Privacy
Version 2026-09-14 · last updated September 14, 2026
Kodbloom is used by children. We have built it so that we collect as little about them as possible, and so that the person who decides is the adult.
This page says exactly what we hold, why, where it lives, and how to make us delete it. It is written to be read, not to be survived.
The account belongs to a grown-up
A child of seven to twelve cannot lawfully agree to a service like this on their own. So the account is not theirs — it is yours.
When you register you confirm that you are the parent or legal guardian, that you are old enough to enter into a contract where you live, and that you agree to this policy and the terms on behalf of your child.
What we collect
Deliberately little. All of it, in full:
- Your email address and the name you give — used to sign you in, to send receipts, and to let you reset a forgotten password. Give a first name or a nickname; nothing requires a real full name.
- Your password, stored only as a bcrypt hash. We cannot read it, and neither can anyone who steals the database.
- What the child does in the game: which challenges they finished, how many stars, how long a challenge took, the day streak. This is the progress that makes the map fill in.
- Sign-in records: when, from what kind of device, and a shortened IP address. By default the last part of the address is replaced with zero, which is enough to spot a household or a burst of password guessing and not enough to locate anybody.
- If you subscribe: a Stripe customer identifier, the plan, and the renewal date. Card numbers never reach our servers — Stripe collects them directly.
What we do not do
Some of this is the law, some of it is a choice. All of it is true of this build.
- No adverts inside Kodbloom. Nothing to buy in the game, no sponsored content, and no advert on any screen a child sees — that part has not changed and will not.
- We do advertise Kodbloom elsewhere, and we measure it. Google Analytics counts visits across the site, and the Meta (Facebook) Pixel runs on our public pages — the landing page, pricing, these policies, and sign-up — so we can tell which of our adverts brought somebody here. Meta may use that visit to show you Kodbloom adverts later. Neither tool is ever sent a name, an email address, or anything that identifies a child.
- Neither runs on a screen a child uses. The Meta Pixel is switched off completely on the game and on the parent report, so no part of what a child does is ever sent to an advertising company.
- We never sell or rent personal data, to anyone, for any price.
- We do not use anybody’s data — child or adult — to train artificial-intelligence models.
- We ask children for nothing beyond the game: no photographs, no voice, no location, no contacts, no date of birth.
- There is no chat, no profile visible to other users, and no way for one child to contact another.
Who else sees it
Five processors, each doing one job. The last two run only on the public pages and never see anything about a child:
- Stripe — payments. Receives your email and name when you subscribe. It never receives your child’s progress.
- Our email provider — sends the messages described in the terms. Receives your address and the content of those messages.
- Our hosting provider — runs the servers the database sits on.
- Google Analytics — counts visits. Receives a page address and a cut-down IP, never a name or an email.
- Meta — advertising measurement, on the public pages only. Receives that a browser visited one of them, never a name, an email or anything about a child.
Where the data lives, and crossing borders
Kodbloom runs on servers we control, and the database is not replicated anywhere else.
If you are in the European Economic Area and our servers are outside it, that transfer needs a legal basis. Morocco has no European Commission adequacy decision — its 2009 request is still pending — so transfers to a Moroccan server rely on Standard Contractual Clauses rather than adequacy. Stripe processes payments under its own transfer safeguards.
How long we keep it
Account and progress data: while the account exists. Delete the account and it goes with it.
Sign-in and challenge records: 24 months, then removed.
Payment records: as long as tax law where we operate requires, which is longer than the rest and outside our discretion.
Your rights, and how to actually use them
Under the GDPR, Morocco’s Law 09-08 and comparable laws elsewhere you may ask for a copy of the data, correction of anything wrong, deletion, a machine-readable export, or that we stop a particular use. Under COPPA you may additionally review your child’s information and refuse any further collection.
Email privacy@kodbloom.com from the address on the account and we will answer within 30 days. There is no charge and no form to fill in. If you are unhappy with the answer you may complain to your national data protection authority — in Morocco that is the CNDP.
Cookies
One cookie, for signing in. It holds a signed token saying which account you are, lasts 30 days, and is removed when you sign out.
Google Analytics sets its own cookies to tell a returning visit from a new one.
The Meta Pixel sets advertising cookies, and only on our public pages. It tells Meta that a browser visited one, which is how we learn that an advert worked, and Meta can use it to show you Kodbloom adverts elsewhere. This is the one thing on the site that feeds an advertising profile. It does not load once you are signed in — not on the game, not on the report — and you can refuse it in your browser or in Meta’s own advert settings without losing anything here.
If something goes wrong
If personal data is ever exposed we will notify the relevant supervisory authority within 72 hours of becoming aware, and tell affected account holders directly where the risk to them is high.
Contact
Written questions, requests and complaints: privacy@kodbloom.com.