โ† Back to BeadBrain
๐Ÿ”’ Privacy Policy
Last updated: May 2026 ยท GDPR compliant
Our commitment to you
BeadBrain never sells your data, never shows ads, and treats your child's privacy with the highest standards. This policy explains exactly what we collect and why.
1. Who We Are

BeadBrain Learning operates the BeadBrain abacus education app.

Country: Netherlands

Contact: hello@beadbrain.app

We are the Data Controller for the purposes of GDPR.

2. What Data We Collect

Parent/guardian account

  • Email address โ€” for login and account management
  • Display name โ€” shown in the app
  • Password โ€” stored as a secure hash, never in plain text

Child profile data

  • Child first name or nickname (chosen by parent)
  • Age range (not exact date of birth)
  • Learning mode preference

Learning and usage data

  • Lesson completion records and quiz scores
  • XP, level, streak, diamond balance
  • Badges and shop purchases
  • Weekly activity for screen time controls

Payment data

We use Stripe to process payments. We never store card numbers or banking details. Stripe is PCI-DSS compliant.

What we do NOT collect

  • We use no advertising or tracking cookies
  • We use no third-party analytics
  • We do not collect children's email addresses
  • We do not collect photos or biometric data
3. Children's Privacy

BeadBrain is designed for children aged 4โ€“10 under parental supervision. We are fully committed to child safety online.

  • Only the parent/guardian's email is collected โ€” not the child's
  • Child usernames contain no identifying information
  • There is no direct messaging between children
  • The friend system is opt-in and username-only
  • Parents can view, edit, or delete all child data from the Parent Dashboard
  • Parental consent is required when creating a child profile
4. How We Use Your Data
  • To create and manage your account
  • To track and display your child's learning progress
  • To process subscription payments
  • To allow optional social features within private friend groups
  • To enforce parental controls you have set

We never use your data for advertising, profiling, or sell it to third parties. Ever.

5. Data Sharing

We share data only with essential service providers:

  • Supabase โ€” database and authentication, EU-hosted, GDPR compliant
  • Stripe โ€” payment processing, PCI-DSS certified
  • Netlify โ€” hosting infrastructure

We never share data with advertisers, data brokers, or marketing companies.

6. Your GDPR Rights

Under GDPR you have the right to:

  • Access โ€” request a copy of all data we hold
  • Rectification โ€” correct inaccurate data
  • Erasure โ€” request deletion of your account and all data
  • Portability โ€” receive your data in a machine-readable format
  • Object โ€” to processing based on legitimate interests

Email hello@beadbrain.app to exercise any of these rights. We respond within 30 days.

7. Security
  • All data is transmitted over HTTPS (TLS encryption)
  • Passwords are hashed โ€” never stored in plain text
  • Database access is protected by Row-Level Security
  • Payment data never touches our servers
8. Data Retention
  • Account data โ€” retained while your account is active
  • Deleted accounts โ€” all personal data removed within 30 days
  • Payment records โ€” retained 7 years (Dutch tax law)
9. Cookies

We use only essential session cookies required for login. No advertising, analytics, or tracking cookies are used.

10. Contact & Complaints

Privacy questions: hello@beadbrain.app

You have the right to lodge a complaint with the Dutch Data Protection Authority: autoriteitpersoonsgegevens.nl

Questions about privacy?
hello@beadbrain.app
View Terms of Service โ†’
1