← glurpa

Privacy Policy

Glurpa is a parental-control service for children, so this notice is written to meet the Children's Online Privacy Protection Act (COPPA). It is meant to be read by a parent, not a lawyer.

Who we are

Glurpa is operated by an individual developer. A parent is the account holder; children never have their own account. An account can hold two parents, and a parent can hand a babysitter a short-lived code — see “Who else can reach your child’s screen” below for exactly what each of them sees. Questions, requests, or complaints: hello@glurpa.com. We answer every message about a child's data.

What we collect from the parent

What we collect about your child

Everything below is entered by you, or triggered by your child pressing play or tapping an "ask a grown-up" topic. It is stored under your account, not under an account of the child's.

That is the complete list of what we hold about your child. We do not collect a child's email address, photos, voice, location, contacts, birth date, screen name, or any free-text the child types — the child's screen has nothing to type into. One housekeeping note, so the list above stays complete: like any server, ours sees the internet (IP) address of every device that connects, and requests from each address are counted to slow down abuse. That counting now happens in the hosting network's memory rather than in our database, so we no longer write the address or the count down ourselves, and the count is never linked to an account, a profile, or a child. One thing derived from the address we do keep: when you create an account we store the country it was made from, so we know which countries Glurpa is being used in. That is a country name, never the address itself, and it sits on your account, not your child's profile.

Why we collect it

The profile exists so a household with more than one child keeps their approved channels and their place in a video separate. The watch history exists so you can see what your child watched, so a video resumes where it stopped, and so daily screen-time limits can count down. The settings exist to enforce the rules you chose, the optional age exists to aim channel suggestions, the ask-a-grown-up requests exist to reach your dashboard, and the pairing token exists to keep the screen paired, together with a note of the most recent day each screen was used, so you — and we — can tell a connected screen from one that has silently stopped. Beyond that, the only other use is the aggregate counting described below, which is not linked to your child.

What the child's screen does not have

No advertising of any kind, no behavioral or targeted advertising, no advertising trackers, no tracking pixels, no externally hosted fonts, no social buttons. The one outside script that does run there is Cloudflare’s bot protection, described under Cloudflare below: a security check on the connection, not advertising. We do not sell, rent, or trade any personal information about a parent or a child, and we never use a child's information to build a profile for advertising. We currently run no analytics of any kind beyond what this page describes: the “which door” label on a parent’s account above, and the counts and screen reports under “Aggregate statistics” and “Error reports” below. If we ever measure page visits, it will be a cookieless, identifier-free count on our parent-facing pages only — never on a child's screen — and this policy will say so before it happens.

Third parties who receive data, and what each one gets

We do not disclose personal information to anyone else, except where the law requires it or to protect a child's safety.

Where your data lives, and how it gets there

Glurpa’s database is run for us by Cloudflare, a United States company, in its western North America region, and our email goes out through Resend, also a United States company. So whatever country you live in, our database and email records are stored in North America and handled by United States companies under United States law. When your device connects, the request is first answered at whichever Cloudflare data centre is nearest to you, which may be in your own country, and from there it reads and writes that database. Each company that processes data for us — Cloudflare and Resend today, and Anthropic if the Glurpa Score is ever switched on — does so under a written data-processing agreement that limits it to handling the data on our instructions and requires it to keep the data secure, including the European standard contractual clauses where those apply. Google and Microsoft are different: when you choose “Continue with Google” or “Continue with Microsoft”, and when a video plays in YouTube’s player, those companies handle your data under their own privacy policies, not under a contract with us. If the law where you live gives you rights about data leaving your country, this paragraph is the notice that it does.

Who else can reach your child’s screen

Two features hand real access to somebody who is not you. Both are yours to grant, both are yours to end, and neither happens unless you do it.

Neither of these is a sale, a share with a company, or an advertising use. They are access you chose to give to a person, and we would rather write it down here than let you find out from someone else’s screen.

Aggregate statistics

We count how often a channel is added or watched across all accounts, so we can improve the curated library and spot channels that have drifted. These counts are keyed only by the public YouTube channel — they are not linked to any account, profile, or child, and cannot be traced back to one. We do not build a profile of a child, and we never share these counts in any form that could identify anyone.

Error reports

When a page breaks — a fault in our own code, or a video YouTube refuses to play — that screen tells us so, because otherwise a child would be left looking at a broken screen and nobody would know. These reports go only to Glurpa's own servers; no analytics company, advertiser, or other outside party is involved, and nothing is stored on the device to recognise it later; the only thing it keeps is a count of blocked requests waiting to be reported, erased once sent. A report is a fixed code and nothing else: which kind of screen it was (the parent's dashboard or a child's screen), which sort of fault occurred, and — for a fault in our own code — the line of our own program that failed, a location in code we wrote, not in anything your child watched or you typed. It also says which version of our program that screen was running, so we can tell which line the number refers to. It carries no name, no email, no profile, no video, and no error text — error messages can quote whatever was on screen, so we deliberately never send them.

The same screen also tells us which step of setting itself up it has reached — one of seven fixed words, such as “showing the install instructions”, “showing the pairing code” or “ready to watch” — because when a TV stops part-way through setup, nothing else records where it stopped. That is a fact about the screen, not about your child: it carries no name, no email, no pairing code, no address, and nothing typed or watched.

Where Glurpa is available

Glurpa is offered to families in the United States, Australia, New Zealand, Mexico, Israel and Indonesia. We do not accept new accounts from other countries, and we would rather turn a family away than take their data before we can meet the children's-privacy obligations that apply where they live. If you sign up from a country we do not serve, we do not store your email address at all. Existing families keep working normally while travelling.

Your rights as a parent

COPPA gives you these rights, and the app gives you buttons for them:

We will never require a child to disclose more information than is reasonably necessary to watch a video.

How long we keep things

We keep a child's information only as long as it is needed for the purpose it was collected for, and we do not keep it indefinitely.

Security

Traffic is encrypted in transit, passwords are stored only as PBKDF2 hashes, and access to the database is limited to the operator. No system is perfect; we will tell affected parents by email if we ever learn that account data was exposed, and we will notify the privacy regulator where the law where you live requires it (for example as soon as practicable in Australia and New Zealand). We keep a written record of every security incident, whether or not it had to be reported.

Changes

If we ever change what we collect about a child, what we do with it, or who receives it, we will email the parent and get consent again where the law requires it before the change applies.

Contact

Email hello@glurpa.com for any privacy question, to review or delete your child's information, or to withdraw consent.

This page is information about our practices, not legal advice. Last updated: 2026-09-26.