Who is responsible for your data
Twinklenook is operated by Viacheslav Chekanovskyi, acting as an individual. For the purposes of the EU and UK General Data Protection Regulation, that person is the data controller for the personal data described here.
You can reach us about anything in this policy, including privacy complaints, at privacy@twinklenook.com. We answer privacy requests within 30 days, and deletion requests within 7 days.
We use YouTube API Services
Twinklenook uses YouTube API Services to find and show videos. All video playback happens inside the official embedded YouTube player. We never download, copy, re-host or modify YouTube videos, and we never place our own advertising over the player.
By using our service you also agree to the YouTube Terms of Service. Google processes data through the embedded player under the Google Privacy Policy, which is separate from this one and which we recommend you read.
We use YouTube read-only endpoints exclusively. We do not upload, edit, rate, comment on or delete anything on YouTube, and we never ask you to sign in to a YouTube account.
What we collect about the parent
- E-mail address: required to create the account and sign in.
- Display name: optional, shown in the parent area.
- Password: stored only as a bcrypt hash. We never store the password itself and cannot recover it.
- Google account identifier: only if you choose "Sign in with Google". We request just your e-mail address and basic profile; we receive no access to your YouTube account, subscriptions or watch history.
- Parent PIN: stored as a hash, used to lock the parent area on a shared family device.
- Sign-in sessions: hashed refresh tokens and their expiry dates.
- Consent record: whether you allowed your block decisions to be counted anonymously (see below), with the dates you granted or withdrew it.
- Subscription record: plan, status and expiry date, when a subscription is present on the account.
What we collect about the child
A child profile is created by the parent, from the parent account. Children do not register, do not provide an e-mail address, and cannot create or change a profile themselves.
- Name or nickname chosen by the parent, and an optional avatar.
- Date of birth and gender, used to pick the age rating and to bias search results towards age-appropriate content.
- Interface languages and the language used to bias search results.
- Age rating (0–3, 3–6, 6–9 or 9–12), enabled topic categories, and the parent-entered keywords that are preferred or blocked for this child.
- Screen-time settings: daily limit, allowed days and hours, and the family time zone used to evaluate them.
- Paired child devices: a device name chosen by the parent, a hashed device token, and the time the device was last seen.
What we collect about viewing activity
So the parent can see what their child watched and so we can suggest better videos, we store a record of activity in the app.
- Watch history: the YouTube video and channel identifiers, the video title and thumbnail address, how long the video was, and when it was watched.
- Likes set by the parent for a child, as a signal for recommendations.
- Collections created by the parent: the collection name, the videos in it, and which children it is assigned to.
- Blocks created by the parent: blocked videos, channels and words, with an optional reason.
- Moderation log: when an automatic filter hides a video, we record which filter matched, the video and channel identifiers and the video title.
Technical data and server logs
We do not store IP addresses in our product database. An IP address is processed while a request is being served: it appears in server logs and in short-lived counters that stop brute-force attempts on sign-in and device pairing. These are security records, they are not linked to a child profile, and they are not used to build a profile of you or your child.
We use no advertising network and no tracking pixels. The only measurement tool from a third party is the optional usage analytics described in the next section, and it runs only if you allow it.
Usage analytics, only with your permission
If you choose “Allow” in the cookie banner, we use Google Analytics 4, loaded through Google Tag Manager, to understand how parents use the website and the parent area. We use it only to improve the service.
We measure which pages are opened, which buttons and links are clicked, and whether signing up or signing in worked. Google Analytics also records general information about each visit, such as the country, the type of device and browser, the language and the website you came from.
We never send names, email addresses, child profiles, video titles, search queries or anything else you type. Page addresses are sent without identifiers (a child's profile page is sent as /parent/children/:id), and from link parameters we keep only campaign tags such as utm_source.
Analytics never runs in the children's area, on the profile picker or on a child's paired device, so we collect no analytics about children.
Google Analytics does not log or store IP addresses. Google signals, advertising features, ad personalization and data sharing with other Google products are switched off, we do not use the User-ID feature, and Google Analytics keeps event-level data for 2 months.
Nothing is loaded until you choose “Allow”, and if you choose “Decline”, Google Analytics is not loaded at all. You can change your choice at any time with “Cookie settings” at the bottom of the website and of the parent area. When you withdraw consent, we also delete the Google Analytics cookies from your browser.
How long we keep YouTube data
Video titles and thumbnail addresses come from YouTube. In line with the YouTube API Services Developer Policies we do not keep them for longer than 30 days without refreshing them. A scheduled job runs daily: in watch history, likes and moderation logs, titles and thumbnail addresses older than 30 days are erased, while the fact that the video was watched (the date, the duration and the video identifier) is kept so that the parent area still shows an accurate history. Videos saved to a parent collection keep working because their details are refreshed from YouTube instead of being erased.
How long we keep everything else
- Account data, child profiles and settings: for as long as the account exists.
- Expired sign-in sessions, used pairing codes and revoked devices: removed automatically every day.
- Usage analytics in Google Analytics: event-level data for 2 months.
- Anonymous block counts: kept after account deletion, because they carry no link to you (see the next section).
Who we share data with
We do not sell personal data, we do not share it with advertisers, and we do not use it for advertising, remarketing or profiling for advertising.
- Google and YouTube: when a video plays, the embedded player communicates with YouTube directly from the browser. We use the privacy-enhanced youtube-nocookie.com domain, so YouTube does not set its usual tracking cookies unless the video is played.
- Hosting and infrastructure providers, who store the database and run the servers on our instructions.
- Anonymous block counts: only if you switch this consent on, the fact that some parent blocked a particular video or channel is added to a shared counter. That counter records the video or channel identifier and a number. It carries no link to you, your account or your child, and it stays in place if you later delete your account, because there is nothing in it to delete. You can withdraw this consent at any time in the parent settings.
- Google, as the provider of Google Analytics, only if you allow analytics: page addresses without identifiers and the clicks described in the usage analytics section. Google processes this data on our behalf.
- Where the law requires it, for example a valid legal request.
Children, COPPA and GDPR
Twinklenook is directed to children, and we have notified Google of that. The parent, not the child, is our user: the parent creates the account, creates every child profile, and is the person who gives consent for the processing of their child's data under the GDPR and the United States Children's Online Privacy Protection Act.
We show no advertising of our own. We do not run personalized advertising, remarketing or interest-based profiling, and we do not allow any third party to do so through our service. Advertising that YouTube itself places inside the embedded player is served by Google under its own policies, and we neither control, block nor modify it.
We collect from a child only what the parent enters when creating the profile, plus what the child watches inside the app. A child cannot type free-form personal information into the service, cannot message anyone, and cannot publish anything. Usage analytics never runs in the children's area.
Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a copy in a portable form, and withdraw a consent you gave. The parent may exercise these rights on behalf of their child.
To exercise any of them, write to privacy@twinklenook.com. You also have the right to complain to your local data protection authority.
Deleting your data
You can delete your account yourself, at any time, from Settings in the parent area. Deleting the account permanently removes your account, every child profile on it, and all associated settings, watch history, likes, collections, blocks, sessions and paired devices. This happens immediately and in every case within 7 days. The only thing that survives is the anonymous block counter described above, which contains no information about you.
Security
Passwords and PINs are stored as hashes, sign-in tokens are stored hashed and expire, all traffic is encrypted in transit, and the parent area is protected by a separate PIN so a child on a shared device cannot change limits or unblock content. No service can promise perfect security, but we treat family data as sensitive and design accordingly.
Where data is processed
Our servers and database are operated by hosting providers that may be located outside your country. Where data leaves the European Economic Area, we rely on the safeguards offered by those providers, such as the European Commission Standard Contractual Clauses. If you allow analytics, Google may also process usage data outside your country, relying on the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses.
Changes to this policy
If we change this policy we will update the effective date at the top of this page. If a change materially affects how we handle your data or your child's data, we will tell you in the app before it takes effect.
Contact us
Privacy questions, requests and complaints: privacy@twinklenook.com.