Skip to document

Privacy notice

How Whistle Handles Data

Notice version privacy-open-beta-2026-07-15-v1 · Last updated July 15, 2026

Open Build Beta And Publication Status

This notice describes the data practices for Whistle's open build beta. Authenticated adults may create parent or provider beta accounts. Only an authenticated parent or legal guardian may create a reader, and only after reviewing the direct children's notice and separately affirming guardian authority and the disclosed Azure audio processing. A provider account alone grants no reader access; the authenticated parent must select the exact reader and authorize the provider link. Commercial checkout, broad public publication, final operating entity, physical notice address, monitored privacy email, telephone number, and final legal signoff remain separate and pending. The public privacy/account web form is the current intake path.

Data We Collect

Adult accounts include email, password hash, name, role, and provider practice details when applicable. Reader profiles include a nickname or quest name, optional interests, practice mode, practice targets, guardian/audio consent timestamps, and linked provider or guardian relationships.

Practice data can include sessions, expected prompt text, recognized text, pronunciation scores, phoneme scores, content-match status, points, streaks, and levels. Support requests include the message submitted by the account holder.

Whistle receives adult information directly from the account holder and, where an optional paid or message flow applies, payment or delivery status from the named processors. Child information comes from an authenticated parent's authorized reader setup and practice, automated speech processing, and structured targets from a provider whom that parent linked to the exact reader. Whistle does not buy child data from a broker or infer a legal identity from a quest alias.

Audio And Scoring

Practice audio is sent to Azure Speech for pronunciation assessment. Whistle stores scoring results and recognized text needed for practice evidence. Whistle does not intentionally store raw child audio in its application database.

Story And Prompt Generation

Third-party child story generation and live cloud narration are disabled and are not authorized for this open-build-beta configuration. Before deployment, Whistle may use Azure Speech to turn fixed, publisher-authored text containing no child information into narration files. Playback loads those fixed files from Whistle and sends no story text, reader context, or child information to a narration provider. Whistle does not substitute a device or browser voice when a governed narration file is unavailable. A new processor or purpose requires separate review, updated notice, and renewed parental consent when required before child information is sent.

Children

Children do not create Whistle accounts. An authenticated parent or legal guardian creates and manages each reader profile. Whistle does not create a reader, collect its profile fields, process child speech, or persist child practice until that adult has reviewed the direct notice and separately affirmed guardian authority and Azure audio processing. This build-beta path records an authenticated guardian attestation; it is not a card-payment or manual identity-verification process and is not represented as final commercial or legal signoff. A provider cannot create a reader or gain access through signup or a code alone. The authenticated parent must separately select the exact active reader and authorize the provider link.

Reader profiles should avoid child legal names, school names, contact details, birthdates, diagnoses, insurance identifiers, medical record numbers, and student identifiers.

Service Providers

Whistle uses service providers for hosting, database storage, real-time speech processing, payments, and parental-consent email. Stripe handles payment details; Whistle stores billing status and minimized transaction evidence, not full card numbers.

The child-data processor inventory is Microsoft Azure Speech, Neon, Vercel, Stripe, and Resend. Twilio and Cloudflare Email Routing are separately limited to minimized adult/operator alerts and inbound adult contact; an inbound email address cannot be published until its destination-mailbox provider is identified and approved. Optional child generation and third-party narration providers are disabled and are not authorized processors. The complete named inventory, purpose, and restrictions appear on the Whistle Subprocessors page. Whistle does not authorize processors to sell child information, use it for targeted advertising, or train general-purpose models with it.

Retention

Whistle uses fixed, purpose-based retention periods. An unused child-data-free consent request is deleted when its one-time token expires; an expired or closed generic provider linking code is deleted within 30 days; handled content-free email delivery receipts and routine operational events are deleted after 30 days; Stripe event identifiers, types, dispositions, and timestamps are retained for 24 months; support message content is purged after 12 months and the minimized closed record follows the applicable three-, six-, or seven-year schedule; routine audit events are retained for 24 months. Minimized privacy and consent evidence may be retained for six years, and required Terms, Privacy, auto-renewal, billing, or refund acceptance evidence for seven years. The structured public form keeps only hashed abuse-control receipts for 24 hours; they become eligible then and are removed by the next hourly sweep, ordinarily within 25 hours, while the support case follows its separate schedule. Deployment-bound edge-review evidence contains no request or child content, expires from launch health within 24 hours, and is retained for six years. Backup expiration and processor deletion remain publication gates until dated provider evidence verifies the stated schedule.

Your Choices And Requests

A verified adult may request access, correction, export, deletion, withdrawal of consent, removal of provider access, or review of a denied privacy request. Whistle acknowledges and completes requests within the periods required by applicable law. Whistle will publish a shorter operational target only after staffing, escalation, appeal, and fulfillment evidence support it. Submit through the signed-in privacy path or the structured public adult-request form.

A routine dashboard export is data-minimized. A verified complete child-data access response can include every maintained child category, including recognized text, through a privileged short-lived delivery path that is not attached to support and is purged after seven days. A denial explains the basis and appeal path; the appeal is reviewed by a person who did not make the initial decision. Whistle does not sell or share personal information for cross-context behavioral advertising, so there is no sale or targeted-advertising opt-out flow.

Security

The build beta operates account authentication, parent ownership checks, least-privilege access, encryption in transit, signed short-lived reader authorization, credential and secret controls, logging limits, withdrawal and deletion controls, and incident-response procedures. Whistle continues to document and test its written child-data information security program, coordinator coverage, risk assessment, retention evidence, processor assurances, and annual evaluation before commercial publication and final legal or security signoff. No online service can guarantee absolute security. Suspected unauthorized access should be reported through the privacy/account form without including a child legal name, recording, health record, or school record.

Deletion And Support

Account holders can request deletion, privacy review, refund review, billing review, cancellation, initiate a dispute notice, opt out of arbitration, or request account support through the signed-in support form. If sign-in is unavailable, the limited public privacy/account form accepts only the adult account email and one structured category; it does not accept request details or child information. Signed-in privacy requests may use a reader nickname, but must not include a child legal name or sensitive identifier.

Provider And HIPAA Posture

Some provider uses may require business associate agreements, HIPAA controls, school data agreements, or other compliance steps. Those requirements depend on the provider, setting, data, and workflow. Whistle should not be used for those workflows until the required agreements and controls are in place.

Whistle is not a diagnosis, medical device, or substitute for services from a licensed speech-language pathologist. It is practice support and practice evidence only.

Changes And Jurisdiction-Specific Rights

Whistle will post material changes and provide direct notice when required. It will obtain renewed or separate parental consent before a material expansion of child-information collection, use, disclosure, or retention when required. Applicable state law may provide additional access, correction, deletion, portability, appeal, authorized-agent, or regulator-contact rights; Whistle applies the right that law requires without reducing COPPA rights. Nothing in this notice limits a nonwaivable right or a report to a regulator or law-enforcement authority.