Privacy Policy

Privacy Policy

Last updated: July 02, 2026

This Privacy Policy describes how Cogni5 Inc ("the Company", "We", "Us" or "Our") collects, uses, and discloses information when You use the Talkido application, the Mio device, and our website (together, the "Service"), and tells You about Your privacy rights and how the law protects You.

Talkido is used by parents, caregivers, and educators. Children do not use the application directly; they play with the Mio device, and the Service processes the resulting usage data and presents statistics to the adult account holder. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

Interpretation and Definitions

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access the Service.

  • Application refers to Talkido, the software program provided by the Company.

  • Company ("the Company", "We", "Us" or "Our") refers to Cogni5 Inc, Delaware, with registered office at 8 The Green STE D, Dover, Delaware, County of Kent, 19901, USA.

  • Family Account means an Account created by a parent or caregiver for personal use with their own child.

  • Institutional Account means an Account created by or on behalf of a school, clinic, or other organization for use by educators or therapists.

  • Mio is the Bluetooth-connected device that children play with and that the Talkido Application works with.

  • Service refers to the Application, the Mio device, and the Website, together.

  • Service Provider means any third party that processes data on behalf of the Company to facilitate, provide, or analyze the Service.

  • Usage Data refers to data collected automatically from the use of the Service or its infrastructure.

  • Personal Data is any information that relates to an identified or identifiable individual.

  • Website refers to Talkido, accessible from https://talkido.com .

  • You means the individual (parent, caregiver, or educator) accessing or using the Service, or the institution on whose behalf they act.

Family Accounts and Institutional Accounts

The Service handles children's information differently depending on the account type:

  • Institutional Accounts do not collect children's names or other personally identifiable information about children. Educators and therapists use the Service with anonymous or institution-managed learner profiles, and the Company receives no child PII from Institutional Accounts.

  • Family Accounts may include limited information about a child, provided directly by the parent or caregiver with verifiable parental consent, as described below.

Compliance with FERPA and COPPA

We are committed to protecting the privacy of children and students, and we comply with the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA).

For Family Accounts, we require verifiable parental consent before collecting any personally identifiable information (PII) relating to a child under age 13. Consent is obtained from the parent or caregiver during account setup, before any child information is entered, and is confirmed through the parent's verified account email. We collect no information from children directly: all child-related information is provided by the adult account holder, and we never request more information about a child than is reasonably necessary to provide the Service.

Parents may consent to our collection and use of their child's information without consenting to its disclosure to third parties, except for disclosures to Service Providers that are necessary to operate the Service.

Parents, guardians, and schools have the right to review, update, or request deletion of children's or students' information at any time. Educational data generated by the Service (such as activity logs, accuracy, and engagement metrics) is only accessible to the account holder and, for Institutional Accounts, authorized institution members.

The operator collecting and maintaining information through the Service is Cogni5 Inc (contact details in the "Contact Us" section below). We do not share student information with third parties for advertising or commercial purposes, and we do not sell student or children's personal information.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using the Service, We may ask You to provide certain personally identifiable information, which may include: email address; first and last name; phone number; and address, state, province, ZIP/postal code and city (including shipping address for product delivery).

Information About a Child (Family Accounts Only)

On Family Accounts, the adult account holder provides limited information about the child, which may include the child's name and onboarding/diagnostic answers (for example, developmental questions such as whether the child tries to imitate sounds or voices). This information is used only to personalize the Service and present progress to the account holder, is kept under the account holder's control, and is never used for advertising.

Child data collected through use of the Mio device is limited to learning-activity logs (for example, correct and incorrect responses, time on task, and game levels). Institutional Accounts do not collect children's names or other child PII.

Payment Information

To facilitate purchases, we collect payment information such as your card number, expiration date, and security code. We do not store your card details on our servers; they are passed directly to our payment processor, Stripe ( https://stripe.com/privacy ). We retain only the card type (e.g., Visa, MasterCard) to confirm the method of payment.

Usage Data

Usage Data is collected automatically and may include Your device's IP address, browser or operating system type and version, the screens of the Service You visit, the time and duration of Your visits, unique device identifiers, and other diagnostic data.

Voice Recordings

Voice recordings in the Service are created by adult users (parents, caregivers, or educators). By default, all voice recordings are processed and stored locally on the device and are not collected or stored on our servers — no recording leaves the device unless a cloud feature is explicitly enabled by the user.

For Institutional Accounts, an optional, strictly opt-in cloud backup and sharing feature allows a user to upload recordings and share them with authorized institution members for educational purposes. This feature is off by default; it operates only when the user explicitly enables it, and such recordings are then stored securely in the cloud. Family Accounts do not include cloud storage of voice recordings. We do not knowingly collect or store recordings of children's voices, and recordings are intended to be created by adults only.

Analytics and Session Recording

We use PostHog, a product-analytics and session-replay service, to understand how the Application is used and to improve it. PostHog collects Usage Data (for example, screens visited, features used, approximate location derived from Your IP address, and device and diagnostic information) and records app sessions — a reconstruction of the on-screen interactions of the adult using the Application.

Text that could identify You or a child, including names, is masked on Your device before any recording is sent, so it never reaches PostHog. This data is processed and stored on PostHog's servers in the United States. Session recordings are retained for a limited period and then deleted automatically, and both analytics data and recordings are deleted when You delete Your account. This is separate from the voice recordings described above. For more information, see PostHog's Privacy Policy at https://posthog.com/privacy .

Cookies and Tracking Technologies

We use cookies and similar technologies to authenticate users, remember Your preferences (such as language), and analyze and improve the Service. You can instruct Your browser to refuse cookies, but some parts of the Service may not function properly without them.

Do Not Track

Some browsers offer a "Do Not Track" ("DNT") signal. There is currently no common industry standard for responding to DNT signals, and the Service does not currently respond to DNT browser signals. If a standard is established, we will update this policy and our practices accordingly.

Marketing Communications

We may send You promotional or marketing communications about the Service, such as product updates or offers. You can opt out of marketing communications at any time by using the unsubscribe link included in every such email or by contacting us at wecare@talkido.co. We will continue to send You non-promotional messages necessary to operate the Service (for example, order confirmations, security notices, and policy updates). We never send marketing communications to children.

Parental Rights and Choices

Parents and caregivers may review, correct, or delete any personal data collected from their child. Parents can revoke consent and request deletion of all associated data by contacting us at wecare@talkido.co.

Data Security

Safeguarding your information is a priority. We store data on secure cloud servers and use SSL/TLS encryption for communications between the Service and your devices, along with access controls and regular security assessments. No method of transmission or storage is 100% secure, but we use commercially acceptable means to protect your data.

If we become aware of a breach of security affecting Your Personal Data, we will notify You and the relevant authorities as required by applicable law, without undue delay.

Sharing of Data

We may share information in the following situations:

  • With Service Providers, such as Microsoft Azure (cloud hosting), MongoDB (database), Stripe (payments), shipping carriers (deliveries), and PostHog (analytics and session recording, as described above). Service Providers process data only on our behalf and under contractual obligations consistent with this Privacy Policy.

  • With authorized institution members, when a user of an Institutional Account explicitly opts in to share a recording.

  • For legal reasons, to comply with a legal obligation, respond to lawful requests by public authorities, or protect the rights, property, or safety of the Company, our users, or the public.

We do not sell your personal information, and we do not share student or children's information for advertising or commercial purposes.

Where Your Data Is Stored; International Data Transfer

The Service's application servers are hosted on Microsoft Azure, and Your data is stored in a MongoDB database located in the United States. Analytics data and session recordings collected by PostHog are stored on PostHog's servers in the United States.

Where data is transferred outside your jurisdiction, we take steps to ensure it is treated securely and in accordance with this Privacy Policy and applicable law.

Data Retention and Deletion

We retain account information and educational usage logs only for as long as reasonably necessary to provide the Service and support progress monitoring, and we do not retain personal data — including children's data — indefinitely.

  • Account deletion: When You delete Your account, we delete your associated data, including any child information on Family Accounts and the analytics data and session recordings held by our analytics provider.

  • Inactive accounts: If an account remains inactive for 2 years, we delete the account and its associated data. We will notify You by email before this deletion takes place, and You can keep Your account active simply by signing in.

  • Parental requests: Parents may request deletion of their child's data at any time, regardless of account status, by contacting us at wecare@talkido.co.

We may retain certain limited information where we have a legal obligation or lawful basis to do so (for example, transaction records required for tax and accounting purposes).

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date, and, where appropriate, via email or a prominent notice within the Service.

Contact Us

If you have any questions about this Privacy Policy, you can contact us:

  • By email: wecare@talkido.co

  • For data deletion requests: wecare@talkido.co

  • By phone: (360) 821 7605