Tubara Privacy Policy
Last Updated: January 1, 2026
Effective Date: January 1, 2026
Version: 1.0
Introduction
Welcome to Tubara! We are committed to protecting the privacy of families who use our service. This Privacy Policy explains how we collect, use, store, and protect your information and your children's information.
Tubara is a parent-controlled educational video platform that allows parents to curate safe YouTube content for their children. We take the privacy of children very seriously and comply with all applicable laws, including the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and the U.S. Children's Online Privacy Protection Act (COPPA).
Who We Are
Service Provider: Tubara
Service Description: Parent-controlled educational YouTube platform for children
Contact Email: support@tubara.world
Privacy Email: privacy@tubara.world
COPPA Email: coppa@tubara.world
Website: https://www.tubara.world
Registered Office: [YOUR REGISTERED BUSINESS ADDRESS]
Company Registration: [YOUR COMPANY REGISTRATION NUMBER]
ICO Registration: [YOUR ICO REGISTRATION NUMBER - if applicable]
Data Controller: Tubara is the data controller responsible for processing your personal data and your children's personal data.
Information We Collect
1. Parent Account Information
When you create a Tubara account, we collect: - Email address - Password (encrypted and hashed with bcrypt) - Account creation date - Subscription tier (Trial, Free, Starter, Pro, or Unlimited) - Payment information (processed securely by Stripe - we do not store your full credit card details) - IP address (for security and fraud prevention)
Purpose: To create and manage your account, process payments, verify you are an adult (18+) for COPPA compliance, and communicate with you about your subscription.
Legal Basis (UK/EU GDPR): - Performance of contract (account management) - Legitimate interest (security and fraud prevention) - Legal obligation (COPPA adult verification)
2. Children's Profile Information
For each child profile you create, we collect: - Child's first name (encrypted with AES-256) - Child's age or age range (encrypted with AES-256) - Selected avatar (visual representation only - no photos) - Selected theme (color preference) - Parental approval timestamp - Age group category (3-5, 6-8, 9-11, 12-14, 15-17 years)
Purpose: To provide age-appropriate content filtering and personalized user experience for your child.
Legal Basis (UK/EU GDPR): Parental consent (you provide consent as the parent/guardian)
COPPA Compliance (US): We only collect this information after receiving verifiable parental consent through your account creation and payment method verification.
Data Minimization: We intentionally collect the minimum information necessary. We do NOT collect: - Children's last names - Children's exact birthdates (only age ranges) - Children's email addresses - Children's phone numbers - Children's physical addresses - Children's photographs - Biometric data
3. Content Preferences
We collect information about: - YouTube channels you approve for your children - Videos your children watch (watch history) - Favorite channels selected by each child - Content categories (Science, Math, Art, History, Language, Music, Technology, Life Skills) - Parent review timestamps and decisions
Purpose: To display approved content to your children and help you monitor their viewing habits and learning progress.
Legal Basis (UK/EU GDPR): Parental consent, performance of contract
COPPA Compliance (US): Watch history is considered personal information under COPPA. We only collect it with your verifiable parental consent and use it solely to provide the Tubara service to your family.
Data Retention: Watch history is retained for 24 months, then automatically archived or deleted.
4. Usage Information
We automatically collect: - Screen time and viewing duration per child profile - Device type and browser information (e.g., "Chrome on Android") - IP address (for security, fraud prevention, and service delivery) - Session cookies (for authentication only) - Log files (for security monitoring and troubleshooting) - Timestamp of account actions (login, profile creation, channel approvals)
Purpose: To provide and improve the service, monitor screen time limits, ensure platform security, and prevent fraud and abuse.
Legal Basis (UK/EU GDPR): - Legitimate interest (security, service improvement) - Performance of contract (service delivery)
COPPA Note: IP addresses and persistent identifiers are considered personal information under COPPA. We collect them only for internal operations (security, service delivery, fraud prevention) and do not share them with third parties for marketing or advertising purposes.
Data Retention: - Session logs: 90 days, then deleted - Security logs: 90 days, then deleted - Aggregated analytics (anonymized): Retained indefinitely - Screen time data: 12 months, then deleted
5. Information We DO NOT Collect
We intentionally do not collect: - ❌ Children's last names - ❌ Children's exact birthdates (only age ranges) - ❌ Children's contact information (email, phone, address) - ❌ Children's precise location data - ❌ Children's photos, videos, or audio recordings - ❌ Social security numbers or government IDs - ❌ Biometric data (facial recognition, fingerprints) - ❌ Children's social media information - ❌ Children's browsing history outside of Tubara - ❌ Children's device contacts or photo library - ❌ Children's precise geolocation
We do not use any tracking cookies or third-party analytics that would collect children's browsing behavior outside of Tubara.
How We Use Information
Primary Uses
- Account Management
- Create and maintain your parent account
- Authenticate your login sessions securely
- Process subscription payments and billing
-
Verify you are 18+ (adult verification for COPPA compliance)
-
Service Delivery
- Display age-appropriate content to children based on their age range
- Filter content based on child's age group and parental approvals
- Enable parental control features (channel approval, content curation)
- Track screen time and enforce limits you set
-
Remember child preferences (favorite channels, theme selections)
-
Parental Insights
- Show you what your children are watching and when
- Display usage analytics and learning categories
- Provide screen time reports and trends
-
Help you understand your children's learning interests
-
Safety & Security
- Protect accounts from unauthorized access and fraud
- Prevent abuse of the platform
- Detect and prevent security threats
-
Comply with legal obligations
-
Communication
- Send transactional emails (account creation, password resets, email verification)
- Send subscription-related emails (payment confirmations, renewals, cancellations)
- Respond to your support requests and inquiries
-
Notify you of material changes to our policies or service
-
Service Improvement
- Understand how families use Tubara (aggregated, anonymized data only)
- Identify and fix bugs and technical issues
- Develop new features based on usage patterns
- Improve age-filtering accuracy
We DO NOT Use Information For:
- ❌ Third-party advertising or marketing
- ❌ Selling or renting to data brokers or third parties
- ❌ Building marketing profiles or behavioral targeting
- ❌ Tracking children across other websites or apps
- ❌ Any purpose other than providing the Tubara service to your family
Automated Decision-Making and Profiling
No Automated Decisions with Legal Effects
We do NOT use automated decision-making or profiling that: - Produces legal effects concerning you or your children - Similarly significantly affects you or your children without human oversight
Our automated systems: - Age-filtering: Automated but you retain full control to override filters - Content recommendations: Based solely on your approved channels, not behavioral profiling - Screen time limits: Automated enforcement of limits YOU set, with override capability
All important decisions require human oversight: - Channel approvals: You (the parent) must manually approve every channel - Content curation: You decide what your children can watch - COPPA compliance: You provide explicit parental consent
You have the right to: - Contest any automated decision - Express your viewpoint about automated processing - Request human intervention and review
How We Share Information
We Share Information ONLY In These Limited Circumstances:
1. Service Providers (Data Processors)
We share information with trusted service providers who help us operate Tubara. All service providers are bound by data processing agreements requiring them to protect your data and use it only for providing services to Tubara.
| Service Provider | Information Shared | Purpose | Location | Safeguards |
|---|---|---|---|---|
| Stripe | Payment information, email address | Process subscription payments and verify payment methods | USA | EU-US Data Privacy Framework, Standard Contractual Clauses |
| Neon (PostgreSQL) | All account and usage data (encrypted) | Database hosting and storage | EU (Frankfurt) or US (specified in your account) | Encryption at rest, Standard Contractual Clauses |
| Vercel | Website request data | Frontend hosting and CDN | USA/Global CDN | Standard Contractual Clauses, GDPR compliance |
| Railway/Render | Application logic data | Backend hosting | USA | Standard Contractual Clauses |
| YouTube (Google) | Channel IDs and video IDs only (NOT personal information) | Video embedding via Privacy-Enhanced Mode | USA | EU-US Data Privacy Framework, YouTube API Terms |
| SendGrid | Email address (for transactional emails only) | Email delivery (password resets, confirmations) | USA | Standard Contractual Clauses |
Important: We do NOT share your personal information or your children's personal information with YouTube. Only non-personal channel and video identifiers are shared for the purpose of embedding videos.
2. Legal Compliance and Protection
We may disclose information if required by law or to protect rights and safety: - In response to valid court orders, subpoenas, or legal requests - To comply with child protection laws and reporting obligations - To protect the rights, property, or safety of Tubara, our users, or the public - To detect, prevent, or address fraud, security, or technical issues - To enforce our Terms of Service
We will challenge overly broad or inappropriate legal requests and notify you when legally permitted.
3. Business Transfers
In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the new owner.
Your rights in this scenario: - You will be notified via email at least 30 days before transfer - The new owner must honor this Privacy Policy - You may delete your account before the transfer if you don't consent
We DO NOT:
- ❌ Sell your information or your children's information to third parties
- ❌ Share children's information with advertisers or marketing companies
- ❌ Allow third-party tracking, analytics, or advertising networks to collect children's data
- ❌ Display targeted advertising based on children's information
- ❌ Rent or lease user data
Data Security
How We Protect Your Information
Encryption: - All children's personal information (names, ages) is encrypted at rest using AES-256 encryption - All data transmission uses TLS 1.3 encryption (HTTPS) - Passwords are hashed using bcrypt with 10+ salt rounds (industry standard) - Database backups are encrypted - Encryption keys are stored separately from data
Access Controls: - Role-based access control (RBAC) limits who can access data - Only essential personnel can access user data, and only for legitimate operational purposes - All access is logged and audited - Multi-factor authentication required for administrative access - Regular security training for all personnel
Infrastructure Security: - Secure cloud hosting with SOC 2 Type II certified providers - Regular automated and manual backups - Disaster recovery and business continuity plans - Firewall protection and intrusion detection systems - DDoS protection - Regular security audits and penetration testing - Vulnerability scanning and patch management
Account Security: - Secure password requirements (minimum 8 characters) - Session management with secure, httpOnly cookies - Protection against brute force attacks (rate limiting) - Account lockout after failed login attempts - Secure password reset process with email verification
YouTube Privacy: - All video embeds use youtube-nocookie.com for privacy-enhanced mode - No YouTube tracking cookies in child viewing experience - Children never leave Tubara to watch videos
Application Security: - Input validation and sanitization to prevent injection attacks - Content Security Policy (CSP) headers - Cross-Site Request Forgery (CSRF) protection - Cross-Site Scripting (XSS) prevention - SQL injection protection
Monitoring and Incident Response: - 24/7 security monitoring and alerting - Incident response plan and procedures - Regular security audits and vulnerability assessments - Prompt patching of security vulnerabilities
Limitations: While we implement robust security measures using industry best practices, no system is 100% secure. We cannot guarantee absolute security against all possible threats. You acknowledge that you use Tubara at your own risk regarding data security.
Data Breach Notification
In the Event of a Data Breach
Our Commitment: If we discover a data breach affecting your personal information or your children's information, we will:
- Notify affected users within 72 hours of becoming aware of the breach (GDPR requirement)
- Report to supervisory authorities (ICO in UK, relevant authority in EU) within 72 hours where required
- Provide clear information about:
- The nature of the breach
- What data was affected
- The likely consequences
- Steps we are taking to address the breach
- Steps you can take to protect yourself
For Breaches Affecting Children's Data: - We will provide additional support and guidance to parents - We will offer free credit monitoring if financial data was compromised - We will work with relevant authorities to ensure child safety
How We'll Contact You: - Email to your registered email address - Notice in your account dashboard - If email is compromised, we will use alternative contact methods
Your Rights After a Breach: - You may terminate your account and request immediate data deletion - You may request a full report of what information was affected - You have the right to lodge a complaint with the ICO or your supervisory authority
Data Retention
How Long We Keep Information
Active Accounts: - Account information: Retained as long as your account is active - Children's profiles: Retained as long as your account is active - Watch history: 24 months, then automatically archived or deleted - Screen time data: 12 months, then automatically deleted - Content approvals: Retained as long as your account is active
Deleted Accounts: When you delete your account: - Personal data is permanently deleted within 30 days - Children's data is permanently deleted within 30 days - Anonymized, aggregated data may be retained for analytics - Backups containing your data are overwritten within 90 days - Legal or financial records may be retained longer as required by law
Legal Requirements: - Payment transaction records: 7 years (UK tax law requirement) - Legal dispute records: Until resolution + 6 years (UK limitation period) - Child protection reports: As required by law
De-identification: After deletion, any remaining records are de-identified so they can no longer be associated with you or your children.
Your Rights (UK/EU GDPR)
Data Subject Rights
Under UK GDPR and EU GDPR, you have the following rights regarding your personal information and your children's information:
1. Right to Access (Subject Access Request) - Request a copy of all personal data we hold about you and your children - Receive information about how we process your data - How to exercise: Account Settings > Export Data OR email privacy@tubara.world - Format: JSON or CSV file - Response time: Within 30 days (may extend to 60 days for complex requests) - Cost: Free for first request; may charge reasonable fee for excessive requests
2. Right to Rectification - Correct inaccurate or incomplete personal information - How to exercise: Account Settings > Edit Profile OR email privacy@tubara.world - Response time: Within 30 days
3. Right to Erasure ("Right to be Forgotten") - Delete all your data and your children's data permanently - How to exercise: Account Settings > Delete Account OR email privacy@tubara.world - Effect: Account termination, all data deleted within 30 days - Exceptions: We may retain data if required by law (e.g., financial records) - Response time: Immediate via Account Settings, or within 30 days via email
4. Right to Data Portability - Receive your data in a structured, commonly used format (JSON/CSV) - Transfer your data to another service provider - How to exercise: Account Settings > Export Data - Format: Machine-readable JSON or CSV - Response time: Immediate download
5. Right to Object - Object to processing based on legitimate interests - Object to direct marketing (we don't do any) - How to exercise: Email privacy@tubara.world - Response time: Within 30 days
6. Right to Restrict Processing - Request temporary restriction of data processing while we verify accuracy or assess legal basis - How to exercise: Email privacy@tubara.world - Effect: Your account may be suspended during restriction period - Response time: Within 30 days
7. Right to Withdraw Consent - Withdraw consent at any time (by deleting account or specific child profiles) - How to exercise: Account Settings > Delete Account or Delete Child Profile - Effect: Processing stops immediately; account may be terminated - Note: Withdrawal does not affect the lawfulness of processing before withdrawal
8. Right to Lodge a Complaint - Complain to the Information Commissioner's Office (ICO) in the UK - Complain to your local supervisory authority in the EU - See contact information in the "Contact Us" section below
Request Processing Timeline: - We will acknowledge all rights requests within 48 hours - We will provide a full response within 30 days - For complex requests, we may extend to 60 days and will explain why - If we extend the timeline, we will notify you within the first 30 days
Verification: To protect your privacy, we may ask you to verify your identity before processing rights requests. We'll only ask for information necessary to verify your identity.
Parental Rights (COPPA - US Users)
Special Rights for Parents Under COPPA
If you are a parent or guardian of a child under 13 years old using Tubara, you have additional rights under the US Children's Online Privacy Protection Act (COPPA):
1. Right to Review - Review all personal information we have collected from your child - How to exercise: Account Settings > Child Profiles > View Data - Response time: Immediate via dashboard, or within 48 hours via email
2. Right to Delete - Delete your child's personal information at any time - How to exercise: Account Settings > Child Profiles > Delete Profile - Effect: Child profile and all associated data deleted within 30 days - Note: This does not delete your parent account
3. Right to Refuse Further Collection - Refuse to allow further collection or use of your child's information - How to exercise: Delete child profile OR delete your entire account - Effect: Service terminated for that child or entire account
4. Right to Consent Withdrawal - Withdraw parental consent at any time - How to exercise: Account Settings > Delete Account - Effect: Account termination, all child data deleted within 30 days
5. Right to Control Information Collection - You control every aspect of what information is collected about your children - You approve every channel your children can access - You can export all of your children's data at any time
How to Exercise COPPA Rights: - Via Account Settings: Instant action - Via Email: coppa@tubara.world - Response within 24 hours - Via Phone: [PHONE NUMBER] - Available 9am-5pm EST weekdays
Verification: To protect your children's privacy, we will verify your identity before processing COPPA requests. We may ask for: - Email confirmation (if your email is verified) - Last 4 digits of payment method on file - Answer to security question
Parental Consent (COPPA)
How We Obtain Verifiable Parental Consent
Tubara complies with COPPA by requiring verifiable parental consent before collecting personal information from children under 13.
Our Consent Mechanism:
- Adult-Only Account Creation
- Only adults (18+) can create Tubara accounts
-
Age verification through payment method
-
Payment Method Verification
- All users (including trial and free tier) must complete Stripe Setup Intent
- Credit/debit card verification constitutes verifiable parental consent under FTC guidelines
-
This method is approved by the FTC as one of the acceptable mechanisms
-
Explicit Parental Declaration
- You confirm you are the parent or legal guardian during registration
- You acknowledge that you are 18+ years old
-
You consent to collection of your children's information
-
Ongoing Parental Control
- You maintain full control over children's profiles and data at all times
- You can delete child data instantly from Account Settings
- You approve every piece of content your children can access
For Trial/Free Tier Users: All users must complete payment method verification (Stripe Setup Intent) to establish verifiable parental consent under COPPA. No charges are made to trial or free tier users, but credit/debit card verification confirms: - You are an adult (18+ years old) - You are the parent or legal guardian - You consent to the collection of your children's information
What Consent Covers: - Collection of child's first name and age/age range - Tracking watch history and screen time - Displaying parental analytics and insights - Providing age-appropriate content filtering
Withdrawing Consent: You may withdraw consent at any time by: - Deleting individual child profiles (Account Settings > Delete Child Profile) - Deleting your entire account (Account Settings > Delete Account) - Emailing coppa@tubara.world
Effect of withdrawal: Service terminates for affected children, all data deleted within 30 days.
Cookies and Tracking
What Cookies We Use
Essential Cookies (No Consent Required):
These cookies are strictly necessary for the service to function and are exempt from cookie consent requirements under UK/EU law (PECR and ePrivacy Directive).
| Cookie Name | Purpose | Duration | Type | Third Party? |
|---|---|---|---|---|
connect.sid |
Session authentication and login | Session (until browser closes) | HTTP-only, Secure | No |
tubara_session |
User session management | Session | HTTP-only, Secure | No |
stripe_mid, stripe_sid |
Payment processing security | Stripe session | HTTP-only, Secure | Yes (Stripe) |
Preference Cookies (Consent Required):
| Cookie Name | Purpose | Duration | Type | Third Party? |
|---|---|---|---|---|
tubara_consent |
Cookie consent preferences | 12 months | Preference | No |
child_theme_pref |
Remember child's theme selection | 12 months | Preference | No |
We do NOT use: - ❌ Advertising cookies or tracking pixels - ❌ Third-party analytics cookies (Google Analytics, etc.) - ❌ Social media tracking cookies - ❌ Behavioral targeting cookies - ❌ Cross-site tracking cookies
YouTube Cookies: When videos are embedded, YouTube may set minimal cookies even with youtube-nocookie.com (Privacy-Enhanced Mode). These are significantly reduced compared to regular YouTube embeds and do not track your children across the web.
How to Manage Cookies: - Browser settings: You can delete or block cookies through your browser settings - Effect of blocking essential cookies: You will not be able to log in or use Tubara - Effect of blocking preference cookies: Your preferences will not be saved
Cookie Policy: For more detailed information, see our separate [Cookie Policy] (if you create one).
International Data Transfers
Data Processing Locations
Primary Data Storage: - Database: EU (Frankfurt, Germany) via Neon PostgreSQL - Application: USA via Vercel/Railway hosting - Backups: EU and USA (encrypted)
Cross-Border Transfers:
When your data is transferred outside the UK/EU, we ensure adequate protection through approved transfer mechanisms:
✅ EU-US Data Privacy Framework (for US service providers who participate)
✅ Standard Contractual Clauses (SCCs) approved by the European Commission
✅ Data Processing Agreements with all service providers
✅ Encryption of data in transit and at rest
Specific Safeguards by Provider:
| Provider | Location | Transfer Mechanism | Additional Protections |
|---|---|---|---|
| Stripe | USA | EU-US Data Privacy Framework + SCCs | Strong encryption, limited data shared |
| YouTube/Google | USA | EU-US Data Privacy Framework + SCCs | Privacy-Enhanced Mode, no personal data shared |
| Vercel | USA/Global | SCCs + DPA | CDN with EU endpoints available |
| SendGrid | USA | SCCs + DPA | Transactional emails only, minimal data |
| Neon | EU (Frankfurt) | No transfer (EU-based) | Data remains in EU |
For UK Users: Following Brexit, transfers from the UK to the EU are currently recognized as adequate. Transfers to the USA and other countries are protected by Standard Contractual Clauses and our data processing agreements.
For EU Users: We comply with GDPR Chapter V requirements for international transfers. Your data may be transferred to the USA or other countries with different data protection laws, but only when appropriate safeguards are in place.
Your Rights Regarding International Transfers: - You may request information about safeguards in place - You may object to transfers on compelling legitimate grounds - You have the right to lodge a complaint with your supervisory authority
Children's Privacy
Special Protections for Children
Age Restrictions: - Tubara is designed for children aged 3-17 years old - Only adults (18+) can create Tubara accounts - Children cannot create accounts independently - Children cannot modify settings or approve content
How We Protect Children:
✅ Parent-Approved Content Only
- Children can only access channels explicitly approved by you
- No random discovery or recommendations
- No YouTube homepage or trending videos
✅ No Third-Party Advertising or Tracking
- We do not display any advertisements
- We do not track children across other websites or apps
- We do not create behavioral profiles
- We do not sell children's information
✅ Privacy-Enhanced YouTube Embeds
- All videos use youtube-nocookie.com domain
- Minimizes YouTube tracking
- Children never leave Tubara to watch videos
- No YouTube comments or social features
✅ Encrypted Data Storage
- All children's names are encrypted with AES-256
- All children's ages are encrypted with AES-256
- Encryption keys stored separately from data
✅ Complete Parental Control
- You control all settings and data
- You can delete child data instantly
- You can export all child data
- You receive analytics and insights
✅ COPPA Compliance
- Verifiable parental consent required
- Data collection limited to service necessity
- No behavioral advertising
- Parental rights honored promptly
Educational Focus: Tubara is designed as an educational tool with parental oversight, not a social media platform or entertainment service. We do not collect more information than necessary to provide age-appropriate educational content.
No Social Features: - No comments, likes, or shares - No friend connections or social networking - No direct messaging or chat - No user-generated content - No public profiles
If You Believe a Child Under 13 Has Provided Information Without Parental Consent: Contact us immediately at coppa@tubara.world and we will: - Investigate promptly (within 24 hours) - Delete the information if consent was not obtained - Take steps to prevent recurrence
Changes to This Privacy Policy
How We Handle Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational needs.
How We Notify You:
For material changes (affecting how we collect or use information): - ✉️ Email notification to your registered email address at least 30 days before changes take effect - 📢 Prominent notice on website homepage - 🔔 Notice in your account dashboard when you log in - 📅 Updated "Last Updated" date at the top of this policy
For minor changes (clarifications, formatting): - 📅 Updated "Last Updated" date only - No email notification required
Your Acceptance: - Continued use of Tubara after changes constitutes acceptance of the updated policy - If you don't agree with changes, you may delete your account before changes take effect - You'll have at least 30 days' notice for material changes
Material Changes Affecting Children (COPPA Requirement): If we make material changes to: - How we collect children's information - How we use children's information - Who we share children's information with
We will: 1. Notify you by email at least 30 days in advance 2. Obtain fresh parental consent before implementing changes 3. Allow you to opt out by deleting child profiles or your account 4. Provide clear explanation of what's changing and why
Version History: We maintain a history of all Privacy Policy versions: - Current version always available at https://www.tubara.world/privacy-policy - Previous versions available at https://www.tubara.world/privacy-policy/archive
Contact Us
Questions or Concerns About Privacy?
General Privacy Inquiries:
📧 Email: privacy@tubara.world
🌐 Website: https://www.tubara.world
⏱️ Response Time:
- General inquiries: Within 2 business days
- Data subject rights requests: Acknowledged within 48 hours, resolved within 30 days
- COPPA requests: Within 24 hours
- Security incidents: Immediate acknowledgment
Support and Account Help:
📧 Email: support@tubara.world
⏱️ Response Time: Within 2 business days
COPPA-Specific Inquiries (US Parents):
📧 Email: coppa@tubara.world
📞 Phone: [YOUR PHONE NUMBER]
⏱️ Hours: Monday-Friday, 9:00 AM - 5:00 PM EST
⏱️ Response Time: Within 24 hours
ℹ️ FTC COPPA Information: https://www.ftc.gov/coppa
Data Protection Officer (if applicable):
📧 Email: dpo@tubara.world
📬 Postal Address: [DPO ADDRESS]
Mailing Address:
Tubara
[YOUR REGISTERED BUSINESS ADDRESS]
[CITY, POSTAL CODE]
[COUNTRY]
Supervisory Authority - United Kingdom
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office (ICO)
📬 Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
📞 Phone: 0303 123 1113
🌐 Website: https://ico.org.uk
📧 Report a concern: https://ico.org.uk/make-a-complaint
Supervisory Authorities - European Union
For EU users, you may contact your local data protection authority:
Find your authority: https://edpb.europa.eu/about-edpb/board/members_en
Common EU Authorities: - Ireland (GDPR lead for many tech companies): Data Protection Commission - https://dataprotection.ie - Germany: Bundesbeauftragter für den Datenschutz - https://www.bfdi.bund.de - France: CNIL - https://www.cnil.fr - Spain: AEPD - https://www.aepd.es
Summary for Parents
What We Collect: - ✅ Your email and payment method (for adult verification) - ✅ Your child's first name and age (encrypted) - ✅ Videos your children watch (to show you their learning)
Why We Collect It: - ✅ To provide the Tubara service - ✅ To verify you're an adult (COPPA requirement) - ✅ To filter age-appropriate content - ✅ To show you what your children are learning
How We Protect It: - 🔒 AES-256 encryption of all child data - 🔒 TLS 1.3 encryption for all data transmission - ❌ No sharing with third parties for marketing - ❌ No advertisements or tracking cookies - ✅ Privacy-enhanced YouTube embeds (youtube-nocookie.com)
Your Control: - ✅ Delete all data anytime (instantly from Account Settings) - ✅ Export all data anytime (JSON or CSV format) - ✅ Control what your children can watch (every channel requires your approval) - ✅ View what your children are watching (full transparency) - ✅ Set and enforce screen time limits
Your Rights: - ✅ Access your data (free) - ✅ Correct your data (instant) - ✅ Delete your data (within 30 days) - ✅ Export your data (instant download) - ✅ Object to processing - ✅ Lodge complaints with ICO/supervisory authority
Questions?
📧 Email: support@tubara.world
📧 Privacy: privacy@tubara.world
📧 COPPA: coppa@tubara.world
Legal Declaration
By using Tubara, you acknowledge that:
- You have read and understood this Privacy Policy in full
- You consent to the collection, use, and processing of your information and your children's information as described
- You are the parent or legal guardian of all children whose profiles you create
- You are 18 years of age or older
- You have the authority to provide consent on behalf of your children
- You understand your rights under applicable privacy laws (UK GDPR, EU GDPR, COPPA)
- You understand how to exercise your rights (Account Settings or email)
Last Updated: January 1, 2026
Effective Date: January 1, 2026
Version: 1.0
© 2026 Tubara. All rights reserved.