Privacy Policy — Their First Words

Last updated: July 10, 2026


Plain-language summary

This summary is informational. The full policy follows.


1. Who we are

This Privacy Policy describes how Their First Words LLC, a California limited liability company (“we,” “us,” “our”), collects, uses, and shares information through the Their First Words mobile application (the “App”), available on the Apple App Store and Google Play.

Contact:

We are the data controller for purposes of GDPR. For users in the United Kingdom, we act as data controller under UK GDPR.

2. Scope

This policy applies to information collected through the App itself. It does not apply to the App Store listing pages (governed by Apple’s and Google’s policies), or to any third-party website you may navigate to from the App.

3. What we collect

Using the App without an account: sections 3.1–3.4 describe what we store for a signed-in account. Without an account, the child profile (§3.2) and learning data (§3.3) exist only on your device — none of it reaches our servers. (§3.5’s technical data and §3.4’s purchase state still apply as described there.)

3.1 Account information (created only when you sign in)

Accounts are created by signing in with Apple or Google (there is no App-specific password). When you do, we collect:

Data Source Why we collect it
Email address Your Apple or Google account (Apple users may share Apple’s private relay address instead of their real one) Account identification
Firebase User ID (UID) Generated by Firebase on first sign-in Internal identifier for your account

3.2 Child profile information

For each child profile, we store:

Data Source Why we store it
Child’s first name You type it Personalized greeting; display in Progress
Child’s age range You pick a range (0–24 months, 2–3 years, 3–5 years) Serves age-appropriate content
Character / avatar gender You pick Boy or Girl Sets the avatar’s art variant
Selected character (avatar) You select it from a catalog Display in the app’s top bar and flashcard screens
Accessory selection (optional) You select it from a catalog Display on the character avatar
Character avatar (generated image) Created by the app from your character and accessory choices Displays the personalized avatar
Content language An app setting (default English); the parent changes it in-app, and it syncs across their devices Selects the language of flashcard text and audio
Display & playback preferences You set these in-app (e.g. voice, auto-advance, sound on/off, show/hide word, image style, and the Progress chart / language views) Remembered across your devices

We do not collect: the child’s last name, the child’s email, the child’s date of birth (we use an age range only), the child’s photo, the child’s voice recordings, the child’s precise location, or any biometric data.

3.3 Learning data (generated as you use the App)

As the parent and child use the App together, we generate and store:

Data What it is
Word progress For each word, per language: whether it has been seen, learned, or in-progress, and the date it was marked learned
Favorites Words the parent has marked as favorites
Session events Timestamps of completed practice sessions, and the content language of each session
Milestone events When the child crosses 10/25/50/100/etc. learned-words thresholds

This data is tied to the parent’s account and the relevant child profile. It is used to display the Progress screen, populate Today’s Words selection, and power the in-app milestone celebrations.

3.4 Purchase state (from Apple / Google via RevenueCat)

Pro is a one-time purchase handled by Apple or Google. RevenueCat (our purchase-management service) tracks whether the purchase has been made, keyed to an anonymous app identifier — and, once you sign in, to your Firebase UID (a purchase made before sign-in is linked to your account when you sign in).

When the purchase screen (paywall) is shown, we also send RevenueCat a paywall-view event so we can measure how many parents who saw the screen chose to buy. This event contains no information about your child.

We never see your credit card number, expiration date, CVV, or any other payment information. Those are handled entirely by Apple or Google.

3.5 Technical data (collected automatically)

Data Source Purpose
Firebase installation ID Firebase SDK Crash diagnostics; first-party analytics
Device language Device Future localization fallback (currently unused at launch)
Time zone Device (Intl.DateTimeFormat) Scheduling optional, time-appropriate features
App version App Diagnostics
First-party analytics events Firebase Analytics in restricted mode App usage analysis (see §4.3)
Crash report (device model, OS version, app version, stack trace) Firebase Crashlytics Diagnose + fix app crashes — no child data (see below)

Crash diagnostics: if the App crashes we collect a crash report — device model, OS version, app version, and a technical stack trace (no child names, ages, or learning data) — via Firebase Crashlytics (Google), a processor under our Firebase Data Processing Addendum, to diagnose and fix stability problems.

App configuration: the App fetches remote configuration from Firebase Remote Config (Google) to check whether your installed app version is still supported, to display a maintenance notice during planned downtime, and to turn specific features on or off. This fetch sends your Firebase installation ID, the app version, and basic device information (operating system, language, and region) to Firebase; it does not send your account, child-profile, or learning data. Firebase Remote Config is a processor under our Firebase Data Processing Addendum.

3.6 Feedback you send us (you give us this)

If you choose to send feedback through the App (Account → Send feedback), we store the message you write, together with your account’s user ID, the app version, your platform (iOS or Android), the active flashcard language, and the time you sent it. We use this to read and act on your feedback and, where appropriate, to reply to you.

The legal basis is performance of a contract / handling the request you initiated (GDPR Article 6(1)(b)) — the same basis as your account data. Replying is inherent to a request you sent us, so no separate consent is required.

We ask you not to include your child’s name or other personal details in your message, and we never attach any child profile data to it. If personal details slip in, we remove them when we act on the feedback. Feedback is private — it is sent only to us and is never shown to other users. It is deleted when you delete your account (see §7 and §8).

3.7 What we explicitly do not collect

4. How we use information

4.1 To provide the App

To create and maintain your account, store and display child profiles, track learning progress, present Today’s Words and Categories, manage favorites, and run flashcard sessions.

4.2 Purchase management

To verify whether the one-time Pro unlock has been purchased (so paid content is available), via RevenueCat.

4.3 First-party analytics (Firebase Analytics, restricted mode)

We use Firebase Analytics in “restricted” configuration:

We track in-app events — for example session_started and session_completed (including the session’s content language and playback settings, such as the voice and auto-advance mode used), word_learned and word_favorited (which catalog word), category_opened, paywall_viewed, language_changed, audio_failed (so we can tell when a word’s audio fails to play on a device), and purchase events — to understand how the App is used in aggregate. The Firebase User ID we set is the same UID that identifies your account — which means you can delete it via in-app account deletion (see §8).

For completed sessions we also record the content language (for example, how many sessions were in Spanish) so we can see which languages families use in aggregate. This is a usage figure — never tied to a child’s identity.

We do not track the child’s name, birthday, age or age range, gender, or any other child-identifying property as an Analytics user property or event parameter. The parameters we record are usage dimensions only — for example a catalog word or category identifier, the content language, and playback settings — never the child’s information.

You control analytics with an in-app privacy setting. In the European Economic Area, the United Kingdom, and Switzerland, analytics is off unless you turn it on. Everywhere else, analytics is on by default and you can turn it off at any time; turning it off stops collection going forward. This first-party, restricted-mode analytics supports only the App’s internal operations — we do not use it for advertising, and we share no analytics data with any third party for their own purposes.

4.4 Communications

4.5 Legal compliance and safety

To comply with legal obligations, respond to lawful requests from public authorities, and detect, prevent, or address fraud or abuse.

4.6 App configuration and version support

We use Firebase Remote Config to check whether your installed app version is still supported (and prompt you to update if it is not), show a maintenance message during planned downtime, and enable or disable specific features. This relies only on your app version and basic device information; it does not read or transmit any account, child-profile, or learning data.

5. Who we share information with

We do not sell your data. We do not share it with advertising networks. We do share information with the following service providers (“processors”), who act on our behalf under contractual privacy obligations:

Processor What they receive Purpose Contractual basis
Google (Firebase) All account data, child profile data, learning data, first-party analytics events, crash diagnostics (Crashlytics), remote-configuration request metadata (app version, device information) Authentication; database; analytics; crash reporting (Crashlytics); remote configuration (Remote Config) Firebase Data Processing and Security Terms
RevenueCat An anonymous app identifier (and, once signed in, the parent’s Firebase UID); one-time-purchase state from Apple/Google IAP; paywall-view events In-app purchase management and purchase-conversion analytics RevenueCat DPA
Apple / Google (IAP) Payment information you provide directly to them; transaction state shared back to RevenueCat In-app purchase processing Apple Privacy Policy / Google Play Terms

Each processor is bound by contract to use the data only to provide the specific service we engage them for, not for their own purposes, and not to combine it with data from other sources for profiling.

We do not engage advertising networks, attribution SDKs (Branch, Adjust, AppsFlyer, etc.), third-party analytics services (Mixpanel, Amplitude, PostHog, etc.), session replay tools (FullStory, LogRocket), or any other data-broker-adjacent service.

6. Children’s privacy

Their First Words is parent-led: the App is intended for parents to use with their child. The child does not create an account, sign in, type, or make any choices that send data to us — every piece of information about the child is entered by the parent.

We design and operate as if the Children’s Online Privacy Protection Act (COPPA), the GDPR’s protections for children (Article 8 / GDPR-K), and the UK Children’s Code (Age Appropriate Design Code) all apply, because the data we hold is about an identifiable child.

6.1 United States (COPPA)

Verifiable Parental Consent (VPC). No child data reaches our servers before consent — without an account, the child’s profile and learning data live only on the parent’s device. When the parent chooses to save that data to the cloud, they create an account by signing in with their own Apple or Google account. At that sign-in the parent agrees to our Terms of Service — which include confirming that they are the child’s parent or legal guardian (see Terms §2) — and to this Privacy Policy, and consents to our collection and use of their child’s profile and learning data as described in this policy. This authenticated, parent-agreed account creation is the consent transaction; child data is stored server-side only under that account, and the parent’s email address is already verified by Apple or Google.

No third-party disclosures of child data. As noted in §5, every processor that handles child-related data is bound by a data processing agreement to act only on our behalf. We disclose no child data to third parties for their own use. Because our collection supports only the App’s internal operations and involves no such disclosure, COPPA permits us to obtain parental consent through an email-based method (16 CFR §312.5(b)(2)(viii)); we are not required to obtain a separate, more rigorous form of consent such as a credit-card transaction, government-ID check, or video call.

Retention. See §7.

Parental rights. Parents may, at any time:

6.2 European Union and United Kingdom (GDPR / UK GDPR / Children’s Code)

Legal basis. Processing of parent account data is under contract (GDPR Article 6(1)(b)). Processing of child profile data is under the parent’s verified parental consent (Article 6(1)(a) and Article 8 for the child’s data) given via account creation. Optional analytics is processed under the parent’s separate, granular consent settings managed in-App.

Child’s age threshold. We treat every account as if the most restrictive EU member-state threshold (age 16) applied. Because the parent is always the account holder and always provides consent on the child’s behalf, the per-country variance does not change our flow.

UK Children’s Code. We have completed a Data Protection Impact Assessment (DPIA) covering all 15 standards; the DPIA is available on request to privacy@theirfirstwords.org. Notable defaults:

Data Protection Officer. We have not appointed a Data Protection Officer because we do not meet the GDPR Article 37 thresholds (no large-scale systematic monitoring; no large-scale special-category data). Privacy inquiries are handled by our privacy contact at privacy@theirfirstwords.org.

7. How long we keep information

Category Retention
Active accounts (signed in within the last 24 months) For as long as the account is active.
Inactive accounts (no sign-in for 24 months) 30-day warning email, then automated deletion of all child profile data (name, age range, character/avatar gender, progress, favorites). The parent’s Firebase Auth record remains so the parent can sign back in to a fresh slate — and the Pro purchase is unaffected: it belongs to the parent’s Apple/Google account and restores on any device.
Feedback you send us (§3.6) Stored while your account is active; deleted when you delete your account (in-App or via the 24-month inactive-account deletion).
Parent-initiated deletion Immediate, irreversible. See §8.
First-party analytics events Up to 14 months at the Firebase Analytics retention limit (the most privacy-protective non-default setting), then automatically purged.
Server-side logs (Cloud Function execution logs) 30 days, then automatically purged by Google Cloud Logging defaults.

We do not maintain backups of deleted user data beyond the standard transient cloud-platform replication window (typically a few days), after which the deletion is fully propagated.

8. Your rights and how to exercise them

8.1 In-App account deletion (recommended)

Inside the App: Account → Delete account. A confirmation modal will ask you to type “DELETE” to proceed. After re-authentication, the App will:

  1. Delete your account record (users/{your UID}) and all child profiles, progress, milestone events, and any feedback you sent us from our database
  2. Delete any per-user content in Storage
  3. Unlink your purchase record on RevenueCat from our systems (your one-time Pro purchase itself stays with your Apple/Google account — deleting your App account neither refunds nor removes it, and there is no ongoing billing — see §9)
  4. Delete your Firebase Authentication record

This deletion is immediate, irreversible, and complete. There is no soft-delete, no grace period, and no undelete option.

8.2 Other rights

You may also exercise the following rights by emailing privacy@theirfirstwords.org:

We will respond within 30 days. If we need to extend that window for complex requests, we will tell you why.

8.3 Right to lodge a complaint

If you are in the EU/UK and believe we have mishandled your data, you may complain to your national data protection authority. The UK’s authority is the Information Commissioner’s Office (https://ico.org.uk). A list of EU authorities is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

9. Purchases and billing

The Pro unlock is a one-time in-app purchase processed by Apple (App Store) or Google (Play Store), not by us. We never receive your payment card information.

There is no subscription and no recurring billing — you are charged once, when you confirm the purchase, and never again. There is nothing to cancel.

Refunds are handled by Apple and Google under their own policies. Deleting your App account does not refund or remove the purchase; it stays with your Apple/Google account and can be restored on any device via Restore purchases.

10. International data transfers

Our data is processed on Google Cloud / Firebase infrastructure, which may operate in multiple regions. Where data is transferred outside your country (notably from the EU/UK to the United States, where Google’s primary infrastructure is located), the transfer is governed by:

You may request a copy of the relevant safeguards by emailing privacy@theirfirstwords.org.

11. Security

We implement industry-standard security practices, including:

No system is perfectly secure. If we ever become aware of a security incident that compromises your data, we will notify you and any required regulator within the timeframes prescribed by applicable law (72 hours for GDPR; without unreasonable delay for COPPA / state laws).

12. Changes to this policy

We may update this policy from time to time. When we do, we will:

  1. Update the “Last updated” date at the top.
  2. If the change is material (for example: a new category of data, a new processor, or a new purpose of processing), notify you in-App and/or by email at least 30 days before the change takes effect.
  3. Keep prior versions of this policy available on request at privacy@theirfirstwords.org.

Continued use of the App after a non-material change indicates acceptance of the updated policy. For material changes, we will obtain renewed parental consent where required.

13. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your data:

For users in the EU/UK, you may also lodge a complaint with your national supervisory authority as described in §8.3.