Skip to content
PebbleYard
Why usHow it worksFeaturesPricingBlogAboutFree Tools
For SchoolsLog inStart free trial
Why usHow it worksFeaturesPricingBlogAboutFree ToolsFor SchoolsLog inStart free trial
Legal

Privacy policy

Last updated 14 August 2026

PebbleYard is a learning app for children aged five to eleven, bought and run by the adult responsible for them. This policy explains exactly what we hold, why we hold it, who else can see it, and how to get rid of it. It is written to be read rather than skimmed past, because the people it concerns most cannot read it themselves.

On this page

  1. 1.The short version
  2. 2.Who we are
  3. 3.What we collect
  4. 4.Children's data
  5. 5.Google sign-in and Google user data
  6. 6.How we use what we collect
  7. 7.We do not sell your information
  8. 8.Our legal grounds (UK and EU users)
  9. 9.Who else processes your data
  10. 10.Security and encryption
  11. 11.How long we keep things
  12. 12.Where your data is held
  13. 13.Your rights, and how to use them
  14. 14.Schools, kindergartens and childcare centres
  15. 15.Cookies and local storage
  16. 16.If something goes wrong
  17. 17.Changes to this policy
  18. 18.Contact us

1.The short version

This summary is not a substitute for the sections below, but nothing below contradicts it.

  • We do not sell personal information. Not ever, to anyone, for any price. That covers parents, children, teachers, schools, classrooms, childcare centres and everyone in a contact form.
  • We do not rent, trade, broker or share personal information for advertising. There are no ad networks, no data brokers, no marketing pixels and no behavioural profiles in this product.
  • There is no advertising in PebbleYard, and nothing a child reads, answers or scores is ever measured. We count visits to the public marketing pages with Google Analytics, and only if you accept it when asked. The Analytics script is present on every page for technical reasons explained in section 15, but it is switched on for the public pages alone and never for the app your children use.
  • A child account holds no email address, no password, no billing details and no personal information beyond a display name an adult chose. It is created by an adult, it sits under their account, and it shows the child their own topics and scores and nothing else.
  • Everything is encrypted: in transit with TLS, and at rest on the servers that store it.
  • We do not use anyone's data to train AI models, and we do not give it to anyone else for that purpose.
  • You can delete everything yourself, from Settings, in one action, including your login.

2.Who we are

PebbleYard operates the website at pebbleyard.com and the learning app reached through it. In the language of the Australian Privacy Principles we are the entity that holds your personal information; in the language of the GDPR we are the data controller for parent accounts and for the child accounts created under them.

Privacy questions, access requests and deletion requests: privacy@pebbleyard.com. Anything else: hello@pebbleyard.com. A human reads both.

Where a school, kindergarten or childcare centre enrols children on PebbleYard, that institution decides what is collected about its pupils and we act on its instructions. In that arrangement the institution is the controller and we are the processor. Section 14 covers what that changes.

3.What we collect

The complete list. If a category is not here, we do not hold it.

Your account

  • Email address. Needed to sign you in, to send the password reset you asked for, and to tell you when a free trial is about to end.
  • Password, if you sign up with one. Stored only as a salted hash by our authentication provider. Nobody at PebbleYard can read it, and we cannot tell you what it is.
  • Display name, if you choose to set one. Optional, and only ever shown back to you.
  • Account timestamps: when you signed up, when your trial ends, whether the trial reminder has been sent.

Child accounts

  • A display name you type in. It can be a first name, a nickname or anything else; nothing checks and nothing requires it to be real. This is the only identifying detail a child account holds.
  • A public alias, only if you switch a child's results on for the leaderboard. This is separate from the display name precisely so a child's name never has to appear on a shared board.
  • Settings you choose for them: timer mode, time limit, whether the timer is locked, and how they progress through a topic.
  • A picture they are shown by, if you pick one. It is chosen from a fixed set of drawings we ship - a rocket, a cat, a star - and there is no way to upload anything.
  • A PIN, if you give them their own login. Stored only as a salted hash, exactly as an adult password is. Nobody at PebbleYard can read it and we cannot tell you what it is: the one moment it is ever displayed is the card you print when you set it.
  • A record of each device they are signed in on, if you give them their own login: when the session started, when it was last used, the browser and operating system it reports, and a one-way scrambled form of the network address. This exists so you can see what is signed in and sign it out. The address itself is never stored.

We do not ask for, and there is no field anywhere to store, a child's date of birth, school, year level, address, photograph, voice, contact details or any government identifier.

Learning activity

  • Which topic and section a child worked on, and when.
  • How many questions were answered, how many were right, how long it took, and whether the run was timed.
  • The answers given on a run, so that the review screen can show what happened and why an answer was marked the way it was.
  • Which lesson pages have been read, so progress can be shown.

Topics you ask us to write

  • What you typed when you asked for a topic, and the age band you chose. Kept so you can see what a topic was asked to be, and so we can improve what comes back.
  • The topic itself: the lesson pages, questions, answers and spelling words, whether we wrote them or you did.
  • A record of the safety check on every request, meaning the decision, the reason for our own records, and the wording you typed, capped at 500 characters. This is written whether the request was allowed or declined, because a record of refusals alone has nothing to compare against. Section 6 of the Terms explains what is checked and why.
  • How many topics you have generated this month, so your plan's allowance can be counted.

Writing a topic means sending what you typed, the age band you chose, and the text produced from it to a third-party AI provider. We never send a child's name, results, progress or answers to any AI provider, and nothing a child does is used to generate anything.

Which provider receives it depends on your plan. On most plans it is the AI provider PebbleYard has contracted with, named in section 9. On plans that require you to supply your own AI provider key, your topic request goes to your account with your provider instead, under whatever agreement you hold with them; we pass it through and never see more of it than we already hold. Which provider we use is a configuration choice rather than something fixed in the product, so it can change as the technology does. We will update section 9 and the date at the top of this policy whenever it does.

The safety checks are the one exception, and always run on our own provider account rather than yours. That is deliberate: a check that decides whether something is fit for a child to read must not depend on a key a customer can change, remove or let expire.

Where we are the AI provider's customer, our agreement with them does not permit your content to be used to train their models, and we do not use it to train any model of our own. Where you supply your own key, what your provider may do with content sent under your key is governed by your agreement with them rather than by ours, so read their terms if that matters to you.

Safety-check records are readable only by PebbleYard staff with administrator access. They are not visible inside your account, are not shared with anyone else, and are not used to advertise to you or to change what you are charged.

Billing

  • A Stripe customer reference, subscription status, plan, billing interval and renewal date. That is the whole of it.
  • We never see, receive or store card numbers. Payment details are entered on Stripe's own checkout page and stay with Stripe. Nothing in our database can hold a card number, because there is no column for one.

Technical

  • Standard server logs kept by our hosting provider: IP address, timestamp, and which request was made. These are operational records used to keep the service running and to investigate abuse; they are not built into profiles and are not used for marketing.
  • A bot-protection check on the sign-in page, described in section 15.
  • Visits to our public pages, measured with Google Analytics: which page was viewed, the site or search that sent you, roughly where in the world you are, and the type of browser and device. This is switched on for the marketing pages only: the home page, features, pricing, blog, contact and these legal pages. No dashboard, lesson, quiz, leaderboard or admin screen is ever measured, so no child's activity reaches it. It is never joined to your account, and it never sees a name, an email address or a child. Section 15 explains what you are asked, what happens before you answer, and how to refuse.

When you contact us

If you use a contact form or email us, we keep what you sent so we can reply: your name, email, and for a school enquiry the institution name, your role, phone number if you gave one, and the approximate number of children. Enquiry details are used to answer the enquiry. They are not sold, and they are not passed to anyone else.

4.Children's data

This is the section that matters most, so it is the most specific one.

Each child gets an account of their own in PebbleYard, which the app calls a child profile. It is genuinely theirs: their topics, their lessons, their scores, their progress. What it is not is a second copy of the adult's account.

A child account holds no email address, no password of the child's own, no billing or payment information, no subscription or account settings, no photograph and no contact details. A child in their own space can read a lesson, answer questions and see how they are doing. That is the whole of it.

Who creates one, and how a child gets in

Only an adult can create a child account, from inside their own signed-in account: a parent, a carer, or a staff member at an enrolling institution. That adult types the display name and chooses the settings. There are two ways in, and the adult decides which. A child can work on the adult's own signed-in device, opened from the adult's dashboard, which is how it works if nothing further is set up. Or the adult can switch on the kids' login, described next.

Either way, a child only ever sees their own space. Billing, payment details, subscription settings, the adult's account settings and other children's results are not reachable from it.

The kids' login

The kids' login is off until an adult switches it on. When they do, the family gets one web address of its own and each child gets a PIN of four to six digits that the adult chooses. The child opens the address, taps their name, types their PIN, and lands on their own topics.

A child signing in this way still has no account with us in the ordinary sense. There is no email address, no password of their own, no membership of the account, and nothing they can change. They cannot rename themselves, cannot alter their own settings, cannot reach a sibling's results, and cannot reach anything to do with money.

The PIN is held only as a salted hash, the same way an adult's password is, so it cannot be read back out of our database by us or by anyone else. It is displayed exactly once, on the card the adult prints when they set it. Five wrong tries in a row locks that one child out for fifteen minutes; it does not lock their brother or sister out.

Signing in leaves a session on that device, which is what stops a child being asked for their PIN every single time. It is a random value in a browser cookie, held for thirty days, and our copy of it is scrambled so that the value in the cookie cannot be worked out from our records. The cookie is not an advertising or tracking cookie, it is not shared with anyone, and it does nothing on any other website.

The adult can see and end any of it, at any time. The kids' login page lists every device currently signed in - the browser it reports and when it was last used - with a button to sign out one device or all of them at once. Changing the family address, turning a child off, resetting a PIN or switching the whole thing off signs every affected device out immediately. So does a subscription lapsing. Nothing the child has done is deleted by any of that.

Alongside each device we keep a one-way scrambled form of the network address it connected from, so that two tablets in one house can be told apart in that list. The address itself is never written down, and the scrambled form cannot be turned back into one. We use it for one further thing: telling the adult, by their usual notifications, the first time a child signs in from a device the family has not used before. That message can be switched off in Settings.

The family's address is a private link. It is never listed anywhere, search engines are told not to index it, and it is not advertised or shared. It is a guessable address rather than a secret, though, so it is worth being plain about what sits behind it: a page listing the children's display names, and nothing else. No scores, no progress, no ages and no topics appear before a PIN is entered. The PIN is the credential; the link is only an address, and no link, printed card, shortcut file or QR code we produce ever contains a PIN.

A child account is visible to the adult who created it and to nobody else, unless that adult deliberately turns on leaderboard sharing.

What is not in the product at all

There is no messaging, no chat, no comments, no friend list, no profile photograph and no way for a child to be contacted through PebbleYard, by us or by another user. Children cannot see each other except as an alias on a leaderboard an adult has switched on.

Leaderboards are off until an adult turns them on

Every child account starts private. A result appears on a shared leaderboard only when an adult sets that child to public, and when they do, the board shows the public alias rather than the display name. The setting is reversible at any time, and switching it off removes those results from the board.

Verifiable parental consent

Under the US Children's Online Privacy Protection Act, and the equivalent expectations elsewhere, the operator of a child-directed service must have a parent's consent before collecting personal information from a child under 13. Our design answers that at the root. A child account can only be brought into existence from inside an adult account that already exists and whose holder has accepted this policy. Every identifying detail in it, which is to say the display name and nothing else, was typed by that adult. A child using the app is never asked to register, never asked for an email address, and has no profile of their own to fill in.

What we never do with a child's data

  • We never sell it, rent it, licence it or disclose it to a data broker.
  • We never use it to target advertising, and no advertising is shown in this product at any time.
  • We never build behavioural or psychographic profiles from it.
  • We never use it to train machine-learning or AI models, and we never supply it to a third party who would.
  • We never make it public, other than an opt-in alias on a leaderboard.

5.Google sign-in and Google user data

Signing in with Google is optional. Email and password works identically, and nothing in the product requires a Google account.

If you choose it, Google asks you to approve the request and then returns a limited set of information to us through our authentication provider. What we receive is:

  • Your email address, which becomes the identifier for your PebbleYard account.
  • Basic profile information, meaning your name and profile picture URL as Google supplies them, used to fill in your display name so you do not have to type it.
  • A stable Google account identifier, so that signing in again returns you to the same PebbleYard account rather than creating a second one.

We request only these basic sign-in scopes. We do not request, receive or hold access to your Gmail, Google Drive, Contacts, Calendar, Photos or any other Google service, and PebbleYard has no feature that would read or write any of them.

PebbleYard's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, information obtained through Google sign-in is used only to create and authenticate your account and to provide the features you can see in the product. It is not sold, not transferred to others except as required to run the service or by law, not used for advertising of any kind, and not used to train generalised AI or machine-learning models. Humans do not read it, except with your explicit permission for a support issue you have raised, where it is needed for security, or where the law requires it.

You can disconnect PebbleYard from your Google account at any time at myaccount.google.com/permissions. Doing so stops future Google sign-ins; it does not by itself delete your PebbleYard account, which you can do from Settings as described in section 13.

Facebook sign-in

Signing in with Facebook works the same way and is equally optional. We receive an email address and basic profile information for the sole purpose of authenticating you, we request no other permission, and we cannot see your posts, your friends or anything else on your Facebook account. Everything said above about how we use, refuse to sell and refuse to advertise against sign-in data applies identically. You can remove PebbleYard from your Facebook account under Settings, Apps and Websites.

6.How we use what we collect

Every use is one of these. There is no other purpose.

  • To run the product: sign you in, keep you signed in, show a child their topics, mark their answers, and show you their progress.
  • To keep score honestly. Answers are marked on the server so a score reflects what actually happened.
  • To handle billing: start a trial, take a subscription payment through Stripe, and show you what you are paying for.
  • To send the few emails the service requires: address confirmation, password reset, a notice two days before a free trial ends, and receipts. These are transactional. You can unsubscribe from the optional monthly newsletter at any time; that link does not affect the transactional ones, which stop when you close your account.
  • To write the topics you ask for, and to check both the request and the result before a child can see either. This is why safety-check records exist: to keep the checks working, and so that an account repeatedly asking for content we will not write for a child is something we know about.
  • To keep the service secure and available: investigate abuse, block automated sign-up attempts, diagnose faults.
  • To see how our public pages are doing: how many people read a blog post, which page they arrived from, where the pricing page loses them. This is the marketing site only, it is counted in aggregate, and it stops at the sign-in door.
  • To answer you when you get in touch.
  • To meet legal, tax and accounting obligations.

We also look at aggregate, de-identified counts, such as how many runs were completed on a topic, to decide what to build next. Those figures do not identify anyone and cannot be traced back to a person or a child.

7.We do not sell your information

PebbleYard does not sell personal information, and never has. We do not sell, rent, trade, licence or otherwise disclose for value the personal information of parents, carers, children, teachers, school staff, schools, kindergartens, childcare centres, classrooms, or anyone who fills in a form on our site.

To leave no room for interpretation, all of the following are things we do not do:

  • Selling or sharing personal information for money or any other consideration.
  • Sharing personal information for cross-context behavioural advertising, as that term is used in US state privacy laws. We have never done this and there is nothing in the product that could.
  • Passing data to advertising networks, ad exchanges, retargeting services or marketing platforms.
  • Passing data to data brokers, list vendors, credit reference agencies or people-search services.
  • Selling or licensing school, classroom or institutional contact lists.
  • Allowing a third party to use anyone's data for their own purposes, including AI training.
  • Running advertising of any kind inside the product.

The only companies that touch your data are the service providers in section 9, each of which processes it strictly on our instructions in order to make the product work, and none of which is permitted to use it for their own purposes.

If PebbleYard were ever acquired or merged, personal information could transfer to the acquiring entity as part of that transaction. That is a change of custodian, not a sale of data to a third party: we would notify you by email in advance, the commitments in this policy would continue to apply to the transferred data, and you would be able to delete your account before any transfer takes effect.

8.Our legal grounds (UK and EU users)

Where the UK GDPR or EU GDPR applies to you, we rely on the following lawful bases:

What we doLawful basis
Run your account and provide the app to you and your childrenPerformance of a contract (Article 6(1)(b))
Take payment and administer subscriptionsPerformance of a contract (Article 6(1)(b))
Send service emails such as password resets and trial remindersPerformance of a contract (Article 6(1)(b))
Write a topic you asked forPerformance of a contract (Article 6(1)(b))
Check a topic request and its result, and keep a record of that checkLegitimate interests (Article 6(1)(f)): keeping content written for children safe for them to read, and identifying misuse of a service used by children
Keep the service secure, prevent abuse and diagnose faultsLegitimate interests (Article 6(1)(f)): running a safe service
Publish a child's result on a leaderboard under an aliasConsent (Article 6(1)(a)), given by the adult and withdrawable at any time
Send the optional monthly newsletterConsent (Article 6(1)(a)), withdrawable at any time
Store an analytics cookie and count your visit to a public pageConsent (Article 6(1)(a)), given in the banner on your first visit and withdrawable at any time from the footer
Load the analytics script before you have answered, so that it can be verified as installedLegitimate interests (Article 6(1)(f)): operating a site whose measurement tooling can be checked. It writes nothing to your device in this state
Keep financial recordsLegal obligation (Article 6(1)(c))

9.Who else processes your data

This is the complete list of third parties that handle personal information on our behalf. Each is bound by contract to process it only on our instructions, and none may use it for their own purposes.

ProviderWhat it doesWhat it can see
SupabaseDatabase, authentication and file storage: the service itselfAccount emails, child display names, activity results, subscription status
StripePayments and subscription billingYour email, payment details you enter on Stripe's own page, billing history. Card numbers go to Stripe, never to us
GoogleOptional Google sign-in, and Google Analytics on the public marketing pagesFor sign-in: that you signed in, and the basic profile described in section 5. For the Analytics script file itself: your browser's IP address at the moment the file is requested. For Analytics measurement, which happens on the public pages only: which page was visited, what sent you there, your approximate location and your device type. Never your account, your children or anything they do. Our typeface is served from our own domain, so no font request reaches Google at all
Our AI providerWrites a topic you asked for, and runs the safety checks on the request and on what comes back. Which provider we use is a configuration choice we may change; this row is updated when it does, and we will confirm the current one in writing for a procurement reviewThe wording you typed when asking for a topic, the age band you chose, and the lesson and question text produced from it. Never a child's name, results, progress or activity. Processed on our instructions only, and not permitted to be used to train their models
Meta (Facebook)Optional Facebook sign-inThat you signed in, plus the email address and basic profile described in section 5. Only if you choose that button
CloudflareTurnstile bot check on the sign-in pageTechnical signals from the browser used to tell a person from a script. It is a privacy-preserving check that does not track you across sites
ResendSends transactional email such as the trial reminderThe recipient email address and the contents of that message
VercelHosts and serves the site and the appThe technical request log every web host keeps: your IP address, the page requested, and your browser type

Beyond these, we disclose personal information only where the law requires it, meaning a valid court order, warrant or lawful request from a regulator, or where disclosure is necessary to protect the safety of a child or another person. We are not obliged to volunteer anything, and we do not.

The only analytics anywhere near this product is Google Analytics on the public marketing pages, and it stops at the sign-in door. There is no analytics, no session recording and no heatmap on any page of the app: not the dashboard, not a lesson, not a quiz, not a leaderboard, not the admin screens. There are no advertising pixels, no retargeting tags and no data brokers anywhere at all, on the marketing site or in the app. Nothing a child does is measured by a third party.

10.Security and encryption

  • Encrypted in transit. Every connection to PebbleYard, and every connection between PebbleYard and the providers above, uses TLS. There is no unencrypted route into or out of the service.
  • Encrypted at rest. Databases, file storage and backups are encrypted on disk by the infrastructure that holds them.
  • Passwords are never stored. Only a salted hash is kept, by our authentication provider. It cannot be reversed, and nobody at PebbleYard can read your password.
  • Card numbers never reach us. Payment details are entered directly on Stripe's PCI-DSS certified checkout.
  • Row-level security in the database. Access rules are enforced by the database itself on every single query, rather than by application code that could be bypassed. A parent's queries can only ever return that parent's own rows and the child accounts beneath them. This is a property of the data layer, not a check we remembered to write.
  • Privileged keys stay on the server. Operations that need elevated access, such as deleting an account, run in isolated server-side functions. No key capable of reading across accounts is ever sent to a browser.
  • Answers are graded server-side, so scores cannot be forged by editing what the browser sends.
  • Bot protection on sign-in, to keep automated sign-up attempts away from the account system.
  • Least access internally. Very few people can reach production data, only for support and operations, and never as a matter of routine.

No system is perfectly secure and we will not pretend otherwise. What we can say is that the boundary is enforced at the database rather than assumed at the edges, which is the difference that matters when something does go wrong.

11.How long we keep things

DataKept for
Parent and child accountsAs long as your account is open. Deleted when you delete the account
Activity results and progressAs long as the child account exists. Deleting a child account deletes its results
Billing and subscription recordsAs long as your account is open, then as long as tax and accounting law requires us to keep financial records
Topics you made, and what you asked forAs long as your account is open. Deleted when you delete the topic or the account
Safety-check records for topic requestsAs long as your account is open, so that a pattern is visible over time rather than only within a month. Deleted when you delete your account
Contact form and email enquiriesUp to 24 months after we have finished helping you, then deleted
Server and security logsA short operational window, typically no more than 90 days
Marketing-site visit statisticsHeld by Google for the retention window set on our Analytics property, no more than 14 months. These are counts of visits to public pages, tied to no account and to no child
BackupsDeleted data disappears from live systems immediately and cycles out of encrypted backups within 30 days

If your account has been closed and no legal obligation requires us to keep something, we delete it rather than keeping it in case it turns out to be useful.

12.Where your data is held

Our database and file storage sit in a single hosting region with Supabase. Some of the providers in section 9, Stripe, Google, Cloudflare, Resend and our AI provider among them, operate globally, so the specific data each one handles may be processed outside your country, including in the United States. Where you supply your own AI provider key, that provider's location is determined by the account you hold with them rather than by us.

Where personal information leaves Australia, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, as APP 8 requires. For transfers out of the UK or EEA, we rely on the UK and EU Standard Contractual Clauses or an applicable adequacy decision. Write to us at the privacy address if you would like details of the safeguards in place for a particular provider.

13.Your rights, and how to use them

Delete everything, yourself, right now

Settings → Delete account removes your login, your own details, every child account beneath it, and every result those children recorded. Any active subscription is cancelled as part of the same action. It is immediate and it is not reversible: there is no soft-delete, no 30-day grace period and no shadow copy. Deleting a single child account, without closing your account, deletes that child's results too.

Everything else

  • Access: ask for a copy of what we hold about you and your children.
  • Correction: most fields are editable in the app; ask us for anything that is not.
  • Portability: ask for your data in a machine-readable format.
  • Withdraw consent: turn a leaderboard off, or unsubscribe from the newsletter, at any time.
  • Object or restrict: where the UK or EU GDPR applies, object to processing based on legitimate interests, or ask us to restrict it.
  • Non-discrimination: where US state privacy laws apply, exercising a right never changes the price you pay or the service you receive. It could not, since we have nothing to lose by honouring it.

Email privacy@pebbleyard.com and we will respond within 30 days, usually much sooner. We may need to confirm you are the account holder before acting on a request, which protects the very data you are asking about. There is no charge.

If we get it wrong

Tell us first and we will try to fix it. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au; if you are in the UK, to the Information Commissioner's Office at ico.org.uk; and if you are in the EEA, to your national data protection authority.

14.Schools, kindergartens and childcare centres

When an institution uses PebbleYard with children in its care, that institution decides what pupil information is entered and we process it on their instructions. We do not use pupil data for our own purposes beyond providing and securing the service.

We do not sell school, classroom, staff or pupil data, and we do not market to pupils. A demo enquiry does not put an institution on a list that is sold to anyone.

  • Institutions choose the display names entered for pupils. A first name, an initial or a code all work; the product does not require a real name.
  • Leaderboards are off by default and are enabled per child, so an institution decides whether any pupil result is visible beyond staff.
  • Pupil data is returned or deleted on request when an institution stops using PebbleYard.
  • A data processing agreement, and answers to a procurement or safeguarding questionnaire, are available on request. Write to us at the privacy address.

15.Cookies and local storage

PebbleYard uses only what it needs to work:

  • A sign-in token, kept in your browser so you are not asked to log in on every page. Clearing site data or signing out removes it.
  • Cloudflare Turnstile, on the sign-in page only, to distinguish a person from a script. It does not track you across other websites.
  • A small amount of local storage used to carry over anything you set up in the browser before you had an account. It never leaves your device except to be imported into your own account.
  • Google Analytics cookies, named _ga and _ga_id, on the public marketing pages, and only if you accept them. They let us tell one visit from another and a returning reader from a new one. They hold a random identifier and nothing else: no name, no email address, no child, nothing that identifies you as a person.

You are asked first, and you can change your mind

The first three items above are what the site needs in order to work at all, so they are not optional. Analytics is, and we ask before switching it on. No analytics cookie is set until you accept. Declining is one click in the same banner, the same size as accepting, and it is remembered.

One detail we would rather state than bury. The Analytics script file is loaded by your browser on every page, before you have answered anything, because Google's own verification tools have to be able to find it in the page and they cannot answer a consent banner. Loading a file is not measuring you. Until you accept, it is started in Google's "denied" mode, which cannot write a cookie; and if you decline, we switch it off entirely, so it sends nothing at all afterwards. The one thing it does regardless is what any file fetched from another company does: Google sees your IP address at the moment the file is requested. That is now the only such request on the site. Our typeface is served from our own domain rather than fetched from Google, so it is no longer one of them.

Changed your mind? Cookie choices, in the footer of any public page, asks again. Withdrawing stops the measurement immediately in that tab and deletes the analytics cookies already set.

Your answer is stored on the device you gave it on, not against your account, because the question is about this browser and most people who see it do not have an account. Answering on your laptop therefore does not answer for a shared classroom computer.

The app your children use never asks, because it never measures. Analytics is never switched on for a signed-in page whatever you choose here. No page a child sees sends anything to Google, and a child's session cannot carry an analytics cookie even on a device where an adult accepted one.

There are no advertising cookies and no cross-site tracking cookies anywhere: not on the marketing site, not in the app. Nothing here follows you onto other websites, and nothing here builds a profile of you. Browser cookie controls and tracker-blocking extensions work normally on top of all this, and every page keeps working exactly as before.

16.If something goes wrong

In the event of a data breach likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and any other regulator with jurisdiction, including notification within 72 hours where the UK or EU GDPR applies. Our notification will tell you what happened, what was affected and what to do about it, rather than reassure you in general terms.

17.Changes to this policy

We update this policy when the product changes. The date at the top always reflects the current version. For any change that materially reduces protection for you or your children, we will email account holders before it takes effect, so that closing your account remains a real option.

One commitment is not subject to change by amendment: we will not begin selling personal information. If that ever became the intention, existing users would be notified directly and given the opportunity to delete their data first.

18.Contact us

Privacy, access requests, deletion requests, school data agreements: privacy@pebbleyard.com

Everything else: hello@pebbleyard.com

If a question about your child's data is urgent, say so in the subject line and we will treat it that way.

See also our Read the terms of service.

PebbleYard

A reading-first learning app for ages 5 to 11, where you build the topics.

  • Private by default: aliases, opt-in boards
  • Child-safety statement and safeguarding policy
  • No ads, ever

Product

  • Book Week 2026
  • Why PebbleYard
  • How it works
  • Features
  • Topics
  • Pricing
  • Changelog
  • Roadmap

For schools

  • For schools & centres
  • Try the demo
  • Pricing enquiry
  • Data processing

Company

  • About
  • Blog
  • Brand sheet
  • Contact

Support

  • Help centre
  • Resources for families
  • Contact support
  • Feature requests
  • Status

Legal

  • Privacy policy
  • Terms
  • Child data & safeguarding
  • Cookie choices

PebbleYard acknowledges Aboriginal and Torres Strait Islander peoples as the Traditional Custodians of the lands on which we work, learn and build. We recognise their continuing connection to Country, culture and community, and pay our respects to Elders past, present and those emerging as tomorrow's leaders.

© 2026 PebbleYard. All rights reserved.

We also madeKidSafeTube.aiKindyHero
Built by Apptimistic