Privacy policy
Last updated: 2026-09-28
Umilo helps a parent turn a page of homework into a short quiz, and shows what the child found clear and what is worth revisiting. This page explains exactly what Umilo holds, what it never holds, and who else touches it.
Who we are
Umilo is operated by Vasyl Vynnytskyi (ФОП Винницький Василь Михайлович), a sole trader registered in Ukraine, who is the data controller for the data described on this page. Contact: [email protected]. The account holder is always an adult parent or guardian.
How a quiz works
Every quiz follows the same four steps.
- A parent photographs the homework or types a topic.
- Google Gemini processes the photo or topic to identify concepts, generate questions and review their answers. Standard quizzes have 5, 10 or 15 questions; focused follow-ups have two.
- The parent confirms the subject and the concepts, then sends a link. The child needs no account.
- The child taps answers. The parent sees a cautious per-concept readout and one coaching example.
Homework photos
A photo of a child's homework is the most sensitive thing Umilo touches, so it follows a single rule: Umilo never keeps it.
- The photo is resized in your browser before it leaves your device.
- It is sent to the server once, for one analysis, and held only in memory while that analysis runs.
- It is never written to the database, never written to file storage, and never written to logs.
- What survives the analysis is only the subject, the list of concepts, and a short scrubbed summary that you confirm before anything is sent to your child.
- Umilo does not promise zero retention by any provider.
What Umilo stores
Umilo keeps only what it needs to show a parent how their child is doing.
- Parent account: the email address and name supplied by Clerk when the account is created.
- Child profile: the child's name, exact grade, an optional display name, an optional avatar image, the content language, and the timestamp of your consent.
- Quiz content: the confirmed subject, the concepts, the short scrubbed summary, and the generated questions.
- Child responses: which option was tapped, and when.
- Results: the readout and the coaching example shown to you.
- Optional feedback: a parent survey answer, and any question reports you file.
- Parent help: your questions, generated replies, source references, explanation language and optional tried/helpful feedback.
The page your child sees
The page a child opens is deliberately plain, and it stays that way.
- No advertising, and no links to any other website.
- No cookies used for tracking.
- No score, no timer, and no leaderboard.
- Product analytics on this page run in memory-only mode and record the attempt identifier alone — no name, no IP address, no page address, and no referrer. The answers themselves are sent to PostHog by Umilo's server, with the child's profile name removed, to check the quality of the questions (see “Who else processes the data”).
Cookies
Umilo uses cookies for three jobs — keeping a parent signed in, taking a payment, and measuring advertising for visitors outside the EU, the UK and Switzerland. The page your child opens sets none of them.
- Clerk sets a session cookie on the parent side so you stay signed in.
- Creem sets its own cookies during checkout.
- PostHog records product analytics on the parent side.
- The page your child opens sets no tracking cookies at all.
- Meta sets advertising cookies on the parent-facing pages, and only for visitors outside the EU, the UK and Switzerland. Visitors from those countries are served pages that contain no Meta code.
Where the data goes
Your family's data is stored in the EU, and some vendors process it in the United States.
- Storage in the EU: Supabase (eu-west-1) for the database, the avatar images and the read-aloud audio clips; PostHog's EU cloud for product analytics.
- Some data is processed outside the EU by Clerk, Google Gemini, Vercel, Resend and Google Cloud (the read-aloud voice).
- Those transfers rely on the EU–US Data Privacy Framework or on Standard Contractual Clauses.
- Homework photos are not transferred anywhere for storage, because they are never stored.
- Meta processes advertising measurement in the United States, and only for visitors outside the EU, the UK and Switzerland.
Why Umilo may hold this data
The child never signs up. The parent does, and the parent supplies the child's data.
- Under COPPA, the parent is the account holder, provides the child's information, and gives parental consent when the child profile is created; that consent is recorded with a timestamp.
- For families in the EU, the UK and Ukraine, that parental consent together with the contract to provide the service is the legal basis under the GDPR and its rules for children's data.
- The consent timestamp is stored on the child profile, so you can always see when it was given.
Who else processes the data
Umilo uses a small set of vendors. Each one sees only what its job requires.
- Clerk — parent sign-in and account management.
- Supabase — the PostgreSQL database and the file storage that holds avatar images and the read-aloud audio clips, in the EU region eu-west-1.
- Google Gemini — processes homework photos and typed topics to identify subjects and concepts, generated questions for review, selected answers for coaching, and parent requests for help.
- Google Cloud Text-to-Speech — turns the text of a question, an answer option or an explanation into the voice a child can play on the quiz page. It receives that text only — never the photo, the child's name or the answers given — and the audio clip is kept in Supabase for up to 30 days so it is not generated twice.
- Creem — merchant of record for payments, operated by Armitage Labs OÜ in Estonia. Creem handles the card details; Umilo never sees them. Creem sends Umilo only what it needs to switch the plan on and off: a customer identifier, a subscription identifier, the subscription status, the dates of the current billing period, any scheduled change such as a pending cancellation, and the identifier of the product you are on. Creem's own privacy policy is at creem.io/privacy.
- PostHog — product analytics, in the EU cloud. So that the quality of the questions can be checked and improved, PostHog also receives the text of every quiz — the subject, the topics, and each question with its options, correct answer, hint and explanation — and, for each question a child finishes, which options were tapped and in what order, whether a hint was shown and how long it took. It also receives a diagnostic copy of the requests Umilo sends to Google Gemini to read a homework photo, to write and check questions and to write and review coaching, and of the answers it gets back; the coaching copy contains the questions and the child's answers. All of this is linked to the parent's account. Before anything is sent, Umilo removes email addresses, phone numbers and names written after a label such as “Name:”, and removes the child's name as entered in the profile from the quiz text and answers. A name written some other way — in a typed topic or on a homework page — can still get through, so please leave personal details out of topics. PostHog never receives the homework photo or a quiz's share link, and for parent help it receives only timing and error information — never a parent's question. How long these copies are kept, and how to have them deleted, is explained below.
- Resend — email to the parent: a welcome note after sign-up, a message when a child finishes a quiz, and, unless the parent turns them off, reminders — when a quiz has not been opened a day after it was made, and a re-check about a week after a topic needed help. It receives the parent's email address, the child's name as the parent entered it, the quiz topic and a link to the parent's own page — never the child's answers, the questions or the child's quiz link. Every reminder has an unsubscribe link.
- Telegram — operational alerts for the operator. It receives an account's email address and what happened — a sign-up, a quiz created or finished (with its broad curriculum area, grade and number of questions), or an error code — never a child's name, answers or homework content.
- Vercel — hosting.
- Google Gemini also processes selected answers and parent questions to draft and review explanations. Known profile names are removed from parent-help inputs; avoid including identifying details.
- Meta — advertising measurement. Umilo reports four events: a page view, a completed sign-up, a created quiz and a paid subscription. Meta receives a one-way hash of the account's email address and identifier, its own advertising cookies, the IP address and the browser user agent. It never receives a name, a child's data, a homework photo, a question or a share link, and nothing is sent at all for visitors in the EU, the UK or Switzerland.
How long Umilo keeps things
Different data has a different life.
- Homework photos: not kept at all.
- Responses, readouts and coaching remain until you delete the associated child or account, or request deletion. Automatic deletion after 12 months is not currently implemented.
- Quiz text, answers and AI diagnostic copies in PostHog: kept under the analytics project's retention, separately from the database, until deleted on request (see “Deleting data”).
- Share links: they stop working 30 days after the quiz is created, and you can stop one sooner from your dashboard.
- Account and child profiles: kept until you delete them.
- Parent-help conversations expire after 30 days and are removed by daily cleanup. Deleting an associated quiz, child or account removes dependent conversations sooner.
Deleting data
You are in control of everything Umilo holds about your family.
- Deleting a child profile also removes that child's quizzes, responses and readouts.
- Deleting the account removes the Clerk record and cascades the deletion through the database.
- Deleting a child, a quiz or the account does not reach the copies held in PostHog. Write to [email protected] and Umilo deletes everything PostHog holds for your account within 30 days.
- Deletion is permanent. Umilo cannot restore a deleted profile or a deleted account.
Your rights
Depending on where you live, you can ask Umilo to do the following. Umilo answers within 30 days.
- See the data held about you and your child.
- Correct anything that is inaccurate.
- Delete a child profile, or the whole account.
- Receive a copy of the data in a portable form.
- Withdraw consent for a child, which means deleting that child's profile.
- Complain to your national data protection authority.
Changes to this policy
If this policy changes in a way that affects what Umilo collects or who processes it, the account holder is told by email before the change takes effect. The date at the top of this page always shows the version you are reading.
Contact
Questions about this document? Write to [email protected].