Skip to main content

Privacy Policy

Last Updated: June 5, 2026

WobbleTalk ("we," "us," or "our") is committed to protecting the privacy of all users, especially children. This Privacy Policy explains how we collect, use, store, and protect personal information when you use our speech therapy application.

1. Overview

WobbleTalk is a speech therapy platform designed for children and adults with communication needs. We operate under strict privacy-by-design principles, collecting only the minimum data necessary to provide our services. We comply with the Children's Online Privacy Protection Act (COPPA), and when used in clinical settings, we support HIPAA-compliant workflows.

2. Data We Collect

Account Information

  • Email address (parent/therapist accounts)
  • Display name and role selection
  • Age range for child accounts (not exact date of birth)

Usage Data

  • Communication board interactions
  • Exercise completion and scores
  • Session duration and frequency
  • Vocabulary level progression

Optional Data (with explicit consent)

  • Voice recordings during speech exercises
  • AI-generated session summaries
  • Therapist notes and observations

Data We Do NOT Collect

  • Exact date of birth, physical address, photos/videos of children, social media accounts, or location data.

3. COPPA Compliance

We fully comply with COPPA. For users under 13:

  • Verifiable Parental Consent via our in-app consent flow before account activation.
  • Data Minimization — only what's needed to deliver therapy.
  • Parental Access — review, modify, or delete a child's data from the Parent Dashboard.
  • No Behavioral Advertising.
  • No Third-Party Sharing of children's data for commercial purposes.
  • Right to Revoke consent and request full deletion at any time.

4. HIPAA Considerations

When WobbleTalk is used in clinical settings by licensed SLPs:

  • Session data may constitute Protected Health Information (PHI).
  • Business Associate Agreements (BAAs) available for clinical accounts.
  • Encryption at rest (AES-256) and in transit (TLS 1.3).
  • Role-based access control and audit logging of all AI interactions.
  • Clinical Mode flag enforces stricter de-identification and full audit capture.

5. AI Features & De-Identification

WobbleTalk uses OpenAI's GPT-4o mini model to power AI features such as session summaries, vocabulary suggestions, and exercise generation. We do not use any heavy on-device SDKs, and all AI requests are made server-to-server.

  • De-identification layer: Before any text is sent to OpenAI, our server runs a de-identification pass that strips emails, phone numbers, SSNs, dates of birth, ZIP codes, and common name patterns.
  • Metadata-only requests: Vocabulary and exercise prompts contain only counts, levels, and category metadata — never PHI.
  • Audit trail: Every AI call is logged with action type, data category, status, latency, and a clinical-mode flag — without storing input or output content.
  • No model training: Our usage of OpenAI's API does not contribute to model training under OpenAI's API data policy.
  • Clinical Mode: When enabled by a therapist, AI calls log additional context and require de-identified inputs.

6. Data Storage & Security

  • Encrypted at rest (AES-256) and in transit (TLS 1.3)
  • Row-level security on every database table
  • Role-based access control with audit logging
  • Automated encrypted backups
  • 72-hour breach notification policy

7. Third-Party Services

  • OpenAI (GPT-4o mini): AI features — de-identified text only.
  • Web Speech API: Browser-native TTS, runs locally.
  • No analytics, ad networks, or social trackers.

8. Your Rights

  • Access, correction, deletion, export, restriction, withdrawal of consent, and objection.

9. Data Retention

  • Active accounts: data retained while active
  • Inactive accounts: deleted after 12 months
  • Deleted accounts: removed within 30 days
  • Voice recordings: auto-deleted after 90 days unless saved

10. Changes to This Policy

We will post material changes here and update the date. Changes affecting children's data require fresh parental consent.

11. Contact Us

  • Email: privacy@wobbletalk-app.com
  • Response time: within 48 hours