Privacy Policy
Last updated: 7 July 2026
This is a draft. We may update this policy before Doodle Den opens to everyone β nothing here changes the promises at the heart of it: no ads, nothing sold, and as little data as possible.
The short version
- No accounts. No login, email, password, name, or birthdate β your child just plays.
- No ads, no ad tracking, and we never sell or share personal data for marketing. We do no third-party advertising or analytics β just a little private, first-party counting to keep the service running (explained in section 3).
- To make a colouring page, the words your child types are sent to our servers, hosted in the EU. There, an automated filter removes personal details (names, ages, addresses, school names and the like) and the request is rewritten into a drawing description β only that rewritten description is ever sent to the trusted third-party AI provider that draws the picture (which may be based in the United States). Your child's original words never leave our own systems.
- We keep a private, anonymous device token so we can prevent abuse and keep things fair. It isn't tied to who your child is.
- You can ask us to delete everything linked to a device at any time β pictures, share links, history, tokens, the lot. Just email support@doodleden.app.
1. Who this is for
Doodle Den is a colouring app made for young children β roughly ages 4 to 8 β to be used with a parent or carer nearby. Because it's designed for children, we treat it as a child-directed service and aim to meet the expectations of children's privacy rules such as the Children's Online Privacy Protection Act (COPPA) in the United States and the UK Age Appropriate Design Code and GDPR protections for children in the UK and EU.
In plain terms: we built this to be safe and quiet in the background, collecting as little as we can and never using your child's activity to advertise to them.
2. What we don't collect
We designed Doodle Den to work without knowing who your child is. That means:
- No accounts. There's no login, email, password, real name, birthdate, or child profile.
- No advertising. No ads, no behavioural advertising, and no third-party advertising SDKs.
- No third-party advertising or analytics SDKs. We don't embed trackers from advertising or analytics companies, or from social networks. (We do keep a little private, first-party count of aggregate service activity β described in section 3 β but that stays with us and isn't shared for marketing.)
- Nothing sold or shared for marketing. We do not sell or share personal data for advertising, ever.
- No social features beyond the optional share link described below.
3. The device token & app integrity
To keep the service fair and safe without accounts, the app uses a private token instead of a login.
An anonymous device token
The first time the app opens, it receives an opaque, backend-signed device token. This token is stored safely on the device using the operating system's secure storage β the iOS Keychain or Android Keystore. We use it only to:
- rate-limit how many pages can be generated (so the system isn't overwhelmed),
- prevent abuse, and
- understand basic, aggregate service activity (like how many pages are made overall). This is our own first-party counting β it isn't shared with advertising or analytics companies.
This token is not linked to a real-world identity. It doesn't tell us who your child is, where they are, or what they look like.
Confirming the app is genuine
The app's first call to our servers is protected by Apple App Attest or Google Play Integrity. This simply confirms the app is the real Doodle Den and not a tampered copy, which helps keep the service safe. To do this, the app checks in with Apple's or Google's own attestation services at that first launch, so a small amount of standard integrity information is handled by Apple or Google as part of confirming the app is genuine. We list them as processors for this limited purpose in section 7.
4. Android reinstall recovery
On Android, if the app is uninstalled and reinstalled, we want it to keep the same anonymous identity so that any safety limits stay in place. To do this, the app may send the device's Android identifier (ANDROID_ID / SSAID).
We never store the raw value. Our servers keep only a one-way hashed digest of it β a scrambled fingerprint that can't be turned back into the original. That's enough to recognise a returning device without knowing anything more about it.
Keeping the same anonymous identity across a reinstall is also what lets safety limits and any block on a rule-breaking device carry over β so a device that's been blocked for breaking the sharing rules (see section 6) can't simply reinstall to start fresh.
On iOS, there's no equivalent step β the app relies on the Keychain to remember its token instead.
5. Making a colouring page (the AI part)
This is the one place where a small amount of text leaves the device, so we want to be clear about it.
When your child types a short prompt describing a picture β for example, "a dragon riding a bicycle" β here's what happens to that text:
- The typed prompt is sent to Doodle Den's servers, hosted in AWS's EU regions.
- First, an automated filter removes personal details from the text (explained just below).
- The cleaned-up text is then checked against child-safety rules and rewritten into a fresh drawing description that works well for the image model. Both of these steps β the filter and the rewrite β run within our own AWS environment in the EU; no outside AI company is involved up to this point.
- Only that rewritten drawing description is sent to a third-party AI image-generation provider, which creates a black-and-white colouring page. Your child's original typed words are never sent outside our own systems.
Removing personal details first
Children sometimes type things about themselves β a name, an age, a school, a home address. Before a prompt goes anywhere beyond our own backend, it passes through an automated personal-information filter that runs within our own AWS environment, in AWS's EU regions:
- It removes names, ages, home addresses, school names, phone numbers, email addresses, and online handles β in whatever language the prompt is typed.
- It removes whole personal statements, not just the identifying word. If a prompt says "draw a dog β I go to school in [town]", the entire "I go toβ¦" part is dropped, and only the drawing request goes on. Places that are simply part of the picture ("a cat drinking tea in Paris") are kept β that's the drawing, not personal information.
- Two independent checks run on every prompt: an AI-based screen that understands context, and a separate pattern-based detector for things like street addresses, phone numbers, and email addresses.
- The filter fails safe: if the screening can't run for any reason, the colouring page simply isn't generated β unscreened text is never sent onward.
- As part of this screening, prompts are translated into English, and it's this cleaned-up English version β never the original raw text β that is kept with the picture and shown in places like share pages.
No automated filter is perfect, so we've tuned this one to over-remove rather than under-remove β and it still helps to remind your child not to type personal details into any app.
So the words your child actually types are processed only within Doodle Den's own EU-hosted backend. What the third-party AI image provider receives is the rewritten drawing description produced there β not your child's original words. Those image providers may operate in the United States, which means the rewritten description may be transferred outside the UK and EU. We use them under agreements intended to restrict their use of the data to providing this service to us.
We can't promise specific certifications or zero-retention from these providers, so we won't claim that. We're describing the contractual posture we intend to hold them to β and we'll keep this policy honest as those arrangements are finalised.
Re-using finished pages
Once a colouring page has been drawn, we may add it to our catalogue and re-use it to answer a similar request from someone else β it saves regenerating the same idea twice. This is safe to do because every page is produced from the rewritten drawing description, after personal details have been removed: the picture carries no personal information, and nobody can see who originally asked for it.
Unsafe prompts & what our own records keep
Prompts that break our safety rules are rejected. The original raw text of a prompt is kept only briefly, on a short-lived processing record that expires and deletes itself automatically, so we can review abuse and keep the service safe. Raw prompt text is never written to our long-term logs or permanent records β those keep only the cleaned-up version with personal details removed, or just the fact that a prompt of a certain length was handled.
7. Where things are stored
A few trusted service providers help us run Doodle Den. Under UK/EU data-protection law, Doodle Den is the data controller and these providers act as our processors, handling data on our instructions for the limited purposes below:
- Amazon Web Services (AWS), EU regions. Hosts our backend (Frankfurt) and stores the generated colouring images, which are delivered to the device for offline colouring. AWS also runs the personal-information filter and the safety-check-and-rewrite step described in section 5, using AWS's own AI and text-analysis services in its Ireland region. These run inside our own AWS environment β the text never goes to an outside AI company, prompts are not used to train the underlying AI models and are never shared with the companies that made them, and we have additionally opted our AWS organisation out of content being used to improve any AWS AI service. This is what keeps your child's original typed words inside our own environment.
- Third-party AI image providers (which may be US-based). Receive only the rewritten drawing description β never your child's original typed words β and use it to generate the colouring page, as described in section 5. Because these may operate in the United States, using them can involve a transfer of that rewritten text outside the UK and EU.
- Cloudflare. Serves and protects this website and the public share-preview pages as a content delivery network. To do that, it processes standard web-request data such as IP addresses, from anyone who visits those pages, to deliver and secure them.
- Apple and Google (attestation services). For the limited purpose of confirming the app is genuine at first launch (App Attest / Play Integrity, described in section 3), the app communicates with Apple's or Google's attestation services, which handle standard integrity information for that check.
8. Phone permissions we don't use
In the current version, Doodle Den does not access your device's location, contacts, photos, camera, or microphone. There's no photo-to-colouring feature. If that ever changes, we'll update this policy first.
9. Children & parental rights
Because Doodle Den is made for children, we keep data to the minimum and never use it to advertise. As a parent or carer, you have the right to access or delete the data associated with your child's device.
Just email us at support@doodleden.app. For a step-by-step guide β including where to find the Device ID in the app β see our data deletion page. On request, we delete all data associated with a device using a built-in erasure process that covers every place device data lives: generated colouring images, shared pages and their images (any public share preview is unpublished), generation history, the device token, rate-limit records, the hashed Android identifier, and feature-entitlement records. Each erasure is recorded in an internal log noting what was deleted (counts only β no child content), so we can show your request was honoured.
One honest nuance: a page created on your child's device may have been re-used from our catalogue and shared by a different family (see section 5 β re-used pages carry no personal information). That family's share isn't part of your device's data, so an erasure doesn't remove it directly β but every share expires automatically within 90 days, so any such copies disappear on their own.
Two narrow things survive an erasure: if a device was blocked for breaking the sharing rules, the block itself remains (deleting data isn't a way to undo a block), and the internal moderation log just mentioned β which contains no prompts, images, or other child content β is kept as our compliance record.
We may need a little information to identify the right device so we can act on your request accurately.
10. Your rights & our legal basis
Doodle Den is designed for families in the UK, the EU, and beyond, so this section sets out the roles and rights that data-protection laws such as the UK GDPR and EU GDPR expect.
Who is the controller
Doodle Den is operated by CodeCask B.V. (KvK 90036824), a private limited company established in the Netherlands, which is the data controller for the limited data described in this policy. The trusted providers listed in section 7 (AWS, our third-party AI image providers, Cloudflare, and Apple/Google for app integrity) act as our processors, handling data only on our instructions and for the purposes we've described.
The lawful bases we rely on
Where UK/EU data-protection law applies, we rely on:
- Legitimate interests β to keep the service safe, fair, and working: the anonymous device token, app-integrity checks, rate-limiting, abuse-prevention, hashed identifiers, and our own aggregate service counting. We've weighed these against your child's interests and kept them narrow and privacy-protective.
- Performance of the service you asked for β to turn a typed prompt into a colouring page, which necessarily involves sending that text to our EU-hosted servers, and sending the rewritten drawing description produced there to the AI provider that draws it.
Your data-protection rights
Subject to the law that applies to you, you (or a parent acting for a child) can ask us to:
- Access the data associated with a device.
- Rectify data that's inaccurate.
- Erase data (delete everything linked to a device).
- Restrict or object to certain processing.
- Portability β receive certain data in a usable form, where that right applies.
To use any of these, email support@doodleden.app (see section 9). You also have the right to lodge a complaint with a data-protection supervisory authority. Because we are established in the Netherlands, our lead supervisory authority is the Dutch Data Protection Authority β the Autoriteit Persoonsgegevens (AP), autoriteitpersoonsgegevens.nl. You can also complain to your own local supervisory authority anywhere in the EU, or, if you're in the UK, to the Information Commissioner's Office (ICO).
11. How long we keep things
We aim to keep as little as possible, for as short a time as possible:
- Raw prompt text is never written to long-term logs or permanent records. It lives only on a short-lived processing record that expires and deletes itself automatically; what's kept beyond that is the cleaned-up version with personal details removed (see section 5).
- The device token and hashed identifiers are kept while they're needed to enforce safety limits and prevent abuse.
- Generated images are stored so they can be delivered to the device, re-used from our catalogue for similar requests (see section 5), and β if shared β shown on a public preview. They are kept until the device that created them has its data erased (see section 9).
- Shared pages expire on their own after 90 days. A share can also end earlier β removed by moderation (see section 6) or deleted as part of an erasure (see section 9).
- Hashed reporter IPs are kept only as long as needed to handle abuse.
You can ask us to delete device-associated data at any time (see section 9). When you do, any public share preview tied to that device is unpublished as part of the deletion.
12. Changes to this policy
Doodle Den is currently in closed testing, and this policy is a draft that may be updated before public launch. When we make meaningful changes, we'll update the "Last updated" date at the top of this page. Please check back from time to time.
13. How to reach us
Questions about privacy?
Email us at support@doodleden.app
CodeCask B.V. Β· KvK 90036824 Β· BTW NL865190355B01
Oude Tilsterweg 15, 9981 JT Uithuizen, the Netherlands
You can also read our Terms of Service or head back to the Doodle Den home page.