Privacy Policy
Simple and transparent, as it should be when it comes to children.
Last updated: October 2026.
Monster Nerd is made for children, so we take privacy seriously. This policy explains, in simple terms, what data we use and why, in accordance with Brazil's General Data Protection Law (LGPD, Law 13.709/2018), especially Article 14, which covers data of children and adolescents.
Who is responsible for the data
Monster Nerd. Contact for any privacy matter: [email protected].
Who can create an account
Only the father, mother or legal guardian. By creating the account, the parent or guardian gives specific consent for the child to use the app.
What data we use
- From the parent or guardian: email and password (to sign in to the account) and the record of consent.
- From the child: nickname, the chosen monster and progress in the app (points, completed study sessions, grades entered). We do not ask for the child's full name, address, school or a photo of their face.
- Photos of lessons: the images of the notebook or textbook uploaded to create a study session. We ask that children photograph only school content. The photos are not stored: after the study session is generated, we keep only the summary and the questions.
- Waitlist: the email provided on the website, used only to notify you about the launch of plans.
What we use it for
- To make the app work: saving the monster, points and study history.
- To create study sessions: photos and text from the lessons are processed by a contracted artificial intelligence service (Anthropic), solely to generate a summary, cards and questions about that content.
- To show the progress report to the parent or guardian.
We do not sell data. We do not show ads. We do not use the child's data for advertising or to build a consumer profile.
Who we share it with
Only with the services needed for the app to work: hosting and database (Cloudflare and Supabase) and the artificial intelligence service that generates the study sessions (Anthropic). They process the data solely to provide that service.
How long we keep it
For as long as the account is active. If the parent or guardian requests deletion, we delete the account and associated data within 30 days, unless retention is required by law.
Rights of the parent or guardian
You may, at any time, request access to, correction or deletion of the data, or withdraw consent, by writing to [email protected].
Security
Data is kept on services with encryption in transit and access control. Each parent or guardian can only see their own children's data.
Changes to this policy
If anything important changes, we will let you know in the app and ask for new consent when necessary.