The account belongs to a parent
A parent or legal guardian creates and manages the Piko account. Child profiles are created under that adult account; children do not create independent Piko accounts. The parent chooses profile settings and is responsible for deciding whether a child may use Piko.
The parent account can include an email address, account identifier, and profile or family settings. If you invite another parent into a paid family plan, the invitation may use that adult’s email address. Piko also keeps account, subscription, and support-request records needed to run the service.
Questions sent through Parent Zone may include the parent’s message and any details the parent chooses to share. Parent Zone features such as Coach can also process a parent’s question and response.
Information connected to a child profile
A parent may add a child’s first name, age or age band, interests, and preferences. Settings can include response style, voice and image access, memory, transcript history, and other parent-managed guardrails.
When a child uses Piko, the service may process and save:
- Questions and responses, stories, quiz activity, and saved learning activity.
- Voice-session details and, when transcript history is enabled, the words spoken or transcribed during a session.
- Generated images and related story or voice output.
- Optional memory items and safety or moderation records.
Saved voice transcripts are encrypted before they are stored in Piko’s database. This describes Piko’s transcript storage; it does not describe copies a service provider may process.
Live voice is processed to provide the conversation. Piko’s current product documentation says live audio is not recorded by default. If a parent enables transcript history, the transcript can be saved for review. When Show Piko video is used, camera frames are sent for the live feature and are not stored by Piko as image uploads.
AI features and service providers
Piko currently uses Google Gemini and OpenRouter for AI processing. Depending on the feature and route, a request may include a question, relevant conversation context, a selected age style, or an image needed to provide the response. The route can change by feature.
We use Supabase for account services, databases, and file storage; Mixpanel for parent-consented product analytics; and RevenueCat with Apple’s App Store for subscription and purchase processing. Piko may also create moderation and safety records to help identify unsafe content or abuse.
We do not display ads to children. Piko does not send child prompts, voice, images, or child-session events to advertising platforms. A limited parent-only attribution flow is separate from a child’s activity: Apple attribution services may process an install signal, and an opaque Apple attribution token may be sent to Apple and RevenueCat. The Meta SDK is initialized only after a parent passes the Parent Zone gate and authorizes Apple’s tracking request. The tracking explanation and system prompt are shown to the parent, never to a child.
After the parent chooses analytics, Mixpanel may receive a parent account or device identifier and fixed product events such as screens, feature use, plan tier, or age style. Piko’s analytics wrapper does not include message or media content.
A picture moderation event can record the selected age style, whether an image passed or was blocked, broad reason categories, model label, processing cost, and time. The current moderation-event table does not include the image or parent account ID.
Purchases are made through Apple’s in-app purchase system. RevenueCat helps Piko check purchase status and restore access. Piko’s servers also keep subscription and purchase event records needed to maintain entitlements.
Parent controls, consent, and choices
Parents manage child profiles and can change voice, image, response-style, memory, and transcript-history settings in Parent Zone. A parent PIN or Face ID protects sensitive areas such as purchases, transcripts, exports, and deletion.
Analytics is a separate parent choice. The iOS tracking permission prompt for ad measurement is requested only in the parent area after the parent gate. A parent can decline it. Declining does not prevent a child from using learning features.
When a family uses an AI feature, the information needed to answer the request is sent to the AI provider for that feature. Parents can disable supported features in the child’s settings and can stop using Piko at any time.
How long information is kept
Piko applies scheduled retention to several kinds of saved information:
- Chat messages and saved voice transcripts: up to 90 days.
- Generated images: up to 180 days.
- Stored story audio: up to 180 days.
- A requested data-export file: up to 24 hours after it is ready.
- RevenueCat purchase-event records: up to 24 months.
Safety records may be kept for abuse review. The in-app deletion screen says safety events can remain for 24 months. Some encrypted safety evidence is cleared when its expiry is reached. Short-lived pairing codes expire after ten minutes and can be used once.
These periods describe Piko’s current server retention rules. They do not set the retention period of copies handled by AI, analytics, app-store, or other providers. Those periods depend on the provider route and its settings.
Review, export, or delete information
Parents can review available child activity in Parent Zone, change profile settings, turn off transcript history or memory, and request an export. To remove one child profile, use Parent Zone → Privacy Center → Export and delete → Delete a child profile.
To delete the parent account: open Parent Zone → Privacy Center → Export and delete → Delete my parent account. Confirm the signed-in parent email, then enter the parent PIN. The request permanently deletes the account and its child profiles and saved content, and the app signs out when deletion completes. This action cannot be undone.
Deleting your Piko account does not cancel an Apple subscription. Cancel it separately in your Apple account’s subscription settings to prevent future renewal. Some limited safety, purchase, or legally required records may need to be retained; provider copies follow the provider’s own retention rules.
See Support: delete your account for the same steps.
Contact and jurisdiction
For account or privacy requests, use Parent Zone → Privacy Center in Piko. For other help, use Parent Zone → Feedback and safety report. You can also read the support page.
The working jurisdiction for this policy is India, subject to confirmation by the owner and legal review.
We may update this policy as Piko changes. The effective date above will change when a revised version is posted.