Skip to content

Nalevi Privacy Policy

Last updated: March 8, 2026

This policy explains what information Nalevi collects, why we collect it, how we use it, and the choices you have. It covers the Nalevi website, waitlist, and product — including parent and child-facing features.

We have written this policy in plain English on purpose. If anything is unclear, email hello@nalevi.com and we will clarify.

The short version

We collect only what we need to run Nalevi. Children's data gets extra care. We do not sell your information, we do not run ads, and we do not use your family's conversations to train AI models. Your data is stored in the European Union.

What we collect

Account information

When a parent creates an account, we collect an email address, a password (which we store hashed — we never see or store the original), a name, a timezone, and an avatar selection. We also store a hashed parent PIN used to protect access to child profiles.

Child profile information

For each child profile, we collect a first name or nickname, an avatar choice, a birth year, and the settings the parent configures: daily time limits, content controls (which sensitive topics are allowed or blocked), and topic preferences. We also store a short personalization memory that helps Nalevi remember the child's interests and adapt its conversation style.

Conversation data

We store the messages exchanged between the child and Nalevi, along with conversation titles, AI-generated summaries, engagement signals, struggling-topic markers, and content flags. This is what allows the product to work and lets parents review their child's activity.

Usage data

We track daily message counts and time spent in the app so that time limits work and parents can see usage patterns.

Waitlist information

If you join the waitlist, we collect your email address and anything you include in the optional message field.

Billing information

Polar handles checkout, billing management, invoices, customer portal access, and payment processing for subscriptions. Nalevi stores billing-related metadata needed to run the product, including Polar customer and subscription IDs, billing status, trial or promo state, and the household plan tier.

Nalevi does not store raw payment card details. Payment card information is handled by Polar in hosted flows.

Technical data

We collect basic server logs, device and browser information from standard HTTP headers, and IP addresses used for rate limiting. We keep server logs for up to 90 days. We use a single session cookie to keep you signed in — more on that below.

How we use your information

We use the information we collect to:

  • Run the service — authentication, rendering the app, enforcing time limits, applying content controls.
  • Power AI conversations — sending messages to language models, generating age-appropriate educational responses.
  • Keep kids safe — detecting adversarial prompts, flagging concerning behavior for parent review, generating conversation summaries.
  • Personalize the experience — remembering interests, adjusting vocabulary and tone by age.
  • Communicate with you — waitlist notifications and support.
  • Manage subscriptions — syncing checkout, trial, invoicing, and billing access state.
  • Protect the service — rate limiting, abuse prevention, server monitoring.

What we do not do

  • We do not serve ads.
  • We do not sell your data to anyone.
  • We do not use your family's data to train AI models.
  • We do not profile children for marketing purposes.
  • We do not use analytics or tracking tools.

How AI processing works

Nalevi uses third-party AI model providers to generate responses in conversations. When your child chats with Nalevi, the conversation messages, the child's approximate age, and personalization context are sent to those providers so they can generate a response.

These providers process the data to return an answer — they do not retain it to train their models. We do not train our own models on your family's conversations either.

Who sees your data

We share information only when needed to run the service. Here is who has access and why.

  • AI model providers. Conversation messages and context are processed by third-party AI providers through a routing service to generate responses. This data may be processed outside the EU, with appropriate safeguards in place.
  • Email provider. We use a cloud email service to send notifications. Only your email address is shared for this purpose.
  • Polar. Polar processes hosted checkout, billing management, invoices, customer portal sessions, payment collection, and billing-related emails.
  • Educational content APIs. When Nalevi looks up reference material (from sources like Wikipedia), only text search queries are sent — no personal data.
  • Hosting provider. All Nalevi data is stored on infrastructure in the EU-West region (Ireland/Netherlands).

We do not share your data with advertisers, data brokers, or anyone not listed here.

Cookies

Nalevi uses one cookie: a session cookie that keeps you signed in. It is strictly necessary for the service to work. We do not use analytics cookies, advertising cookies, or any third-party tracking.

Billing flows may also use Polar-hosted pages and customer portal sessions. Those flows are subject to Polar's handling in addition to this policy.

Children's data

This is the section we care about most.

Nalevi is designed for children ages 8–16. A parent or guardian who is at least 18 years old must create the account and set up each child's profile. Children do not provide their own email address and do not create their own accounts.

When a parent creates a child profile and configures its settings, that act serves as parental consent for us to process the child's data as described in this policy.

Parents have full visibility. You can see every conversation, every summary, every flag, and all usage data for your children at any time. You can modify content settings, change time limits, and delete child profiles and their associated data whenever you choose.

We practice data minimization. We collect a birth year, not a full birthdate. A nickname, not a surname. We do not collect photos, location data, or contact lists from children.

If you believe a child provided us personal information outside of a parent-managed setup, please contact us at hello@nalevi.com and we will investigate promptly.

Where your data lives

Your data is stored on servers in the EU-West region (Ireland/Netherlands). When conversation messages are processed by AI providers, data may temporarily leave the EU. We rely on appropriate safeguards for those transfers.

How we protect your data

Passwords and parent PINs are cryptographically hashed — we never store them in plain text. All data is transmitted over HTTPS. Sessions use signed tokens with expiration. We enforce rate limiting and role-based access controls so parents only see their own family's data.

No system is perfectly secure, and we will not pretend otherwise. But we work to limit access, reduce risk, and protect your information in transit and at rest.

How long we keep your data

  • Active accounts. We keep your data for as long as your account is active.
  • Child profiles and conversations. Kept until you delete them or delete your account.
  • Waitlist entries. Kept until you are onboarded or ask to be removed.
  • Server logs. Kept for up to 90 days.
  • Account deletion. When you delete your account, all associated data — child profiles, conversations, messages, flags, usage data — is permanently removed.

Your rights

Under European data protection law, you have the right to:

  • Access — ask us what data we hold about you or your children.
  • Correction — ask us to fix inaccurate information.
  • Deletion — delete your account, child profiles, or conversations at any time. You can also ask us to delete specific data.
  • Portability — ask for a copy of your data in a standard format.
  • Restrict processing — ask us to limit how we use your data.
  • Object — object to processing based on our legitimate interests.
  • Withdraw consent — where processing is based on consent (like the waitlist), you can withdraw it at any time.
  • Complain — you have the right to lodge a complaint with Portugal's data protection authority (CNPD) or with the supervisory authority in your own country.

To exercise any of these rights, email hello@nalevi.com. We will respond within one month.

Parents exercise these rights on behalf of their children.

Changes to this policy

If we change this policy, we will update the date at the top and post the revised version here. If the change is significant, we will also notify registered users by email.

Contact

Questions, requests, or concerns about privacy can be sent to hello@nalevi.com.