Loading...
Loading...
CrayonLyf & CuddlyDuddly Private Limited — Commitment to data protection, parental control, and child safety under the DPDP Act, 2023.
This Privacy Policy ("Policy") explains how CrayonLyf ("CrayonLyf," "CuddlyDuddly," "the App," "we," "us," or "our"), a company affiliated with CuddlyDuddly Private Limited, collects, uses, shares, and protects personal data obtained through the CuddlyDuddly Parenting App and related services.
This Policy is designed to align with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable laws in India. Under the DPDP Act, we act as the Data Fiduciary in relation to the personal data described below. The parent who first registers and opens a child profile is the Primary Account Holder. The Primary Account Holder controls the child account. A person subsequently added through an invitation link is a Member. A Member may include the child's other parent or another person invited by the Primary Account Holder.
Because the App is used by parents and to manage information relating to their children, and because a child (any individual under 18 years of age) is the subject of much of the data processed, we have applied heightened safeguards throughout this Policy in line with Section 9 of the DPDP Act, which governs the processing of children's personal data.
By registering on or using the App, the parent consents to the practices described in this Policy on their own behalf and, where legally permitted, on behalf of their child.
This Policy applies to:
Exclusion note: This Policy does not apply to data about which specific applications a child uses on their device — the App only records elapsed time against a timer the parent sets (e.g., for "TV" or "gaming"), and does not monitor, log, or identify individual apps, content, or on-device activity.
Before any child's profile can be created, the registering adult must confirm, through a one-time password (OTP) sent to their registered mobile number, that they are an adult and the child's parent. This process verifies that the registering individual controls the mobile number provided; it relies on the parent's own declaration of their relationship to the child, which is not independently verified against any external record.
No child's profile, screen-time data, or food-analysis data is collected or processed until this step is completed. The first parent who completes this registration becomes the Primary Account Holder.
Parents may withdraw their consent at any time (see Section 13). The Primary Account Holder may invite Members to the child's profile by sending an invitation link. A person becomes a Member after accepting the invitation and acknowledging this Privacy Policy.
At present, CuddlyDuddly accepts registration for a child profile only from the child's parent. The first parent who registers becomes the Primary Account Holder. Other persons, including the child's other parent, may join the child profile only as Members after accepting an invitation link from the Primary Account Holder.
Collected directly at registration, including identity and contact details necessary to verify the parent is an adult and to operate the account.
Provided by the parent when creating the child's profile:
The App records the duration a timer runs against a parent-defined category (e.g., TV, gaming). The App does not identify, access, or record which specific application, website, or content the child used — only the elapsed time against the set timer.
A Member's name and contact details are collected when the Member accepts an invitation link from the Primary Account Holder. Members have the same permissions regardless of whether the Member is the child's other parent or another invited person. Members can view the child's profile, activities, screen-time information, and AI food/nutrition information, and can upload food photographs. Members cannot edit the child's profile, delete activities or screen-time records, or change account settings. Only the Primary Account Holder can manage the child account and exercise rights concerning the child's data.
When a parent or child uses the AI food-analysis feature, a photograph of food is captured and transmitted for analysis. The photograph and the resulting food/ingredient/nutrition analysis are linked to the child's profile and stored. Images that are not of food — including any image containing or depicting the child — are automatically rejected by the AI system and are not processed for analysis.
We do not use any third-party analytics, advertising, or crash-reporting SDKs.
Our processing of personal data under this Policy is based on consent obtained from the parent (and, where relevant, the member) under Section 6 of the DPDP Act. We do not rely on any of the "certain legitimate uses" grounds under Section 7 of the Act (such as employment, medical emergencies, or government functions), as none of those apply to our processing activities.
| Purpose | Data Used |
|---|---|
| Creating and managing a child's profile | Name, age, gender, school, location, class |
| Verifying parent is an adult | Parent identity and contact details, OTP verification |
| Recording screen-time against parent-set timers | Timer category, duration |
| Coordinating member responsibilities | Member name/contact, assigned activity |
| Sending app notifications | Push notification token |
| Food/ingredient/nutrition identification | Food photograph |
| Improving the general AI food-recognition model | De-linked food photograph with identifying information removed (see Section 8) |
| Customer support | Parent contact details, nature of inquiry |
Strict safeguard (Section 9, DPDP Act): We do not use a child's data to build behavioural profiles, to infer habits or patterns about the child, or to serve targeted advertising or content to the child, consistent with Section 9 of the DPDP Act.
The App's AI food-analysis feature involves processing submitted food photographs for the following purposes:
The App primarily stores personal data in India. However, where the App uses an AI processing provider located outside India, certain food photographs may be transferred outside India for processing.
Where OpenAI API is used for food-image analysis, the submitted food photograph may be transferred to OpenAI's servers in the United States for the purposes described in Section 8. The transfer is carried out in accordance with applicable requirements governing the transfer of personal data outside India, including Section 16 of the Digital Personal Data Protection Act, 2023, and any applicable restrictions or requirements issued by the Central Government.
The photograph is transferred for the purposes described in Section 8, including generating the food/ingredient/nutrition analysis and, where applicable, the general AI-model improvement processing described in Section 8(b). Before a photograph is used for general AI-model improvement, the profile link or tag connecting it to the child's profile is removed and identifying information associated with the profile is removed, as described in Section 8(b).
Other personal data, including child profile information and stored food photographs, is otherwise stored using infrastructure located in India, as described in Section 10. We apply contractual and organisational safeguards appropriate to the processing and the applicable legal requirements when personal data is transferred to an AI processing provider outside India.
We do not sell personal data. We share personal data only where necessary for the purposes described in this Privacy Policy, to provide the App's services, to comply with law, or in connection with a permitted business transfer.
Food photographs may be shared with the AI processing provider used by the App, including a locally hosted Qwen model or the OpenAI API, depending on the processing configuration. The AI processing provider may process the photograph for the purposes described in Section 8, including generating food, ingredient and nutrition analysis.
Where a photograph is used for general AI-model improvement, the processing is carried out as described in Section 8(b). Before such use, the photograph is de-linked from the child's profile by removing the profile link or tag and identifying information associated with the profile. The photograph is therefore not provided for model improvement together with the child's profile information. Where OpenAI API is used, the photograph may be processed outside India as described in Section 9.
We may disclose personal data where reasonably necessary:
We do not share children's personal data for targeted advertising or marketing purposes.
Access to personal data by service providers and other recipients is limited to what is reasonably necessary for the relevant purpose and is subject to appropriate contractual, organisational, and security safeguards.
We implement reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, misuse, or destruction. These measures include, as appropriate:
Access to personal data is limited to authorised personnel and service providers who require such access for the purposes described in this Privacy Policy or as otherwise permitted by law.
Where food photographs are used for AI model improvement, they are processed separately from the child's profile information and the associated identifying information is removed or de-linked before such use, as described in Section 8.
No security measure can guarantee absolute security. In the event of a personal-data breach, we will take appropriate steps to contain and assess the incident and provide notifications to affected persons and the relevant authorities where required by applicable law.
We retain personal data only for as long as necessary to provide and maintain the App, fulfil the purposes described in this Privacy Policy, and comply with applicable legal and regulatory requirements.
For active accounts, personal data, including child profile information and food-analysis data, is retained while the account remains active and for as long as it is necessary for the purposes described in this Policy.
Account deletion: The Primary Account Holder can delete the account using the Delete Account option available in the App. When an account is deleted, we will delete the personal data associated with the account (which may include the child's profile, screen-time history, food photographs, food-analysis history, and other personal data associated with the account) within 30 days, unless particular data is required or permitted to be retained under applicable law.
Certain security, access, transaction, or audit records may be retained for a limited period after account deletion where reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, or the establishment, exercise, or defence of legal claims. Such records will be deleted when they are no longer required for these purposes.
Retention periods may therefore vary depending on the type of data, the purpose for which it is processed, and applicable legal or regulatory requirements.
As a Data Principal (or as parent exercising rights on behalf of a child), you have the right to:
Member note: Members do not hold data export or deletion rights over the child's data; only the Primary Account Holder may exercise those rights. A Member may leave the child's profile, after which the Member's personal data will be deleted within 30 days, subject to data that is required or permitted to be retained under applicable law. To exercise these rights, contact our Grievance Officer at the details in Section 16. Requests will be processed within 30 days or as required by law.
We maintain reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, misuse, or destruction. In the event of a personal data breach, we will:
The security measures described in this Policy are designed to reduce the risk of unauthorised access or misuse of personal data, but no security measure can guarantee absolute security.
The App is designed for use by parents to manage information and activities relating to their children. Children do not create independent accounts on the App.
A child profile may be created only by a parent through the parent-managed registration process described in Section 4. We do not knowingly process a child's personal data through a child-created account or independent child registration.
except where such processing is permitted by applicable law.
Where personal data relating to a child is processed through the App, the parent may exercise the applicable rights described in Section 13 on behalf of the child.
If we become aware that a child's personal data has been processed through the App without the required parental consent, we will take appropriate steps to address the situation, including deletion of the relevant personal data where required by applicable law.
For questions or concerns regarding the processing of a child's personal data, parents may contact our Grievance Officer using the details provided in Section 16.
CuddlyDuddly Private Limited
Name: Aranya Basu
Designation: Information Security Executive
Address: Globsyn Crystal, Tower 1, 4th Floor, Unit 3A, Salt Lake, Kolkata 700091
Email: [email protected]
For questions, concerns, or to exercise your rights under this Policy, please contact the Grievance Officer above. Requests will be acknowledged and processed within 30 days.
This Policy may be updated periodically to reflect legal, regulatory, or operational changes — including as further provisions of the DPDP Act and DPDP Rules, 2025 come into force. Updates will be communicated through the App.