The Unomundi App Privacy Policy
🌍 Hi, explorer, this part is for you
We made Unomundi for you. Before you start exploring, we want to tell you, plain and simple, what happens with your stuff while you're here.
This is the short, honest version. The longer one for grown-ups is further down.
What we keep
So Una can guide you and remember where you've been on the map, we keep:
-
Your nickname (whatever you choose, it does not have to be your real name)
-
Your age (so Una talks to you the right way; a 7-year-old and an 11-year-old don't want the same thing)
-
The country you call home
-
The countries you've explored and how far you've got
-
Your favourites (things you tap and save as you go through lessons; this is yours, it builds your travelbook)
-
What you tell Una while you're chatting with her, if your grown-up has switched chat on
That's it. No school. No address. No last name. No phone number.
What we never ask for
Una will never ask you for:
-
Your school or where you live
-
Your phone number or email
-
Your photo
-
Your full name
If you ever tell her any of these by accident, she won't repeat them and we don't keep them.
About chatting with Una
Una is an AI. She's clever, and she's kind, but she's not a person, and she's not a secret friend. Here's the deal:
-
Your grown-up has to switch chatting on before you can talk to her. Until they do, the chat is locked.
-
What you tell Una is not a secret from your grown-up. If something you say sounds like you're not safe, or like you're really sad, our team and your grown-up may see a short summary so they can help. We won't promise to keep things hidden from the people who look after you. That's not us being nosy, that's us looking out for you.
-
One important exception: if you ever tell Una that someone at home is hurting you, she won't tell that person. She'll help you find another grown-up you trust (a teacher, a grandparent, a friend's parent), and our wellbeing team will help too.
Who sees your stuff
Three groups, and that's it:
-
You
-
Your grown-up (the parent or carer who set up your account, the one who is linked to your account)
-
A small Unomundi team who keep the app safe and working
Every person on our team who can see your information has had a background check. That's a special check done by another company to make sure they are a safe, trusted person to look after kids' information. We did this because we wanted to, not because someone made us. Keeping kids safe is the whole point.
We never sell your information. Not to advertisers. Not to anyone. We will never use your favourites, your travelbook, your chats, or anything else about you to send you targeted ads or to build a profile of you for ads. There are no ads inside Unomundi today, and if we ever did add any, they would never be picked just for you.
How long we keep things
-
While you use Unomundi: we keep your progress so you can pick up where you left off.
-
After your grown-up closes the account: most of your stuff is gone in 90 days. Some things grown-ups have to keep a bit longer because the law says so. We will list those things clearly in the grown-up section so nothing is hidden.
-
You can take a break and come back. During those 90 days, if your grown-up changes their mind, your travelbook is still there and they can switch the account back on.
Your rights
As a kid, you have rights about your own information. You can:
-
See what we have about you
-
Change things that are wrong
-
Ask us to delete it (most of it, see the grown-up section for the small list of things we have to keep)
-
Take a break and come back later
Ask your grown-up to help, they know how to reach us.
Got questions?
You can always ask Una "what do you keep about me?" and she'll tell you, in her own words. Or your grown-up can email us at [privacy@unomundi.com].
👨👩👧 For grown-ups
This section sets out how Unomundi (operated by Unomundi Ltd, "we", "us") collects, uses, shares, and protects personal data when a child uses our app, and the choices you have as the child's parent or legal guardian.
We have written it to comply with the UK Data Protection Act 2018, the UK GDPR, the ICO Age Appropriate Design Code (Children's Code), the EU GDPR (where applicable extraterritorially under Article 3(2)), and COPPA for users in the United States.
1. Who the controller is
The data controller is Unomundi Ltd, a UK private limited company in formation, registered office 66 Paul Street, London, EC2A 4NA. Unomundi Limited is wholly owned by Una's World Holding Limited (UK Company No. 17032480).
You can reach us at:
-
General privacy questions: privacy@unomundi.com
-
Data Protection Officer: dpo@unomundi.com
-
Designated Safeguarding Lead: Sonja Keerl, sonja@unomundi.com
2. Children’s data, parental consent, and the pre-link phase
Unomundi is designed for children aged 6 to 12.
A child can create an Explorer profile without a guardian present. When they do:
-
The profile is created on the device, and a minimal record (nickname, age, home country, and lesson progress) is stored on our backend (Supabase) so the child can continue where they left off if they reopen the app on the same device.
-
The Explorer profile cannot be used on a different device until a guardian links it.
We want to be honest about this: even though we do not collect a real name, email, contact details, or device location, the server-side record described above is still personal data of a child under UK GDPR, because the combination of a persistent profile identifier with age, country, and behavioural progress can identify a specific child. We treat it as such.
The lawful basis for this minimal pre-link processing is Article 6(1)(b) of UK GDPR, that is, the processing is strictly necessary for the provision of the service the child has chosen to use. We have minimised the data collected to the four fields above to satisfy that strict-necessity test, and a documented Legitimate Interests Assessment supports this position as a secondary basis.
Two protections apply during the pre-link phase:
-
Strict data minimisation. We store only the four fields above. No name, email, address, phone, photo, device location, contact lists, biometric data, or behavioural advertising identifiers.
-
Time limit on unlinked profiles. If a guardian does not link to the Explorer profile within 30 days, the profile and all associated data are automatically and permanently deleted from our servers.
Two features remain off until a guardian both links and gives explicit consent:
-
Conversational AI with Una (separate Conversational AI Usage Terms required, see Section 4)
-
Subscription and credit purchases (guardian-only)
Once a guardian links to an Explorer profile, we obtain verifiable parental consent for ongoing processing of the child's personal data, in line with UK GDPR (including Article 8), the ICO Children's Code, and COPPA. At launch, our verifiable consent flow uses email-based one-time-password (OTP) verification of the guardian's email address, plus an explicit declaration of legal guardianship. We reserve the right, at any future point, to require formal third-party legal identity verification of guardians (for example via a regulated identity verification provider) where we believe this is necessary to protect children using the app.
Note for US users. COPPA requires verifiable parental consent before any personal information is collected from a US-based child under 13. Because our pre-link phase involves server-side storage, our COPPA approach for US users is (a) geo-restrict pre-link play so US Explorers must have a guardian link before profile creation; (b) treat all US users as requiring guardian-link-first regardless of geo.
3. What personal data we collect, and why
We collect only what we need. The full list is below.
Explorer (child) account data
Guardian (adult) account data
Technical data
4. Conversational AI (Una)
Una's conversational AI is off by default. A guardian must explicitly enable it and accept a separate set of conversational AI usage terms before any conversation can take place.
When enabled:
-
Conversations are processed by our vertical AI stack (cultural and developmental layer, child-optimised behaviour engine, safety guardrails). Our current AI conversation provider is ElevenLabs.
-
What we share with ElevenLabs and what we do not. We share the conversation audio with ElevenLabs so it can be processed for the AI response. We do not share the Explorer's nickname, age, country, or any account-level identifying information alongside the audio. The audio itself is personal data because it is the child's voice. We do not use voice data for biometric identification or voice-print matching, and our agreement with ElevenLabs prohibits any such use.
-
A short safety summary of each session is generated and may be reviewed by our internal Child Wellbeing Team. Summaries are shared with the guardian if the guardian has opted in to summaries.
-
Safety classification (Levels L1 to L5) is performed by our Child Safety Agent, which runs through n8n workflows on anonymised data only. These workflows never see the user ID or any data that links a conversation back to a specific Explorer or Guardian. The link is only re-established server-side when a human safeguarding decision needs to be made.
-
Safeguarding override. If a child discloses abuse by the guardian who would normally be notified, the disclosure is escalated to our internal Child Wellbeing Team only, who follow local mandatory reporting laws. The implicated guardian is not notified.
-
Conversation transcripts may be used in moderated, human-reviewed form to improve Una's safety and quality. This use is opt-in via a separate guardian setting and can be turned off at any time without affecting the child's access to the app.
AI Act compliance. Una is an AI system regulated under the EU AI Act. Specifically:
-
First-interaction transparency. When a child first opens a conversation with Una, the app makes clear in age-appropriate language that Una is an AI, not a real creature. A persistent visual indicator confirms this throughout the conversation, in line with Article 50(1) of the AI Act.
-
No prohibited practices. As set out in Una's Constitution and our product design, we do not use subliminal manipulation, do not exploit age-related vulnerabilities to drive engagement or data sharing, and do not perform emotion recognition in any educational or assessment context. These align with Article 5 of the AI Act.
-
AI-generated content provenance. From 2 August 2026, AI-generated content within the app (such as generated stories or visuals) carries machine-readable watermarking and provenance metadata as required by Article 50(2) of the AI Act.
-
AI literacy. Our staff, contractors, and partners who work on or with Una receive AI literacy training appropriate to their role, in line with Article 4 of the AI Act.
5. The Child Wellbeing Team and access controls
Access to children's personal data inside Unomundi is restricted to a small Child Wellbeing Team with a documented safeguarding role. Specifically:
-
Every person with access to children's data has passed a third-party background check in their country of residence. This is a commitment we have chosen to make. It is not a UK GDPR or ICO Children's Code requirement. We do it because it is the right thing.
-
The Designated Safeguarding Lead and Deputy DSL hold Level 3 DSL certification, refreshed every two years.
-
Access is role-based and tiered. Routine safety review (escalation levels L1 to L4A) is restricted to the Child Wellbeing Team. The most sensitive safeguarding logs (escalation levels L4B and L5) are accessible only to the DSL, Deputy DSL, and Board-level Safeguarding Lead.
-
All access is audit-logged.
6. How we share data
We share personal data only with:
-
Sub-processors who help us run the service, currently:
-
ElevenLabs (conversational AI)
-
Supabase (database)
-
RevenueCat (payments)
-
AWS (hosting infrastructure)
-
Sentry (crash reporting and logging)
-
Unity (3D engine, globe interaction, to be confirmed: verifying whether Unity telemetry/analytics is enabled)
-
Mux (video streaming - has a built-in analytics product “Mux Data”)
-
n8n (orchestration of the Child Safety Agent, anonymised data only)
-
Amplitude (Analytics)
-
All sub-processors are bound by data processing agreements meeting UK GDPR Article 28 standards. A current list lives at [unomundi.com/subprocessors].
-
Our internal Child Wellbeing Team, for safeguarding purposes.
-
Authorities, where local mandatory reporting laws require it (for example, credible disclosure of abuse).
No advertisers selecting children. No data brokers. No social media tracking SDKs. No profiling for advertising. Ever. This commitment includes favourites, travelbooks, lesson behaviour, conversations with Una, and every other piece of information we hold about a child or their family. Unomundi is ad-free at this time. If we ever introduce any form of advertising in the future, it will never be behavioural, targeted, or based on profiling of children or their families. That is a hard line.
7. International transfers
Where data leaves the UK, we rely on UK International Data Transfer Agreements (IDTAs), the UK Addendum to the EU SCCs, or applicable adequacy decisions as the transfer mechanism. Where EU GDPR applies, we additionally rely on EU Standard Contractual Clauses. Data residency for primary processing is within the UK and EEA. Details and copies of transfer mechanisms are available on request.
8. Retention
We keep data only as long as we need it. The table below sets out our defaults. Some categories survive account deletion because we are legally required to keep them; those carve-outs are listed explicitly so nothing is hidden.
90-day soft-delete window. When a guardian initiates account deletion, the account enters a pending_deletion state for 90 days. During this window the guardian can restore the account and all data is recovered intact. After 90 days, all categories above are purged according to the table, with the exception of the consent records and safeguarding logs noted in bold.
Why those carve-outs exist. UK GDPR Article 17(3)(b) and (e) recognise that the right to erasure does not override legal obligations or processing necessary for safeguarding. We could pretend they don't, but we won't. If a child has ever been the subject of a safeguarding escalation, we are legally required to preserve those specific logs even if the family deletes the account. We tell you this here, in plain language, so the deletion promise is honest.
Where we tell you this. We surface these retention carve-outs in three places: (1) here in the privacy policy, (2) in the account deletion confirmation email sent to the guardian when deletion is initiated, and (3) in our Terms and Conditions. We do this so no guardian is ever surprised, after deletion, by what we have kept and why.
9. Your rights
Under UK GDPR, the child (exercised through the guardian) has the right to:
-
Access the data we hold (data export available in-app under Settings → Data & Privacy)
-
Rectify inaccurate data
-
Erase the data, subject to the carve-outs in Section 8
-
Restrict or object to processing
-
Data portability
-
Withdraw consent at any time
-
Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk). Where EU GDPR applies, also the relevant EU supervisory authority.
Under COPPA, US-based parents additionally have the right to review the personal information collected from their child, refuse to permit further collection, and request deletion (subject to the same legal-obligation carve-outs above).
To exercise any of these rights: [privacy@unomundi.com]. We respond within 30 days.
If you believe consent for your child's account was given without your knowledge or authorisation (for example, by another adult in the household, or by the child themselves bypassing our verification), please contact us immediately at [trust@unomundi.com]. We will investigate, suspend the account pending review, and follow our documented misappropriated-consent policy.
10. Security
We use:
-
Encryption in transit (TLS 1.2+) and at rest (AES-256)
-
Role-based access controls and audit logging
-
Multi-factor authentication for all internal access to systems holding children's data
-
Continuous breach detection and incident response procedures
-
Third-party background checks for every team member with access to children's data (see Section 5)
-
Anonymisation of data passed to the Child Safety Agent's n8n workflows (see Section 4)
-
Regular third-party penetration testing every three months.
-
A documented data breach response policy aligned with UK GDPR Articles 33 and 34, including 72-hour supervisory authority notification
A Data Protection Impact Assessment (DPIA) is in place and will be completed before launch as required by UK GDPR Article 35 and conforming to the UK Information Commissioners Office guidelines:
11. Cookies and similar technologies
We use cookies and similar device-storage technologies sparingly, and only where necessary to operate the service or where you have given explicit consent.
We do not use marketing, advertising, or behavioural tracking cookies in any context where a child may interact with the app. For guardian-only sections of our service, any non-essential cookies require your explicit consent through a compliant consent banner with a "reject all" option on the first layer, granular controls, and an easy withdrawal mechanism.
A full list of the cookies and similar technologies we use, their purposes, and how to manage them, is available in our Cookie Policy. You can withdraw cookie consent at any time from Settings > Privacy & Cookies.
12. Changes to this policy
If we make material changes, particularly any that affect what we collect from children or how we use it, we will notify guardians by email and require renewed consent before the change takes effect.
13. Contact
-
General privacy questions: [trust@unomundi.com]
-
Data Protection Officer: [dpo@unomundi.com]
-
Designated Safeguarding Lead: sonja@unomundi.com
-
Postal address: Unomundi Limited, 66 Paul Street, London, EC2A 4NA
Unomundi was built on a simple promise: we never compromise children's safety or privacy, no matter the financial gain. This policy is one of the ways we keep that promise.



