Cocoon

Legal

Privacy Policy

This explains what Cocoon AI collects about your family, why, and what you can do about it. It applies to every account created by a parent or guardian, and to every child profile created inside that account.

Last updated 17 August 2026

In plain terms

  • Only a verified adult can open a Cocoon account or add a child profile - a child can never sign up on their own.
  • We confirm you're a real adult with a small card charge that is refunded automatically. We never see or store your full card number.
  • Your child's PIN is encrypted before it's stored - even our own engineers can't read it back out.
  • There's no open chat and no ad tracking. We don't sell data, and we don't run third-party advertising trackers on this product.
  • You can see everything your child does from your parent dashboard, and delete their profile at any time - deleted data is fully purged within 90 days.
  • If your child publishes a project from Studio, it becomes visible at a public link until you unpublish it.

1. Who this covers

Cocoon AI is built and operated by Think Grid Technologies Private Limited ("Cocoon," "we," "us"). This policy covers the parent or guardian who creates a family account (the account "Owner"), any co-parent added as a "Member," anyone invited as a read-only "Viewer," and every child profile created inside that family account. There is always exactly one Owner per family - the adult who is legally responsible for the account.

A child never creates their own Cocoon account. Every child profile is created, configured, and can be deleted by the family's Owner or Member.

2. What we collect

From the parent account: your name, email address, login credentials, and family role (Owner, Member, or Viewer).

From each child profile: a display name, age, region, an avatar (an emoji, a preset image, or an uploaded image), a login PIN, language preference, a "tone" setting that controls how Emma speaks to them, daily screen-time limits you set, and the topics you've allowed or restricted. The PIN is encrypted before it ever touches our database - we store a ciphertext, not the PIN itself.

Activity and content: your child's conversations with Emma, the lessons they complete, the code and projects they build in Studio, and any files they attach or upload as part of a project.

Payment and identity-verification data: when you subscribe or verify your identity as a parent, our payment processors (Stripe and Razorpay) handle your card details directly. We only ever receive back the last four digits of the card, the card brand, and a reference ID from the processor - never the full card number or CVV.

Device and session data: login tokens issued when you or your child sign in (including QR-code "launch session" logins on shared or classroom devices), so we can keep the right session tied to the right profile.

3. How we use it

  • To run Emma's lessons and respond to your child inside a lesson - not to power open-ended chat.
  • To enforce the screen-time limits, topics, and tone you've configured for your child.
  • To verify you're a real, consenting adult before a child profile can be created or its access extended.
  • To process subscription payments and keep your billing status accurate.
  • To review uploaded content for safety, and to investigate abuse reports.
  • To respond to support requests and grievances.
  • To keep the product secure - rate-limiting abuse, auditing access, and detecting fraud.

We do not use your child's data to build advertising profiles, and we do not sell personal data to anyone, under any circumstance.

4. Children's privacy (COPPA & DPDP)

Cocoon is designed for use by children under the supervision of a parent or guardian, and we built the product around that from the start - not bolted on afterward. Where the U.S. Children's Online Privacy Protection Act (COPPA) or India's Digital Personal Data Protection Act, 2023 (DPDP Act) apply, here is specifically how we meet verifiable-parental-consent requirements:

  • A child profile cannot be created, and cannot have its access extended, without a verified adult account.
  • We verify that adult using a real, small card charge (typically ₹2, $0.50, or AED 2 depending on your region) that is reversed automatically the moment it's confirmed. This is a consent check, not a purchase - see our Refund Policy for how it differs from a paid subscription.
  • You can review every conversation, project, and setting attached to your child's profile from your parent dashboard at any time.
  • You can deactivate or permanently delete a child's profile at any time. Deactivating stops all further collection immediately; the underlying data (conversations, attachments, and the profile itself) is permanently and irreversibly deleted within 90 days of deactivation, as described in section 7.
  • You can withdraw consent and request deletion of your child's data by contacting us at any time.

5. When your child's content is public

Projects your child builds in Studio are private by default. If you or your child publishes a project, it becomes viewable at a public web address and may appear in Cocoon's public project gallery, until it is unpublished. Only the project itself - the app or page your child built - is made public; your child's account details, PIN, chat history, and family information are never included in a published project.

Publishing and unpublishing is controlled entirely by the parent or Member on the account. If you're ever unsure whether a project is public, check the publish toggle in Studio or ask us directly.

6. Who we share data with

We share data only with the vendors that operate the product on our behalf, and only for that purpose:

  • Payment processors - Stripe and Razorpay, to process subscription and identity-verification charges. They are PCI-DSS compliant and handle your raw card data directly; we never store it.
  • Cloud infrastructure - hosting and object-storage providers (including Cloudflare R2) that store your child's uploaded files and projects securely.
  • AI providers - used solely to generate Emma's response to a specific lesson prompt. A prompt is sent only to generate that response; it is not used to build an advertising profile of your child.

We do not share data with data brokers, advertisers, or any third party for their own marketing purposes. We disclose data to law enforcement or regulators only where we are legally required to.

7. How long we keep it

When a child profile is deactivated, we stop all further data collection for that profile immediately. The profile, its conversations, its attachments, and its projects are then permanently deleted within 90 days (this window can be shortened for certain jurisdictions). A minimal audit-log entry recording that the deletion happened is retained separately, for security and compliance evidence only - it does not contain your child's conversations or content.

Content flagged during safety moderation is retained for up to 30 days for review purposes before deletion.

8. Your rights

Depending on where you live, you have some or all of the following rights over your family's data:

  • Access the personal data we hold about you and your child.
  • Correct inaccurate or outdated data.
  • Request erasure of your data, including your child's profile, at any time.
  • Withdraw consent for further collection of your child's data.
  • Nominate another individual to exercise these rights on your behalf, in the event of your death or incapacity (available to users in India under the DPDP Act).
  • Lodge a grievance with us directly, and escalate to your local data-protection authority if unresolved.

To exercise any of these rights, use the controls in your parent dashboard or contact us at hello@cocoonai.app.

9. Security

  • Child PINs are encrypted at rest, not stored in plain text.
  • Card and payment data is tokenized by our PCI-DSS compliant payment processors; we never handle raw card numbers.
  • Family access is role-gated - a "Viewer" cannot read PINs, reset credentials, or delete data, only Owners and Members can.
  • Login and PIN attempts are rate-limited to prevent brute-force guessing.
  • Access to production data is logged and audited.

No system is perfectly secure, and we can't guarantee absolute security. If we ever become aware of a breach affecting your data, we will notify you as required by applicable law.

10. International transfers

We serve families in India, the United States, and the GCC region, and our infrastructure and vendors may process data in countries other than your own. Where we transfer personal data internationally, we rely on our vendors' contractual and technical safeguards to keep it protected to the standard required by applicable law.

11. Cookies

We use only the cookies and local storage strictly necessary to keep you signed in and your session secure. We do not run third-party advertising or cross-site tracking cookies on Cocoon.

12. Changes to this policy

If we make a material change to how we handle your data, we'll notify account Owners by email and show a notice in the product before the change takes effect. The "Last updated" date at the top of this page always reflects the current version.

13. Contact & grievances

Think Grid Technologies Private Limited is the entity responsible for your data under this policy. For any privacy question, data request, or grievance - including grievances under the DPDP Act - contact our Grievance Officer at hello@cocoonai.app. We aim to acknowledge every request within a few business days.