This is our privacy notice for children's accounts on FuzzyCode. It explains what information
we collect, how we use it, and the choices you have as a parent or guardian. The direct notice
is included in the signup confirmation email sent during parent verification, and
FuzzyCode records when that email is sent.
a private child label, birthday information used to derive under-13 compliance timing, a reserved username, and child-created project/profile content
Parent account information used to manage billing, consent, and account safety.
Operational and security data needed to run the service and protect against abuse.
How we use this information
To create and manage your child's private creative experience.
To let you manage billing, privacy choices, and review requests.
To route parent-reviewed friend requests, which you can turn off for a child, and to enable approved-friends visibility only after the required parent approval.
To enable other visibility options you specifically approve — like unlisted link-sharing or public sharing — when available.
To send optional, grouped approval-request and reminder emails to the verified parent when the production email lane is activated. Parents can turn these activity emails off in Parent Communication Settings; essential consent, account, security, billing, and legal messages are separate.
To maintain service integrity, security, abuse prevention, moderation, and legal compliance.
Service providers we work with
Supabase — current account, database, and authentication infrastructure provider.
Cloudflare — network delivery and security.
Stripe — parent payment and verification processing.
AWS / AWS Bedrock — infrastructure, prompt screening, and approved AI processing.
Groq — approved AI processing and safety workflows where enabled.
Sentry — limited error, performance, security, debugging, and support telemetry. We do not use it for advertising, sale of information, or behavioral profiling, and we do not intentionally attach prompts, generated content, child names, emails, or account identifiers.
AI processing providers and provider gateways or routing services — used to generate requested outputs where allowed by the product.
Equivalent authentication, account-storage, database-hosting, managed file-storage, cloud-infrastructure, and related service-operation providers — if we need them to keep the service reliable, secure, available, or scalable.
Email, moderation, and security providers used to operate the service safely.
Your rights as a parent
Review the information we hold about your child.
Ask us to stop collecting or using your child's information going forward.
Request takedown, unpublish, archive, or deletion of your child's content or account.
Submit requests from the parent contact page. Logged-in parents can complete review, stop-future-use, archive, unpublish, and takedown requests right away when eligible. Destructive deletion is verified by our team first; requests without a logged-in parent wait for identity verification.
What happens if consent isn't completed
If parent verification isn't completed, child setup stays blocked. During this pre-launch
release, the automated unfinished-signup cleanup runs in report-only mode and does not
delete production data. Parents may request verified deletion from the parent contact page.
Incomplete or failed verification attempts never unlock child data collection.