Spellito
Menu

Built to the UK Children’s Code

Privacy

Anonymous play, no tracking inside practice, no adverts. Adults can use email and password or Google, with self-service password recovery. This page explains what Spellito stores, why it needs it, and how to ask us to delete it.

Last updated: 16 September 2026

What Spellito does with your stuff

Here’s the short version, in plain English:

  • You can practise without signing up. If a grown-up creates a parent account, we save their sign-in and your first name, school year, buddy and any school they confirm. Spellito may send just your first name inside a fixed hello message to Google’s business voice service so the approved Spellito voice can greet you. We do not send your grown-up’s email, school, answers or progress with it.
  • Finding your school is a grown-up job. We use the official Department for Education school list. We do not ask where you live or keep the words typed into the search box.
  • A class invitation does not add you anywhere. Inside a parent account it shows the official school, class and teacher. Your grown-up must choose you and ask to join, then the teacher must still say yes.
  • Your class nickname is picked by Spellito. Once a class is connected, the database gives you a friendly three-word name such as “Bright Owl Pencil”. It is unique inside that class, and nobody can type their own. Classmates see only these nicknames, positions and correct totals on the class board.
  • If your grown-up asks to join a class, verified teachers registered for that class can see your first name, the first letter of your surname and your school year so they can say yes or no. They cannot see how you practise while the request is waiting. If they confirm you, those same details stay in their private class roster.
  • If your class pays for your school practice, we keep a small record of your grown-up’s request so trying again does not add you twice. Your grown-up can download that record and remove it by deleting your profile. A pending request does not let a teacher see your practice before they confirm you.
  • Your practice stays private. Without an account, it stays in your browser and we do not see it. When your grown-up signs in, practice is also saved to their account. If the internet drops, a small copy waits on that device for up to seven days so it can try again when the connection comes back. A supported browser may also wake Spellito in the background to try again. It never includes the answer you typed. If a teacher has confirmed you in their class, they can see how many attempts were correct, your accuracy, activity date, streak and daily time spent answering from then on. They can also open a curriculum-word chart showing attempts, correct answers, usual correct-answer speed and daily totals from then on. Empty words come from the shared curriculum list, not from your practice. They never see the answer you typed. Active answer time is not time when the app is left open.
  • Spellito tells you who can see saved progress. On your home and practice screens, a small Privacy sign says whether it is your grown-up only, your grown-up and confirmed class teacher, or your class teacher only for assigned schoolwork. You do not see this sign during guest play because that practice is not saved to an account.
  • Your teacher can send a spelling set to your home screen. We save which set was sent to your profile, which teacher sent it and when. Only your grown-up’s account can open it, and only while your class link is still confirmed. If that link is cancelled, the set disappears straight away.
  • Your grown-up can see your private progress. Their family account can show your active answer time, lifetime accuracy, tricky words and a curriculum-word chart with attempts, correct answers, usual correct-answer speed and daily totals. It uses the same signed-in practice already saved for your profile and does not collect anything extra. Another family cannot open it.
  • If a grown-up types in your spelling list, Microsoft Azure helps us write the practice sentences, then Google Cloud makes the teacher’s voice. Neither company is allowed to use your words to teach its computer new things.
  • We don’t show you adverts. Ever.
  • We don’t share anything about you with other companies for marketing.

A grown-up can clear the local data from the browser. Signed-in grown-ups can also use the parent account page to download saved family data or just one child’s data, delete saved data, or ask us for help by emailing privacy@spellito.com.

For parents and carers: the detail

Spellito is built to the UK Children’s Code. This section covers what UK GDPR Article 13 requires us to tell you. It is longer than the kid summary above on purpose, but the substance is the same.

Who runs Spellito

Spellito is a product of K. Lam Executive Support Ltd, trading as Wacky Works Digital (company number 17011921). Its registered office is 142-143 Parrock Street, Gravesend, Kent, England, DA12 1EY. The company is registered with the Information Commissioner’s Office under registration reference ZC185373. For any privacy question or request, email privacy@spellito.com.

For direct family use, the company named above is the data controller. If a school instructs its teachers to use Spellito for confirmed pupils, that school is the controller for the school-directed use and the company acts as its processor under the Wacky Works Digital trading name. A written Article 28 agreement must be signed before a live school pilot. Read the school data-processing summary.

What personal data we process

Very little, by design. We don’t ask for or store on our servers:

  • Your child’s surname, date of birth, email, photo, or home address.
  • Your phone number or postal address.
  • A readable copy of your password in Spellito’s database. Our Azure-hosted Supabase Auth receives it securely and stores only its own password verifier.
  • Geolocation, a device fingerprint, or an advertising ID.

What we DO process:

Email/password and Google sign-in are available. If support has given you a sign-in code, you can enter it through the separate help option. A password exists briefly in the sign-in, reset or change form while you type it, then goes directly to our Azure-hosted Supabase Auth over an encrypted connection. It is not sent through a Spellito server route, stored in Spellito’s application database, or sent to analytics. After a successful sign-in, a temporary one-time navigation marker can tell this browser to show the Spellito welcome. It contains no name, email, account ID or sign-in secret and is removed from the address immediately. Google sign-in is also available to adults. Temporary records created during private verification are deleted immediately. Self-service export and deletion are built and tested end to end.

When you enter an adult email and press Continue, our Azure-hosted service checks whether that address already has a Spellito sign-in. The next screen shows either password sign-in or account creation, so someone entering an address can learn whether it has an account before verifying ownership. This check reveals no other account or child details and does not sign anyone in. We do not keep a separate copy of the submitted address or log it in this check. We temporarily keep protected, coded values derived from the email and network address to limit repeated checks, rather than the raw values. Their counting windows last up to fifteen minutes; expired values are removed on the next check or when the application process ends. Our ordinary hosting-log rules below still apply.

If you choose Google sign-in, Google receives the sign-in request and return address, which can identify the page or purchase you are returning to. Google provides your account identifier, email address and verification status, name and profile-picture address when available. These adult details and the sign-in provider can be kept with your Supabase Auth record and included in your account export. We do not request access to Gmail, Google Drive or contacts, or send child profiles or practice records to Google sign-in. Google operates its account service under its own Privacy Policy. Email sign-in remains available if you prefer not to use Google.

On your device (browser storage)
An optional first name for local greetings, a preset profile badge, the year band you picked (Reception–Year 6), your practice preferences (typing, drag-the-letters, or showing the word to copy), and any legacy device-only weekly word lists. The last 100 spelling attempts record which word, year, right or wrong, and how long it took. For a guest with no remembered name, that year and those attempts stay only in the current tab and are cleared when it closes. If the child asks Spellito to remember a first name, the year and attempts persist on that device until cleared in Settings or unused for 12 months. Anonymous practice progress is never transmitted to us. If a signed-in practice write fails, a minimised copy can wait in the browser’s private IndexedDB storage for up to seven days. It is capped at 500 attempts and contains no typed answer, child name, email, auth token or credential. A successful replay deletes the exact session from the device. Each retry checks the current sign-in and ownership again. A supported browser may use Background Sync, which lets it wake Spellito briefly to retry after a connection returns; this is optional, not supported by every browser, and does not guarantee delivery. Otherwise, Spellito retries in the foreground when the app opens, comes online, gains focus or becomes visible.
A parent account (Azure-hosted Supabase Auth and Postgres)
The parent’s email address and sign-in provider are held by Supabase Auth. Our account row stores the parent’s first name, the privacy notice version they accepted, and when they accepted it. Each parent-owned child profile stores a first name, school year, buddy and, only if confirmed, an official school reference. Weekly school words added by the parent are attached to the exact child profile they chose, never to another family. When personalised greetings need preparing, a private Azure queue stores only that profile’s identifier, fixed job state, retry count and timestamps. It does not copy the child’s name, buddy, school, answers or voice script. The worker reads the current profile after the parent’s saved change, generic audio remains available while it works, and deleting the child profile deletes its queue row. A one-letter last initial is added only if the parent asks to connect that child to a registered class. While the parent is signed in, each practice session also stores its start and end time, source, year, total and correct count. Each attempt stores the word, time taken, input mode, result and number of hints used. What the child literally typed is used only for the immediate results screen and is not saved. The same parent account can see private 30-day active-answer time, exact cumulative lifetime accuracy, up to ten tricky-word aggregates and a full curriculum-word mastery matrix for each owned child. The matrix combines the shared curriculum catalogue with aggregate attempt/correct totals, average correct-answer time and daily aggregate history. Those views add no new stored data and return no raw attempts. Database row-level security keeps each family’s rows separate.
A teacher account (Azure-hosted Supabase Auth and Postgres)
The teacher’s email address and sign-in provider stay in Supabase Auth. Our teacher row stores the professional display name, separate consent evidence and, only when chosen, an official school reference. A class adds only its familiar label, school year and explicit teacher membership. A private invitation adds one random code for that class. Creating any of these rows, or possessing the invitation, does not grant access to a child profile. Payment, school selection or a class invitation does not establish teacher authority. Wacky Works Digital separately verifies the teacher’s connection to that official school. We store the verified school reference, verification time and internal revision number. The security audit stores fixed action and outcome codes, adult actor and target references, the school reference and revision, and the decision time, not child details or identity documents. Verification audit records can remain after the teacher account is deleted.
Family Pass and Class Licence payment records
Where activation-code checkout is available, you can buy a Family Pass activation code as a guest, without creating a Spellito account before payment. Stripe collects the adult’s payment and contact details directly. Spellito never receives or stores card details. After verified payment confirmation, we read the purchase email address from Stripe and store that address and an eight-character activation code in a private encrypted delivery queue. This purchase email can differ from the verified adult sign-in used to redeem the code. Redemption requires parent consent and gives that account 12 months from first redemption, not from payment. Unused activation codes have no expiry date, but a refund or payment dispute can prevent redemption. The purchase code is not a sign-in code. The account-first Family checkout remains available during this rollout. It requires a verified adult sign-in before payment and starts the 12-month term from payment; existing purchases keep their original dates and do not become code purchases. Class Licence checkout remains account-first: we verify the adult sign-in before payment, and teacher consent, an official school and an exact teacher-owned class are required for its paid access. Class access continues to run from payment, not code redemption. Our commercial records store the adult account UUID when linked (which can become null after account deletion), the fixed product, its stable internal launch-catalogue label, the fixed amount of 900 or 5,900 pence in GBP, opaque Stripe Checkout Session and PaymentIntent IDs, payment states and timestamps, and the exact 12-month entitlement dates and activation or revocation evidence. The catalogue label is not the access end date. These are manual annual purchases, not subscriptions: Stripe is not instructed to renew or charge again automatically. If an adult buys another year after expiry, we retain the earlier term as renewed commercial history. A new Family activation term starts on redemption; an account-first purchase term starts on payment. If the adult disputes a payment, we also keep the opaque Stripe Dispute ID, bounded dispute status, disputed amount and lifecycle timestamps. A normal open dispute pauses only that paid access; a warning inquiry does not. A win restores access and a loss leaves it revoked. A Class Licence also stores its exact class and official school. We never store full Stripe payloads, dispute evidence or invoices, or child profile or practice data, in payment records.
Family activation delivery and verification
The encrypted delivery queue contains the purchase email address and activation code, bound to the specific order. The private order ledger also holds keyed verification values for the code and purchase email, payment references, redemption state and the redeeming adult account identifier when applicable. Delivery records hold an opaque provider operation reference, delivery state, retry counts and timestamps. This processing does not include child profiles or practice data. The readable email address, code and message body are not written to application logs or returned by purchase-status checks. Authorised server code decrypts the payload to send the transactional email.
Wacky Works Digital owner access
Spellito keeps its owner role separate from parent and teacher accounts. The private owner membership and audit tables cannot be opened by a normal browser session and do not grant a broad view of child practice. The live support lookup first proves the signed-in adult is authorised, then accepts one complete adult email in a private server request. It returns only that adult’s role, account dates and child-profile or teacher-class counts. It does not return child names, schools or practice records. A separate owner recovery control can send a fresh sign-in code only to that exact existing adult. It cannot create an account. The audit record keeps only fixed codes and adult IDs, never the email address or a free-text note. Deletion requires the complete adult email again, rejects a changed sign-in record and cannot delete an administrator. A confirmed deletion removes the adult sign-in and linked parent, child or teacher rows; the fixed-code audit record remains. The separate owner audio-repair workshop can identify one exact existing recording, ask Google Vertex AI for a new version and activate it only after the owner listens to both recordings. Its private ledger stores content hashes, a label, cast character, exact spoken script, pronunciation direction, version, status, owner audit IDs and timestamps. For a personalised greeting or whisper, the script can contain the first name already supplied with parent consent; it contains no child-profile or family ID, adult email, school, class, answer or progress. Rollback restores the original without overwriting either recording.
Generation allowance
When a signed-in adult asks Spellito to create new practice sentences or voice clips, a parent list needs a current Family Pass or Class Licence. Preparing a teacher set also needs an active Class Licence for that exact class. We store the adult account ID, UK calendar date, item count and timestamps in the shared 100-operation daily allowance. We do not copy the words, sentences, child profile, class or payment identifiers into that counter. The audio job stores its words and sentences plus the initiating adult account ID, but no child, profile, class, school, name, email, payment identifier or spelling answer. Only that signed-in adult can open the generic job progress; current teachers can separately see progress for sets in their exact classes. Older jobs that have no owner keep the former random-link status access until the existing 90-day clean-up. Every status response leaves out the job’s words and sentences.
In-app support tickets
The purple bug button can send a general report inside Spellito instead of opening an email app. It accepts one fixed category, a broad page area and up to 1,200 characters that the reporter deliberately types, and warns people not to name a child or paste private information. A separate adult-only whole-school licence enquiry deliberately includes the adult’s name and contact email, official school name, self-declared procurement role, approximate pupil-count band and an optional question in that same bounded ticket detail. Those contact details are owner-only and used only to reply, verify purchasing authority and arrange access. The self-declared procurement role or authority is unverified until Wacky Works Digital verifies it; sending an enquiry does not grant a licence or access. Spellito adds a random ticket reference, the app build and broad browser, device and installed-app labels. It does not copy the page address or query, class invite code, cookies, browser storage, child or profile identity, spelling answer, practice record, card information, raw browser identification or any upload. If a grown-up is already signed in, the ticket may link to that adult account ID so we can reply through the account. Guest reports stay anonymous, so the reporter should keep the random reference shown after sending. A day-only keyed anti-flood value is derived on the server instead of storing an IP address and is cleared after two days. Ticket text is not sent to analytics or an AI provider. Only an authorised Wacky Works Digital owner can open the private queue.
When a parent opens a private class invitation
A signed-in, consented parent account can use the random code to see the official school name and address, class label and school year, and the professional display names of its registered teachers. The invitation contains no child or family identifier and does not create a class link. The parent must separately choose one of their own child profiles at the matching official school or, where class funding allows it, request a new child profile. Teacher confirmation is still required.
School-funded child admission records
When a parent requests a new school-funded child profile, we keep the account, child profile and original class references, a request reference, creation time and a retry fingerprint. This SHA-256 value is calculated from the normalised invitation code, first name, school year and last initial. It prevents a repeated request from creating another child and distinguishes a school-funded profile from the ordinary free profile. The fingerprint is derived personal data, not anonymisation or a device fingerprint. It is not a payment record and does not add another copy of the name, an email, an answer or card details. It stays in our existing Azure-hosted database and backups. Access is restricted to ownership-checked operations; a pending request does not give teachers access to the child’s practice. We include the admission record in your family or child data export. You do not need a Family Pass or active school funding to exercise these rights. A class request, withdrawal, funding expiry or refund does not cancel an independently purchased Family Pass.
A private teacher spelling set
A teacher can save a set name, exact class, broad practice year, optional due date and ordered spelling words with optional sentences. Spellito asks Microsoft Azure to write any missing sentences, then asks Google Vertex AI to record only audio that is not already in our content-hash library. The set belongs to that class, so only its current registered teachers can read the draft or recording progress. The creator is kept as an audit reference while that teacher remains. Saving a draft does not send it to a child.
When a teacher sends a spelling set
We store the exact set, child profile, assigning teacher reference and assignment time. Publishing includes only children currently confirmed in that exact class; sending again adds only children confirmed since the previous send. The child home and practice pages require the signed-in profile-owning parent plus a still-confirmed link to that class. Each homework practice session records the exact set reference. Cancelling the class link hides the set immediately, while the parent-owned assignment remains in the family data export until the child profile or class set is deleted.
When a parent asks to connect a child to a class
We store the exact child profile, registered class, request status and request time. If a teacher confirms or rejects it, we also store the decision time and which registered teacher made it. While the request is waiting, only teachers attached to that exact class can see the child’s first name, last initial and broad school year. They cannot see practice history, accuracy, streaks or spelling words. After confirmation, those same identity fields remain visible in that class’s private roster, together with unique words practised, practice-day, attempt and correct totals, accuracy, last-practice date, current activity streak and 30 days of daily active answer time calculated only from signed-in attempts made after confirmation. They can also see whether practice happened in the previous seven days and up to ten spelling-word labels ranked by post-confirmation failures and a full curriculum-word mastery matrix. Each word tile combines the shared curriculum catalogue with at most the child’s five most recent attempts for that word inside a rolling 90-day window and after class confirmation. A daily drill-down covers the same 90-day window with aggregate totals and average correct-answer time. Answer speed is not used as a mastery judgement. Unattempted words contain no child-derived metric. For a spelling set that was actually sent to a pupil, the same teacher can also see a pupil-by-word matrix containing only that set’s practice: aggregate attempts, correct answers, average correct-answer time and last-practice time from sessions carrying the exact set reference and completed after assignment. Active answer time adds up completed attempt response times; it is not background screen time. Teachers do not receive raw attempt rows, and typed answers are never saved. Cancelled and rejected requests are kept as audit history until the child profile or class is deleted.
While a parent looks for a school
We compare the rough school name and town they type with the official Get Information About Schools directory. The search is normalised in memory and is not saved. If they confirm a result, we save only that school’s official URN. We do not use Google Maps, artificial intelligence, a home postcode or geolocation.
A parent-submitted weekly word list (self-hosted Supabase on Azure)
When you submit a weekly word list, the word + sentence pairs, test date and an unguessable recording-job ID are stored against the exact child profile the signed-in parent selected. Direct browser access to the list table is blocked; ownership is checked again whenever a list is saved, opened or deleted. The audio clip itself is stored in a public bucket, keyed only by a content-derived hash, so it carries no child or family name. Two parents who submit the same word reuse the same clip.
Public website and gateway logs (Vercel)
Like any website, our public host records request metadata (IP address, browser user-agent, page or gateway path and status code). The active Wacky Works Digital Pro plan keeps these logs for one day. Authenticated application and payment processing runs in Microsoft Azure; Vercel holds no database admin, voice, job or payment credential.
Aggregate public-page visits (Vercel Web Analytics)
The public home, parent-information and teacher-information pages record a cookie-free, anonymous page view so we can see how many people visit Spellito and where they found it. They also count a short fixed list of public actions, such as starting practice, opening account setup, sharing Spellito, reading our privacy work or opening a bug report. Only the action label is sent: never the bug report text or anything a visitor types. Vercel may include the page path, referrer, broad location, device type, operating system and browser in aggregate reports. We remove query strings and do not run this analytics script in the game, parent account or teacher dashboard. It receives no child profile, school, practice answer or progress data.

What we send to third parties

  • Stripe: Stripe hosts Family Pass and Class Licence Checkout and collects the adult’s payment and contact details directly. Where offered, Family activation-code Checkout can happen before account creation; only this code purchase uses the encrypted code-delivery queue described above. Account-first Family and Class Licence Checkout require a verified adult sign-in and do not use a Family activation code. Stripe may act as our processor for payment facilitation and as an independent controller for fraud prevention, legal and platform purposes. Spellito never receives or stores card details.
  • Google Cloud (Vertex AI): after Microsoft Azure has prepared a missing practice sentence, we send the word and finished teacher script to Google Vertex AI only when Spellito needs a new Teacher-voice MP3. After a parent has consented and created a child profile, we may also send only that child’s first name inside fixed Spellito or buddy lines so the approved voices can greet and help them. When an authorised owner repairs one of those recordings, we send the exact spoken script and a pronunciation direction so the replacement keeps the approved character voice. A runtime script may therefore contain that already consented first name. We do not include an email, account/profile ID, school, class, typed answer or progress in any of these voice requests. Vertex AI operates under Google’s enterprise data-processing agreement, which contractually prohibits Google from using your submissions to train its models. This is the substantive difference between Vertex AI and the consumer Gemini API. Voice processing currently takes place in Google’s us-central1 region (Iowa, USA) because the approved voice models are available there. Google remains Spellito’s voice provider so new audio matches the existing cast. Even so, we recommend not using your child’s name as a practice word, as defence in depth.
  • Microsoft Azure: hosts the Supabase Auth, Postgres and Storage services operated by Wacky Works Digital, database-bound app routes and encrypted backups. Azure OpenAI writes missing practice sentences from the broad year band and parent- or teacher-supplied words; it receives no account profile or typed spelling answer. We use a managed identity rather than a stored model key, and Microsoft’s terms say this content is not made available to OpenAI or used to train foundation models without our permission or instruction. Azure Communication Services Email delivers adult account-confirmation and recovery links, one-time email links and one-time codes. Azure Communication Services Email also delivers Family Pass purchase emails containing the purchase email address, activation code and fixed instructions. These are transactional messages, not marketing. Neither type includes child profiles or practice data. Engagement tracking is disabled. A successful send status does not guarantee that a message reaches your inbox.
  • Vercel: our hosting provider. Vercel publishes a data processing addendum covering UK data-protection law and Article 28 subprocessor terms. Spellito runs in the Wacky Works Digital Pro account; standard runtime logs are retained for one day. Vercel also supplies the cookie-free aggregate Web Analytics used only on the public home, parent-information and teacher-information pages.

We never sell or share data for advertising or marketing. We do not use Google Analytics, PostHog, Plausible or cross-site advertising analytics. The limited Vercel report above measures aggregate visits and fixed public-button counts on those three public marketing pages only. It does not load in the game, family dashboard, teacher account area or sign-in journey and cannot be joined to a child or account.

The Department for Education supplies the public school directory. It does not receive information from Spellito when a parent searches.

Lawful basis

For direct family use and essential service-operation records, our lawful basis under UK GDPR Article 6 is legitimate interests: the interest in providing a free, ad-free spelling-practice tool for primary-school children, balanced against (and not outweighing) the rights and freedoms of the children practising. We have completed a documented Legitimate Interests Assessment.

For school-directed use, the school is responsible for choosing and explaining its lawful basis. Wacky Works Digital processes that data only under the school’s signed instructions. The parent-authorised class confirmation remains an extra safeguarding control; it does not replace the school’s own UK GDPR assessment.

For adult Family Pass and Class Licence payment records, our lawful bases are contract to supply the requested pass or licence, legal obligation to keep required financial records, and legitimate interests in fraud prevention, security and reconciliation. Contract also covers sending the purchased Family activation code; this is not a marketing subscription.

For general in-app support tickets, our lawful basis is legitimate interests in keeping Spellito safe and working. Contract also applies when a signed-in adult asks for account or payment support. For an adult whole-school licence enquiry, we use the details to take steps at that adult’s request before a contract and, where a contract follows, to perform it; legitimate interests also apply to security and verifying purchasing authority. A safeguarding report may need processing under a legal obligation. Sending a ticket never gives permission to use its text for analytics, advertising or AI training.

For owner audio repair, our lawful basis is legitimate interests in correcting a faulty or unsuitable child-facing recording and keeping the approved British voice cast consistent. The owner must review the replacement before activation, and the process is not used to monitor or profile a child.

How long we keep it

  • Parent accounts and child profiles: retained while the parent keeps the account. A signed-in parent can delete one child immediately or delete the whole account, including the sign-in identity, every child profile, synced practice history and class-link history. If the same adult has an open payment Checkout, Spellito first cancels that hosted payment session. If Stripe cannot yet confirm cancellation or completion, nothing is deleted and the adult is asked to try again. A class link is also removed if its class is deleted. Temporary test records are deleted after each verification run.
  • School-funded admission records: retained with the child profile to prevent duplicate requests and preserve its funded origin. Deleting the child profile or whole parent account removes the admission record. Deleting the class clears its reference but does not remove that record. Withdrawing a request or losing class funding does not delete the child’s profile or admission record. A parent can still withdraw a pending request after funding ends and separately export or delete the child’s data. These records do not use financial-record retention.
  • Teacher accounts: retained while the teacher keeps the account. A signed-in teacher can delete the teacher account through the account controls. An open payment Checkout is cancelled first; if its payment state is not yet certain, nothing is deleted. Class memberships and classes with no teacher left are removed too. A class’s private invitation, draft spelling sets and linked audio-preparation jobs are removed with that class. Shared content-hash audio is kept while another active class set still references it. If a set’s creator leaves but a co-teacher remains, the class and its draft content remain and the creator reference is cleared. If the same sign-in is also a parent account, the family data is kept; otherwise the sign-in identity is deleted. Temporary verification rows are deleted after each test.
  • Family Pass and Class Licence payment records: after any open Checkout is safely cancelled or a completed payment is reconciled, deleting a teacher account removes the adult role and paid access. The stored adult account UUID may then become null, but minimal orphaned financial and dispute records can remain for up to six years for accounting, tax and legal-claims purposes. A payment dispute never deletes the family, class or practice records covered by their own retention and deletion rules. An expired or renewed annual term remains part of that minimal commercial history; it does not authorise another charge or extend access by itself.
  • Family activation email and code: the encrypted delivery payload is separate from minimal financial history. Once both first redemption and a successful send have been recorded, we remove the recoverable email/code payload when the later step completes. Sending alone or redemption alone does not clear it. Unused codes retain their encrypted payload for delivery and recovery; pending or failed delivery also keeps it for retry. There is no automatic age-based deletion of these payloads or retrospective purge of historical records. A refund clears it, as does deleting the adult sign-in that redeemed the code. If the payload has not already been cleared, a payment dispute retains it so a corrected outcome can resume the same delivery. Once cleared, a corrected dispute can restore paid access without restoring a cleared email/code payload. A guest purchase is not linked to an account before redemption, so deleting a different or unlinked sign-in does not remove its delivery payload. Contact privacy@spellito.com about access or erasure of an unredeemed purchase; we need to verify purchase ownership before acting. The code-verification and commercial records are not the same as the recoverable email/code payload.
  • Generation allowance counters: deleted by the daily Azure clean-up after 31 UK calendar days, or immediately when the adult sign-in identity is deleted. They contain only the adult account ID, date, count and timestamps.
  • Audio-generation jobs: terminal jobs are removed after 90 days unless an active teacher set still links them. A linked parent-submitted list is removed with its job. Older ownerless jobs follow the same existing 90-day clean-up. For new jobs, deleting the adult sign-in also deletes their owned audio jobs; audio still needed by a class set remains protected through its separate content-hash references.
  • In-app support tickets: kept until 12 months after they are resolved or closed, then removed by the scheduled Azure clean-up. The day-scoped anti-flood value is cleared after two days. This includes the owner-only adult school-enquiry contact details; they are not copied into a separate licence or billing record unless a later, verified purchase requires one. An anonymous reporter receives only a random reference and must keep it if they want to identify the report later. Safeguarding evidence is kept longer only where the law requires it.
  • Teacher-set assignments: retained while the child remains confirmed in that class and the class set exists. Removing a confirmed pupil from a class deletes that pupil’s assignments for the class immediately. Deleting the child, whole family account, class or set also removes them.
  • The official school directory: retained as public reference data and refreshed from the Department for Education. It contains school details, not family data.
  • Guest year and attempts with no remembered name: until that browser tab closes, with only the latest 100 attempts kept. If the child asks Spellito to remember them, the current year and attempts move into their device-only named profile.
  • Remembered name and local progress: until you clear that named profile in Settings or it has not been used for 12 months. Other device preferences remain until you clear your browser’s site data. We have no remote handle on this. The exception is a failed signed-in practice write: that minimised local fallback or private IndexedDB outbox is removed after successful sync or expires after seven days, and is capped at 500 attempts.
  • Parent-submitted word lists in our database (Azure-hosted Postgres): automatically deleted 90 days after they are submitted, by a daily cron job.
  • Runtime voice clips (Azure-hosted Storage): school-word clips follow their 90-day list clock. A shared personalised greeting bundle follows a separate 90-day clock from the last parent-consented request for that first name. The daily job removes an MP3 only when no active list, teacher item or personalised bundle still shares its content hash. A reviewed replacement for runtime audio follows the same source clock: the candidate MP3 is removed first, then its private repair ledger row. Static curriculum repairs remain with the committed curriculum recording.
  • Curriculum audio (committed in the app bundle): not deleted. These are the pre-recorded teacher-voice MP3s for the standard SATs curriculum words, contain no user data, and ship as static content with the app.
  • Public website and gateway logs (Vercel): retained for one day on the active Wacky Works Digital Pro plan.
  • Azure application operational logs: retained for 30 days in the Wacky Works Digital Log Analytics workspace. Application logging is designed not to include child answers, profile names or adult email addresses.
  • Authentication and purchase emails (Azure Communication Services): message content is processed in real time using the Europe data location. Wacky Works Digital has not enabled optional Azure Monitor delivery logs. Microsoft may temporarily retain recipient addresses for hard-bounced messages to prevent spam and abuse.

Your rights

Under UK GDPR you have the right to be informed, to access your personal data, to correct it, to have it erased, to object to processing, and to lodge a complaint with the UK Information Commissioner’s Office (ICO).

Local-only data can be removed with your browser’s site-data controls. Signed-in parents can use the parent account page to set or change an optional password, download a JSON copy for the whole family or one selected child, delete one child profile, or delete the whole family account. An open payment Checkout is safely cancelled first; an uncertain payment state blocks deletion without removing any data. Family export schema v4 includes the family’s class links, teacher-set assignments, exact-set practice sessions and attempts. A child-only export omits the adult sign-in record, parent account and every sibling while including that child’s related Spellito records. These downloads remain available after a Family Pass expires or is refunded; paid dashboards can close without taking away your right to a copy of data we still hold. Signed-in teachers can use the teacher page to delete their teacher account and class memberships. You can also ask for help by emailing privacy@spellito.com. If you want us to remove a specific word list, include the words (for example, “please delete my list with the words prejudice, programme, relevant”) and we’ll match and purge.

You can complain to the ICO at ico.org.uk/make-a-complaint or by phone on 0303 123 1113.

International transfers

Our self-operated Supabase Auth, Postgres database, audio storage, database-bound app routes and encrypted backups run in Microsoft Azure’s Sweden Central region.

The Azure OpenAI account used for sentence generation is in UK South. Its Global Standard model deployment may process prompts in Microsoft Azure regions globally under Microsoft’s Data Protection Addendum. We send only the broad year band and parent- or teacher-supplied words, not an account profile or typed spelling answer.

Teacher, Spellito and buddy voice synthesis through Google Vertex AI is performed in Google’s us-central1 region (Iowa, USA). This transfer relies on Google LLC’s certification under the EU-US Data Privacy Framework and the UK Extension to that Framework, a transfer mechanism published by the UK government as providing an adequate level of protection for personal data transferred from the UK to certified US recipients. A first name is sent only after parent consent, inside fixed voice copy and without a linking account, school, answer or progress record.

Authentication emails are dispatched through Azure Communication Services Email, as are Family Pass purchase emails, with its Europe data location. Microsoft says message content is processed in real time using that selected geography, although service data may transit or be processed through global endpoints. Wacky Works Digital has not enabled optional delivery-log export. These messages contain an adult email address and an account confirmation link, password-recovery link, one-time sign-in code or Family activation code with fixed purchase instructions, never a child profile or practice result.

When an adult opens Family Pass or Class Licence Checkout, Stripe may process the adult’s payment and contact details globally, including in the United States. Stripe’s Data Processing Addendum and Data Transfers Addendum, together with applicable UK safeguards, govern those transfers. No pupil data is sent to Stripe.

For account-first purchases, including Class Licence, we verify your adult email before payment unless you are already signed in with a verified email. A guest Family activation purchase does not perform that account check before payment. Instead, we check the verified redeeming adult, parent consent and existing Family access when the code is entered. An already active Family Pass prevents another code from being consumed. The email-first sign-in check described above can reveal whether an account exists, but it does not verify ownership or grant access.

For account-first purchases, Spellito keeps a server-generated purchase reference linked to your verified adult login, the chosen product, the payment status and the exact request needed to resume an interrupted Stripe checkout safely. No child details or card details are stored in that request. The reference is sent to Stripe to prevent duplicate payments; a permanent checkout identifier in your browser is no longer needed. Payment and dispute records remain subject to the financial-retention rules above. An unresolved payment is checked before its recovery information is removed.

For a guest Family activation purchase, this browser tab instead keeps a random purchase reference in session storage so an interrupted checkout can be checked or resumed. It contains no email, activation code or card details and is cleared with the tab’s session storage. Our server stores a keyed verification value for that reference and uses one order reference to prevent duplicate payment requests to Stripe. Network-derived keyed values and attempt counters limit purchase and redemption abuse; raw network addresses are not stored in those counters. Expired counters are removed when a later rate-limit check runs.

Cookies and similar

We don’t set tracking cookies. Vercel Web Analytics uses no cookies and discards its short-lived visitor hash after 24 hours. When a parent signs in, our Azure-hosted Supabase Auth uses a strictly necessary authentication cookie to keep that session secure, including while an adult checks out. Browser-side settings use the standard localStorage API, not cookies. We do not use them for advertising or to track you across services.

Children specifically

Spellito is designed for UK primary-school children (Reception–Year 6, ages 4–11). We maintain a Data Protection Impact Assessment (DPIA) against the ICO’s Children’s Code 15 standards. Signed-in progress totals are limited educational profiling: Spellito automatically summarises spelling performance so the child, their grown-up and a confirmed class teacher can see where practice may help. It is never used for advertising, content feeds or a decision with a legal or similarly significant effect. We do not use nudge techniques, the default settings are the most private settings, and anonymous play remains the default. Optional child profiles are parent-owned, have no child credentials, and are isolated from other families. A private class invitation is only an opaque locator: it reveals official school/class details and teacher names inside a parent account, but cannot link a child by itself. A pending class request reveals only first name, last initial and school year to teachers registered for that exact class; it does not reveal practice. After confirmation, those teachers can see the child’s class pseudonym, aggregate attempt and correct totals, accuracy, last-active date, activity streak and 30 days of daily active answer time only for signed-in practice completed from that point onwards. They can also see up to ten spelling-word labels ranked by failures and a curriculum-word matrix. Each word tile uses at most the child’s five most recent attempts for that word inside a rolling 90-day window and after confirmation. Its daily drill-down aggregates the same 90-day period. Answer speed is not used as a mastery judgement, and unattempted cells contain only the shared curriculum word. An assigned-list matrix can also show the same confirmed teachers each pupil-and-word cell for one exact set, using only aggregate practice completed after that set was assigned. It excludes other practice even when the spelling word happens to match. Active answer time is not background screen time. They cannot read raw attempts, and Spellito does not save what a child literally typed. A sent teacher set appears only inside the profile-owning parent session while the exact class link remains confirmed; cancellation removes access immediately. Generic practice cannot claim to be teacher homework, and each real homework session stores the exact set reference. A confirmed class profile also receives a database-picked three-word pseudonym that is unique inside that class and cannot be chosen by the family. The deployed class and school ranking services can be requested only by the owning parent of a child whose link remains confirmed. The class board returns confirmed classmates’ pseudonyms, rank and lifetime correct total. The school top 50 includes only confirmed pupils at the same official school and in the same academic year, adding the class label so matching class-local pseudonyms remain distinguishable. Neither board returns a classmate profile ID, real name, last initial, raw attempt or spelling word.

Changes to this notice

If we change what we collect or how we use it, we’ll update the “last updated” date at the top of this page. For material changes (new third parties, new categories of data), we’ll surface a notice on the home page until you’ve seen it.

Found a wobble?

Tell us what you tapped, what you expected and what happened instead. This sends a private ticket inside Spellito. We add only the broad page area and general browser and device type.

Please do not include a child's name, an email, payment details or any other private information.