed by Apple (App Store) or Google (Play Store), not by us. We never receive your payment card information.
There is no subscription and no recurring billing — you are charged once, when you confirm the purchase, and never again. There is nothing to cancel.
Refunds are handled by Apple and Google under their own policies. Deleting your App account does not refund or remove the purchase; it stays with your Apple/Google account and can be restored on a compatible device using that same storefront account via Restore purchases.
10. International data transfers
Our data is processed on Google Cloud / Firebase infrastructure, which may operate in multiple regions. Where data is transferred outside your country (notably from the EU/UK to the United States, where Google’s primary infrastructure is located), the transfer is governed by:
- For EU/UK transfers: the European Commission’s Standard Contractual Clauses as incorporated into Firebase’s Data Processing Terms.
- Google’s certifications under the EU–US Data Privacy Framework (DPF) and UK Extension.
You may request a copy of the relevant safeguards by emailing privacy@theirfirstwords.org.
11. Security
We implement industry-standard security practices, including:
- All network traffic between the App and our servers is encrypted via TLS 1.2+
- Database access is restricted via Firebase Security Rules so that each parent can only read and write their own account data and that of their own children
- The committed App Storage rules deny every client read and write, including authenticated clients; deployed-rule state is verified separately
- There is no App-specific password to store or breach — sign-in is delegated to Apple and Google
- Cloud Functions secrets (Apple sign-in token revocation credentials) are stored via Google Secret Manager and accessed only by authorized server-side code
- We maintain a documented data-protection compliance baseline (available on request)
No system is perfectly secure. If we ever become aware of a security incident that compromises your data, we will notify you and any required regulator within the timeframes prescribed by applicable law (72 hours for GDPR; without unreasonable delay for COPPA / state laws).
12. Changes to this policy
We may update this policy from time to time. When we do, we will:
- Update the “Last updated” date at the top.
- If the change is material (for example: a new category of data, a new processor, or a new purpose of processing), notify you in-App at least 30 days before the change takes effect and use another legally permitted channel when one is available.
- Keep prior versions of this policy available on request at
privacy@theirfirstwords.org.
Continued use of the App after a non-material change indicates acceptance of the updated policy. For material changes, we will obtain renewed parental consent where required.
13. Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your data:
- Email:
privacy@theirfirstwords.org - Postal: Their First Words LLC, 2108 N St, Ste N, Sacramento, CA 95816, United States
For users in the EU/UK, you may also lodge a complaint with your national supervisory authority as described in §8.3.