Skip to content
L2P – Learn to Play
Parent-controlled learning reward system
Home Features Pricing Guides Updates Program Access
Contact Us
Home Features Pricing Guides Updates Program Access Privacy Terms Contact Us

Privacy Policy

Effective Date: 2026-08-04

Version: 1.1

Operator: OTEKIK PTY LTD

Brand: L2P – Learn to Play

Privacy Contact Position: Privacy Officer

Privacy Contact: privacy@learn2play.com.au

Support Contact: support@learn2play.com.au

Telephone: +61 459 625 918

This Privacy Policy explains how OTEKIK PTY LTD ("we", "us", or "our") collects, uses, holds, and shares personal information when you use L2P – Learn to Play ("L2P"), including the mobile application and related services (the "Service").

L2P is a parent-controlled learning reward system. Parents or legal guardians create the account, create child profiles, pair child devices, choose Learning Apps and Play Apps, and set rules that convert learning time into play access. L2P is designed around a local-first, summary-first privacy model: the child device handles real-time Screen Time enforcement locally where possible, while cloud systems hold account, pairing, rule, summary, subscription, reward, privacy-request, and limited operational records needed to run the Service.

This is L2P's core privacy notice for the places where the Service is offered. It does not mean that L2P has launched or is legally available in every country. We may limit availability or provide an additional regional notice, translation, representative, age check, or consent process before offering some or all features in a particular place.

1. Who This Policy Applies To

This Privacy Policy applies to parents, guardians, and other adult account holders who create or manage an L2P account; child profiles and paired child devices managed under a parent-controlled account; visitors to the L2P website; people who contact us for support, privacy requests, or account questions; and people who receive Service notices from us, such as privacy or inactive-account notices.

L2P is not designed as a standalone child sign-up service. Child Mode is intended to be set up and managed by a parent or legal guardian.

2. Children and Parent-Controlled Use

L2P processes child-related information because parents use the Service to manage child profiles and paired child devices.

Parents or legal guardians are responsible for ensuring they have authority to create and manage each child profile and child device, reviewing the rules, app selections, rewards, and privacy controls they enable, keeping Parent Mode and account access secure, and contacting us if child information should be accessed, corrected, exported, cleared, or deleted.

Children do not create their own L2P cloud account in the current product design. If a child contacts us directly, we may require parent or guardian involvement before acting on account, privacy, or deletion requests.

During parent sign-in, the adult must agree to the Terms of Use and confirm that they have read this Privacy Policy before sign-in can proceed. Where a law requires a particular form of age assurance, direct notice, or verified parental consent, those confirmations alone may not be sufficient. We will use an additional process before making the relevant child-data feature available in a place where one is required.

We consider the child's best interests when designing and operating child-facing features. We do not ask a child to disclose more information than is reasonably needed to use a feature, and we do not condition participation on unnecessary disclosure.

L2P does not use child data for third-party advertising, cross-app tracking, data-broker sharing, or child-behaviour monetisation.

3. Information We Collect

We aim to limit the personal information we collect and hold to what is reasonably needed to operate, secure, support, and improve the Service.

Parent account and sign-in information

We may collect parent email address and display name, account identifiers from supported sign-in providers, account/session identifiers used to keep you signed in, authentication status, selected plan or feature access state, and account activity records needed for privacy, retention, support, and security.

The current parent sign-in surface supports Google sign-in and Sign in with Apple. Sign in with Apple may provide a private relay email address. We do not receive your Apple or Google password.

Child profile and family setup information

We may collect child profile name, nickname, or label entered by the parent; avatar choice and active/inactive child profile state; parent-child account relationship; family join invite status, expiry, and claim records; pairing status and unlink/relink status; and identifiers used to keep the correct parent, child, and device linked.

Child device pairing information

When a child device joins a parent account, we may collect a generated child-device identifier used for pairing validation, device name and platform, pairing status, paired time, last-seen time, unlinked time, invite and pairing metadata, and local child-device state needed to detect when a device is no longer linked.

If a child profile or account is deleted while the child device is offline, local enforcement may continue temporarily from cached rules. When the child device next comes online or validates its pairing state, it is expected to stop L2P monitoring, release L2P shields where possible, clear linked local state, and show that it is no longer linked.

Screen Time app selections, rules, and local enforcement state

Parents choose Learning Apps and Play Apps on the child device because Apple's Screen Time app picker runs on the device that has the relevant app list. Depending on the feature and device state, L2P may process Learning App and Play App selections, Apple Screen Time selection data needed to sync rules, rule version, reward ratio, feature access state, local cached rules, remaining-play balance, app shield state, and setup diagnostics.

Screen Time app-selection data can be sensitive. L2P is designed to use it for app-control functionality, not advertising or profiling. Privacy exports summarize app-rule state and do not expose underlying Screen Time selection tokens.

Learning, play, summaries, and operational records

To provide the Learn -> Earn -> Unlock -> Play -> Lock loop, L2P may collect or create daily learning minutes, daily play minutes, earned, used, bonus, and remaining play minutes, the child local time zone used for daily boundaries, summary sync timestamps and freshness state, limited earn/use transaction records, play request records where applicable, records used to prevent duplicate processing and support retry, and current-day enforcement state such as whether an L2P Play App shield is applied.

The cloud model is summary-first. Detailed per-app minute breakdowns and detailed Screen Time processing records are intended to remain local on the child device by default unless a future feature clearly discloses otherwise.

Rewards, Bonus Time, Program Access, and subscriptions

Depending on the plan and features enabled, we may collect reward rule settings, daily tasks, weekly rewards, parent reward goals, points, claims, redemptions, whether Rewards are shown or hidden on the child device, Bonus Time grants and daily grant state, Program Access code redemption and grant state, active plan and feature access state, App Store product identifiers and subscription entitlement state, and subscription status needed to enable Free, Plus, or Pro feature rules.

Apple manages App Store payments, renewals, refunds, and subscription cancellation. We do not receive your full payment-card details from Apple.

Privacy requests and export files

When a parent uses Privacy & Data controls, we may hold export, clear-history, child-deletion, and account-deletion request records; request status, timestamps, and error state; minimal audit events; export file metadata and storage details while retained; and temporary download link expiry state.

The export ZIP is designed as a parent-friendly export, not a technical data dump. It currently includes files such as family profile, children, reward rules, app-rule summary, daily activity summary, progress summary, Bonus Time, Rewards, Program Access, pairing status, and subscription status.

Support, communications, camera, and local notifications

If you contact us, we may collect your name and contact details, support message contents, screenshots, logs, or diagnostic information you choose to send, and our support and complaint-handling records. We may use an email service provider to send privacy, account, and retention notices to the parent account email address on record.

L2P asks for camera permission only so a device can scan a parent-issued family join QR code. L2P does not use the camera for photo storage, face recognition, advertising, or background capture.

The child app may ask for local notification permission to show learning milestone reminders and play-time countdown warnings. These alerts are generated on the device through iOS notification features. L2P does not use these notifications for advertising, third-party marketing, or cross-app tracking.

Website information

When you visit the L2P website, our web-hosting provider may process ordinary delivery and security information such as IP address, browser or device type, requested page, referral information, and request time. The website does not currently use advertising cookies or analytics tracking scripts. The contact form prepares a message in your own email application; it does not submit the form contents to the L2P website.

4. How and Why We Use Information

We collect information from parents when they sign in, create child profiles, choose rules, pair devices, manage rewards, manage subscriptions, use Privacy & Data controls, or contact support; from child devices when paired and syncing or validating state; from Apple and Google when a parent uses their sign-in, billing, or platform features; from Apple's Screen Time services on the child device; and from our service systems when they create operational, audit, and retention records.

We use personal information to create and manage parent accounts and child profiles, authenticate parents and maintain sessions, pair, validate, unlink, and relink child devices, store and sync app rules, reward rules, plan capabilities, and parent settings, calculate earned, used, bonus, and remaining play time, apply supported Screen Time restrictions, show local reminders and warnings, show dashboards, child setup state, progress, Rewards, Bonus Time, and account status, prevent duplicate reward or usage processing, process Privacy & Data requests, send support, account, privacy, retention, and operational notices, troubleshoot, secure, and maintain the Service, prevent misuse and unauthorized access, comply with legal obligations, and enforce our Terms of Use.

Where a law requires us to identify a legal basis, the basis depends on the activity. We may process information to perform our agreement with the adult account holder and provide requested features; with consent where consent is appropriate and requested; to comply with legal obligations; and for legitimate interests such as securing, supporting, and improving the reliability of the Service, provided those interests are not overridden by a person's rights or a child's best interests. We do not rely on a parent's direction as a substitute for a specific form of verified consent where the law requires more.

You may withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing that was lawful before withdrawal. Some information is necessary to provide an account, pairing, or requested control feature; if it is not provided or must be deleted, that feature may not work.

L2P uses configured rules and local device state to automate product behaviour such as calculating play balance and applying or releasing Play App shields. Parents choose the relevant rules and can change supported settings. L2P does not make credit, employment, insurance, health, or legal decisions.

5. Local-First, Summary-First Design and Sharing

L2P is designed around parent-led setup and control, minimum necessary child data, local child-device enforcement where possible, summary-first cloud records, no ad-driven child data use, and privacy controls for export, clear history, child deletion, and account deletion.

Child devices may continue enforcing locally from cached rules while offline. Parent-visible summaries and cloud state may update later when a child device has network access and a safe sync opportunity.

We may disclose personal information to Supabase for cloud hosting, authentication, database, and storage infrastructure; Apple for App Store distribution, subscriptions, Sign in with Apple, and Screen Time-related platform services; Google when a parent chooses Google sign-in; Resend for privacy and retention notice email delivery; Vercel for website delivery and security; support, security, operational, professional, or legal service providers; a parent or legal guardian who manages the relevant child profile; regulators, courts, law enforcement, or other parties where required or permitted by law; and parties involved in a proposed or completed merger, acquisition, restructuring, financing, asset sale, or similar business transfer, subject to confidentiality and applicable law.

Depending on the service involved, these organisations may process information on our instructions or may handle information under their own terms and privacy policies as independent controllers. Where an organisation processes information on our behalf, we require it to handle that information only for the relevant contracted service, subject to the applicable agreement and law. We assess provider roles and safeguards in proportion to the information and risk involved.

We do not sell personal information. We do not share child data with data brokers or use or disclose it for third-party targeted advertising. We do not knowingly use cross-context behavioural advertising for any L2P user.

6. Overseas Disclosure and International Processing

L2P's primary Supabase project is currently configured in Australia. Apple, Google, Resend, Vercel, and their subprocessors may process information in the United States and other countries where they operate. Support and professional providers may also process information in the country from which they provide their service.

Privacy laws and government-access rules can differ between countries. Where an international transfer requires a legal safeguard, we will use an available mechanism appropriate to that transfer, such as an adequacy decision, contractual safeguards, or another lawful transfer mechanism, and additional technical or organisational measures where appropriate. If a required safeguard or representative arrangement is not in place, we may restrict the relevant regional availability rather than claim that the transfer is covered.

You may contact us for more information about the main processing locations and safeguards relevant to your information.

7. Your Privacy & Data Controls

Parent accounts can use Settings -> Privacy & Data for the following controls.

Export My Data

Export My Data generates a private ZIP file with parent-friendly files and summaries. The ZIP is retained for 7 days. Download links are signed and valid for 1 hour. While the export is retained, the app can request a fresh signed download link.

The export masks or omits system-only identifiers, generated child-device identifiers, join codes, access codes, auth/session tokens, underlying Screen Time selection tokens, and system-only API names unless there is a clear product or legal need to include them. Pairing status exports may include parent-visible device name, platform, pairing status, and relevant pairing timestamps.

Clear History

Clear History is designed to clear older, safe-to-clear history before the current child-local week. It preserves current-week and current-day enforcement state, current remaining balance, active child profile, app rules, reward rules, Program Access, subscription state, pairing state, active Rewards state, points/level, lifetime learning totals, required audit/security records, and current lock/unlock truth.

L2P also keeps clear markers so older offline child-device rows cannot be replayed later as fresh history after a clear.

Delete Child Profile

Delete Child Profile permanently removes the selected child profile and child-scoped data. It does not delete the parent account, other children, Program Access, or the Apple subscription.

Delete Account & Family

Delete Account & Family starts permanent deletion of the L2P account and family data. L2P removes retained export ZIPs and deletes the account after related account and family data is processed through a secure server path. A minimal privacy request audit record may remain for accountability, security, legal, and operational integrity.

Deleting an L2P account does not cancel an Apple App Store subscription. Parents must manage Apple subscriptions in the App Store or Apple ID subscription settings.

8. Retention

We retain personal information only for as long as reasonably necessary for the purposes in this Privacy Policy, including to provide the Service, support parents, secure the Service, meet legal obligations, resolve disputes, and maintain operational integrity. The account and feature state, sensitivity of the information, risk of harm, legal requirements, and whether the information can be deleted or de-identified affect the period.

  • Privacy export ZIPs: retained for 7 days.
  • Signed export download URLs: valid for 1 hour.
  • Stale claimed, expired, or revoked Join Family invites: scheduled cleanup after 30 days.
  • Old child activity and operational history: settled daily summaries, Bonus Time daily records, and legacy learning/play operational rows are retained only while reasonably necessary for current product operation, parent-visible history, security, support, a dispute, or a legal obligation. Eligible information may also be cleared through Clear History or removed through child-profile or account deletion.
  • Old non-active child-device pairings: unlinked or replaced pairing records are retained only while reasonably necessary for pairing integrity, security, support, a dispute, or a legal obligation. They are removed when no longer reasonably needed or through the applicable child-profile or account deletion process. Active pairings are preserved while needed to provide the Service.
  • Privacy audit records, privacy notice records, and Program Access audit records: generally retained for up to two years for accountability, security, support, and legal purposes, then deleted or de-identified unless a longer period is reasonably necessary or required by law.
  • Inactive accounts and associated family data: scheduled for deletion after two years without observed account or family activity. We may send inactivity reminders after 365 days and will provide reasonable advance notice before scheduled deletion where current contact information is available.
  • Resuming account or family activity before the scheduled deletion date will cancel the inactivity deletion. An account holder may use Delete Account & Family or make a verified deletion request at any time instead of waiting for the inactivity period.
  • Stuck non-destructive privacy requests: surfaced by timeout handling; stale account-deletion requests require manual review rather than hidden deletion.
  • Privacy request audit rows: retained as needed for accountability, support, security, retry or manual review, and legal obligations.
  • Local child-device data: may remain on the device until the device is unlinked, reset, the app is removed, or local app data is cleared.

Deletion or de-identification may be delayed where information remains reasonably necessary for security, fraud prevention, support, an unresolved transaction or dispute, exercise or defence of legal claims, or another legal obligation. If we materially change these retention periods or deletion practices, we will provide appropriate notice where required.

9. Privacy Rights and Choices

Depending on where you live and subject to applicable exceptions, you may ask us to provide access to personal information we hold about you or a child profile managed under your account; correct inaccurate, out-of-date, incomplete, or misleading information; export or obtain a portable copy; clear or delete eligible information; restrict or object to particular processing; withdraw consent; opt out of a sale, sharing, or targeted advertising where those concepts apply; explain how we handled a privacy request; appeal a decision; or investigate a privacy complaint. L2P does not currently sell personal information or use it for targeted advertising.

Use the in-app Privacy & Data controls where available, or contact us at privacy@learn2play.com.au. Please include enough information for us to verify your identity and locate the relevant account or child profile.

An authorised agent may make a request where local law permits. We may ask for information reasonably needed to verify identity, authority, and the relationship to a child profile. We will respond within the period required by applicable law. We may refuse, limit, or delay a request only where permitted by law, and will provide an explanation and appeal or complaint information where required. We will not discriminate against you for exercising a privacy right.

For a complaint, use the subject line "Privacy Complaint" and describe what happened and the outcome you seek. We will acknowledge the complaint, investigate it, and provide a reasoned response within the period required by law. If we need more time, we will explain why where required. If you remain dissatisfied, you may complain to the privacy or data-protection regulator available where you live.

10. Regional Information

This core notice is interpreted together with mandatory law where L2P is offered. Depending on the region, the following may apply.

  • Australia: eligible individuals may complain to the Office of the Australian Information Commissioner after first giving us a reasonable opportunity to respond.
  • European Economic Area and United Kingdom: eligible individuals may have rights to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to their local supervisory authority. OTEKIK PTY LTD is the controller for the processing described in this policy unless a separate notice says otherwise. Any required local representative and transfer details will be provided before the relevant regional offering.
  • United States: applicable federal and state law may provide parent rights for child information and consumer rights to know, correct, delete, obtain a copy, opt out, appeal, and avoid discriminatory treatment. Where verifiable parental consent is required, L2P will use an appropriate additional process before the relevant collection or use.
  • Canada: eligible individuals may request access and correction, withdraw consent where applicable, and complain to the relevant privacy regulator. L2P may restrict availability in Quebec unless and until French-language versions of the Service, Terms, Privacy Policy, and other materials required by applicable law are available.
  • Brazil: eligible individuals may have rights under the LGPD, and child and adolescent information must be handled in their best interests. Any locally required contact or representative details will be provided with the relevant offering.

Other countries may provide additional rights. Contact us and tell us your country or region so we can give you the correct route. If required regional safeguards are not ready, we may not make the Service available there.

11. Security and Third-Party Services

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorized access, modification, and disclosure. Measures may include authentication, role-based access controls, private storage, short-lived signed URLs, data minimization, redacted diagnostics, audit records, and provider safeguards.

No system can guarantee absolute security. Parents are responsible for protecting their own devices, Apple or Google accounts, L2P account access, and Parent Mode access.

We assess suspected personal-information incidents and will notify affected people and regulators where applicable law requires notification.

Third-party services may handle information under their own terms and privacy policies. Relevant providers include Apple, Google, Supabase, Resend, and any support or infrastructure providers we later use.

Parents should also review Apple settings, Screen Time settings, Family Sharing settings, App Store subscription settings, and the privacy terms of any sign-in provider they choose.

12. Changes to This Privacy Policy

We may update this Privacy Policy to reflect product, provider, legal, or operational changes. If a change materially affects how we use personal information or a person's rights, we will provide notice through the app, website, email, App Store listing, or another appropriate channel before the change where required. We will request new consent where required. The version and Effective Date appear at the top.

13. Contact Us

Operator Legal Name: OTEKIK PTY LTD
Brand: L2P – Learn to Play
Privacy Contact Position: Privacy Officer
Privacy Email: privacy@learn2play.com.au
Support Email: support@learn2play.com.au
Telephone: +61 459 625 918
Operator Location: Melbourne, Victoria, Australia
Website: otekik.com.au

A postal address, data-protection representative, or other local contact details will be included in an additional regional notice before offering the Service where those details are legally required. If you need this Privacy Policy in another format, contact us and we will take reasonable steps to provide it in an appropriate form.

L2P – Learn to Play
Parent-controlled learning reward system

L2P turns learning into play time.
Parents set the rules, kids earn play time.

Product

Features Pricing FAQ Guides Updates Program Access Contact us

Trust

Privacy Terms support@learn2play.com.au
© OTEKIK PTY LTD — L2P. Built for calm, parent-led digital balance.