Last updated: July 10, 2026
This summary is informational. The full policy follows.
This Privacy Policy describes how Their First Words LLC, a California limited liability company (“we,” “us,” “our”), collects, uses, and shares information through the Their First Words mobile application (the “App”), available on the Apple App Store and Google Play.
Contact:
privacy@theirfirstwords.orgWe are the data controller for purposes of GDPR. For users in the United Kingdom, we act as data controller under UK GDPR.
This policy applies to information collected through the App itself. It does not apply to the App Store listing pages (governed by Apple’s and Google’s policies), or to any third-party website you may navigate to from the App.
Using the App without an account: sections 3.1–3.4 describe what we store for a signed-in account. Without an account, the child profile (§3.2) and learning data (§3.3) exist only on your device — none of it reaches our servers. (§3.5’s technical data and §3.4’s purchase state still apply as described there.)
Accounts are created by signing in with Apple or Google (there is no App-specific password). When you do, we collect:
| Data | Source | Why we collect it |
|---|---|---|
| Email address | Your Apple or Google account (Apple users may share Apple’s private relay address instead of their real one) | Account identification |
| Firebase User ID (UID) | Generated by Firebase on first sign-in | Internal identifier for your account |
For each child profile, we store:
| Data | Source | Why we store it |
|---|---|---|
| Child’s first name | You type it | Personalized greeting; display in Progress |
| Child’s age range | You pick a range (0–24 months, 2–3 years, 3–5 years) | Serves age-appropriate content |
| Character / avatar gender | You pick Boy or Girl | Sets the avatar’s art variant |
| Selected character (avatar) | You select it from a catalog | Display in the app’s top bar and flashcard screens |
| Accessory selection (optional) | You select it from a catalog | Display on the character avatar |
| Character avatar (generated image) | Created by the app from your character and accessory choices | Displays the personalized avatar |
| Content language | An app setting (default English); the parent changes it in-app, and it syncs across their devices | Selects the language of flashcard text and audio |
| Display & playback preferences | You set these in-app (e.g. voice, auto-advance, sound on/off, show/hide word, image style, and the Progress chart / language views) | Remembered across your devices |
We do not collect: the child’s last name, the child’s email, the child’s date of birth (we use an age range only), the child’s photo, the child’s voice recordings, the child’s precise location, or any biometric data.
As the parent and child use the App together, we generate and store:
| Data | What it is |
|---|---|
| Word progress | For each word, per language: whether it has been seen, learned, or in-progress, and the date it was marked learned |
| Favorites | Words the parent has marked as favorites |
| Session events | Timestamps of completed practice sessions, and the content language of each session |
| Milestone events | When the child crosses 10/25/50/100/etc. learned-words thresholds |
This data is tied to the parent’s account and the relevant child profile. It is used to display the Progress screen, populate Today’s Words selection, and power the in-app milestone celebrations.
Pro is a one-time purchase handled by Apple or Google. RevenueCat (our purchase-management service) tracks whether the purchase has been made, keyed to an anonymous app identifier — and, once you sign in, to your Firebase UID (a purchase made before sign-in is linked to your account when you sign in).
When the purchase screen (paywall) is shown, we also send RevenueCat a paywall-view event so we can measure how many parents who saw the screen chose to buy. This event contains no information about your child.
We never see your credit card number, expiration date, CVV, or any other payment information. Those are handled entirely by Apple or Google.
| Data | Source | Purpose |
|---|---|---|
| Firebase installation ID | Firebase SDK | Crash diagnostics; first-party analytics |
| Device language | Device | Future localization fallback (currently unused at launch) |
| Time zone | Device (Intl.DateTimeFormat) |
Scheduling optional, time-appropriate features |
| App version | App | Diagnostics |
| First-party analytics events | Firebase Analytics in restricted mode | App usage analysis (see §4.3) |
| Crash report (device model, OS version, app version, stack trace) | Firebase Crashlytics | Diagnose + fix app crashes — no child data (see below) |
Crash diagnostics: if the App crashes we collect a crash report — device model, OS version, app version, and a technical stack trace (no child names, ages, or learning data) — via Firebase Crashlytics (Google), a processor under our Firebase Data Processing Addendum, to diagnose and fix stability problems.
App configuration: the App fetches remote configuration from Firebase Remote Config (Google) to check whether your installed app version is still supported, to display a maintenance notice during planned downtime, and to turn specific features on or off. This fetch sends your Firebase installation ID, the app version, and basic device information (operating system, language, and region) to Firebase; it does not send your account, child-profile, or learning data. Firebase Remote Config is a processor under our Firebase Data Processing Addendum.
If you choose to send feedback through the App (Account → Send feedback), we store the message you write, together with your account’s user ID, the app version, your platform (iOS or Android), the active flashcard language, and the time you sent it. We use this to read and act on your feedback and, where appropriate, to reply to you.
The legal basis is performance of a contract / handling the request you initiated (GDPR Article 6(1)(b)) — the same basis as your account data. Replying is inherent to a request you sent us, so no separate consent is required.
We ask you not to include your child’s name or other personal details in your message, and we never attach any child profile data to it. If personal details slip in, we remove them when we act on the feedback. Feedback is private — it is sent only to us and is never shown to other users. It is deleted when you delete your account (see §7 and §8).
To create and maintain your account, store and display child profiles, track learning progress, present Today’s Words and Categories, manage favorites, and run flashcard sessions.
To verify whether the one-time Pro unlock has been purchased (so paid content is available), via RevenueCat.
We use Firebase Analytics in “restricted” configuration:
google_analytics_adid_collection_enabled: false — advertising ID collection is disabledgoogle_analytics_default_allow_ad_storage: falsegoogle_analytics_default_allow_ad_user_data: falsegoogle_analytics_default_allow_ad_personalization_signals: falseWe track in-app events — for example session_started and session_completed (including the session’s content language and playback settings, such as the voice and auto-advance mode used), word_learned and word_favorited (which catalog word), category_opened, paywall_viewed, language_changed, audio_failed (so we can tell when a word’s audio fails to play on a device), and purchase events — to understand how the App is used in aggregate. The Firebase User ID we set is the same UID that identifies your account — which means you can delete it via in-app account deletion (see §8).
For completed sessions we also record the content language (for example, how many sessions were in Spanish) so we can see which languages families use in aggregate. This is a usage figure — never tied to a child’s identity.
We do not track the child’s name, birthday, age or age range, gender, or any other child-identifying property as an Analytics user property or event parameter. The parameters we record are usage dimensions only — for example a catalog word or category identifier, the content language, and playback settings — never the child’s information.
You control analytics with an in-app privacy setting. In the European Economic Area, the United Kingdom, and Switzerland, analytics is off unless you turn it on. Everywhere else, analytics is on by default and you can turn it off at any time; turning it off stops collection going forward. This first-party, restricted-mode analytics supports only the App’s internal operations — we do not use it for advertising, and we share no analytics data with any third party for their own purposes.
To comply with legal obligations, respond to lawful requests from public authorities, and detect, prevent, or address fraud or abuse.
We use Firebase Remote Config to check whether your installed app version is still supported (and prompt you to update if it is not), show a maintenance message during planned downtime, and enable or disable specific features. This relies only on your app version and basic device information; it does not read or transmit any account, child-profile, or learning data.
We do not sell your data. We do not share it with advertising networks. We do share information with the following service providers (“processors”), who act on our behalf under contractual privacy obligations:
| Processor | What they receive | Purpose | Contractual basis |
|---|---|---|---|
| Google (Firebase) | All account data, child profile data, learning data, first-party analytics events, crash diagnostics (Crashlytics), remote-configuration request metadata (app version, device information) | Authentication; database; analytics; crash reporting (Crashlytics); remote configuration (Remote Config) | Firebase Data Processing and Security Terms |
| RevenueCat | An anonymous app identifier (and, once signed in, the parent’s Firebase UID); one-time-purchase state from Apple/Google IAP; paywall-view events | In-app purchase management and purchase-conversion analytics | RevenueCat DPA |
| Apple / Google (IAP) | Payment information you provide directly to them; transaction state shared back to RevenueCat | In-app purchase processing | Apple Privacy Policy / Google Play Terms |
Each processor is bound by contract to use the data only to provide the specific service we engage them for, not for their own purposes, and not to combine it with data from other sources for profiling.
We do not engage advertising networks, attribution SDKs (Branch, Adjust, AppsFlyer, etc.), third-party analytics services (Mixpanel, Amplitude, PostHog, etc.), session replay tools (FullStory, LogRocket), or any other data-broker-adjacent service.
Their First Words is parent-led: the App is intended for parents to use with their child. The child does not create an account, sign in, type, or make any choices that send data to us — every piece of information about the child is entered by the parent.
We design and operate as if the Children’s Online Privacy Protection Act (COPPA), the GDPR’s protections for children (Article 8 / GDPR-K), and the UK Children’s Code (Age Appropriate Design Code) all apply, because the data we hold is about an identifiable child.
Verifiable Parental Consent (VPC). No child data reaches our servers before consent — without an account, the child’s profile and learning data live only on the parent’s device. When the parent chooses to save that data to the cloud, they create an account by signing in with their own Apple or Google account. At that sign-in the parent agrees to our Terms of Service — which include confirming that they are the child’s parent or legal guardian (see Terms §2) — and to this Privacy Policy, and consents to our collection and use of their child’s profile and learning data as described in this policy. This authenticated, parent-agreed account creation is the consent transaction; child data is stored server-side only under that account, and the parent’s email address is already verified by Apple or Google.
No third-party disclosures of child data. As noted in §5, every processor that handles child-related data is bound by a data processing agreement to act only on our behalf. We disclose no child data to third parties for their own use. Because our collection supports only the App’s internal operations and involves no such disclosure, COPPA permits us to obtain parental consent through an email-based method (16 CFR §312.5(b)(2)(viii)); we are not required to obtain a separate, more rigorous form of consent such as a credit-card transaction, government-ID check, or video call.
Retention. See §7.
Parental rights. Parents may, at any time:
privacy@theirfirstwords.org)Legal basis. Processing of parent account data is under contract (GDPR Article 6(1)(b)). Processing of child profile data is under the parent’s verified parental consent (Article 6(1)(a) and Article 8 for the child’s data) given via account creation. Optional analytics is processed under the parent’s separate, granular consent settings managed in-App.
Child’s age threshold. We treat every account as if the most restrictive EU member-state threshold (age 16) applied. Because the parent is always the account holder and always provides consent on the child’s behalf, the per-country variance does not change our flow.
UK Children’s Code. We have completed a Data Protection Impact Assessment (DPIA) covering all 15 standards; the DPIA is available on request to privacy@theirfirstwords.org. Notable defaults:
Data Protection Officer. We have not appointed a Data Protection Officer because we do not meet the GDPR Article 37 thresholds (no large-scale systematic monitoring; no large-scale special-category data). Privacy inquiries are handled by our privacy contact at privacy@theirfirstwords.org.
| Category | Retention |
|---|---|
| Active accounts (signed in within the last 24 months) | For as long as the account is active. |
| Inactive accounts (no sign-in for 24 months) | 30-day warning email, then automated deletion of all child profile data (name, age range, character/avatar gender, progress, favorites). The parent’s Firebase Auth record remains so the parent can sign back in to a fresh slate — and the Pro purchase is unaffected: it belongs to the parent’s Apple/Google account and restores on any device. |
| Feedback you send us (§3.6) | Stored while your account is active; deleted when you delete your account (in-App or via the 24-month inactive-account deletion). |
| Parent-initiated deletion | Immediate, irreversible. See §8. |
| First-party analytics events | Up to 14 months at the Firebase Analytics retention limit (the most privacy-protective non-default setting), then automatically purged. |
| Server-side logs (Cloud Function execution logs) | 30 days, then automatically purged by Google Cloud Logging defaults. |
We do not maintain backups of deleted user data beyond the standard transient cloud-platform replication window (typically a few days), after which the deletion is fully propagated.
Inside the App: Account → Delete account. A confirmation modal will ask you to type “DELETE” to proceed. After re-authentication, the App will:
users/{your UID}) and all child profiles, progress, milestone events, and any feedback you sent us from our databaseThis deletion is immediate, irreversible, and complete. There is no soft-delete, no grace period, and no undelete option.
You may also exercise the following rights by emailing privacy@theirfirstwords.org:
We will respond within 30 days. If we need to extend that window for complex requests, we will tell you why.
If you are in the EU/UK and believe we have mishandled your data, you may complain to your national data protection authority. The UK’s authority is the Information Commissioner’s Office (https://ico.org.uk). A list of EU authorities is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
The Pro unlock is a one-time in-app purchase processed by Apple (App Store) or Google (Play Store), not by us. We never receive your payment card information.
There is no subscription and no recurring billing — you are charged once, when you confirm the purchase, and never again. There is nothing to cancel.
Refunds are handled by Apple and Google under their own policies. Deleting your App account does not refund or remove the purchase; it stays with your Apple/Google account and can be restored on any device via Restore purchases.
Our data is processed on Google Cloud / Firebase infrastructure, which may operate in multiple regions. Where data is transferred outside your country (notably from the EU/UK to the United States, where Google’s primary infrastructure is located), the transfer is governed by:
You may request a copy of the relevant safeguards by emailing privacy@theirfirstwords.org.
We implement industry-standard security practices, including:
No system is perfectly secure. If we ever become aware of a security incident that compromises your data, we will notify you and any required regulator within the timeframes prescribed by applicable law (72 hours for GDPR; without unreasonable delay for COPPA / state laws).
We may update this policy from time to time. When we do, we will:
privacy@theirfirstwords.org.Continued use of the App after a non-material change indicates acceptance of the updated policy. For material changes, we will obtain renewed parental consent where required.
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your data:
privacy@theirfirstwords.orgFor users in the EU/UK, you may also lodge a complaint with your national supervisory authority as described in §8.3.