Privacy Policy

Last updated: October 2026

Your Privacy Matters

NeuroKids is committed to protecting the privacy of children and families. We are aligned with UK GDPR and are designed with children\u2019s safety at the centre.

UK schools: looking for the DPO compliance pack?

DPIA template, sub-processors list, MDM profiles — all in one place.

1. Who We Are

NeuroKids is operated by Linked2Link Ltd ("we", "us", "our"). We provide a digital platform to support children with autism and their families through interactive tools, learning resources, and tracking features.

2. Information We Collect

We collect information you provide directly: parent name, email, and password for account creation; child name and age for profile setup; emotion logs, sleep data, diet records, and activity progress you choose to record; support tickets and contact form submissions. We do not collect location data, photos, or biometric data from children.

3. How We Use Your Information

Your data is used to provide and improve our services: displaying progress dashboards and reports; generating AI-powered insights and recommendations; sending notification emails (with your consent); providing customer support. We never sell your data to third parties.

4. Data Storage & Security

All data is stored in encrypted databases. Authentication uses secure HTTP-only cookies. All connections are encrypted via HTTPS/TLS. We follow industry best practices for data protection including bcrypt password hashing and XSS sanitisation.

5. Children's Privacy

NeuroKids is designed for use by parents and caregivers on behalf of children. Children's accounts require parental setup and a 4-digit PIN. We do not knowingly collect personal information directly from children under 13 without parental consent. Parents can review, modify, or delete their child's data at any time through the app. Our primary regulatory alignment is UK GDPR; if we introduce services aimed at US residents in future we will additionally align to COPPA at that time.

6. Cookies

We use essential HTTP-only cookies for authentication (keeping you logged in). We do not use advertising or third-party tracking cookies. You can clear cookies through your browser settings, which will log you out.

7. Third-Party Services

We use the following services to operate NeuroKids: Resend (transactional emails), Stripe (payment processing — we do not store card details), and OpenAI/Google AI (for AI features — no personally identifiable child data is sent to AI services).

8. Your Rights (GDPR)

You have the right to: access your personal data; correct inaccurate data; request deletion of your data; export your data (available via our Export Data feature); withdraw consent for marketing communications. To exercise these rights, contact us at neurokidsspace@gmail.com.

9. Data Retention

We retain your data for as long as your account is active. If you delete your account, all associated data will be permanently removed within 30 days. Anonymised, aggregated data may be retained for service improvement.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of significant changes via email. Continued use of NeuroKids after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related questions or concerns, contact Linked2Link Ltd at neurokidsspace@gmail.com or through the Contact form on our About page.

12. School Deployment & MDM

When NeuroKids is deployed by a UK school, the school is the Data Controller and Linked2Link is the Data Processor under UK GDPR Article 28. We support managed deployment via Apple Configurator, Jamf, Mosyle, Microsoft Intune, and Google Workspace for Education. A DPIA template, Information Sharing Agreement, sub-processors list, and MDM configuration profiles are available at /for-schools. Pupil data shared by schools is limited to first name, age, and SEN focus area — no surnames, addresses, photos, or biometric data. Pupil records are deleted within 30 days of removal from the school roster, with 7-year aggregate retention per DfE guidance. Breach notification SLA to the school DPO: 24 hours (we tighten the ICO’s 72-hour deadline to ourselves).

© 2026 Linked2Link Ltd. All rights reserved.