Privacy
Last updated 23 September 2026
What changed: Google Analytics, Google Ads and the cookie banner are gone, so there are no analytics cookies anywhere. We added Stripe (payments) and GoatCounter (cookieless page counts) to the services we use, and explained what we keep for billing, how the free daily allowance is counted, and how a tutor can set up a pupil's account.
Puzzitron is a brain-training app for children aged 7–11. The app is run by a single small operator (not a large company), so this policy is short and direct. We collect the minimum we need to make the app work, and you can ask us to delete everything we hold at any time.
Who runs Puzzitron
Puzzitron is operated by an individual UK-based operator trading as Puzzitron. For privacy questions, data deletion requests, or anything else covered by this policy, email hello@puzzitron.com.
What we collect, and why
For adult (parent / tutor / teacher) accounts:
- Email address used to send the magic sign-in link and (rarely) account-related notifications. No marketing emails without separate explicit opt-in.
- Display name optional. Shown in the dashboard so an adult with multiple devices recognises their own account.
- Sign-in cookies a JWT session cookie after sign-in. Cleared on sign-out. Used only to keep you signed in across pages.
- Billing details, if you pay: the id of your customer record at Stripe, the id and status of any Puzzitron Plus or tutor subscription (for example “active” or “cancelled”), and the date a Plus pass runs out. That is all we keep. Your card details go straight to Stripe; we never see or store card numbers.
For player (child) accounts:
- First name what the adult typed when they added the child. Shown only on that child’s own screen and in the adult’s dashboard.
- A globally-unique handle (e.g.
tiger.river.galaxy). Three random child-friendly words from a curated list, auto-generated. Used to sign in. The child’s display name is not in the handle, so it doesn’t identify them outside their family / adult context. - A bcrypt hash of the child’s 4-digit PIN. We never store the PIN itself. The hash is used to verify sign-in.
- Avatar configuration what colour / accessory the child picked for their pixel-art avatar.
- Practice history which questions the child answered, whether they got each right, how long they took, plus session-level summaries (level, mode, score). This is what makes the app useful. Without it we can’t show progress or adapt difficulty.
- A daily question count: on the free tier a child can answer a set number of questions a day. We work that out from the practice history above, counting the questions answered on the child’s local calendar day. It needs no new data.
- A child sign-in cookie random token, 1-year expiry, HttpOnly. Cleared on sign-out, or any time the parent revokes the session from the dashboard.
What we don’t collect. No date of birth (we ask the adult to confirm the child is in our 7–11 age range. We don’t store the answer). No location. No device fingerprinting. No behavioural-advertising signals. No third-party social sign-in.
Marketing-page measurement. The public marketing pages (the homepage, /for-parents, /for-tutors, /for-schools, /pricing, /cat4-practice, /11-plus-practice, /non-verbal-reasoning, /blog, this privacy page, /terms) load GoatCounter, a page-view counter that sets no cookies and keeps no personal data. It tells us how many people read a page, nothing about who they are. It is never loaded on the part of Puzzitron your child uses (everything under /play, /profiles, /dashboard, or /invite). We do not use Google Analytics, advertising tags or any other tracker.
Legal basis
Adult accounts: contract (UK GDPR Art. 6(1)(b)). We need the email to provide the sign-in service the adult asked for.
Child accounts: parent-mediated consent (UK GDPR Art. 6(1)(a) + Art. 8). The adult who creates the child account confirms they have the right to do so on the child’s behalf (parent / legal guardian / authorised teacher). We don’t collect age verification beyond that confirmation. We don’t use child data for any purpose other than running the practice game and showing the adult what their child has been doing.
When a tutor sets up the account. A tutor can add a pupil themselves. Before they can, they tick a box confirming that “the pupil’s parent or guardian has agreed to them using Puzzitron and to me setting up their account”, and we record who ticked it and when. That confirmation is the parent’s permission we rely on. A parent can take the account over at any time through a handover link from the tutor: it then belongs to the parent’s own sign-in, nothing is copied or reset, and the parent can remove the tutor from the child’s settings. A parent who has not been asked can email us and we will act on their wishes, including deleting the account.
Payments: contract (UK GDPR Art. 6(1)(b)), because we need the billing details above to provide the plan you bought. GoatCounter page counts: legitimate interests (Art. 6(1)(f)) in knowing which pages are read, using no personal data and no cookies.
How long we keep it
Your data lives in our database for as long as your account does. When you delete an account or a child:
- The account / child row is removed immediately.
- All linked data (sessions, attempts, flags, coin spends) cascades and is removed at the same time.
- Database backups (daily) retain a copy for up to 30 days; after that point all traces are gone.
- An entry in our
audit_logtable records that a deletion happened, but contains no personal data beyond the event timestamp and the account / child id.
Billing details (the Stripe customer id, subscription status and pass expiry) stay on your account while it exists and go when it is deleted. If a paid plan ends, we keep them so the account knows what it had; ending a plan never deletes a child or their history. Stripe keeps its own record of each payment for as long as the law requires, under its own privacy policy.
Your rights
Under the UK GDPR you have the right to:
- See what we hold the parent dashboard has a “Download data” button per child that produces a JSON export of everything we have on that child. Email us if you want your own adult-account export.
- Ask us to delete it there’s a delete button on the dashboard, or you can email us and we’ll do it within 7 days.
- Ask us to correct it most child-facing fields (name, avatar) you can edit yourself from the child’s settings page. For anything else, email us.
- Complain to the regulator: the UK Information Commissioner’s Office at ico.org.uk.
Where the data lives
Puzzitron uses six outside services. Five process data only on our instructions and only for the job listed. Stripe is a processor for our billing records and also a controller in its own right for the payment itself, as explained below.
- Vercel Inc.: runs the app servers and serves static assets. Hosting region: EU (Frankfurt). DPA.
- Neon Inc.: hosts the Postgres database that holds all account / child / session data. Region: UK (London, AWS eu-west-2). DPA.
- Resend Inc.: sends the magic sign-in emails to adults. Receives the recipient email address and a one-time link. Doesn’t store email content beyond delivery diagnostics. DPA.
- Cloudflare Inc.: CDN in front of Vercel. Sees IP addresses and request paths in transit; doesn’t persist them. DPA.
- Stripe: takes payments for Puzzitron Plus and the tutor plan, only if you buy one. Stripe receives the adult’s email address and the id we use for your Stripe customer record; you give your card and billing details to Stripe directly on its own checkout page, and we never see card numbers. Our Stripe account uses Stripe Managed Payments, so Stripe acts as the merchant of record for the sale and is an independent controller of the payment data it collects. Stripe privacy policy. No child data is ever sent to Stripe.
- GoatCounter: counts page views on the marketing pages only. It sees your IP address and browser details in passing to count a visit, but does not store them or set cookies. GoatCounter privacy.
We never sell or rent personal data, and we never share it with advertisers or data brokers. We use no advertising or analytics service that receives personal data.
Families outside the UK
Puzzitron is operated from the UK and welcomes families outside it, including in the UAE, Singapore and Hong Kong. Wherever your family is, your data is stored and processed in the UK or EU, on the same Vercel and Neon infrastructure described above. If you pay for a plan, Stripe handles the payment under its own privacy policy. UK data protection law governs how we handle it, regardless of where you live; we don’t apply a different standard by country. Your rights under this policy, seeing what we hold, exporting a copy, and asking us to delete it, are the same wherever you are.
We also store your child’s time zone (for example “Asia/Dubai”), used to work out their local calendar day so the Daily Mission changes over at their own midnight, not UK time. It’s read from their device at every sign-in and overwritten on their record each time; no history of past time zones is kept, so a family that moves or travels is reflected automatically.
Cookies
Puzzitron uses two cookies, both first-party and both necessary for sign-in to work:
authjs.session-token: adult sign-in (Auth.js JWT). HttpOnly, Secure, SameSite=Lax. Cleared on sign-out.puzzitron_kid_session: child sign-in. HttpOnly, Secure, SameSite=Lax, 1-year expiry by default. Cleared on sign-out or when the parent revokes from the dashboard.
That is all. There are no analytics or advertising cookies anywhere on Puzzitron, which is why there is no cookie banner to click through. GoatCounter, which counts page views on the marketing pages, sets no cookies and does not follow you between sites.
When you pay, Stripe’s checkout and billing portal run on Stripe’s own pages, which may set their own cookies for payment and fraud prevention under Stripe’s privacy policy. None of that happens on Puzzitron itself.
Security
Adult passwords don’t exist. Sign-in is magic-link only, so there’s no password to leak. Child PINs are stored as bcrypt hashes (cost 10), so even a full database leak doesn’t expose the PIN itself. All traffic is HTTPS. Database is in a private network and accessed only over TLS.
Changes to this policy
If we change something material, we’ll bump the “Last updated” date at the top and add a one- line summary explaining what changed.
Questions, concerns, or want a copy of your data? Email hello@puzzitron.com.