Skip to document

Direct notice to a parent or legal guardian

Whistle Children's Privacy and Parental Consent Notice

Notice version consent-open-beta-2026-07-15-v1 · Last updated July 15, 2026

Open build beta status

This notice governs Whistle's open build beta. Authenticated adults may create beta accounts, and an authenticated parent or legal guardian may create and manage a reader under the controls described here. Commercial publication, checkout, final operator details, and final legal signoff remain separate and pending; they are not represented as complete and do not block build-beta use. The public privacy/account web form is the current intake path.

Why you are receiving this notice

You are signed in as the adult who is asking Whistle to create a reader. Children do not create accounts or credentials. Whistle will not create a reader unless you review this notice and separately affirm both that you are the reader's parent or legal guardian and that you authorize the disclosed Azure audio processing. If you do not make both affirmations, no reader is created and no child practice begins.

Authenticated guardian and audio affirmations

In the open build beta, Whistle uses your authenticated adult account and two separate in-app affirmations: one confirming your parent or legal-guardian authority and one authorizing the disclosed Azure audio processing. Whistle records minimized evidence such as the adult account, notice and consent versions, time, reader reference, affirmation method and result, and any later withdrawal or revocation. This is an authenticated in-app build-beta guardian attestation, not a card-payment or manual identity-verification process, and it is not represented as final commercial or legal signoff. Each reader requires its own affirmations.

What happens after consent

The protected reader-creation action verifies your authenticated parent account, current Terms and Privacy acceptance, this notice version, and both required affirmations. Only then does it create a blank reader profile. You next choose a data-minimized quest alias, optional favorite topics, and a practice mode. Do not use a legal name, initials, birthdate, address, contact information, school or classroom, student or patient number, diagnosis, clinical note, insurance information, or other direct identifier. Practice is available only while the parent-owned reader, consent, and account access remain active. A provider account or linking code creates no reader access by itself. To link a provider, you must separately select the exact reader and explicitly authorize that one-time link; you may remove it at any time.

Child information Whistle collects

After valid consent and authorized practice, Whistle may collect the quest alias, filtered interests, practice mode, theme, assigned targets, provider link, expected prompt text, live microphone audio, recognized speech text, pronunciation and phoneme-level automated scores, content-match and attempt status, retries, duration, sessions, progress, points, streaks, levels, rewards, and device or security records needed to operate and protect the service. Whistle does not intentionally store raw microphone audio in its application database. Recognized text and derived practice signals are child personal information, not anonymous or legally de-identified data.

How Whistle uses the information

Whistle uses child information only to deliver the requested practice, transcribe and score attempts, select a bounded practice focus, present progress to the parent and an authorized provider, maintain rewards and continuity, prevent abuse and cross-account access, respond to verified access or deletion requests, investigate incidents, and retain minimized evidence required to document consent and compliance. Whistle does not sell child information, use it for targeted advertising, build an unrelated profile, enable public profiles or child-to-child communication, or train a general-purpose model with it.

Necessary service providers and authorized recipients

Microsoft Azure Speech receives temporary live practice audio, prompt text, and speech-processing metadata for transcription and pronunciation processing. Neon stores the application database. Vercel hosts and secures the application. Stripe handles adult payment information and supplies signed transaction evidence. Resend delivers the direct and follow-up parental notices. Twilio and Cloudflare Email Routing are limited to adult and operator communications and are not authorized to receive child practice content. An approved linked speech-language pathologist may view the reader's authorized practice information, but the parent can remove that access. Optional third-party child story generation and cloud narration are disabled. The current named inventory and data scope appear on the Subprocessor page.

Retention and deletion

An unused request is deleted when its one-time token expires. A generic provider linking code expires within fourteen days and, when no longer referenced, is deleted within thirty days. A consented reader profile and attributable practice information are kept only while consent and authorized access remain active and the documented business need continues. Withdrawal blocks future collection immediately and enters the reader into the deletion queue; family-owned reader and practice information is deleted within thirty days unless a narrower period applies or a specific record is subject to a documented legal or security hold. Routine account closure uses a maximum ninety-day deletion period when no earlier event applies. Minimized consent and privacy-request evidence may be kept for six years, and required financial evidence for seven years, without keeping child practice content merely as proof. Backup and processor-expiration periods will not be published as verified guarantees until dated provider evidence supports them.

Your choices and rights

You may refuse consent without losing an adult-only account or a separately available adult service. You may review and correct reader information, remove provider access, refuse further collection or use, withdraw consent, request deletion, and appeal a denied privacy request. A routine dashboard export is intentionally minimized. A verified complete child-data access response can include every maintained child-data category, including recognized text, through a privileged short-lived delivery path that is not attached to support and is purged after seven days. Whistle may verify identity and guardian authority before disclosing or changing child information.

Withdrawal, local device data, and limits

Withdrawal immediately invalidates future reader authorization, clears the selected-reader session, schedules server deletion, and triggers a versioned purge of Whistle practice, adventure, and generated-content caches on the device when that device next reaches Whistle. Whistle cannot remotely erase a device that never reconnects, a user-created screenshot, or an export already lawfully downloaded; the adult must delete those copies. A processor restoration or backup that reintroduces deleted information must be reconciled under the retention program before the data returns to active use.

Security and material changes

The build beta operates account authentication, parent ownership checks, access controls, encryption in transit, signed short-lived reader authorization, logging limits, withdrawal and deletion controls, and incident-response procedures. Whistle continues to document and test its written child-data information security program, designated coordinator coverage, risk assessment, retention evidence, processor assurances, and annual evaluation before commercial publication and final legal or security signoff. No system is risk-free. Whistle will provide direct notice and obtain renewed or separate parental consent before a material new child-information collection, use, disclosure, processor, or retention practice when required.

Consent statement

By completing the protected reader setup, you affirm that you are the reader's parent or legal guardian; received and reviewed this notice, the Privacy Notice, and the Subprocessor Notice; authorize the described collection, use, and Azure audio processing; understand that Whistle is practice support and not diagnosis or emergency care; understand that automated signals may be inaccurate; and understand that you may withdraw consent and request deletion. Consent is specific to one reader and does not authorize a provider link, unrelated disclosure, or a future material change. A provider link requires a separate exact-reader authorization by the authenticated parent.