Their curiosity belongs to them
Wondoki is operated by Tallinio LTD, Cyprus. For support or a privacy request, contact info@tallinio.com.
Wondoki stores the profile, settings, conversations, and learning notes needed to run your family space. Parents can review, export, and delete this information.
We do not include advertising or sell child data. Raw conversations are excluded from product analytics. Questions, responses and retrieved articles pass through safety checks. Parents can enable voice, photo questions and filtered Wikipedia search. Wondoki does not save original recordings or photos; text sent in a conversation follows the family’s retention setting.
Setting up a profile records your acknowledgement. A public launch requires a verified parental consent process appropriate to the countries served.
This early version is for evaluation with fictional profiles. It is not open for real children’s personal information. Before a public launch, the operator must complete the processing-location, consent and processor reviews and publish approved legal terms.
Conversations and parental access
Parents can separately enable voice, image questions and filtered Wikipedia search. Recordings and resized photos are processed by Groq; Wondoki does not store the original audio or image. Text prepared from them may be held briefly for request recovery and, when sent, becomes part of the retained conversation. Search sends the checked current question to Wikipedia, without conversation history, profile details or device identifiers. Read-aloud uses a local device voice when available. Pinning a chat does not extend its retention period.
For ages 6–12, the authorized parent or guardian can view the complete stored conversation history. The dashboard shows learning activity and neutral safety notices first. Children are told during connection and in their learning space that their parent can read their chats. There is no private-from-parents chat mode.
Your family chooses a retention period of 7, 30 or 90 days. Parents can delete one conversation or all conversations for a child. Deletion removes linked messages, safety records, model-usage rows and cached replies. Parent-written learning notes, the child profile and subscription remain. Deleting the child profile also deletes its associated conversations and notes. We do not keep a separate conversation archive in the application.
Learning summaries describe recorded activity; they do not diagnose feelings or assess learning ability. Sensitive quotations are excluded from dashboard previews and notification content. Provider and backup deletion must be included in the release review before real-child use.
Child browser sessions use a secure device cookie on HTTPS. Parent sign-in is handled by Supabase, with email verification and account recovery delivered through Resend. Disconnecting a device stops its access. The family data export and deletion controls are in Family settings. No third-party advertising or analytics scripts are included.
Back