top of page

Liaura Privacy Policy

Introduction

Publication date: 20/08/2026

Liaura Limited respects your privacy and is committed to protecting personal data, particularly information relating to children.

This Privacy Policy explains what personal data we collect through the Liaura website and mobile application, why we use it, how it may be shared, how long it is retained and the rights available to users, parents and guardians.

Liaura is designed for supervised use by children. We apply privacy-protective settings by default and seek to collect only the information reasonably necessary to provide a safe, useful and age-appropriate service.

This Privacy Policy applies wherever Liaura is made available. The particular features, consent requirements and verification methods available to a user may vary according to the user’s age, country or region and applicable local law.

Nothing in this Privacy Policy limits any rights provided by applicable data-protection, privacy, consumer-protection or children’s-safety laws.

What data we collect

The personal data we collect depends on who is using Liaura, the features being used and the permissions provided by a parent or guardian.

Parent and guardian information

We may collect:

  • name;

  • email address;

  • account and login information;

  • subscription and payment-status information;

  • communications with Liaura;

  • identity or adult-verification status;

  • parental-consent choices;

  • records showing when consent was provided, refused, changed or withdrawn; and

  • information voluntarily supplied when contacting us, participating in testing or providing feedback.

Child account and profile information

We may collect:

  • name or display name;

  • age, date of birth or age range;

  • country or region;

  • account and profile identifiers;

  • parent or guardian account association;

  • profile image or avatar;

  • approved friends and connections;

  • preferences, settings, badges and achievements; and

  • information required to provide age-appropriate features and parental controls.

We encourage the use of avatars or non-identifiable profile images. Where a parent or guardian uploads a recognisable image of a child, the image is used only for the permitted Liaura purposes and is visible only within the child’s approved network.

User-generated content

Depending on the features being used, we may process:

  • messages and chats;

  • posts and comments;

  • images;

  • audio and video;

  • reports;

  • reactions and other interactions; and

  • other content submitted through Liaura.

Moderation and safeguarding information

We may collect or generate:

  • reported or automatically flagged content;

  • risk indicators and moderation results;

  • incident categories, severity assessments and confidence scores;

  • safeguarding and moderator notes;

  • records of warnings, restrictions, content removals or account actions;

  • communications relating to an investigation; and

  • records showing how a safeguarding or moderation decision was made.

Technical and security information

We may collect:

  • internet protocol address;

  • device type and operating system;

  • browser or app version;

  • user-agent information;

  • account, device and session identifiers;

  • access dates and times;

  • request, diagnostic and event identifiers;

  • crash and error information; and

  • information associated with suspected misuse, fraud, security events or safeguarding incidents.

IP addresses and similar online identifiers may constitute personal data even where they do not directly identify someone by name.

Parental-consent and verification information

Where parental consent or adult verification is required, we may collect:

  • the child’s age or age range and country or region;

  • the parent or guardian’s email address;

  • the child account to which the request relates;

  • the Liaura features or processing activities for which permission is requested;

  • the parent or guardian’s consent choices;

  • the date and time of those choices;

  • confirmation that the person providing consent has been verified as an adult;

  • the verification status and method returned by our verification provider; and

  • technical and audit information needed to demonstrate that the process was completed.

Where Kids Web Services performs the verification, Liaura does not receive or retain the payment-card details, government identification numbers, identity-document images, photographs or face scans used to complete that verification.

How we use your data

We use personal data only where it is necessary to provide Liaura, protect users, secure the platform, meet our legal responsibilities or support the purposes described below.

Providing Liaura

We use personal data to:

  • create and manage parent, guardian and child accounts;

  • authenticate users and manage access;

  • provide messaging, social, learning and parental-control features;

  • manage approved connections and privacy settings;

  • administer subscriptions;

  • provide customer support; and

  • send essential account, service and safety communications.

For adult account holders, this processing may be necessary to perform our contract under Article 6(1)(b) UK GDPR.

When processing a child’s information to provide the supervised service, we generally rely on our legitimate interests under Article 6(1)(f), taking the child’s rights and best interests into account.

Safety, safeguarding and content moderation

We process user-generated content, account information and relevant technical information to:

  • identify content or behaviour that may present a safety or safeguarding risk;

  • detect potential grooming, bullying, self-harm, exploitation, fraud, harmful media and other breaches of Liaura’s rules;

  • prioritise reports and potential risks for review;

  • investigate safeguarding and security incidents;

  • protect children and other users from harm;

  • issue warnings, restrict access, remove content or take other appropriate action;

  • manage repeat or connected incidents;

  • maintain an evidence trail of safeguarding decisions; and

  • respond to lawful requests from regulators, law enforcement or child-protection authorities.

Our usual lawful basis for this processing is our legitimate interest in safeguarding children and operating a safe and secure service under Article 6(1)(f) UK GDPR.

Where processing is required by law, we rely on Article 6(1)(c).

We use safeguards including data minimisation, restricted access, security controls, retention limits and appropriate human oversight.

Automated moderation

Liaura uses automated technology to help identify content and behaviour that may present a safety or safeguarding risk.

This technology may analyse content and generate risk indicators, incident classifications or other moderation results. Automated systems help Liaura identify and prioritise possible risks, but they may occasionally produce an incorrect result.

Liaura does not make a final decision to suspend or permanently close an account solely on the basis of an automated Tuteliq result. A trained member of the Liaura team reviews the relevant information before such a decision is made.

Parents and guardians may ask us to review a moderation decision by contacting hello@liaura.app.

We will explain the outcome where doing so would not compromise another person’s privacy, safety or an active investigation.

Parental consent and adult verification

Depending on a child’s age, country or region, the features requested and applicable local laws or regulations, Liaura may need to obtain parental consent and verify that the person providing consent is an adult.

Where this is required, Liaura may send a parental-consent or adult-verification request through Kids Web Services.

We use parental-consent and verification information to:

  • determine whether parental consent or adult verification is required;

  • contact the parent or guardian identified for the child;

  • explain the features and processing activities for which permission is requested;

  • verify that the person providing consent is an adult;

  • record whether permission was granted, refused, changed or withdrawn;

  • enable only the features for which the required permission has been obtained;

  • prevent children from bypassing age-appropriate restrictions;

  • allow parents and guardians to manage their consent choices; and

  • demonstrate compliance with applicable children’s privacy and online-safety requirements.

Adult verification confirms that the person providing consent has been verified as an adult. The person is also required to confirm that they are the child’s parent or guardian or are otherwise authorised to provide the relevant permission.

Depending on the circumstances, we may rely on:

  • Article 6(1)(c) UK GDPR where processing is necessary to comply with a legal obligation;

  • Article 6(1)(f) where processing is necessary for our legitimate interests in safeguarding children, preventing misuse and providing an age-appropriate service; and

  • Article 6(1)(a) where we specifically request consent for an optional processing activity.

Acceptance of this Privacy Policy does not itself constitute parental consent.

Communications, testing and service development

We may use contact, feedback and participation information to:

  • communicate with parents, guardians, teachers or approved participants;

  • arrange and administer product testing;

  • collect and respond to feedback;

  • improve Liaura’s usability, accessibility, safety and functionality; and

  • provide required reports to funding or development partners.

Information provided to funding or evaluation partners is aggregated or anonymised wherever reasonably possible.

We do not provide identifiable children’s content for general funding, research or product-development reporting.

We rely on consent where we send optional marketing or research communications. Consent may be withdrawn at any time.

Legal and regulatory purposes

We may process personal data where necessary to:

  • comply with applicable laws, court orders and regulatory requirements;

  • respond to lawful requests from law enforcement, regulators or safeguarding authorities;

  • protect the vital interests of a child or another person;

  • investigate suspected unlawful activity;

  • establish, exercise or defend legal claims; or

  • demonstrate Liaura’s compliance with its safety and data-protection responsibilities.

Special-category and criminal-offence information

User content and safeguarding records may reveal sensitive information, including information about health, racial or ethnic origin, religion, sexuality or suspected unlawful activity.

Where we process special-category personal data, we identify both an Article 6 lawful basis and an applicable Article 9 condition.

Where its requirements are satisfied, this may include Article 9(2)(g) UK GDPR together with the safeguarding condition in paragraph 18 of Schedule 1 to the Data Protection Act 2018.

Other conditions may apply depending on the circumstances.

Where records contain criminal-offence information, we process that information only where an applicable legal condition permits us to do so.

We do not use children’s personal data for behavioural advertising, third-party marketing or unrelated profiling.

We do not sell personal data.

Who We Share Your Data With

We share personal data only where necessary to operate Liaura, protect users, meet our safeguarding responsibilities or comply with the law.

Tuteliq

We use Tuteliq AB, based in Sweden, as a data processor supporting automated content moderation and child-safety detection.

Depending on the feature being used, Tuteliq may process:

  • messages, posts, images, audio, video or other content submitted for safety analysis;

  • pseudonymous account, user, file or incident identifiers;

  • IP addresses and related technical metadata where included in a moderation request; and

  • moderation results such as risk categories, confidence scores, severity assessments and incident metadata.

Tuteliq analyses submitted content and returns a moderation result to Liaura.

Liaura remains responsible for deciding how that result is used and what action, if any, is taken.

Under Liaura’s contracted configuration, original content submitted to Tuteliq is processed in real time and deleted by Tuteliq after analysis. Tuteliq does not use Liaura content to train its models.

Tuteliq’s processing is hosted within the European Economic Area and is governed by a data-processing agreement and appropriate security requirements.

Information about Tuteliq’s infrastructure providers is available at:

https://tuteliq.ai/legal/subprocessors.html

Kids Web Services

Depending on a child’s age, location, requested features and applicable local rules or regulations, Liaura may use Kids Web Services to support parental-consent management and adult verification.

Kids Web Services is operated by Kids Web Services Ltd, a wholly owned subsidiary of Epic Games.

To begin the process, Liaura may provide KWS with:

  • the parent or guardian’s email address;

  • a pseudonymous child or account identifier;

  • the child’s country or region and applicable age category;

  • information identifying Liaura as the service requesting consent; and

  • the permissions for which parental consent is requested.

KWS may offer different verification methods depending on the parent or guardian’s country or region.

These methods may include payment-card verification, checks using government-issued identifiers, identity-document scanning or facial age-estimation or verification.

Information required for the selected method is collected directly by KWS or its verification provider.

Liaura does not receive payment-card numbers, government identification numbers, identity-document images, photographs or face scans used during the KWS verification process.

KWS returns information to Liaura confirming whether adult verification was completed and records the parent or guardian’s consent choices.

KWS states that payment-card details, government identification numbers, identity documents, photographs and face scans used for verification are deleted after the verification process.

KWS retains a cryptographically hashed version of the parent or guardian’s email address and basic verification information in its AgeGraph service. This allows the adult’s verified status to be recognised by other digital services using KWS without repeating the full verification process.

Because KWS determines certain purposes and methods relating to its verification and AgeGraph services, Kids Web Services Ltd may act as an independent or joint controller for parts of this processing.

Its use of that information is also governed by the KWS Privacy Policy:

https://www.kidswebservices.com/privacy-policy

 

Other service providers

We may also share necessary personal data with organisations providing:

  • cloud hosting, databases and storage;

  • payment and subscription processing;

  • transactional email and notifications;

  • security, error monitoring and technical support;

  • customer support;

  • professional legal, compliance or safeguarding advice; and

  • research, funding or service evaluation.

These providers may process personal data only for the relevant agreed purpose and subject to appropriate confidentiality, security and data-processing terms.

Authorities and safeguarding organisations

We may disclose relevant information to law enforcement, regulators, courts, safeguarding authorities or child-protection organisations where:

  • disclosure is required by law;

  • disclosure is necessary and proportionate to protect a child or another person;

  • it is required to investigate suspected unlawful activity; or

  • it is necessary to establish, exercise or defend legal claims.

We do not sell personal data or share children’s personal data for advertising, third-party marketing or unrelated commercial purposes.

International Transfers

Liaura aims to store and process personal data within the United Kingdom or European Economic Area.

Some service providers may process information in other countries.

Where personal data is transferred outside the United Kingdom or European Economic Area, we use an applicable legal safeguard, which may include:

  • a UK adequacy regulation;

  • an EU adequacy decision;

  • the UK International Data Transfer Agreement or UK Addendum;

  • EU Standard Contractual Clauses; or

  • another lawful transfer mechanism.

Further information about the safeguard applying to a particular transfer can be requested by contacting hello@liaura.app.

Data Security

Liaura uses appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, alteration, disclosure, misuse or unauthorised access.

These measures include, where appropriate:

  • encryption in transit and at rest;

  • role-based access controls;

  • database row-level security;

  • access logging and monitoring;

  • restricted access to safeguarding information;

  • security testing and vulnerability management;

  • incident-response procedures; and

  • contractual security requirements for service providers.

Only authorised people and systems may access personal data where access is necessary for their role or function.

No online service can guarantee absolute security. Liaura reviews and improves its safeguards in proportion to the sensitivity of the information and the risks to children and other users.

Data Retention

We retain personal data only for as long as it is necessary for the purpose for which it was collected, to protect users or to meet applicable legal, safeguarding or regulatory requirements.

Account and profile information

Account and profile information is normally retained while the account remains active.

When an account is deleted, we promptly delete information that is no longer required, including profile images, stickers, themes, badges and cosmetic display information, subject to backup-deletion cycles and any documented safeguarding or legal exception.

User-generated content

Messages, posts and other user-generated content are normally deleted when the associated account or content is deleted, unless the information forms part of a moderation, safeguarding, legal or security record that Liaura is permitted or required to retain.

Moderation and safeguarding incidents

A moderation or safeguarding incident record may be retained for up to one year from the date the incident is closed.

An incident record may include:

  • relevant reported or flagged content;

  • moderation results and risk indicators;

  • account or pseudonymous user identifiers;

  • IP addresses and related technical information;

  • timestamps;

  • safeguarding or moderator notes;

  • communications relating to the investigation; and

  • actions taken and the reasons for those actions.

At the end of the one-year period, the record is deleted or irreversibly anonymised unless continued retention is legally required or is necessary and proportionate for an active investigation, legal claim or documented ongoing safeguarding risk.

Any extended retention must be specifically documented, access-restricted and periodically reviewed.

IP addresses and technical logs

Routine IP-address, access and security logs that are not associated with an incident are retained for no longer than one year from collection.

We may delete or anonymise them sooner where they are no longer necessary.

Where technical information is necessary evidence relating to a safeguarding, fraud, abuse or security incident, it may form part of the relevant one-year incident record.

Tuteliq processing

Under Liaura’s contracted configuration, original content submitted to Tuteliq is processed in real time and deleted by Tuteliq after analysis.

Moderation and incident results returned to Liaura may be retained by Liaura for up to one year in accordance with the incident-retention provisions above.

Parental-consent records

Liaura retains records showing whether parental permission was granted, refused, changed or withdrawn while the child’s account remains active and for up to one year after the account is closed or the most recent consent decision, whichever is later.

These records may include the requested permissions, consent status, adult-verification status, timestamps and associated account identifiers.

They do not contain the payment-card details, government identification numbers, identity-document images, photographs or face scans used by KWS.

At the end of the applicable period, the record is deleted or irreversibly anonymised unless continued retention is legally required or necessary for an active regulatory matter or legal claim.

KWS applies its own retention periods to the hashed email address and verification information it holds within AgeGraph.

Parents and guardians may contact KWS or follow the instructions supplied by KWS to request removal from AgeGraph.

Identity and age-verification documents

Where KWS performs adult verification, Liaura does not ordinarily receive or retain the underlying identity document, payment-card information, government identification number, photograph or face scan.

Any identity or age-verification documents previously collected directly by Liaura may be retained for up to five years after account closure only where continued retention is necessary to:

  • evidence lawful identity or age verification;

  • demonstrate compliance with safeguarding requirements;

  • respond to legal, regulatory or child-protection enquiries; or

  • establish, exercise or defend legal claims.

Where continued retention is not necessary, the information will be securely deleted sooner.

Legal preservation

We may temporarily suspend deletion where information is subject to a legal-preservation requirement, active regulatory request, court order or ongoing child-protection investigation.

The information will be deleted when the relevant requirement ends unless another lawful reason for retention applies.

Your Data-Protection Rights

Depending on where you live and the circumstances of the processing, you or your parent or guardian may have the right to:

  • ask whether we process your personal data;

  • receive a copy of your personal data;

  • correct inaccurate or incomplete information;

  • request deletion of personal data;

  • restrict how personal data is used;

  • object to processing based on legitimate interests;

  • receive certain information in a portable format;

  • withdraw consent where processing is based on consent; and

  • ask for human review of an automated moderation result that materially affects an account.

These rights are not absolute.

We may need to retain or restrict access to information where deletion or disclosure would create a safeguarding risk, prejudice an investigation, affect another person’s rights or conflict with a legal obligation.

To exercise a right, contact hello@liaura.app.

We may need to verify the identity and authority of the person making the request. We will respond within the period required by applicable law.

Managing parental consent

Parents and guardians may review, change or withdraw their Liaura consent choices through the available parent controls or by contacting hello@liaura.app.

Withdrawing consent does not affect processing that was lawful before withdrawal.

Withdrawal may mean that the child can no longer access a feature that requires parental permission.

Requests concerning information held independently by KWS or its AgeGraph service should be made directly to KWS using the contact information provided during verification.

Complaints

You may complain to the Information Commissioner’s Office:

Website: https://ico.org.uk

Telephone: +44 (0)303 123 1113

Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

If you live outside the United Kingdom, you may also have the right to complain to the data-protection authority responsible for your country or region.

Cookies, Analytics and Similar Technologies

Our website and app may use cookies, device identifiers and similar technologies to provide essential functionality, maintain security, remember settings and understand how Liaura is used.

Information collected through these technologies may include IP addresses, device identifiers, browser or app information and usage events.

This information may constitute personal data even where it does not directly identify someone by name.

Where consent is legally required for a cookie or similar technology, we will request consent before using it.

Essential security and service technologies may be used without consent where the law permits.

Further information is available through Liaura’s Cookie Notice and consent controls.

Third Party Services and Links

Liaura may provide links or secure redirects to approved third-party services where necessary to provide a feature to a parent or guardian.

For example, a parent or guardian may be securely redirected to KWS to complete adult verification and manage parental consent.

Third-party services process information under their own privacy information where they act as independent or joint controllers.

Parents and guardians should review the relevant privacy information before submitting personal data to a third-party service.

Liaura does not provide unrestricted external links that allow child users to leave the protected child experience without appropriate controls.

Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in Liaura, our service providers, technology or applicable law.

We will publish the updated version with a revised effective date.

Where a change materially affects how we use children’s personal data, we will provide an appropriate notice to parents, guardians and affected users before the change takes effect where required.

Continued use of Liaura does not constitute consent to processing that legally requires consent.

Where new or renewed consent is required, we will request it separately.

Contact us

The controller responsible for the personal data described in this Privacy Policy is:

Liaura Limited

Company number: 16228737

Capital House

272 Manchester Road

Droylsden

Manchester

M43 6PW

United Kingdom

Email: hello@liaura.app

Data-protection contact

Questions about this Privacy Policy, data-protection rights or Liaura’s use of personal data can be sent to:

Email: hello@liaura.app

This Privacy Policy explains how Liaura processes personal data.

Using Liaura does not constitute consent to every activity described in this Privacy Policy. Where consent is the appropriate lawful basis, Liaura may request it separately and provide a way to withdraw it.

Your agreement

By using our platforms and submitting your data, you consent to this Privacy Policy and the processing of your information as described. Thank you for supporting Liaura.app and helping us create a safer, more engaging environment for young users.

bottom of page