Back to home

Privacy Policy for Jabba (United Kingdom)

Last updated: 22 July 2026 · Version uk-1.0

This is the UK version. It is written for users in the United Kingdom and is governed by the UK GDPR and the Data Protection Act 2018. If you are in Denmark, a separate Danish policy applies.

In short

Jabba is an app for the home schooling of a single child. It is developed and operated by Cognition Software ApS. We make money by providing the app itself to you — never by selling, renting, or exploiting your child's information.

So we make three simple promises:

  • We never sell data. Neither your nor your child's information is sold, rented, or shared for marketing purposes.
  • No ads and no ad tracking. There are no ads in the app and no third-party ad tracking. The app itself doesn't use analytics tools by default — you can turn it on, but it stays off until you do (see section 11 on cookies and analytics).
  • We collect as little as possible. The app is built "local-first" and stores only what's needed to help the child learn.

This policy explains what information the app processes, why we do it, who the information may be shared with, and what rights you have. We've written it to be understandable — including for a child old enough to read it — even without being a lawyer.

An important note on roles: Cognition Software ApS provides and operates Jabba and decides how and why the child's information is processed. Cognition Software ApS is therefore the legal "data controller". The companies that provide the technology behind the app (see the section on sub-processors) are "data processors" who may only process data on our instructions. As a parent/guardian you are not a data controller — you act as the child's guardian, safeguarding the child's rights and giving consent on the child's behalf (see section 9).

1. Who is the data controller?

The data controller for the processing of the child's and the parents' information is:

  • Company: Cognition Software ApS
  • Company reg. (Danish CVR): 45656462
  • Address: Griegsvej 249, 9200 Aalborg SV, Denmark
  • Email: privacy@cognitionsoftware.dk

If you have questions about how the child's information is processed, you can contact us at the email above.

UK representative (UK GDPR Article 27)

Because we are established outside the United Kingdom but offer Jabba to people in the UK, we are required under Article 27 of the UK GDPR to designate a representative in the UK, unless an exemption applies. Our UK representative acts as a point of contact for UK data subjects and the Information Commissioner's Office. You can reach our UK representative, or the controller directly, at privacy@cognitionsoftware.dk, and we will publish the representative's name and UK postal address here.

Data Protection Officer (DPO)

We have assessed whether we are required to appoint a Data Protection Officer under UK GDPR Art. 37. Although the app processes children's data and potentially special-category data (Art. 9) as a core activity, we assess — at the current scale — that the processing does not constitute "large scale" processing within the meaning of Art. 37, and that a DPO is therefore not legally required. We reassess this on an ongoing basis as the number of users grows, and will appoint a DPO (and update this section with contact details) if the requirements are triggered, or if we choose to do so voluntarily.


2. What information do we process?

About the child

  • Profile: First name or nickname (what we show in the app), role (child/"learner"), and year group / grade level, so the teaching hits the right level.
  • Interests: E.g. dance, music, or Roblox — so Jabba can make the teaching relevant.
  • How the child prefers to talk with Jabba: Whether the child prefers to type, speak, or both, plus break habits.
  • Screen and sound settings: Settings such as reduced motion, sound on/off, and font size.
  • Energy and mood: An input about the child's current energy level, so Jabba can adapt the tone. This is sent to the AI model as part of the conversation.
  • Conversations with Jabba: The child's written messages are stored, so the conversation can continue and be picked up again later.
  • Jabba's audio replies: When Jabba replies with voice, the audio file is stored privately so that you as parents can listen back to it afterwards (replay).
  • Pedagogical support profile: Settings about tone and strategies for calm/regulation, which you as parents set.
Fields we currently do not collect: The app has a technical field for the child's birth year (birth_year), but it is not collected in the current setup (the field is left empty). Year group / grade level, on the other hand, is collected (see "Profile" above).

Important note about the child's voice

When the child speaks to Jabba, the audio is converted to text immediately, and the raw recording is not stored with us — it is discarded right after it has been converted to text. We store only the text.

The raw audio is, however, sent to our speech-to-text provider (ElevenLabs or Google) to be turned into text, and is then discarded by us. How long the provider itself may retain the audio depends on their plan — see the section on sub-processors.

(Jabba's own audio replies are stored, however, so you can listen back — see above.)

Special-category information

If you as parents choose to note information about the child's diagnosis or sensory circumstances (sensory_notes) as part of the support profile, this may be special-category information under UK GDPR Art. 9 (e.g. health information).

Two things are important here:

  1. This information is NEVER sent to the AI model. Diagnosis and sensory notes are kept separate and are not passed to Jabba's "brain" (see sub-processors). Only a secure, limited subset of the support profile (e.g. desired tone) is used by the AI model.
  2. Processing special-category information requires explicit consent (Art. 9(2)(a)). You should only enter such information if you deliberately want to — otherwise leave the field empty (data minimisation).

About safety checks of the child's messages

Before a message is sent to the AI model, it is checked on our own server for signs that the child is in distress (see section 4). Because such a check can reveal matters about the child's health or mental state, we process potentially special-category information here under UK GDPR Art. 9. We do it solely to protect the child, the result is not passed on to third parties, and the scan itself happens on our own server.

About the parent/guardian

  • Login details: Email address and password (handled securely via Supabase Auth).
  • Role: Whether the account is a parent or a child.
  • Family access: If several guardians share access, members and roles (admin/editor/viewer) plus invitation codes are stored, so you can invite each other.

Technical data for operations

  • Login links and device activity: When you create a login link for the child, we store only a

hash of the one-time code plus its creation, expiry, and use times. To show where the child is signed in, we store a coarse device type, browser, operating system, a verified session ID, and login/last-active times. Guardians with access to the child can see this information. These records do not contain the full User-Agent, an exact hardware fingerprint, a raw IP address, or login tokens. Device names are therefore estimates.

  • Memory, so Jabba can remember: Selected text excerpts from conversations are stored together with "embeddings" (a mathematical representation that lets Jabba remember context). These embeddings are computed locally and are not sent to AI or third-party services; the text excerpts themselves are stored like all other data at Supabase (EU). They are not stored if a conversation is marked with a safety flag.
  • Usage metrics: To keep track of operations and costs, we store technical measures per interaction — e.g. number of tokens, number of speech seconds, and which model/provider was used. These measures are linked via the account to your family and thus to the child, so they count as personal data. But they are used only for operations and cost management — never to profile the child and never shared for marketing.

3. What do we use the information for — and on what basis?

Here is each purpose with the lawful basis for processing under the UK GDPR.

PurposeWhat it coversBasis for processing
Create and operate the accountLogin, profile, family access, delivery of the service itselfContract — Art. 6(1)(b) (the service agreement is between Cognition Software ApS and the parent/guardian)
AI teaching with JabbaSending the child's messages to the AI model to get responses tailored to the childConsent — Art. 6(1)(a) (parental consent given by the holder of parental responsibility)
Speech-to-text and text-to-speechConverting the child's speech to text and Jabba's replies to voiceConsent — Art. 6(1)(a)
Pedagogical support profile with special-category informationIf diagnosis/sensory notes are enteredExplicit consent — Art. 9(2)(a) (in addition to Art. 6)
Memory, so Jabba can rememberStoring excerpts + embeddings so Jabba remembers contextConsent — Art. 6(1)(a)
Safety check of the child's messages (distress detection)Scanning the message for signs of distress before it is passed onExplicit consent — Art. 9(2)(a) for the potentially special-category scan. In acute risk, where the child cannot consent on their own, the child's vital interests (Art. 6(1)(d) and Art. 9(2)(c)) may also be a basis.
Operations, security, and cost managementUsage metrics that are technically necessary to provide and operate the serviceContract — Art. 6(1)(b) (limited to what is strictly necessary to provide the service)
Secure login and device overviewOne-time links, session status, and the login/activity times shown to the parentContract — Art. 6(1)(b) (necessary for login, security, and account administration)

We do not rely on "legitimate interests" to process the child's data for AI or profiling. When children are involved, we choose consent as the basis for everything beyond what is strictly necessary to deliver the service itself.


4. The child's safety (safety check / distress detection)

The child's wellbeing comes first. The app therefore has a safety feature (distress detection — an automatic check for signs that the child is in distress):

  • The detection happens in two layers: a fixed check on our own server for unambiguous distress expressions (e.g. clear statements of self-harm), and an assessment by the AI model of whether the child is genuinely expressing distress. Stories, quotes, jokes, and ordinary questions are not flagged.
  • If detected, the child gets a pre-approved, calm response that, among other things, refers to Childline on 0800 1111 — never an improvised AI response.
  • At the same time, the parent/guardian (the account holder) gets an alert in the app and an email. The email contains what was said (the child's message and Jabba's reply), so the parent can follow along directly. Email is sent via our email provider (see section 5).
  • The feature is a per-child setting that is on by default. The parent can turn it off under the child's settings. Even when it is off, the child still gets the calm referral to Childline on an unambiguous distress expression; only the alert to the parent is not sent.
  • There is no external escalation — the information is not automatically passed on to authorities or other third parties.

This processing happens to protect the child, and conversations marked with a safety flag are not stored in the memory feature. Because the check can reveal sensitive matters, we process it on an Art. 9 basis (see section 3).

Jabba is not an emergency service. If a child is in immediate danger, call 999. For non-urgent health advice call NHS 111. Childline (0800 1111) offers free, confidential support for children and young people.

5. Who do we share information with? (Sub-processors)

For the app to function, we use a few technical providers ("sub-processors"). They may only process data on our instructions, and a data processing agreement (UK GDPR Art. 28) is in place with each of them. We do not permit the providers to use the child's content to train their own AI models — where a provider would do so by default (in practice only our voice provider), we turn training off in the account settings, so the child's data is not included in model training. No data is sold or used for advertising.

ProviderPurposeWhat data they receiveRegion
AWS (Amazon Bedrock — Google Gemma 4 31B)Jabba's "brain": generates responses in the conversation, creates schoolwork/activities, and produces daily summaries.The child's message text, conversation history, first name, interests, energy level, and a secure subset of the support profile (for tasks: subject/level; for summaries: the day's activity data). Not diagnosis/sensory notes.EU (Frankfurt, eu-central-1). AWS does not train on data, and the model provider (Google) receives nothing. "Zero Data Retention" is enabled (data_retention_mode=none), so the child's content is not stored in abuse logs or any other logs. Processing stays in the EU/EEA.
ElevenLabs (standard)Text-to-speech (Jabba's voice) and speech-to-textJabba's reply text (for speech) and the child's microphone audio (for text)USA. Transfer under the UK Extension to the EU–US Data Privacy Framework and/or the UK IDTA (see section 6). We have turned off model training on the account.
Google Cloud Speech-to-Text / Text-to-SpeechOptional provider of speech-to-text and text-to-speech. Not used for Jabba's "brain".The child's microphone audio and/or Jabba's reply textEU multi-region. Jabba's Google Cloud routes are fixed to Google's EU endpoints. Google states that data at rest and in use stays within Europe on this path.
Google Gemini API (speech)Separate alternative speech path; not the approved Google Cloud path and not Jabba's active "brain".The child's microphone audio and/or Jabba's reply text, if this provider is selectedUSA. Google does not train on paid-tier data. Transfer under the UK Extension to the EU-US Data Privacy Framework and/or the UK IDTA.
SupabaseDatabase, login, file storage, and sending parent alerts — stores all data mentioned aboveAll stored app data (profile, messages, audio replies, metrics, etc.) plus the contact address for alertsEU-hosted (Frankfurt, eu-central-1). Support access from the USA is covered by the UK IDTA / UK Addendum.
NetlifyHosting of the app itselfTechnical connection data for visitors (e.g. IP address)USA. Transfer under the UK Extension to the EU–US Data Privacy Framework and/or the UK IDTA.
Important note about region and AI training: Our database (Supabase), Jabba's AI brain (AWS Bedrock), and the approved Google Cloud speech path process data in the EU. ElevenLabs and Google Gemini are separate speech paths that process data in the USA. If Google Cloud fails, the current app can fall back to ElevenLabs when that key is configured; the switch is recorded technically. We discard the child's raw microphone audio immediately after transcription, and diagnosis or sensory notes are never shared with a speech provider.

6. International transfers (outside the UK)

Our database (Supabase) and Jabba's AI brain (AWS Bedrock) are hosted in the EU (Frankfurt). Transfers from the UK to the EU/EEA are covered by the UK's adequacy regulations for the EEA, so no additional safeguard is required for that processing — the child's conversation text, tasks, and summaries are processed in the EU/EEA.

Google Cloud speech is processed through Google's EU multi-region when that path answers. The child's audio may still be processed in the USA if ElevenLabs or Google Gemini is selected, or if Google Cloud falls back to ElevenLabs. Netlify (hosting) is American. Supabase stores all data in the EU (Frankfurt) but has an American parent company with possible support access from the USA; AWS likewise has an American parent company.

When personal data is transferred outside the UK, Chapter V of the UK GDPR requires a valid transfer mechanism. We rely on the following:

  • Google Cloud Speech-to-Text / Text-to-Speech: processing uses Google's EU multi-region and is covered by UK adequacy for the EEA. Google's DPA and transfer terms still govern any access or onward transfer outside the EEA.
  • ElevenLabs, Google Gemini (speech), Netlify: the UK Extension to the EU-US Data Privacy Framework where the provider is certified, supplemented or replaced where needed by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
  • Supabase and AWS: data is EU-resident and covered by UK adequacy for the EEA; the UK IDTA / UK Addendum covers any support access from the USA by the provider's parent company.

These transfers are supplemented by technical measures such as encryption, data minimisation (special-category notes are never sent out), and a Transfer Risk Assessment. You can get a copy of the safeguards by contacting us at privacy@cognitionsoftware.dk.


7. How long do we keep the information?

  • Profile, conversations, and support profile: Stored as long as you use the app, or until you delete them.
  • The child's raw microphone audio: Not stored with us — discarded right after conversion to text. (The provider's own retention depends on their plan — see section 5.)
  • Jabba's audio replies: Stored in a private store for parental replay and deleted automatically after 30 days via a scheduled cleanup.
  • Memory excerpts/embeddings: Stored to give Jabba context; not stored on a safety flag and deleted when you delete data.
  • Usage metrics: Stored for up to 12 months and used as long as we need them to keep track of operations and costs.
  • Login links and devices: Link audit information is kept for up to 30 days. An ended device

that is no longer remembered is kept for up to 90 days. Active or remembered devices are kept while needed for login and the device overview, or until the child/account is deleted.

You decide. As parents you can delete the child's data at any time (via the app's delete feature). If you want precise retention periods for a specific provider, these can be provided by the data controller.


8. Automated decisions and profiling

Jabba uses an AI model to create responses and tailor the teaching to the child's interests and level. This means the content is to some extent adapted automatically to the child.

However, no automated decisions with legal effect or similarly significant impact are made about the child (e.g. no automatic assessment that decides something important in the child's life), so Art. 22 UK GDPR is not engaged. The safety feature (distress detection) is a protection of the child and leads only to a calm response plus an alert to the parent — not to decisions about the child towards third parties.

The pedagogical support profile is controlled by you as parents, not by the AI model alone. In line with the ICO Age Appropriate Design Code, we do not use profiling to serve advertising or to nudge the child, and high-privacy settings apply by default.


9. Children's data, the Children's Code, and parental consent

Jabba is aimed at a single child and is used under the parents' responsibility. Children's information enjoys special protection under the UK GDPR.

  • The Children's Code: We design Jabba in line with the ICO's Age Appropriate Design Code. In practice: the best interests of the child come first; product analytics is off by default and never tied to the child; we minimise the data we collect; we do not profile the child for marketing or use nudge techniques; parents have oversight of the child's activity; and we write our information — including this policy — to be understandable.
  • Age of consent for online services in the UK: Under section 9 of the Data Protection Act 2018, a child can give their own consent to an online service from the age of 13. If the child is under 13, the consent must be given or authorised by the holder of parental responsibility.
  • Who consents: Jabba is used by a child under an adult's supervision, and with us it is always the parent/guardian with parental responsibility who creates the account and gives consent on the child's behalf. It must be a person with parental responsibility — not merely someone invited as an "editor" or "viewer" in the family feature.
  • When the child turns 13: The child can consent on their own to processing based on consent. The policy and the consents should be reviewed at that point.
  • Special-category information: If you choose to enter diagnosis/sensory notes, it requires explicit parental consent (Art. 9(2)(a)). Only enter such information if you deliberately want to.
  • Documentation of consent: When you give consent, we record who consented, what was consented to, when, and which version of the text was shown — so the consent can be documented.

10. How do we protect the information?

  • EU hosting: The database is located in an EU region.
  • Access control (RLS): The app uses "row level security", so the child can only see their own data, and guardians only see data corresponding to their role.
  • Private storage of audio: Jabba's audio replies are kept in a private store and accessed only via time-limited, signed links.
  • Data minimisation before AI: Only what is necessary is sent to the AI model; sensitive notes are never sent.
  • Secure login: Passwords are handled via Supabase Auth.
  • No tracking in the app by default: In the app only the necessary session cookie that keeps you signed in is used. Analytics is off by default and only runs if you turn it on yourself (see section 11).

11. Cookies and analytics

We never use ad cookies, and we never sell data. Our use of cookies on our public website is governed by the Privacy and Electronic Communications Regulations 2003 (PECR) and the UK GDPR. Here is exactly what we use — and when.

In the app itself (when the child or you are logged in) only the necessary session cookie via Supabase Auth is used, which keeps you signed in. It cannot be opted out of, as the app otherwise cannot log you in. There are no ad cookies.

Optional product analytics in the app: Under the family settings you can choose to turn on product analytics. It is off by default. If you turn it on, we use PostHog (hosted in the EU) to understand how the app is used, so we can improve it. It is entirely voluntary, and you can turn it off again at any time.

On our public website (getjabba.com — e.g. the front page and the homework-help and science pages) we use analytics cookies from PostHog (hosted in the EU) to see which pages visitors find useful. Under PECR these cookies are set only if you give consent in the cookie banner, the data is not tied to an account or to the child, and you can change your choice at any time. Read more in our cookie policy.


12. Your rights

As a data subject (the child, represented by parent/guardian, and the parent themselves) you have the right under the UK GDPR to:

  • Access — to be told what information is processed, and to get a copy.
  • Rectification — to have incorrect or incomplete information corrected.
  • Erasure ("the right to be forgotten") — to have information deleted. The app has a built-in delete feature for this.
  • Restriction — to have processing restricted in certain cases.
  • Objection — to object to processing.
  • Data portability — to have your data provided in a common, machine-readable format and transferred where technically possible.
  • To withdraw consent — where processing is based on consent, you can withdraw it at any time. It is as easy as giving it, and it does not affect the lawfulness of processing that happened before you withdrew your consent.

We answer your requests without undue delay and at the latest within 1 month (Art. 12). You can exercise your rights by contacting the data controller (see section 1) or using the app's built-in features to view and delete data.


13. Is it voluntary to provide the information?

Using Jabba is voluntary. But some information is necessary for the app to function:

  • Without email/login, an account cannot be created.
  • Without the child's first name and messages, Jabba cannot hold a conversation or teach.

If you choose not to provide this necessary information, the corresponding parts of the app cannot be used. The information based on consent (e.g. sensitive notes) is always voluntary.


14. Changes to this policy

We may update this privacy policy, e.g. if the app gets new features or if the rules change. The latest version is always shown in the app with an updated date at the top. If we want to process information for a new purpose, you will be informed first.


15. Complaint to the Information Commissioner's Office

If you are unhappy with how the child's or your information is processed, we would like to hear from you first — contact the data controller (section 1).

You also always have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO):

  • Information Commissioner's Office
  • Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
  • Helpline: 0303 123 1113
  • Web: www.ico.org.uk

If you have questions about this privacy policy, or wish to exercise your rights, you are always welcome to contact us at privacy@cognitionsoftware.dk.