Privacy + COPPA
What Myzo collects, what we don't, how kid data is protected, and how COPPA shapes every design decision.
Updated 2026-09-07
Myzo is built for kids, which means Myzo is built around COPPA — the Children's Online Privacy Protection Act. Every architectural decision in the app is filtered through what COPPA allows and, honestly, what we think is right regardless of what the law requires. This page is the plain-English version of what all that means for your kid's data.
For the formal legal text, see the Privacy Policy and the COPPA Notice. This page is meant to explain, not to bind.
What Myzo collects about your kid
- A first name (you enter this when adding them).
- A grade level (you enter this).
- Their tasks, focus sessions, flashcards, XP, streaks, and grades (they generate this by using the app).
- A device identifier for their phone, used only to route sync updates to that device. Never linked to any third-party ad network.
That's it. No email address. No last name. No photo. No location. No audio. No phone number.
What Myzo does NOT collect about your kid
- Email addresses.
- Photos or file uploads (avatars are emoji-style SVGs we bundle).
- Location data.
- Contact lists.
- Browsing history.
- Voice or audio recordings.
- Any biometric data.
- Anything from other apps on the phone.
There is also no messaging in Myzo — no chat between kids, no chat between an adult and a kid, no comments, no DMs. This was a hard rule from day one and won't change.
Parental consent
Before your kid's account is created, you sign the parental-consent form as part of your onboarding. That signed record is retained permanently — it's how we prove to Apple, Google, and (if it ever came up) the FTC that consent was actually given for that kid.
You can withdraw consent at any time by deleting the child from your family or deleting the whole account.
Score visibility
Kid-to-kid visibility of XP, streaks, or badges is off by default. You can toggle it on per child in Settings → Kids → [name] → Score visibility, but Myzo will never turn it on for you.
Extra safeguards for under-13 kids
When you add a kid, you tell Myzo whether they're under 13. That flag is editable any time in Child Settings → Device Access. It doesn't hard-block your kid from any feature — it's an advisory signal that changes a few defaults toward the safer side:
- Turning it on will default the "let create flash cards" toggle off (you can turn it right back on if you'd like).
- Regardless of the under-13 flag, the very first time any kid taps "Create Flash Cards" and picks a photo to scan, Myzo sends a push notification to your phone and blocks the scan until you approve. You Allow or Not now inside your app. Approved once = approved for future scans.
- These safeguards apply to the one action in Myzo Kids that sends data to a third party (Anthropic, for flashcard generation). Nothing else in the app leaves the kid's device to any external service.
Analytics
Myzo uses a privacy-respecting analytics tool (PostHog) to understand how the app is used at an aggregate level — which screens are popular, where users drop off, which flows are confusing. For kids, we send only anonymous session IDs — never name, grade, device ID, or any other identifier. For guardians, we associate events with your email so we can debug support cases you file, but you can opt out in Settings → Privacy → Analytics.
We do not sell any data. We do not use it for advertising. Myzo shows no ads to anyone, ever.
Where your data lives
Myzo runs on Supabase, hosted in the United States. All data in transit is encrypted (TLS); all data at rest is encrypted at the database layer. Backups are retained for 7 days, then permanently destroyed.
Third parties
The only third-party services that see any Myzo user data are:
- Supabase — database and auth.
- Paddle — subscription billing (payment info only, no kid data).
- Apple / Google — subscription billing when paid via IAP.
- Resend — sending transactional emails (guardian emails only).
- PostHog — analytics as described above.
- RevenueCat — subscription state mirroring for IAP.
- Anthropic — AI sub-processor for flashcard generation (turning scanned pages into cards and building multiple-choice distractors). Runs under Anthropic's Zero Data Retention (ZDR) terms: photos and card text are transmitted encrypted and are not retained after processing. This is the one action in Myzo that sends any content to an AI provider, and it's gated by the first-scan approval flow.
Each has been vetted for COPPA/GDPR compliance and covered by a signed data-processing agreement.
Data deletion
- Delete a task — restorable for 30 days, then permanently purged.
- Delete a kid — restorable for 7 days, then permanently purged along with every task, session, grade, and XP record they created.
- Delete the account — 7-day wind-down, then everything is permanently purged from every system.
There is no "archived" state we secretly keep around. Deletion in Myzo means gone.
GDPR
Myzo complies with GDPR for European users. This means you can request an export of your data, request corrections, or request deletion at any time. Email privacy@getmyzo.com and we'll respond within the timelines the law requires.
What's next
- Removing a child — the full flow for taking a kid off the account.
- Deleting your account — the full flow for shutting down the whole family.
- Full Privacy Policy — the legal text.
- Full COPPA Notice — the specific COPPA disclosures.