Who we are
Voobi is a service operated by Flux Pillar PTE. LTD., a company incorporated in Singapore. For the purpose of data protection law, we are the data controller. You can contact us at: privacy@voobi.com.
Who this applies to
This policy applies to parents and guardians who create an account and use Voobi to curate a video feed for children in their care. Children do not create accounts and are not required to provide any personal information to use Voobi.
Data we collect
Parent account data
When you sign up, we collect your email address and a hashed password. We do not collect demographic data (such as age, gender, or similar) from you.
Google / YouTube connection
When you connect your YouTube account, we store:
- An OAuth refresh token (encrypted at rest using AES-256-GCM) to make YouTube API calls on your behalf
- Your YouTube channel ID, used to display your connected account in the parent dashboard
- Your Google account subject identifier (sub), email address, and display name, so we can show the connected account and avoid duplicate links
We use this data solely to let you browse YouTube content, build your curated whitelist, and identify the connected Google account in your household. We do not store other Google profile fields beyond what is listed above.
Device linking
When you link a child's device to your household, we store:
- An opaque installation identifier in a browser cookie, stored only as a hash in the linked-device record, so reconnecting the same installation does not create duplicate sessions
- A coarse device description, such as browser and operating system, plus the time it was last active, so you can recognize and manage linked devices
- A session cookie that associates the device with your household, so the correct curated feed is shown
Devices are linked using a time-limited 10-character pairing code that expires after 5 minutes. Children do not log in or create accounts. When a parent links a child's Google account, we may also store that child's Google subject identifier, email address, and display name on the household child profile (see Children below).
Library tools
Saved views store a name and your household's chosen library filters. Recently Removed keeps a snapshot of removed video approvals and list memberships for recovery. Library activity records approval, removal and restoration events, including the acting parent, video title and applicable child profile. These tools are available only to parents in your household.
Watch data
We record how many times each video in your whitelist has been watched within your household. We also store child-linked watch sessions that include start and end timestamps and watched duration, so parents can enforce daily limits and review activity. Household-level watch counts are used to surface trending videos across the service (for example, to help other parents discover popular content). When used for trending, this data is aggregated across households; it is not used to identify you or your household to others.
Website analytics
We use privacy-limited PostHog analytics on public marketing and legal pages, authenticated parent dashboard pages, and the parent video preview. We collect a page path with query strings, fragments, and dynamic video identifiers removed, along with approximate country or region and browser/device information. When a signed-in parent uses the dashboard, we identify the account only by its pseudonymous Supabase user ID, not by email, name, child, household, or viewing details. Public pageviews remain anonymous and are separated before a parent ID is applied.
PostHog analytics is not enabled on child feed or child watch pages, device linking, operator portal pages, or authentication and password-recovery forms. We disable autocaptured clicks, scrolling, form and page text, heatmaps, error capture, and session replay. The browser identifier is kept in memory for the current page session and is not stored by PostHog in cookies or local storage. We do not use analytics for advertising, cross-site tracking, or profiling.
Anonymous child feature statistics
To understand which child-app features work well, Voobi records coarse usage counters such as the selected video-length range, watch or listen mode, a timed-session range, or whether a video or podcast was opened. We do not include a child or household ID, content ID or title, list name, search text, or exact viewing history in these statistics. A one-way device code is generated by Voobi's server and changes every week, so activity cannot be followed across weeks. Operator reports hide any group containing fewer than five devices. These statistics are used only to maintain, measure, and improve Voobi; they are not sent to PostHog, used for advertising, or used to profile a child.
How we use your data
We use your data to:
- Provide and secure the service (authentication, device linking, displaying your curated feed)
- Make YouTube API calls on your behalf when you manage your whitelist
- Identify popular content across the service (using aggregated household watch counts)
- Understand how the service is used and improve it (using privacy-limited analytics)
We do not use your data for advertising, profiling, or any purpose not listed above.
Lawful basis (GDPR)
Our lawful bases for processing are:
- Performance of a contract: to provide you with the Voobi service
- Legitimate interests: to operate, secure, and improve the service, and to surface trending content in aggregated form
- Consent: where required for optional features
Google user data
Our use of data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
We request the minimum YouTube access needed for the service: read access to list channels, playlists, and video metadata so you can build your whitelist. We do not request write access. We do not use Google user data for any purpose other than operating the Voobi service.
We do not sell, license, share, or transfer Google user data to any third party except as necessary to operate the service (see Subprocessors below), and never for advertising or unrelated purposes.
Children
Voobi is designed for use by families. Children use the service through a device linked to their parent's or guardian's account. Children do not create their own Voobi accounts. Parents may create a child profile with a display name, and may optionally link a child's Google account, in which case we store the Google subject identifier, email address, and display name for that profile. We also store child-linked watch sessions (including timestamps and duration) for limits and parent review. Device linking uses the household session cookie and opaque installation identity described above.
We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you believe we have inadvertently collected such information, contact us at privacy@voobi.com and we will delete it promptly.
Data protection
- OAuth refresh tokens are encrypted using AES-256-GCM before storage
- All data at rest is encrypted by our database provider
- All data in transit is protected by HTTPS
No sale of data
We do not sell your personal information to anyone.
Retention
| Data | Retention |
|---|---|
| Account data (email, password hash) | For the life of your account, plus a reasonable period after closure |
| OAuth refresh token, YouTube channel ID, and connected Google sub / email / display name | Deleted when you disconnect YouTube or close your account |
| Device bearer / session cookie and linked device row | Expire 90 days after linking or relinking, or earlier when you unlink the device or close your account |
| Opaque installation identity cookie (stored as a hash in the linked-device record) | Up to 400 days (browser cookie lifetime), so reconnecting the same installation can reuse one device record |
| Household watch counts and child-linked watch sessions | Deleted when you close your account |
| Saved library views | Until you remove the view or its household; child-specific views are also removed when that profile is deleted |
| Recently Removed snapshots | Available to restore for 30 days, then removed by scheduled cleanup or the next history request; removed earlier when the associated child profile or household is deleted |
| Library activity events | Available for 90 days, then removed by scheduled cleanup or the next history request; child-linked events are removed earlier when that profile is deleted, and all household events are removed with the household |
| Aggregated trending data | Retained in anonymised form with no household linkage |
| Website analytics | Up to 24 months, subject to shorter provider limits |
| Anonymous child feature statistics | Up to 90 days; the one-way device code rotates every week |
You can request deletion of your data at any time from the parent dashboard settings or by contacting us (see Your rights below).
Subprocessors
We use the following to operate the service:
- Supabase - authentication and database. Privacy policy
- Hosting (Vercel, Cloudflare, or similar) - infrastructure. Their respective privacy policies apply.
- PostHog EU Cloud - privacy-limited website and parent product analytics. Analytics events are sent to the EU Cloud region. Privacy policy
- YouTube (Google) - we embed YouTube players so you can watch whitelisted videos. When a video is played, YouTube may collect data according to Google's privacy policy.
International transfers
Your data may be processed in countries outside your country of residence, including outside the European Economic Area (EEA). Where we transfer data from the EEA or UK to a third country not deemed adequate by the relevant authority, we use Standard Contractual Clauses approved by the European Commission as a safeguard.
Your rights
If you are in the EEA or the UK, you have the right to:
- Access your personal data
- Have it corrected or erased
- Restrict or object to processing
- Data portability
- Withdraw consent where we rely on it
- Lodge a complaint with your supervisory authority
To exercise any of these rights, use Account deletion in the parent dashboard settings or contact us at privacy@voobi.com. We will respond within the timeframe required by applicable law.
California residents (CCPA): You have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, use Account deletion in the parent dashboard settings or contact privacy@voobi.com.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. For material changes, we will notify you by in-app notice or email. We encourage you to review this policy periodically.