Privacy Policy
Last updated 5 October 2026
Pukki is an app your child can ask why. This page explains, plainly, what Pukki hears, what it keeps, who helps us run it, and the choices you have.
- Your child’s question is turned into text on the phone. The recording never leaves the phone.
- The text goes to Pukki’s server and to OpenAI to write the answer. Pukki asks OpenAI not to store it; OpenAI may still hold it for up to 30 days to detect abuse.
- The answer is spoken by Heart, a voice that runs on the phone. Nothing is sent to a voice service.
- No recordings are saved.
- A one-line summary, in Pukki’s words, and Pukki’s answer are kept for 90 days so you can see what your child was curious about. When Pukki passes a question to you instead, it keeps what the question was about, never your child’s words.
- If you switch it on, each question Pukki answers is kept as your child asked it, with what Pukki said back, for 13 months, to improve Pukki — with no link to your family, your child or your phone. It is off unless you turn it on, and a question Pukki passes to you is never kept this way.
- No ads, no third-party tracking, no selling of data. Delete a child or your whole account at any time in Settings.
1. Who is responsible
Pukki is provided by Veronika Zelinková, Czech Republic, who is the controller of the personal data described here (“Pukki”, “we”, “us”). For anything about privacy, write to privacy@pukki.ai.
2. Pukki is for families, set up by parents
Pukki is made for children aged 3 to 12, but only a parent or legal guardian can create a Pukki account. Children never have an account, an email address or a password of their own. Before a child’s first question is sent from a phone, Pukki shows the parent what happens to it and asks for their agreement, and asks again when that wording changes. Pukki keeps a record of the agreement: which wording, on which phone, and when. A parent can withdraw it by removing the child or deleting the account. Whether your child’s questions may also be kept to improve Pukki is asked separately, as a switch that is off until a parent turns it on; Pukki keeps a record of that choice too.
3. What Pukki collects and why
Your account
- What: your email address and the sign-in you chose — Sign in with Apple, Google, or email and password (the password is stored only as a secure hash).
- With Sign in with Apple, Pukki asks only for your email, which you can hide behind an Apple relay address. We also keep a token from Apple so that deleting your account can revoke Pukki’s access.
- With Google, Google also shares your basic profile (name and profile picture). It is stored with your sign-in, but Pukki does not use or show it.
- Why: to create your family’s account, sign you in, send the codes that confirm your email or reset your password, and answer you when you write to us.
Your children’s profiles
- What: for each child, the nickname you choose (it doesn’t need to be their real name), their age, how much detail you’d like in their answers and whether Pukki may end one with a question, and the small symbol that marks their profile.
- Why: so Pukki’s answers suit your child’s age and your choices, and so your phone and your children’s phones stay in step. Profiles are kept on the phone and in your family’s space on Pukki’s servers.
Your child’s questions
- Listening: Pukki listens only while the microphone button is active. The question is turned into text on the phone; the audio never leaves it and is not saved.
- Answering: the question’s text, your child’s age, the English variant the phone is set to (such as British or American), and their last two questions with Pukki’s answers (so a follow-up makes sense) go to Pukki’s server and to OpenAI, which writes the answer. OpenAI does not receive your child’s nickname, your email or any account number. Pukki asks OpenAI not to store it. What Pukki itself keeps of a question is set out in the next two parts.
- Safety first: before a question reaches OpenAI, Pukki’s server checks it for topics a grown-up should handle, such as a child being hurt. Those questions are not sent to OpenAI; Pukki asks the child to talk to a grown-up instead.
- The answer is spoken by Heart, a voice that comes with the app, runs on the phone and sends nothing to a voice service. If Heart stops working on a phone, the answer is shown as words on the screen instead; no other voice takes over. Answers are written by AI and can sometimes be wrong.
Curiosity summaries and answers
- What: after each answer, one short line in Pukki’s own words — never your child’s words — about what they were curious about, sometimes with an idea to explore together, and the answer Pukki gave.
- Questions passed to you: when Pukki asks your child to talk to a grown-up instead of answering, it keeps the day and what the question was about, so you know what to talk about. Where Pukki itself chose to pass the question on, that is one line in Pukki’s own words, written by OpenAI, which had already received the question. Where the safety check stopped the question first, it is the kind of question from a fixed list (such as “how babies are made”), and nothing is sent to OpenAI. Never your child’s own words. A question about someone hurting your child is not kept at all.
- Explain it to me and Ask them back: on an answer you are reading, you can ask Pukki to explain it for a grown-up, or to suggest questions to ask your child. To write either, Pukki’s own summary and answer and your child’s age go to OpenAI — never anything your child said. What comes back is kept with that answer.
- Why: so you can see, on your phone, what your children wondered about and what they heard, whichever phone they asked on. All of this is deleted after 90 days, or straight away when you remove the child.
Questions and answers kept to improve Pukki
- What: each question Pukki answers, or tries to answer and cannot, as your child asked it — the text the phone made of their words — together with what Pukki said back. With it: your child’s age, the day, the topic Pukki filed its answer under (such as “animals” and “cats”), which version of Pukki’s instructions and which AI model wrote the answer, and whether it came from one of our own test accounts.
- Not linked to you: nothing is kept with it that says whose it was — no account, family, child’s profile, nickname or phone, and the day rather than the time. We do not try to work out who asked. If your child says a name or something personal in a question, that is kept as part of the text.
- Never kept this way: a question Pukki passes to a grown-up, whether the safety check stopped it or Pukki chose to pass it on. That is where a question about a child being hurt goes.
- Why: to check how good Pukki’s answers are and to see what children ask most, so we can make the answers better. They are kept by Pukki’s own server; no analytics company receives them.
- How long: 13 months. Because nothing links them to your family, removing a child or deleting your account does not remove them, and we cannot pick out one family’s questions to show or delete on request.
- Only if you switch it on: keeping these is a choice of its own, separate from your agreement to how answers are written. The app asks it beside that agreement, as a switch that is off until you turn it on, and you can change it at any time in Settings › What Pukki stores. While it is off, nothing is kept this way. Switching it off stops new questions being kept; those already kept are not linked to you, so they stay until their 13 months are up. If you agreed to an earlier wording, nothing is kept this way unless you switch it on.
Your family’s phones
- What: a record of each phone signed in to your family or paired as a child’s phone: its type (such as “iPhone” — never the name you gave it), which child it belongs to, whether it is in Kid mode, and when it was last used. Pairing codes are stored only in scrambled form and expire after ten minutes.
- Why: so a plan covers the right phones, a child’s phone stays with its child, and a phone you remove stops working straight away.
Your plan
- What: whether your family has an active plan, which plan, and when it renews or ends. Payments are made through Apple; we never see your card or payment details.
- Why: to give paying families access and to handle renewals, cancellations and refunds.
What RevenueCat tells us of your purchases
- What: for each thing RevenueCat reports about your subscription — a trial started, a payment, a renewal, a cancellation, a refund — its kind, the plan, the price, the dates, the store, and the reason RevenueCat gives when a subscription is cancelled or ends. No transaction number, and never your card or payment details.
- Why: to count trials and payments over time. Your plan itself is always read from RevenueCat, never from this record.
- How long: 13 months. If you delete your account, the link to your family is removed.
A complimentary pass and a reminder
Pukki may offer a parent who looked at the plans and did not choose one a complimentary pass: three days of Pukki with nothing to pay, no payment details and nothing that renews. It is offered on a parent’s phone only, never on a child’s.
- What: when you first saw the page with the plans; if a pass is offered to you, when it was shown, when you started it and when it ends; and, if you ask for our one reminder about Pukki, that you agreed, on which phone, to which wording, when, the time it was set for and, if you take it back, when. The reminder is set on your own phone by iOS: nothing is sent to Apple’s notification service, and no other notification is ever sent.
- Why: to give each family one pass, and to remind only a parent who asked to be reminded. You can take your agreement back in the same place in the app, and the reminder is removed.
- How long: until you delete your account.
Messages you send us
- What: what you write from Text the founder in the app, and the replies. The conversation belongs to your family’s account. Each new message is also emailed to Pukki’s support inbox with your account’s email address, so it can be answered. When we reply, one short email to your account’s email address says a reply is waiting in the app, at most once a day; the email never contains the reply.
- Why: to answer your questions and ideas, and to fix what you tell us about.
- How long: for 12 months after the last message in the conversation, yours or ours, or until you delete your account, which deletes the conversation with it. Copies in our support inbox are deleted when they are no longer needed to help you.
Keeping Pukki safe and fair
- What: counts of questions per family, per phone and per short time window, and, for a few protections such as limiting repeated wrong pairing codes, a scrambled (hashed) form of the internet address the request came from — never the address itself.
- Why: to apply the daily allowance, show you how many questions have been used today, and stop abuse. These counts are deleted within two days.
How Pukki is used
- What: eleven kinds of event, kept by Pukki’s own server. The app: when it is opened, whether from its icon, a link or our reminder, and whether it was already running. Your child’s side: when a question is asked — the event says only that one was, never what it was; how that turn ended — answered, passed to a grown-up, not answered, not heard, failed, or stopped by the allowance; and when a stretch on Pukki’s screen ends, and how many seconds it lasted. Your side: when the page with the plans is shown, and whether because a plan is needed or from Settings; when a complimentary pass is offered to you, and whether you had come back by yourself or by tapping our reminder; when your side of the app is opened; when you open an answer to read it — only that one was opened, never which; and, when iOS asks for the microphone, whether it was allowed. The phone: when Heart could not speak and the answer was shown as words instead; and when the phone did not yet have the speech model iOS uses to turn a question into text — whether Pukki found that before anyone asked, or a question was asked meanwhile and whether it could be heard. Each event is linked to your family and records whether it came from a parent’s or a child’s phone, the app version and the time. It never holds a name, a question, an answer or anything your child said.
- Why: to see how often and for how long families use Pukki, whether questions get answered, whether parents reach the plans, a pass, their side of the app and the answers, and whether the microphone and Heart work on their phones, so we can improve it. No analytics company receives these events.
- How long: 13 months. If you delete your account, they are kept only in anonymous form: the link to your family is removed and their times are rounded to the day.
What Pukki does not do
Pukki has no advertising, no tracking and no social features. The only record of how the app is used that reaches another company is RevenueCat’s, of the plans page being opened and closed (see section 5). We do not sell or rent personal data, and we do not use your family’s data to build profiles for marketing. Pukki does not ask for your child’s location, photos or contacts.
4. Legal bases
Under the EU General Data Protection Regulation (GDPR) we rely on:
- Contract — to provide the Pukki service you signed up for: your account, profiles, answers, summaries, phones and plan, and a complimentary pass if you start one (Art. 6(1)(b)).
- Consent — the parent’s agreement, given in the app before a child’s first question is sent, to send the question to Pukki’s server and OpenAI to write the answer (Art. 6(1)(a)). You can withdraw it at any time by removing the child or deleting your account; nothing more is sent from then on. Keeping the questions Pukki answers, with its answers and with no link to your family, to improve Pukki rests on a consent of its own: a switch in the app that is off until you turn it on, and that you can turn off again at any time in Settings › What Pukki stores. Separately, our one reminder about Pukki is set only if you agree to it in the app, on its own, and you can take that back in the same place at any time. Joining the waitlist for Pukki is also by your consent, which you can take back by writing to privacy@pukki.ai.
- Legitimate interests — to keep Pukki secure, prevent abuse and apply fair-use limits, to understand from Pukki’s own events how Pukki is used and whether Heart works on families’ phones, to count trials and payments from what RevenueCat tells us of purchases, and to count visits to pukki.ai (Art. 6(1)(f)).
- Legal obligations — where the law requires us to keep or disclose information (Art. 6(1)(c)).
5. Who helps us run Pukki
We use a small number of service providers. They process data only on our instructions, for the purposes below, under data-processing terms.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Pukki’s database, sign-in and servers | Frankfurt, Germany (EU) |
| OpenAI | Writes the answer from the question’s text, the child’s age, the phone’s English variant, and the last two questions with their answers. When you ask, writes Explain it to me and Ask them back from Pukki’s own summary and answer and the child’s age. Pukki asks OpenAI not to store the request. Under OpenAI’s API policies this data is not used to train its models, and OpenAI may keep it for up to 30 days only to detect abuse. | United States |
| Apple | Sign in with Apple, App Store payments and subscriptions | Apple’s own privacy terms apply |
| Sign in with Google (if you choose it), and the Gmail inbox where emails to support@ and privacy@pukki.ai arrive | Google’s own privacy terms apply | |
| RevenueCat | Keeps track of App Store subscriptions. It receives a random account number, your purchase records from Apple, and technical details of the parent’s phone the plan is bought or checked on: an identifier Apple gives Pukki for that phone, its model, iOS version, language and App Store country. It is also told when the page showing Pukki’s plans is opened and closed. It never receives your name, email or your children’s data, and it does not run on a child’s own phone. | United States |
| Resend | Sends the emails with your sign-up and password codes and the email that says we replied in Text the founder, and forwards messages you send from Text the founder to Pukki’s support inbox | United States |
| Cloudflare | Hosts pukki.ai, counts visits to it, and forwards email sent to support@ and privacy@pukki.ai | Global network |
| beehiiv | Runs the waitlist page that the App Store buttons on pukki.ai open until Pukki is on the App Store. It holds the email address you give there, which button brought you, and technical details of your visit | United States |
When data goes to a provider outside the EU, it is protected by the EU–US Data Privacy Framework where the provider is certified, or by the European Commission’s Standard Contractual Clauses.
We may also disclose information if the law requires it, or to protect the safety of a child or anyone else.
6. How long we keep it
| Data | Kept for |
|---|---|
| Recordings | Never saved |
| Questions Pukki answers, as asked, with what it said back — not linked to your family, and only while you have switched this on | 13 months |
| Questions Pukki passes to a grown-up, in your child’s words | Never kept |
| Curiosity summaries, Pukki’s answers, what Explain it to me and Ask them back wrote, and what questions passed to you were about | 90 days, or until you remove the child |
| Account, family and child profiles | Until you remove the child or delete your account |
| Messages you send from Text the founder, and the replies | 12 months after the last message in the conversation, or until you delete your account |
| The record of your agreement to how answers are written | Until you delete your account |
| A removed phone or child’s phone | 30 days after removal |
| Pairing codes and failed pairing attempts | 1 day |
| Question counts for the daily allowance | 2 days |
| Events about how Pukki is used | 13 months; anonymised if you delete your account |
| Subscription notices from RevenueCat | 30 days |
| What RevenueCat tells us of each purchase: its kind, the plan, the price, the dates, the store and why it ended | 13 months; not linked to your family once you delete your account |
| When you first saw the plans, a complimentary pass, and your agreement to our one reminder | Until you delete your account |
| The random account number of a deleted account, so RevenueCat’s record can be deleted again if a renewal brings it back | 15 months after RevenueCat last confirmed its record deleted |
| Your email address on the waitlist | Until Pukki is on the App Store, when the whole list is deleted; sooner if you ask |
7. Deleting your data
You can remove a child in Settings, which deletes their profile, summaries and answers. You can delete your whole account in Settings › Account. Deleting your account removes your family — your account, your children’s profiles, their summaries and answers, your phones and your messages to us — from Pukki’s servers straight away, and Pukki stops working on every phone in your family. We also ask RevenueCat to delete its record of your subscription, and, if you used Sign in with Apple, we revoke Pukki’s access with Apple. A complimentary pass and your agreement to our reminder are deleted with it. A few technical records that contain no questions or profiles — question counts, subscription notices, what RevenueCat told us of your purchases with its link to your family removed, and your random account number, kept so RevenueCat’s record can be deleted again if a subscription you have not cancelled renews — expire on their own within the periods above. The questions and answers kept to improve Pukki are not linked to your family, so deleting it cannot reach them; they are deleted when their 13 months are up.
Deleting your account does not cancel an App Store subscription. Cancel it in your iPhone’s Settings › [your name] › Subscriptions.
8. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time. Write to privacy@pukki.ai and we will reply within one month. As a parent you can exercise these rights for your children.
You can also complain to a data protection authority — in the Czech Republic, the Office for Personal Data Protection (uoou.gov.cz), or the authority where you live.
9. Security
Data is encrypted in transit and stored with our hosting provider in the EU. Access is limited to what is needed to run Pukki, and our server logs record technical details such as timing and errors — never the question.
On the phone, sign-in details and the Kid mode PIN are kept in the iPhone’s secure Keychain, for that phone only; the PIN is stored only in scrambled form and never leaves the phone. The files on the phone that hold your family’s data — profiles, summaries and answers — are left out of backups and are never stored in iCloud. A few settings that say nothing about your family, such as whether the welcome pages have been seen, the light or dark appearance and the plan last checked with its random account number, are part of an ordinary iPhone backup.
No system is perfectly secure. If something goes wrong that affects you, we will tell you and the authorities as the law requires.
10. Our website
pukki.ai uses no cookies and no advertising, and does not follow you to other sites. Cloudflare, which hosts it, counts visits for us: which page was opened and where the visitor came from, the country, the kind of browser and device, and how quickly the page loaded. This stores nothing on your device and does not identify you or follow you from visit to visit.
Cloudflare also processes technical data such as internet addresses to deliver the site and protect it from attacks.
Until Pukki is on the App Store, the App Store buttons on pukki.ai open our waitlist, a page at pukki.beehiiv.com run for us by beehiiv. That page is not pukki.ai, and it uses beehiiv’s own cookies. If you join, beehiiv keeps your email address, which button on pukki.ai brought you there, and technical details of your visit: your internet address, the place it suggests, and your device. We keep your address only in case we write to tell you that Pukki is on the App Store. We send nothing else, and we delete the whole list once Pukki is there. To be removed sooner, write to privacy@pukki.ai.
11. Changes
If we change how Pukki uses personal data, we will update this page and change the date at the top. If a change matters to you, we will tell you in the app or by email first, and ask again for your agreement where the law requires it.
12. Contact
Questions, requests or worries about privacy: privacy@pukki.ai. Anything else: support@pukki.ai.
← Back to Pukki