Privacy Policy
Last updated: September 29, 2026
Who we are
The App is operated by Roy Halevy (individual developer), Israel.
Questions about privacy? Email us at hello@wondereel.app.
Who this App is for
Wondereel is a child-directed service intended for children (approximately ages 9–11). We treat all users as children and apply COPPA protections to everyone. The App is currently offered only in the United States.
What we collect — and what we don’t
We do NOT collect from children:
- No name, email, phone number, address, or photo.
- No account, login, username, or password (there are no accounts).
- No contacts, no precise location (GPS), no microphone or camera access.
- No advertising identifiers. We do not show ads, and the App uses no third-party advertising, analytics, or tracking SDKs — the only outside services are our video player and app backend (described below), used purely to run the App.
What stays on the child’s device only (never sent to us):
- App preferences, “likes” and “saved” videos, learning progress, and the count of videos watched. This information lives locally on the device and is removed if the App is deleted.
What is processed to make the App work (limited “internal operations”):
- IP address / connection data, processed transiently and used only for these specific internal operations: (1) streaming and delivering the video to the device; (2) performing network communications; and (3) maintaining, securing, debugging, and analyzing the technical functioning of the service. It is used for no other purpose.
- Safeguards: we ensure this identifier is never used to contact a specific individual, to build a profile of a child, or for behavioral advertising. The App uses no advertising, analytics, or tracking SDKs, and we do not track children across other apps or websites.
If a child reports a video (optional, child-initiated):
- The App has a “report this video” button. If a child chooses to use it, we receive only the video ID and the report category (e.g., playback, audio, safety) — no identifier of any kind, so a report cannot be linked to a child or device. Duplicate reports are prevented on the device itself.
Anonymous, aggregate content measurement:
- To learn which videos work well, we count per-video totals across all users — e.g., how often a video is watched to the end, skipped, liked, or saved. These counts carry no identifier, are stored only as running totals per video, and are never linked to a child or device: we measure the video, not the child. We do not build profiles of children.
Third-party services we use
- App backend: The video catalog and channel list are served from our backend provider, Supabase, which processes IP/connection data only to deliver that content to the device. Bound by a data processing agreement to protect it and use it only on our behalf.
- Video delivery: Videos are streamed through our hosting/CDN provider, Mux (Mux, Inc.), which processes IP/connection data solely to deliver the video to the device. Bound by a data processing agreement to protect it and use it only on our behalf.
- Subscriptions: If a parent chooses to subscribe, payment is handled entirely by Apple (App Store) or Google (Google Play). We never receive or store payment card details. A parental gate stands between the child and any purchase or external link.
- Within the App we do not sell or rent any data, and we do not share personal information with third parties for their own purposes or for advertising.
Our website
This section is about our marketing website at wondereel.app, which is a separate surface from the App. The website is written for parents and other adults who are deciding whether to download Wondereel. It is not directed to children, and we do not ask anyone to sign in or to give us any details there.
- Advertising measurement: The website uses the Meta pixel so that we can tell which of our ads actually brought people to the page. It is on the website only. The App itself contains no advertising, analytics or tracking code of any kind, and it never will.
- What it records: Two things. That a page was viewed, and that a visitor tapped one of the App Store or Google Play buttons. Each is sent together with the identifier your browser presents to Meta — typically a Meta cookie, your IP address and your browser’s user-agent string.
- Who receives it: Meta Platforms, Inc. receives that information and may use it to measure and target advertising, including in ways it determines, under its own data policy. This is the one place where information leaves us to a third party for advertising purposes, and it involves the website only.
- What it does not do: We have turned Meta’s Advanced Matching off, so no email address, phone number, name or other personal detail is sent to Meta from our pages. We do not upload customer lists. Nothing from inside the App is ever sent to Meta.
- If you opt out: If your browser sends a Global Privacy Control or Do Not Track signal, the pixel does not load for you at all — not the script, not the page view, not the button tap. You can also block it with any content blocker, and the website works exactly the same either way.
- No cookies of our own: Apart from the Meta pixel described here, the website sets no cookies and loads nothing else from anyone else. Our fonts, images and video are served from our own domain.
Data retention and deletion
This is our data-retention policy, as required by COPPA. We keep children’s information only as long as needed for the purpose it was collected, and then delete it.
- On-device data (preferences, likes/saves, progress): stays on the device, is never sent to us, and is removed when the child/parent clears it or deletes the App.
- Operational data — IP / connection logs. Purpose: delivering video and the catalog, and keeping the service working and secure. Business need: the connection data is needed only at the moment of the request and for short-term security, troubleshooting, and technical analysis. Deletion timeframe: retained no longer than 30 days, then automatically deleted. (Our processors, Supabase and Mux, also limit their own infrastructure-log retention under their data processing agreements.)
- Content-report records (video ID + category only, no identifier) and aggregate content counts (per-video totals, no identifier): these contain no personal information about any child. Reports are kept only as long as needed to act on them, and in any case no longer than 90 days, after which they are automatically deleted; aggregate counts are kept as running totals.
- We do not retain children’s information indefinitely.
Parents’ rights and choices
Because Wondereel uses no accounts, stores a child’s activity on the device, and holds no identifier that links any data to a specific child on our servers, parents are fully in control:
- Delete all of the child’s data: use the “Delete my data” button in the Parents area, or simply delete the App — both remove all on-device data. There is no server-side record tied to your child to delete (reports and content counts are anonymous; connection logs are transient and auto-deleted).
- Refuse further collection / ask questions: email hello@wondereel.app and we will respond.
How we protect children’s information
We maintain a written information-security program appropriate to the sensitivity of children’s data, including assigning responsibility for security, assessing risks, applying safeguards (such as encryption in transit), and reviewing these measures regularly.
Parental consent
Because the App collects only the limited information above strictly to support the internal operations of a child-directed service — with no accounts, no third-party sharing, and no behavioral advertising — it operates under COPPA’s support-for-internal-operations basis and does not require separate verifiable parental consent. If we ever change this (for example, by adding a feature that collects additional information), we will provide notice and obtain verifiable parental consent before that change takes effect.
Changes to this policy
If we make a material change to our data practices, we will update this page and, where required, notify parents and obtain consent before the change applies.
Contact
hello@wondereel.app — Roy Halevy, operator of Wondereel.