Skip to content
← Help center
PrivacyParents and operators

How does WonderMind approach COPPA and GDPR-K?

The product is designed around parental consent, data minimization, PIN login, and in-product export and deletion. Those are design choices. They are not a finished legal program, and this site does not claim 'COPPA-first' as a compliance badge.

Updated 8/23/2026

Consent and minimization
A parent or guardian must accept the child-privacy terms before a profile is created. We ask for a first name, age, and avatar — not a school roster dump. Social login is never offered to child PIN profiles.
Access, export, deletion
Parents can read non-lockboxed progress, export a machine-readable archive on every plan including Free, delete a child profile in Controls, or close the grown-up account from the parent dashboard. Those are the product-owned pieces of a rights request.
What counsel still has to finish
Named legal entity, jurisdiction, signed DPA, subprocessors under production contract, verifiable parental consent in every region, a DPO if you serve the EU, and a staffed rights mailbox. The in-app policy pages remain drafts until that review is done. Do not enroll a real under-13 child as production data on this evaluation site.