Privacy Policy
Last updated: July 21, 2026BrightStart is built by Zenerly as a career-adventure learning game for kids ages 3–18. This policy explains, in plain language, what information the app and this website collect, how it's used, and how a parent or guardian can control or delete it. If you have questions after reading this, write to us at app.zenerly@gmail.com — we read every message ourselves.
01 Overview
BrightStart (Android package app.zenerly.brightstart.mobile, and the App Store version when published) is developed and published by Zenerly ("Zenerly," "we," "us"). This policy covers the BrightStart mobile app and the www.brightstart.zenerly.com website.
BrightStart does not require an account or sign-up to play. There is no login, no server-side user profile, and no way for one player to contact another inside the app. Gameplay data — a child's name, age band, XP, coins, badges and streaks — lives on the device itself.
02 Data Stored Only On The Device
When a parent sets up a player profile in BrightStart, the following is saved locally using on-device storage (Android/iOS app storage, never a remote database):
- Player display name and selected age band
- XP, coins, level, badges earned, streak count and mission history
- An optional profile picture, copied from the device's photo library directly into the app's local storage
- Parent Zone settings: screen-time limits, quiet hours, and the analytics opt-out toggle
03 Data You Give Us Directly
The BrightStart website has two forms — Early Access signup and Contact Us — that a parent fills out voluntarily. These are not part of the app itself.
| Form | What we collect | What we do with it |
|---|---|---|
| Early Access signup | Parent/guardian name, email address, child's age band | Sends a confirmation email to you and an internal notification to our support inbox, so we can let you know when a build is ready |
| Contact Us | Name, email address, topic, message | Sends your message and an autoreply confirmation, so we can respond to your question |
These submissions are delivered by email only — we do not store form submissions in a separate marketing database or CRM. They exist as email records in our support inbox (app.zenerly@gmail.com) until deleted. See Data Deletion to request removal.
04 Automatically Collected Data (Analytics)
BrightStart uses Firebase Analytics (a Google service) to understand which missions and features are used, so we can improve the app. This is optional and parent-controlled: it can be switched off entirely at any time from the analytics toggle in Parent Zone.
When enabled, analytics may collect:
- Screen views and in-app events (for example: a mission started, a mission completed, a badge earned) — no free-text or personal content is included
- A device/app-instance identifier used by Firebase to distinguish one installation from another (not tied to a name, email, or account)
Analytics data is transmitted to Google over an encrypted (HTTPS/TLS) connection. It is used in aggregate for product improvement, not for building an advertising profile.
05 App Permissions
| Permission | Why BrightStart asks for it |
|---|---|
| Internet access | Loads optional analytics and (on the website) sends the Early Access / Contact forms. The core game plays fully offline. |
| Notifications | Local, on-device reminders only (for example, a streak-expiry nudge) — scheduled on the device, never sent from a server. |
| Biometric / fingerprint / device unlock | Used only for the "Edit Profile Lock" — requiring a parent's own device PIN, pattern, fingerprint or Face unlock before a child's name or age band can be changed. BrightStart never receives or stores biometric data itself; the device's operating system handles the unlock check. |
| Photo library (optional) | Lets a parent choose a profile picture for their child. The chosen photo is copied into the app's local storage only — it is never uploaded anywhere. |
06 Advertising & AdMob
If BrightStart enables advertising, it will use Google AdMob to serve ads. Consistent with Google's Play Families Policies, Google's Families Ad Program, and applicable children's privacy law (including COPPA in the United States), BrightStart will:
- Mark ad requests as directed to children where required, so AdMob serves only non-personalized, contextual ads to those sessions rather than interest-based or behaviorally-targeted ads
- Not use ad identifiers (such as the Android Advertising ID) to build cross-app advertising profiles of children
- Avoid ad formats prohibited in child-directed treatment (for example, no ads that mimic app content or that link out to age-inappropriate destinations)
- Update this Privacy Policy and the app's Play Console / App Store Connect data-safety disclosures before any ads go live in production
When active, the AdMob SDK may collect technical data (such as IP address, device type, and ad interaction events) directly, governed by Google's Privacy Policy. We will list AdMob explicitly as a data-collecting third party in the Play Console Data Safety section and in App Store Connect's App Privacy details at that time.
07 Children's Privacy
BrightStart is designed for a wide age range (3–18) and is used by children with a parent or guardian as the account/device owner. We take children's privacy seriously:
- No account creation, ever — there is nothing for a child to register, and no persistent personal identifier (name, email, photo) ever leaves the device through normal gameplay
- No chat, no user-generated content, no way for a child to contact anyone — there are no social features of any kind
- Parental gate on profile edits — changing a child's name or age band requires the parent's own device authentication (PIN, pattern, fingerprint or Face unlock)
- No behavioral advertising to children — see Section 6
- Analytics is opt-out at any time from Parent Zone, and off entirely disables the only data leaving the device during normal play
We do not knowingly collect more personal information from children than described in this policy. If a parent believes their child has provided us with personal information beyond what's described here (for example, through the Contact form), please email app.zenerly@gmail.com and we will delete it promptly.
08 Third-Party Services
| Service | Purpose | Data involved |
|---|---|---|
| Firebase Analytics (Google) | Optional, opt-out product analytics | Screen views, in-app events, device/app-instance identifier |
| Google AdMob | Not active in the current release — see Section 6 | N/A until enabled |
| Gmail / Google Workspace | Delivers Early Access and Contact form emails | Name, email address, and message content you submit on the website |
| Google Play / Apple App Store | App distribution, installs, and (if applicable) crash diagnostics provided by the platform | Governed by Google's and Apple's own privacy policies |
We do not sell personal information, and we do not share data with third parties for their own independent marketing purposes.
09 Data Retention & Deletion
Local gameplay data persists only as long as the app remains installed with its data intact — it is removed immediately when the app is uninstalled or its storage is cleared. Website form submissions (emails) are retained in our support inbox until a deletion request is honored or the correspondence is no longer needed. Full instructions and expected timelines are on the Data Deletion page.
10 Data Security
Local app data is protected by the operating system's standard app sandboxing on Android and iOS. Any data that does leave the device (optional analytics, or website form submissions) is transmitted using HTTPS/TLS encryption in transit. No method of storage or transmission is 100% secure, but we do not operate a central database of player data that could be breached — most of what BrightStart knows about a child never leaves their device.
11 Your Choices & Rights
- Turn analytics off anytime from Parent Zone → Privacy settings
- Delete all local data by uninstalling the app or clearing its storage (see Data Deletion)
- Request deletion of emailed form data by writing to app.zenerly@gmail.com
- Unsubscribe from any Early Access emails using the unsubscribe link included in those messages
Depending on your location, you may have additional rights under laws such as the EU/UK GDPR or U.S. state privacy laws (for example, the right to access, correct, or export your data). Contact us and we will respond to verified requests.
12 International Users
BrightStart is available to a global audience. If you access the app or website from outside the country where our systems are hosted, your information may be processed in another country with different data protection laws than your own. We rely on the safeguards built into the third-party services listed above (Google, Apple) for any such transfers.
13 Changes To This Policy
We may update this policy as BrightStart evolves — most notably, before any advertising or new data-collecting feature goes live. Material changes will update the "Last updated" date at the top of this page, and where required by app store policy, we'll also update the app's in-store data safety disclosures. We encourage checking back periodically.
14 Contact Us
Questions, deletion requests, or concerns about this policy — write to us directly: