Privacy Policy
Last updated: March 2026
1. Who are we?
Read Lab is an educational application for children aged 4 to 13, focused on improving reading skills. Read Lab is developed and maintained by Read Lab (hereinafter: "we", "us" or "Read Lab").
2. What data do we collect?
We process the following data:
- Parents/guardians: email address (for the waitlist and communications), name.
- Children: name (entered by the parent/guardian), age, progress data (reading exercises). We do not collect advertising IDs, location data, or tracking data from children.
- Technical data: IP address, device type, browser type — solely for security and debugging.
We do not collect sensitive personal data such as social security numbers, health data, or financial information.
3. Why do we process this data?
- To operate the app and track progress (legal basis: performance of contract).
- To inform parents about their child's progress (legal basis: legitimate interest).
- To manage the waitlist and notify users about the launch (legal basis: consent).
- To comply with legal obligations.
4. Consent for children (GDPR Art. 8 / COPPA)
Because our app is aimed at children under 16 years of age, we require explicit prior consent from a parent or legal guardian before a child can use the app (in accordance with GDPR Art. 8 and COPPA). We do this via a mandatory consent checkbox in the app when the parent creates a child profile. The parent explicitly confirms which data is stored and which is not. Consent via a secure email link is also available as an alternative method.
Without consent, no data about the child is stored.
Withdrawing consent: You can withdraw your consent at any time directly in the app via the parent dashboard (child profile → Revoke consent). This results in the immediate deletion of the child's profile and all associated progress data. Alternatively, you can send an email to privacy@readlab.app.
Deleting data:You can delete the child's profile and all associated data directly via the parent dashboard in the app. Alternatively, you can send an email to privacy@readlab.app.
5. Sharing of data
We never sell your data. We only share data with:
- Supabase (database hosting, based in the EU) — privacy policy.
- Vercel (web hosting for the website, based in the US — SCCs apply) — privacy policy.
- Brevo (based in the EU) — for authentication, processing waitlist sign-ups, and sending newsletters (both via the website and the app) — privacy policy.
- RevenueCat (in-app purchases and subscriptions, based in the US — SCCs apply) — privacy policy.
- Meta Platforms, Inc. (advertising optimisation, based in the US — SCCs apply) — only if you explicitly consent via the checkbox on the sign-up form. We share only a SHA-256 hash of your email address via the Meta Conversions API; your plaintext email is never shared. Meta uses this signal to better target ads to similar audiences — Meta privacy policy.
Third parties may not use your data for their own purposes.
International transfers: Supabase and Brevo process data within the EU. Vercel, RevenueCat and (with consent) Meta are based in the US; for these parties, Standard Contractual Clauses (SCCs) apply to ensure an adequate level of protection.
6. Security
All data is stored and transmitted with encryption (HTTPS/TLS). Access to personal data is restricted to authorised personnel.
7. Retention periods
- Waitlist email addresses: up to 6 months after launch or upon unsubscription.
- Account data and progress: for as long as the account is active + maximum 1 year after termination.
8. Your rights (GDPR Art. 15–22)
Under the GDPR, you have the following rights:
- Right of access (Art. 15): You can request which data we process about you.
- Right to rectification (Art. 16): You can have incorrect data corrected.
- Right to erasure (Art. 17): You can request deletion of your data.
- Right to restriction (Art. 18): You can have the processing of your data restricted.
- Right to data portability (Art. 20): You can receive your data in a structured format.
- Right to object (Art. 21): You can object to processing based on legitimate interest.
- Automated decision-making (Art. 22): We do not make decisions based solely on automated processing that have legal effects on you.
Many of these rights can be exercised directly in the app via the parent dashboard:
- Access: export all your account data as a JSON file.
- Rectification:edit a child's name or age directly.
- Erasure: delete a child profile including all progress data.
- Withdraw consent: revoke parental consent per child profile.
For other requests, send an email to privacy@readlab.app. We will respond within 30 days.
Right to complain: You have the right to lodge a complaint with the relevant data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens ( autoriteitpersoonsgegevens.nl).
9. Contact
Read Lab
Email: privacy@readlab.app