Effective from 3 September 2026. Todi is a platform with games and learning for children, families, and classes. This document explains what information we collect about you and your child, why we need it, who we share it with, and how to delete it. We describe how the service actually works, not how these documents are usually written. For the terms of use, see a separate document, User Agreement. Questions, requests to delete and download your data — use the feedback form on the website, or email info@todi.club.
The service is still under development: sections appear, change, and disappear, and so does the data we need to collect. This privacy policy will change more often than a mature service would, and it describes the situation as of the date above, not forever. Practically speaking: do not entrust Todi with anything whose loss would hurt. We make backups and try not to lose anything, but it would be dishonest to promise data safety during beta.
Let's start with this, because it matters more than lists.
Facebook Pixel, Sentry, or any other third-party visitor tracking system.
stored anywhere.
see below.
and recording would be a separate conversation about consent that we didn't have.
optional, is not an identifier for us, and we don't search for anyone by it.
user identifier and a confirmed email.
@name, interface color, an iconor an uploaded profile picture and cover. The profile is private by default and not visible to strangers.
and time zone; you confirm them. Date of birth is needed for just one thing — to calculate the school year in the mini-school on September 1, so your child gets the curriculum for their age.
your settings, your permissions.
A child's account is created by an adult in the "Family" section. This account is different:
and share.
connected to that account.
We don't verify age at registration and don't collect separate parental consent beyond the fact that the child account is created by an adult from their account. Restricting date of birth to the 3–100 year range is protection from typos, not an age limit.
itself, but its irreversible hash, along with a shortened string of your browser and the expiration date. A session lasts 90 days.
in via link. Treat such a link like a password: whoever has it can log in.
text is not preserved — we don't have version history.
the child.
report doesn't have separate storage; it's calculated from this data.
We don't have object storage. Most uploads — profile pictures and covers, pictures in messages and on the board, cards, game archives, and photographs of children's work — are stored as bytes inside the database itself and end up in its regular backup. Separately, as files on the server disk, are only class board files and audio with documents from uploaded materials. Backups are handled by the server's standard tools.
There aren't many recipients, and we're specific about what goes to each.
When you log in via Google, we verify the token they gave us and extract the identifier and confirmed email from it. Then our own session takes over.
Only by your explicit action. What leaves: lesson name with class name, lesson note, link to it, time, and time zone. Participant lists are never recorded in the event — otherwise Google would send invitations to addresses we didn't give it. The access refresh key is stored with us in encrypted form.
This is the most significant data transfer, and we ask you to read it carefully. The Todi assistant runs on Google's Gemini model. When you or your child write to Todi, Google receives: the entire conversation with the assistant, age group, language, role, and the address of the open page. Before sending, we substitute what we provide: names, @name links, and class names are replaced with tags like [[NAME1]]. But this doesn't protect free text. If a child writes "my name is Masha, I live in such-and-such a city," this goes to Google word for word. Right now we use Google's free tier. Under its terms, **conversation content may be viewed by Google employees and used to improve their products, including for training models**. We consider this temporary and intend to review it, but we must tell you about it plainly right now. The assistant is not available to everyone: it's enabled by a separate permission. If you don't want your child's data to reach Google, don't use the Todi assistant and explain this to your child.
One message: your support request via the feedback form, with your reply address.
If you enabled notifications, your browser's service — Google, Mozilla, or Apple, depending on your browser — can see the delivery address and the fact that a message was sent. Notification content is encrypted and is not available to them.
The conversation goes directly between participants, and when a direct connection is not possible — through our own relay server, which sits next to the platform and doesn't belong to third parties. Credentials for it are temporary, good for one hour. The public address detection server receives not a byte of the conversation. No recording is done.
Games uploaded by users may load Google fonts. This means that when opening such a game, your child's IP address and browser information will reach Google's servers. Loading third-party scripts and any requests to other external addresses from such games are forbidden by us permanently.
only counters without names are visible; hours played are shown only to teachers.
and if the class is linked, the mini-school plan and report. Teacher notes about a student are visible only to that teacher.
Admin login "as" another person is logged. What parents should know: messages in classes and rooms are not moderated. A room owner can invite anyone via link, including people without an account. If your child uses classes and rooms, they may be in conversation with adults you didn't invite.
restore, erase. In the archive they sit for 7 days, then are deleted permanently.
child's work, messages — are deleted too.
deleted.
You have the right to know what data we have about you, request its correction or deletion, withdraw consent, and object to processing. Straight up, how it works today: there's no "download my data" or "delete my account" button in the interface yet. Write to us via feedback form, and we'll do it manually. A parent can delete their child's account themselves, from the "Family" section, anytime. We understand that automatic export and deletion aren't convenience — they're your right, and we intend to add them.
We may change this policy. The date at the top of the document shows when it was last changed. For significant changes, we'll notify you in the interface.
Via the feedback form on the website, or by email to info@todi.club. We respond to requests to delete and download data.