No ads. No resale. No training third-party models on your child's spelling mistakes. A plain-English promise, with the paperwork to back it up.
Every pledge here is contractually backed in our DPA. If we break one, we break the contract.
Spellimus does not run adverts, does not embed third-party ad SDKs, and does not operate an affiliate programme. Children never see sponsored content inside the app.
We don't sell, trade, or share learner data with data brokers, advertisers, or analytics resellers. Our subscription fees are our only revenue — on purpose.
Nothing a child types, speaks, or records is used to train a third-party model. Our adaptive engine runs entirely on your account's own history, in your account's own partition.
All learner data is processed and stored on UK infrastructure (AWS London, eu-west-2). Backups never leave the UK region. No cross-Atlantic transfers for children's accounts.
A parent or school admin can permanently delete an account and everything attached to it with a single action. We honour it within 24 hours, across all backups within 30 days.
If acquiring a company means breaking one of these pledges, we walk. If we're ever forced to change them, we will close the service to existing customers before we re-open under new terms.
| Data | Why we collect it | How long | Shared with |
|---|---|---|---|
| Child's first name | Personalisation inside the app | While account is active | Nobody |
| Year group / age band | Appropriate word selection | While active | Nobody |
| Practice responses | Adaptive engine, mastery tracking | 3 years after last use | Nobody |
| Voice recordings (opt-in) | Your own custom pronunciations | Until you delete them | Nobody |
| Parent email | Login + weekly summary email | Until account closed | Postmark (email delivery, EU) |
| Anonymous usage metrics | Product improvement — aggregated only | 13 months rolling | PostHog (self-hosted, UK) |
| Billing info (parents only) | Processing payment | 7 years (HMRC requirement) | Stripe (PCI-DSS Level 1) |
That's everything. There is no separate "also" list. If it isn't in this table, we don't have it.
Pre-signed, UK GDPR schedule, sub-processor list, SCCs where needed.
Download PDF · 14 pages →Controls, incident response, vendor management — ISO 27001 SoA summary.
Download PDF · 22 pages →How we align with KCSIE 2024, in-product moderation, reporting routes.
Download PDF · 8 pages →Template DPIA pre-filled for schools to adapt — ICO-aligned.
Download DOCX · 12 pages →72-hour notification commitment, severity grading, comms templates.
Download PDF · 6 pages →Executive summary of our 2024 annual pen test. Full report under NDA.
Request under NDA →The ICO's Age Appropriate Design Code sets 15 standards for online services likely to be accessed by children. We map to every one. Our detailed self-assessment is available on request.
Request self-assessmentFor SARs, deletion requests, DPA queries, or anything that mentions the ICO. Our DPO reads every email personally.
Found something that worries you? We'd love to hear. Coordinated disclosure, hall of fame, small bounties on critical issues.