MekkitEnglishTürkçe

Privacy Policy

Mekkit is a studio where children aged 6–14 build games and apps with blocks. An account is always created by a parent (18+). This policy explains what data we process and why. Last updated: 2026-09-22.

Who is responsible

Mekkit is operated by AED Mobil — email: [email protected]. Write to this address for any privacy question, request or complaint.

What we collect

  • Parent account: email address, a one-way hash of your password (bcrypt) or your Apple/Google sign-in identifier, birth year (to confirm you are 18+), language, country, time zone, and a record of the consents you gave (type, version, date, hashed IP address).
  • Child profile: only a nickname, a chosen avatar, birth year (for age band and mode) and language. We do NOT collect a child's email, phone number, photo, location or real name. There is no camera/photo feature.
  • Your child's work: projects (blocks, texts, drawings, sounds), lesson progress, stars, XP, streak, badges, avatar items and in-app time (a daily total in seconds).
  • AI requests: the idea your child types, a question to Bip, a drawing request and selected blocks are processed only to run that feature. Chat histories are not stored on our servers; usage is recorded only as counts and cost.
  • Voice input (if you allow it): audio is sent only to be transcribed and the audio is not kept. Sounds your child records into a project (with your approval) stay inside that project.
  • Safety records: when an input is blocked we keep only the decision, category, date and an excerpt of at most 60 characters with personal details masked — never the raw text.
  • Technical and usage: app version, platform, device type and our own first-party analytics events such as screen names (no personal information), app error reports (sent to our own server), and subscription status (via the app stores; we never see card details).

How we use it

  • To provide the service: account, child profiles, lessons, the studio, publishing, parent approvals and controls.
  • To keep children safe: personal-information scanning, profanity and safety filtering, gallery moderation, notifying you about repeated unsafe input.
  • To keep you informed: email verification, password reset, approval notifications and the optional weekly progress report.
  • To improve the product: non-personal, aggregated usage statistics (for example, which lesson children find hard).
  • Ad measurement (parents only): see the section below.

AI providers

We use Anthropic for text features (building plans, Bip the tutor, the bug detective, explain-to-unlock, the content generator, the safety classifier and sound-effect/music parameters) and OpenAI for image generation, content moderation and voice transcription. They process data on our behalf as service providers.

Providers receive only the text needed for that request (for example the idea, a project summary or a question) — never the parent's email, the child's nickname or account identifiers. Under our agreements this data is not used to train their models.

The AI is never an open-ended chat companion: it only guides the child on their project, answers are short and age-appropriate, and generated images are moderated too.

Published apps and sharing

  • Private link (default): only people with the link can open it, and it is hidden from search engines; a personal-information scan runs before publishing.
  • Family and class: visible to your family, or to a class your child joined with your approval.
  • Public gallery: only after your approval and then a moderator review. The gallery shows only the nickname, avatar and the app.
  • There is no chat, private messaging, commenting or following between children; the only interaction is four preset emoji reactions. Published apps have no network access and cannot collect data from their users; saves stay on that device.

Who we share data with

We do not sell data. There are no ads and no ad SDKs in the app, and no advertising identifier (IDFA/AAID) is collected in a child session.

  • Anthropic and OpenAI (as described above).
  • Email delivery: Resend (the parent's email address and the email content only).
  • Subscriptions: Apple App Store, Google Play and RevenueCat (subscription status; a random identifier for the parent account).
  • Hosting and network: our servers and Cloudflare.
  • Ad measurement: Meta and TikTok — only parent events (sign-up, trial start, subscription), sent server-side with a one-way SHA-256 hash of the parent's email. No data about children is ever sent.
  • Legal obligations: only when there is a valid legal request.

Ad measurement and our website

Our marketing page (aimed at adult parents) may use the Meta and TikTok pixels. They never run inside the app, the studio or children's published apps (/app, /studio, /p).

On the App Store, the tracking permission prompt (ATT) is shown only during parent onboarding. Nothing is measured while a child profile is open.

How long we keep data

  • Account, child profiles, projects and published apps: for as long as your account is open.
  • When you delete the account, child profiles, projects, asset links and published apps are deleted immediately and published links stop working.
  • Analytics events are deleted after 180 days, safety records (with masked excerpts) after 1 year, and email delivery records after 90 days.
  • Subscription events needed for accounting are kept in de-identified form for the legally required period after deletion.

Your rights

As a parent you can access, correct, export and delete your own and your child's data, and withdraw consent (COPPA, GDPR, GDPR-K and Turkey's KVKK). In the parent area of the app: Download data (a JSON archive of everything), Delete child, Delete account. You can also email us; we reply within 30 days.

If you live in the EU/EEA or Turkey you may also complain to your local data protection authority.

Security

All connections use TLS. Passwords and the parent PIN are stored as one-way hashes, and the PIN locks after repeated wrong attempts. Session tokens are short-lived; the parent area opens with a separate 15-minute token. API keys never reach the device.

Children

How we handle children's information is described in detail in our Children's Privacy Notice (/legal/kids-privacy).

Changes

For material changes we will notify parents in the app and by email, and ask for consent again where required. Version: 2026-09-22.