> Translation notice: This English version is provided for convenience. The Turkish original is the binding text; in case of any discrepancy, the Turkish version prevails.
Policy on the Protection of Children's Personal Data
Draft start date: May 23, 2026 Last updated: July 13, 2026
> V1 draft — this is not proof of child-product safety. The physical device, persistent > parental consent, transcript retention/deletion, two-way moderation, PII redaction, and > the parent panel have not yet been verified end-to-end in a production environment.
1. Scope of the Policy
The Neeko physical device engages in direct voice interaction with children. This Policy explains the rules followed in processing children's personal data across the Neeko product family, the role of parents, child safety measures, and the international compliance framework.
The Policy has been prepared with reference to Law No. 6698 on the Protection of Personal Data ("KVKK", the Turkish Personal Data Protection Law), the United Nations Convention on the Rights of the Child, GDPR Article 8 (children's data), principles parallel to the US Children's Online Privacy Protection Act ("COPPA"), and the UK ICO Age Appropriate Design Code.
2. Design Principles — The Child's Interest Comes First
Neeko products are designed in adherence to the principle of the best interests of the child:
- Data minimization: Only data essential for device functionality and child safety is processed
- Privacy-first default settings: All safety filters are active by default
- Transparency: The parent panel can show where data goes and how long it is retained
- No advertising: Profiling-based advertising is never, under any circumstances, shown to the child
- No behavioral marketing: Children's usage data is not processed for marketing or sales purposes
- No manipulative design: No "dark pattern" elements that push the child toward more usage are used
- Educational priority: Content is prepared with age appropriateness and developmental benefit in mind
3. Roles — Parent and Child
3.1 Parent (Legal Representative)
The parent, acting as the legal representative with respect to the child's data:
- Purchases the device and opens the account
- Performs the device pairing process
- Personally enters the child's profile data (name, age, interests)
- Gives explicit consent approvals on behalf of the child (KVKK Art. 5/1; in the capacity of legal representative)
- Configures device behavior settings (content filters, time limits, blocked topics)
- Views weekly safety reports
- Approves or rejects memory cards
- Requests deletion of the child's data at any time
- May remove the device from the child's access
- When the account is closed, all of the child's data is deleted
3.2 Child
Data belonging to the child:
- Is not collected directly from the child (NeekoApp is not open to children)
- Is processed through the device (voice interaction)
- Is not processed without the parental consent chain
- Is not used for marketing or profiling purposes
As the child's capacity to understand develops (generally age 12+):
- The child has the right to be informed about their own data
- The child, together with the parent, may request deletion of their data
- The parent is encouraged to explain to the child which data is processed, in simple, age-appropriate language
4. What Children's Data Is Processed?
4.1 Profile Data Entered by the Parent
- The child's name (real name or nickname)
- Age
- Interests (e.g., animals, space, stories)
- Conversation style preference (e.g., energetic, calm)
- Blocked topics (topics specifically blocked by the parent)
4.2 Device Interaction Data
In the V1 target, when the child talks to the device, the following limits are designed; they do not count as implemented until the production model, backend, and device tests pass:
- Audio stream target: To process in real time via LiveKit and not persistently store raw audio on Neeko's side; the provider account will be separately verified
- Transcript plan candidate: A maximum of 90 days, followed by anonymous aggregation; to be finalized with legal, purpose, and deletion testing
- Device response plan candidate: The same or a shorter period than approved for transcripts
- Safety event count target: Counts only, instead of moderation, PII redaction, and blocked-topic content; the retention period is subject to legal/backend confirmation
- Memory card target: To store only when the parent explicitly approves
4.3 What Is Not Processed
- Visual data (photo/video): The device has no camera; no visual data is collected
- Location data: The device does not derive location; there is no GPS
- Biometric data: There is no face recognition or fingerprinting; voice recording analysis is directed solely at conversation content
- Advertising tracking identifiers (IDFA/AAID): Not used for the child
- Marketing profile of the child: Never created under any circumstances
5. Child Safety Targets (Awaiting Production Proof)
This section defines acceptance criteria; the items do not count as completed technical safeguards until the real model, backend, parent app, and device tests pass.
5.1 Content Moderation
In the V1 release target, everything the child says to the device and everything the device says to the child must pass through a two-way moderation layer:
- Age-inappropriate content (violence, sexuality, fear, manipulation) is blocked
- Dangerous activity suggestions (taking medicine alone, fire, high places) are blocked
- Personal information (full name, address, phone, school, parents' occupations) is redacted when spoken
In the target behavior, moderation events appear in the parent safety report as counts; raw content does not appear. This report flow has not yet been proven in production.
5.2 Personal Information Masking (PII Redaction)
Personal information appearing in the child's speech:
- Does not appear in the raw transcript; it is stored in redacted form
- Is redacted before being sent to the LLM service
- Remains redacted when converted into memory cards
5.3 Time and Interaction Limits
The parent can apply the following controls:
- Daily usage time limit
- Time-window restriction (blocking nighttime use)
- Interaction frequency and break suggestions
5.4 Blocked Topic List
The parent can block additional topics for the child's specific sensitivities (e.g., the name of a loved one recently mourned, a health condition).
6. Legal Bases for Data Processing (Children's Data)
| Processing | KVKK | GDPR | COPPA parallel |
|---|
| Profile data entry | Art. 5/1 explicit consent (by the legal representative) | Art. 8 (parental consent) | "Verifiable parental consent" |
| Processing of voice data | Art. 5/1 (explicit consent, via the legal representative) | Art. 6(1)(a) + Art. 8 | VPC + limited data |
| Safety moderation | Art. 5/2-f (legitimate interest — child protection) | Art. 6(1)(f) + Art. 9 protection | "Child safety" exception |
| Anonymous statistics | Art. 28 (not personal data) | Art. 5(1)(b) | Anonymous data unrestricted |
7. Transfer of Children's Data
Transfers to the infrastructure providers listed in the Privacy Policy and the KVKK Disclosure Notice (Render, Cloudflare, LiveKit, OpenAI/Anthropic, ElevenLabs, Sentry, Apple/Google) are carried out on the basis of the parent's explicit consent.
Children's data:
- Is not sold, not rented, and not traded to third parties
- Is not shared with any other company for advertising, marketing, or profiling purposes
- Data sent to LLM services (OpenAI/Anthropic) is subject to contractual assurances that the provider will not use it for model training — the provider agreement is shared when needed
8. Retention Periods (Children's Data)
| Data | Period |
|---|
| Child profile data | For as long as the account is active; the parent can delete it |
| Web demo name and curiosity preference | Until the browser tab/session ends or the user clears it |
| Web demo personal TTS input and output | The completed audio result is not written to a time-limited result cache on Neeko's server; only concurrent identical generations may be merged until processing finishes. Browser playback memory and ElevenLabs' current policy may also apply |
| Voice transcript | V1 plan candidate: a maximum of 90 days; to be finalized with legal, purpose, backend, and deletion testing |
| Raw audio file | V1 target: not persistently stored by Neeko; to be verified on the LiveKit/provider account |
| Memory cards | V1 target: only with parental approval, until the parent deletes them |
| Safety event counts | V1 plan candidate: a maximum of 12 months; subject to legal/backend confirmation |
When the account is closed, the child's data:
- Is immediately removed from access
- Is deleted from backups and log records within a reasonable period
- Unless a legal obligation requires otherwise, it is anonymized or completely deleted
9. Parental Rights (On Behalf of the Child)
As a parent, you have the following rights regarding your child's data (KVKK Art. 11):
- To learn whether the child's personal data is being processed
- If processed, to learn which data categories are processed
- To learn for what purpose it is processed
- To learn the third parties to whom it is transferred
- To request correction
- To request deletion of the child's data (the most sensitive right)
- Not to be affected by automated decisions
Requests can be submitted using the methods described in the KVKK Disclosure Notice § 10.
10. International Compliance
10.1 KVKK (Turkey)
The KVKK does not contain a separate article for children; however, where explicit consent is required for processing children's data, the consent is given by the parent or legal representative, and data subject rights also apply to children's data. Turkish Constitutional Court case law interprets additional protection for children's data.
10.2 GDPR Art. 8 (EU)
Parental consent is required for a child's access to information society services between the ages of 13 and 16 (the threshold varies between 13 and 16 depending on the member state). Neeko keeps the parental consent chain above this threshold — the explicit consent of the parent as legal representative is obtained for all children's data.
10.3 COPPA (US) — Parallel
If operations are conducted in the US market in the future, COPPA rules apply:
- Verifiable parental consent (VPC) for data of children under 13
- Data minimization
- Ban on advertising targeted at children
- Third-party sharing limitations
- FTC oversight and "safe harbor" programs
Neeko is not currently offered for sale in the US market. Upon market entry, COPPA compliance mechanisms will be implemented.
10.4 UK ICO Age Appropriate Design Code
In the UK, the ICO's Age Appropriate Design Code (in force since 2021) contains 15 standards. Neeko product design is based on the following standards:
- Best interests of the child (Standard 1)
- Data protection impact assessment (DPIA — performed when the threshold is crossed)
- Default settings high privacy (Standard 5)
- Data minimisation (Standard 8)
- Profiling default off (Standard 12)
- Nudge techniques avoidance (Standard 13)
10.5 UN Convention on the Rights of the Child
The principles of Article 16 (privacy), Article 17 (media access and protection), and Article 19 (protection from harm) serve as references in our design decisions.
11. Stores and Age Threshold
Because the NeekoApp mobile application is a parent management panel, it is not directed at children under 13:
- Apple App Store target age: 13+
- Apple Kids Category: NO (not a children's app)
- Google Play target age: 13+
- Google Designed for Families: NO
The device, as a physical product, is designed for children; child protection rules are applied in the device data pipeline, not in the mobile application's store category. Users aged 13-17 must use the app with the approval and supervision of a parent or legal representative.
12. Data Breach and Crisis Response
In the event of a data breach affecting children's data:
- Notification to the KVKK Board within 72 hours
- Notification to affected parents within a reasonable period
- Public announcement if necessary
- The cause and impact of the breach are explained transparently
- Corrective measures and subsequent safeguards are communicated
13. Complaints and Applications
- Direct application to the data controller: support@neekoai.com.tr
- Complaint to the KVKK Board: If you are not satisfied with the outcome of your application to the data controller, you have the right to file a complaint with the Board (KVKK Art. 14)
- In GDPR countries: The local data protection authority
- Suspected child protection issue: You can write to support@neekoai.com.tr with the subject line "Child Safety"; in urgent risks, local emergency services and child protection authorities should be contacted.
14. Policy Changes
This Policy may be updated due to legislation or product development. For significant changes:
- The "Last updated" date is refreshed
- Parents are notified by e-mail
- If new consent is required, separate approval is obtained in the user flow
15. Contact
E-mail: support@neekoai.com.tr Web: neekoai.com.tr/contact
Related documents: