Privacy policy
Last updated: 2026-09-07
Umilo helps a parent turn a page of homework into a short check, and shows what the child found clear and what is worth revisiting. This page explains exactly what Umilo holds, what it never holds, and who else touches it.
Who we are
Umilo is operated by Vasyl Vynnytskyi (ФОП Винницький Василь Михайлович), a sole trader registered in Ukraine, who is the data controller for the data described on this page. Contact: [email protected]. The account holder is always an adult parent or guardian.
How a check works
Every check follows the same four steps.
- A parent photographs the homework or types a topic.
- The photo or topic is processed by OpenAI to identify concepts, generate questions and check their answers. Standard checks have 5, 10 or 15 questions; focused follow-ups have two.
- The parent confirms the subject and the concepts, then sends a link. The child needs no account.
- The child taps answers. The parent sees a cautious per-concept readout and one coaching example.
Homework photos
A photo of a child's homework is the most sensitive thing Umilo touches, so it follows a single rule: Umilo never keeps it.
- The photo is resized in your browser before it leaves your device.
- It is sent to the server once, for one analysis, and held only in memory while that analysis runs.
- It is never written to the database, never written to file storage, and never written to logs.
- What survives the analysis is only the subject, the list of concepts, and a short scrubbed summary that you confirm before anything is sent to your child.
- OpenAI may keep API content in abuse-monitoring logs for up to 30 days by default, with legal or safety exceptions. Umilo does not promise provider zero retention.
What Umilo stores
Umilo keeps only what it needs to show a parent how their child is doing.
- Parent account: the email address and name supplied by Clerk when the account is created.
- Child profile: the child's name, exact grade, an optional display name, an optional avatar image, the content language, and the timestamp of your consent.
- Check content: the confirmed subject, the concepts, the short scrubbed summary, and the generated questions.
- Child responses: which option was tapped, and when.
- Results: the readout and the coaching example shown to you.
- Optional feedback: a parent survey answer, and any question reports you file.
- Parent help: your questions, generated replies, source references, explanation language and optional tried/helpful feedback.
The page your child sees
The page a child opens is deliberately plain, and it stays that way.
- No advertising, and no links to any other website.
- No cookies used for tracking.
- No score, no timer, and no leaderboard.
- Product analytics run in memory-only mode and record the attempt identifier alone — no name, no IP address, no page address, and no referrer.
Cookies
Umilo uses cookies for two jobs only — keeping a parent signed in, and taking a payment. None of them are used for advertising.
- Clerk sets a session cookie on the parent side so you stay signed in.
- Paddle sets its own cookies during checkout.
- PostHog records product analytics on the parent side.
- The page your child opens sets no tracking cookies at all.
Where the data goes
Your family's data is stored in the EU, and some vendors process it in the United States.
- Storage in the EU: Supabase (eu-west-1) for the database, the avatar images and the read-aloud audio clips; PostHog's EU cloud for product analytics.
- Processed in the United States: Clerk, OpenAI, Vercel, Resend and Google Cloud (the read-aloud voice).
- Those transfers rely on the EU–US Data Privacy Framework or on Standard Contractual Clauses.
- Homework photos are not transferred anywhere for storage, because they are never stored.
Why Umilo may hold this data
The child never signs up. The parent does, and the parent supplies the child's data.
- Under COPPA, the parent is the account holder, provides the child's information, and gives parental consent when the child profile is created; that consent is recorded with a timestamp.
- For families in the EU, the UK and Ukraine, that parental consent together with the contract to provide the service is the legal basis under the GDPR and its rules for children's data.
- The consent timestamp is stored on the child profile, so you can always see when it was given.
Who else processes the data
Umilo uses a small set of vendors. Each one sees only what its job requires.
- Clerk — parent sign-in and account management.
- Supabase — the PostgreSQL database and the file storage that holds avatar images and the read-aloud audio clips, in the EU region eu-west-1.
- OpenAI — reads the homework photo or the topic and drafts the questions. Under the OpenAI API terms, data sent through the API is not used to train their models.
- Google Cloud Text-to-Speech — turns the text of a question, an answer option or an explanation into the voice a child can play on the check page. It receives that text only — never the photo, the child's name or the answers given — and the audio clip is kept in Supabase for up to 30 days so it is not generated twice.
- Paddle — merchant of record for payments. Paddle handles the card details; Umilo never sees them. Paddle sends Umilo only what it needs to switch the plan on and off: a customer identifier, a subscription identifier, the subscription status, the dates of the current billing period, any scheduled change such as a pending cancellation, and the identifier of the price you are on. Paddle's own privacy policy is at paddle.com/legal/privacy.
- PostHog — product analytics.
- Resend — transactional email to the parent.
- Vercel — hosting.
- OpenAI also processes selected answers and parent questions to draft and review explanations. Known profile names are removed from parent-help inputs; avoid including identifying details.
How long Umilo keeps things
Different data has a different life.
- Homework photos: not kept at all.
- Responses, readouts and coaching remain until you delete the associated child or account, or request deletion. Automatic deletion after 12 months is not currently implemented.
- Share links: they stop working 30 days after the check is created, and you can stop one sooner from your dashboard.
- Account and child profiles: kept until you delete them.
- Parent-help conversations expire after 30 days and are removed by daily cleanup. Deleting an associated check, child or account removes dependent conversations sooner.
Deleting data
You are in control of everything Umilo holds about your family.
- Deleting a child profile also removes that child's checks, responses and readouts.
- Deleting the account removes the Clerk record and cascades the deletion through the database.
- Deletion is permanent. Umilo cannot restore a deleted profile or a deleted account.
Your rights
Depending on where you live, you can ask Umilo to do the following. Umilo answers within 30 days.
- See the data held about you and your child.
- Correct anything that is inaccurate.
- Delete a child profile, or the whole account.
- Receive a copy of the data in a portable form.
- Withdraw consent for a child, which means deleting that child's profile.
- Complain to your national data protection authority.
Changes to this policy
If this policy changes in a way that affects what Umilo collects or who processes it, the account holder is told by email before the change takes effect. The date at the top of this page always shows the version you are reading.
Contact
Questions about this document? Write to [email protected].