1. Who is responsible for your information
Spelling Bee Academy, spellingbeeacademy.com, New South Wales, Australia, is responsible for the personal information described in this policy (“we”, “us” or “our”). Email our privacy contact at help@spellingbeeacademy.com.
This policy applies to the Spelling Bee Academy mobile apps, web app, website and support service. It covers information about the adult account holder and any child who uses practice features under that adult’s supervision. It does not govern an app store, social sign-in provider or other third party when it acts independently under its own privacy policy.
2. A short explanation for children
Spelling Bee Academy helps you practise words. Ask your parent or guardian before you use it. They control the account and choose whether you may use a photo or the microphone.
The app saves your spelling words and how you answered so you can continue practising. If you choose speaking mode, a recording is sent to a speech service to turn your voice into letters. If your parent photographs a list, the photo is sent to a service that reads the words. We do not want your full name, school, address, face, health information or secrets. Crop or cover those details and tell your parent if you see something that worries you.
Your parent can ask us to show, fix or delete information. They can contact help@spellingbeeacademy.com. You can also ask your parent to help you contact us.
3. Information we collect and where it comes from
• Account and contact information: Firebase user ID; email address; email-verification status; display name and sign-in provider details supplied by email, Google or Facebook sign-in; support contact email; and authentication and security records. We do not receive the password you give a social sign-in provider. Email/password credentials are handled by Firebase Authentication.
• Learning content and progress: list name, selected English locale and age band, spelling words, generated sentences or short definitions, typed or transcribed answers, answer mode, correctness, round number, timestamps, list source, practice history, monthly usage and quota records. This may be personal information about a child when linked to the family account or when the content itself identifies someone.
• Optional photos and audio: a parent-selected spelling-list photo or camera image; a spoken spelling recording of up to the in-app limit; and text generated from that image or recording. Photos can accidentally include names, faces, school details, handwriting or other information, so crop or cover anything not needed.
• Purchases: app user ID, product and entitlement identifiers, store, transaction-event type, purchase or expiry time, renewal status, cancellation or refund status, environment and subscription-management link. Payment platforms handle full payment-card or store-account details; we do not receive full card numbers.
• Support: category, description, contact email, reference number, platform, app version, status, timestamps and an optional screenshot. If the adult switches on diagnostics, we also receive the current page, browser or device user-agent, screen size and locale.
• Device, network and usage data: IP address and request metadata ordinarily generated when a device connects to our cloud providers; authentication and App Check tokens; browser or device type; app version; locale; error and security logs; and, when Firebase Analytics is configured, page or screen path and title, referring site, feature events, modes and counts. Analytics page locations exclude URL query strings. Our analytics wrapper is designed not to send list words, names, sign-in action codes, transcripts or recordings.
We collect information from the adult account holder, from the child using a supervised practice feature, automatically from the device and Service, from sign-in providers, and from subscription or app-store providers. Please do not provide personal information about another person unless authorised to do so.
4. How we use information
We use the minimum information reasonably needed to: create, authenticate and secure the adult-managed account; extract and confirm spelling lists; generate age-banded example sentences; play spoken prompts; transcribe spoken spellings; save lists, settings, attempts and progress; restore data across supported devices; apply quotas and premium entitlements; process and reconcile subscriptions; respond to support and privacy requests; detect, investigate and prevent fraud, abuse and security incidents; debug and maintain the Service; comply with law; and establish, exercise or defend legal claims.
We do not use a child’s learning content for targeted advertising, behavioural advertising or building advertising profiles. We do not sell personal information for money. Based on the present implementation, we do not “share” personal information for cross-context behavioural advertising as that term is used in California law. We do not use spelling results to make decisions with legal or similarly significant effects.
We will not use personal information for a materially different, incompatible purpose without giving any notice and obtaining any choice or consent required by law.
5. Photo, voice and generated-content processing
A list photo is selected by an adult and compressed on the device before being sent through our Google Cloud Function to Google Vertex AI/Gemini to identify visible spelling words. Our application code does not save the original list photo to Firestore or Cloud Storage. It exists temporarily on the device and in request memory and is discarded by the app after the draft is replaced, confirmed or closed. Google may process request data under our Google Cloud agreement; its infrastructure copies and service data are governed by that agreement rather than by an app promise of instant deletion.
In speaking mode, recording starts only after the microphone control is used. The recording is uploaded after recording stops to our Google Cloud Function and then to Deepgram for speech-to-text processing. Our application code does not save the raw recording in Firestore or Cloud Storage and disposes of the local temporary recording after use. We save the typed or transcribed answer and result as part of practice history. Deepgram’s processing and any transient provider copies are governed by our service agreement with it.
Confirmed words, selected locale and age band are sent to a language-model service to create example sentences. Do not put names or other identifying details in a spelling list. We limit the request to the information needed to generate the sentence.
Words and generated sentences are sent to Deepgram to create audio prompts. Generated MP3 prompts are cached in private Google Cloud Storage and delivered through short-lived signed links; feedback audio may also be returned in the response. The current cache is configured with a 30-day maximum-age target, but deletion depends on the cache-cleanup process.
6. When we disclose information
We disclose only the information reasonably needed for the stated purpose to these current provider categories:
• Google: Firebase Authentication, Firestore, Cloud Functions, Cloud Storage, Hosting, App Check/reCAPTCHA Enterprise, Firebase Analytics when configured, Google social sign-in, and Vertex AI/Gemini image processing.
• Language-model processing: confirmed words, locale and age band for sentence generation.
• Deepgram: raw audio and locale for transcription, and prompt text and voice settings for text-to-speech.
• RevenueCat and its connected payment processor, and Apple or Google app stores where used: account/transaction identifiers and subscription status.
• Meta: sign-in information if Facebook sign-in is enabled and chosen.
• Microsoft 365/email infrastructure: adult support messages and acknowledgements sent through help@spellingbeeacademy.com.
• Professional advisers, insurers, auditors, transaction counterparties and public authorities: only where reasonably necessary for advice, a business transaction, protecting rights or safety, or complying with valid law or legal process.
Our providers may use subprocessors. We do not authorise a processor to use our customer content for its own advertising. Provider terms, data-processing agreements, child-data restrictions and model-training settings must be reviewed and configured before production use; this policy does not create a factual assurance that an unverified provider setting is enabled.
7. International processing
We use cloud providers whose staff, systems and subprocessors may process information outside the country where you live, including in Australia, the United States and other countries in which our providers or their subprocessors operate. RevenueCat states that its customer data is stored in the United States.
Where required, we will use an applicable adequacy mechanism, contractual safeguards such as the UK International Data Transfer Agreement or Addendum, provider data-protection terms, transfer risk assessments and other reasonable measures. Australian cross-border disclosure obligations, Canadian accountability rules, UK restricted-transfer rules and any mandatory local rights continue to apply. Overseas laws may allow courts, law enforcement or regulators to access information.
8. Children and parental choices
The Service is directed to families with children aged approximately 5 to 13, but the account, purchases and support channels are for adults. We treat learning content associated with the account as potentially relating to a child. We do not ask for a child’s name, birth date, email, school or precise location, but a photo, recording, answer or list can still contain child personal information.
For families in the United States, an adult must manage the account and supervise a child’s use of optional photo and voice features. Parents and guardians may contact us to review, correct or delete personal information associated with the child, subject to applicable law.
In Canada, we seek adult consent where a child cannot provide meaningful consent; the federal privacy regulator generally takes the position that, except in unusual cases, a person under 13 cannot do so. Quebec generally requires consent from a parent or tutor to collect personal information from a child under 14, unless an applicable legal exception applies. In the UK, we apply the best interests of the child, high-privacy defaults and age-appropriate transparency required by the UK GDPR, Data Protection Act 2018 and Children’s Code. In Australia, we apply applicable Privacy Act and Australian Privacy Principle requirements; the Children’s Online Privacy Code is not yet final as of this effective date and is due to be registered by 10 December 2026.
A verified parent or guardian may ask to review the child’s personal information, correct it, withdraw permission where processing depends on consent, stop further collection, or delete it, subject to lawful exceptions. We will verify the requester’s identity and authority. We will not require more child information than is reasonably necessary to participate in a feature.
9. Legal grounds for UK processing
For UK users, we rely on: contract where processing is necessary to provide the adult account and requested paid Service; legitimate interests to secure, troubleshoot and improve the Service, prevent fraud, manage support and establish legal claims, after considering the rights and best interests of children; legal obligation where the law requires processing; and consent for an optional activity where consent is the appropriate basis. Where we ask for consent, it may be withdrawn without affecting processing already carried out lawfully.
We do not rely on an adult’s acceptance of this policy as blanket consent. Before relying on legitimate interests for child data, we assess why the processing is necessary and proportionate and consider the child’s rights and best interests.
10. Cookies, local storage and analytics
The web app and mobile app use device or browser storage for settings, temporary account state, local lists in demo/mock mode and resumable practice sessions. Firebase and RevenueCat may use local storage, cookies or similar technologies for authentication, fraud prevention, security, subscription functionality and remembering the account. Clearing app or browser data may remove information stored only on that device.
When a Firebase measurement ID is configured, Firebase Analytics may receive page or screen paths and titles, the referring site, and limited event names and safe parameters such as counts and modes. Analytics page locations exclude URL query strings. We disable Google signals and advertising-personalisation signals in our analytics configuration. We do not send list words, names, sign-in action codes, transcripts or recordings in those analytics events. We do not currently respond to browser “Do Not Track” signals as a sale or targeted-advertising opt-out because we do not engage in those practices; where a legally recognised universal opt-out signal applies to a covered practice, we will honour it.
11. How long we keep information
We keep personal information only for as long as reasonably needed for the purpose for which it was collected, to provide the Service, comply with law, prevent fraud, maintain security or resolve a complaint or dispute. The period varies with the type of information, the account status and legal or operational requirements.
Our application does not intentionally store raw list photos or spoken recordings after the requested extraction or transcription. Saved account information, lists and practice history remain available until they are deleted or the account is closed, subject to protected backups and lawful exceptions. Support and billing records are kept only while reasonably needed for support, reconciliation, accounting, fraud prevention and legal obligations. We delete or de-identify information when it is no longer reasonably needed, unless applicable law permits or requires continued preservation.
12. Security
The current service uses authenticated Firebase access, per-user database rules, server-only storage rules, App Check for production callable functions when configured, limited payload sizes, usage limits, short-lived signed audio links and provider secrets kept on the server. Optional support screenshots are stored in a non-public server-controlled path. We limit internal and provider access to what is needed for authorised duties.
No online service is perfectly secure. Use a unique password, protect access to the adult email and sign-in provider, sign out on shared devices and tell us promptly if you suspect unauthorised access. We will assess and notify affected people and regulators of a personal-data breach when applicable law requires it. This section describes safeguards visible in the present implementation; it is not a guarantee against every incident.
13. Your privacy rights
Depending on where you live and subject to lawful exceptions, you may ask us to: confirm whether we hold personal information; explain its collection, use and disclosure; give access to or a portable copy of it; correct inaccurate or incomplete information; delete it; restrict or object to processing; withdraw consent; or review a decision on a request. You may use an authorised agent where law permits. We will not unlawfully discriminate or provide a worse service because a right was exercised, although deleting information needed for a feature may make that feature unavailable.
Australian users may request access and correction and complain about an alleged breach of the Australian Privacy Principles. UK users may also object to legitimate-interest processing, request portability where applicable and complain to the Information Commissioner’s Office. Canadian users may request access and correction, withdraw consent subject to legal or contractual limits, and challenge our compliance. Residents of California and other covered US states may have rights to know, access, correct, delete and obtain a portable copy, to appeal certain denials, and to opt out of sale, targeted advertising or qualifying profiling. Because we do not presently sell or share personal information for targeted advertising, there is no such opt-out link; contact us if you believe this is incorrect.
Email help@spellingbeeacademy.com with “Privacy request” in the subject. Describe the account and request, but do not email a password or unnecessary identity document. We may verify identity, account control, parental authority or an agent’s authority. We will respond within the time required by the law that applies to the request and explain any lawful refusal or extension. Requests are normally free, but we may charge or decline where law permits for manifestly unfounded, excessive or repetitive requests.
14. Account deletion and device data
A parent can permanently delete an account from My Account. A guest can use Delete guest data from the same screen. Recent authentication may be required. The deletion process removes the Firebase Authentication user and the data stored under that user’s main Firestore record, then clears Spelling Bee Academy’s local app data on that device.
Deletion may not automatically remove separate support tickets, payment-processor records, legal records or protected backups; we will assess and delete or de-identify those records where required and not subject to an exception. You may also email help@spellingbeeacademy.com with a privacy request concerning records that cannot be managed in the app.
Cancelling a subscription does not delete an account, and deleting an account does not cancel a subscription billed by Apple, Google or another payment platform. Cancel the subscription separately before deleting the account if you do not want billing to continue.
15. Complaints and regulators
Send a privacy complaint to help@spellingbeeacademy.com and include enough detail for us to investigate. We will acknowledge it, verify identity where appropriate, investigate fairly, explain our decision and available review options, and respond within the period required by applicable law.
You may also complain to the relevant regulator: in Australia, the Office of the Australian Information Commissioner (oaic.gov.au); in the United Kingdom, the Information Commissioner’s Office (ico.org.uk); in Canada, the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the applicable provincial regulator; and in the United States, the Federal Trade Commission (ftc.gov) or your state attorney general or privacy regulator. Contacting us first may allow a faster resolution, but is not required where the law gives you a direct right to complain.
16. Changes to this policy
We will update this policy when our information practices, providers or legal duties materially change and post a new effective date. If a change is material, we will provide additional notice through the Service or adult account email where required and obtain any consent required for a new use. We will not use an update to reduce rights retroactively. Previous versions will be available on request where reasonably practicable.