Privacy notice
Effective: May 30, 2026
DinkyTask pays particular attention to protecting the data of minors. This notice gives a short overview of what we handle and why.
1. Who handles the data?
- Service: DinkyTask
- Website: https://dinkytask.com
- App: https://app.dinkytask.com
- Contact: hello@dinkytask.com
2. What data do we handle?
Parent accounts
- email address
- hashed password
- optional push token
- subscription-related identifiers
Child accounts
- username
- hashed password
- optional birth year
- avatar, points, reward requests
Usage data
- task submissions and scores
- uploaded audio, images, and files used for OCR or AI
- AI Homework Helper conversations and topics
- AI usage logs and AI credit consumption data
- technical logs, error reports, device and browser information
Contact requests
- name, email address, and message submitted through the contact form
3. Why do we handle it?
| Purpose | Example | Legal basis |
|---|---|---|
| providing the service | accounts, plans, rewards, task attempts | performance of a contract |
| running AI features | OCR, AI review, AI topics | performance of a contract |
| notifications | push or email | consent / legitimate interest |
| security and logging | abuse prevention, limit handling | legitimate interest |
4. Protection of minors
- A child cannot independently create a family setup without a parent.
- We aim to collect the minimum amount of data needed.
- The parent can delete the child account and related data at any time.
- We do not use children's data for marketing profiling.
5. AI and third parties
DinkyTask may use third-party services for AI, narration, error reporting, or payment processing. In those cases, we only send the data needed for the relevant feature.
- OpenAI — processing text, audio, images, moderation, OCR, or AI features for the relevant function
- Google Gemini — depending on configuration, AI narration or related processing
- OmniVoice TTS — depending on configuration, narration for learning materials and AI topics
- Piper TTS — local server-side narration; in this case text is not sent to an external TTS API
- Stripe — payment processing
- Brevo — transactional email
- Sentry — error reports and diagnostic logs
- Browser/platform push providers — delivery of push notifications
- Hetzner — infrastructure and hosting
Uploaded and generated files are stored in S3-compatible object storage on DinkyTask infrastructure. Browser access to these files usually uses time-limited signed URLs.
6. Website analytics and cookies
On the public DinkyTask website (dinkytask.com), we may optionally use Google Analytics 4 to understand which pages are useful, where visitors come from, and where the website should be improved. We do not use this to measure child or family content inside the app.
Google Analytics only activates if the visitor accepts analytics cookies in the cookie banner. If analytics cookies are rejected, we do not load the Google Analytics script. The choice is stored in the browser and can be reopened later via the “Cookie settings” button in the website footer.
- Provider: Google Ireland Limited / Google Analytics
- Purpose: website traffic and page usage statistics
- Legal basis: consent
- Data: technical browser and device information, approximate location, page views, and interactions
7. Data retention
- Some uploaded files are automatically deleted after their retention period.
- Account data is kept until the account is deleted.
- Error-reporting and security logs are kept for a limited period for operations and abuse-prevention purposes.
- Billing, payment, and credit-consumption history may be retained longer for legal, support, dispute-handling, or refund reasons.
- For trial or abuse-prevention logic, some technical fingerprints may be retained for a limited time.
8. Account and family deletion
A parent may request deletion of their own account. If another active parent remains in the family, only that parent account is removed, and the family and child data can continue to be used under the remaining parent's supervision.
If the last parent account is deleted, or if an administrator deletes a family for a valid reason, we remove the family's active product data. This includes, for example:
- personal data in parent and child accounts,
- tasks, plans, task attempts, points, and rewards,
- learning materials, question banks, practice data, and related history,
- AI topics and AI conversations,
- uploaded files and related stored media,
- push notification tokens, webhook settings, and onboarding state.
A minimal technical record may remain in a “deleted” state so that the previous family ID can be looked up for support or billing questions. This record does not contain active product usage data.
If the family has an active Stripe subscription, we automatically attempt to cancel it when the family is deleted. We may keep internal records of billing, payment, and credit-consumption history, such as Stripe customer, subscription, invoice, payment, or refund identifiers, amount, currency, status, billing email address, and AI credit grant/usage data. We keep this for support, dispute handling, refunds, accounting, and legal compliance.
After deletion, we may keep cost, credit, and operational statistics from AI usage history, but we remove family content such as submitted prompts, AI responses, and child-linked identifying data.
9. Beta status
The service is in beta, so data-handling flows and related descriptions may continue to evolve while the product is refined.
10. User rights
- access
- rectification
- erasure
- data portability
- objection and withdrawal of consent
11. Contact
For privacy-related questions, use the official contact form or write to hello@dinkytask.com.