Privacy Policy
Version 1.0.0 · Last updated 10 July 2026
1. Who we are
BoomBoom World("we", "us", "our") provides a personalised children's character creation service for parents and legal guardians. We are the data controller for personal information processed through our website and app.
Questions about this policy: privacy@boomboom.world.
2. Who this service is for
Accounts are for adults aged 18 or over who are parents or legal guardians. Children do not create accounts. You provide information about your child only to create their illustrated character.
3. Information we collect
Account data: email address, display name, sign-in method, and authentication identifiers from our identity provider (Supabase Auth).
Child profile data: first name (for personalisation), optional age band, pronoun preference, workflow status, and timestamps.
Photos: a photo you upload of your child. We sanitise and store it in a private storage bucket. We also store a separate face-crop image used for avatar generation. Photos are not displayed publicly on our platform.
Generated content: illustrated avatar images linked to your account.
Consent records: versioned parental consent confirmations and related audit events.
Technical data: essential session cookies, security logs, and limited analytics events needed to operate and improve the service. See our Cookie Policy.
4. How we use your information
- Create and manage your parent account and child profiles.
- Process uploaded photos to generate an illustrated character.
- Show your approved character in your private account.
- Record parental consent and meet our legal obligations.
- Keep the service secure, debug issues, and prevent abuse.
- Communicate with you about your account or orders when necessary.
We do not use child photos for advertising, public galleries, facial recognition databases, or training unrelated third-party models without your separate informed consent.
5. Legal bases (UK & EEA)
Where UK GDPR or EU GDPR applies, we rely on:
- Contract — to provide the service you request.
- Consent — for uploading and processing your child's photo and for optional communications where required.
- Legitimate interests — security, fraud prevention, and improving reliability, balanced against your rights.
- Legal obligation — where we must retain or disclose information by law.
6. Photo storage and access controls
Child photos and generated avatars are stored in private Supabase Storage buckets in European Union (London, eu-west-2). Buckets are not publicly listable or browsable.
Access is enforced by row-level security: only the authenticated parent account that owns a child profile can read, update, or delete files in that account's folder. When we show an image in your session, we use time-limited signed URLs (currently one hour) rather than permanent public links.
After upload, the full source photo is not shown in the app interface; only a face crop is displayed for avatar review. Your original upload remains in private storage for processing and retention as described below.
Avatar generation may send a temporary signed URL of the face reference to our image-generation provider (e.g. OpenAI) solely to produce your character artwork. That URL expires automatically.
7. Retention
Uploaded child photos are associated with a retention date (currently one year from upload unless you delete them sooner). You may delete a child profile from Settings, which removes associated photos, avatars, and profile data subject to any legal holds or backup cycles.
Account and consent records may be kept longer where needed for legal, accounting, or dispute-resolution purposes, then deleted or anonymised.
8. Sharing and processors
We use trusted service providers who process data on our instructions:
- Supabase — authentication, database, and private file storage (EU region).
- Hosting and infrastructure providers for our application.
- Image-generation providers when you create an illustrated character.
- Email delivery if we send account-related messages.
We do not sell personal information. We may disclose information if required by law, to protect rights and safety, or in connection with a business transfer with appropriate safeguards.
9. International transfers
We aim to store primary personal data in the UK/EU. If a sub-processor processes data outside the UK/EEA, we use appropriate safeguards such as Standard Contractual Clauses or UK International Data Transfer Agreements where required.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. You may withdraw consent where processing is consent-based (for example, photo processing) by deleting the child profile or contacting us.
UK residents may complain to the Information Commissioner's Office (ICO). EEA residents may complain to their local supervisory authority.
11. Security
We use encryption in transit (HTTPS), authenticated access controls, private storage buckets, and least-privilege database policies. No method of transmission or storage is 100% secure; please use a strong password and keep your account credentials confidential.
12. Children's privacy
Our service is designed for parental use. Read our dedicated Children's Privacy & Parental Consent notice for more detail.
13. Changes
We may update this policy from time to time. We will post the new version on this page and update the "Last updated" date. Material changes may require renewed consent where applicable.