Privacy Policy
Last updated: 19 August 2026
Billy and the Wild Forest is operated by Global Solutions Management LLC, a Delaware limited liability company. Registered office: 16192 Coastal Highway, Lewes, Delaware 19958, United States. Company number CRN 10420698.
Billy and the Wild Forest is written for children aged roughly five to seven, but the accounts, purchases and admin all belong to grown-ups. This policy explains, in plain language, what personal information we handle, why, and what choices you have.
1. Who is responsible for your data
Billy and the Wild Forest is operated by Global Solutions Management LLC, a Delaware limited liability company. Registered office: 16192 Coastal Highway, Lewes, Delaware 19958, United States. Company number CRN 10420698. We are the controller of the personal data described here. You can reach us through our contact and support page.
2. Children: our design principle
- There are no child accounts, child sign-ins or child profiles.
- Accounts are held by adults aged 18 or over — a parent, legal guardian or responsible adult at home, or authorised staff at a school. We never ask a child to create an account or to give us login or contact details, and the account information we hold belongs to the grown-up account holder. When an account is created we store that adult's confirmation of age and authority, plus the date and version of the terms accepted. We aim to work in the spirit of children's privacy rules such as COPPA by not collecting children's data at all, but we do not claim any certification or formal approval.
- We never ask for a child's name, email address, date of birth, photograph, school class or location, and there is no field anywhere in the product to enter them.
- We do not build profiles of children and we do not advertise to anyone.
- We cannot promise that no technical identifier ever exists — a child reading on a grown-up's device shares that device's normal internet connection, so hosting and security infrastructure will process ordinary technical data such as an IP address (see section 5). We minimise this and never link it to a child's identity.
- If you believe information about a child has been sent to us by accident — for example in a support message — contact us and we will delete it.
3. Grown-up account data
- Sign-in: your email address and a securely hashed password. We never see or store your password in readable form. A magic email link is available as a backup sign-in method.
- Session and auth metadata handled by our authentication provider — session tokens, sign-in timestamps and security events.
- Access records: which stories your account has bought, membership plan and status, renewal dates, and the order records behind them.
- Legal acceptance records: when a grown-up creates an account, re-accepts an updated version of our documents, or confirms a purchase, we append a record holding the account id, the version of the terms and privacy policy accepted, the 18+ and authority confirmation, the kind of acceptance (account creation, re-acceptance or checkout) and the server timestamp. This is our evidence that an adult agreed. It contains no date of birth, no child details, no IP address and no device fingerprint, and it cannot be edited or deleted through the app — a later change appends a new record rather than rewriting the old one.
- Account activity: a lightweight "last seen" timestamp and the current in-app page, used for support and to spot problems. It is per adult account, not per child.
4. Schools
- School licences store the school (organisation) name, plan, pupil cap and the adult staff accounts attached to it, plus invite records used to add or revoke staff.
- School + Home stores parent or guardian adult accounts linked to that school's licence.
- We do not ask schools for pupil names, emails, dates of birth, photographs or profiles, and we do not create pupil logins.
5. Technical and infrastructure data
Like any website, our hosting, content delivery and security providers necessarily process technical data in order to serve pages and defend the service — for example IP address, approximate region derived from it, device and browser type, requested URLs, timestamps and error logs. This is used for delivery, security, abuse prevention and diagnosing faults, and is retained for short operational periods.
6. Storage in your browser
- Your chosen display language, and the Google Translate preference cookie if you use the translate control.
- Your storage / cookie acknowledgement.
- Guest reading position and reader preferences before you sign in.
- Sign-in session data, which is required for the service to work.
Paid access is never decided in your browser: entitlements, membership and school access are checked on our server. See cookies and storage.
7. Contact and support
When a grown-up sends a support message we store the name, email address, category and message, plus the time it was sent, so our team can read and answer it. Support messages are readable only by our operator team.
8. Payments
Payments are processed by Dodo Payments, which acts as Merchant of Record. Dodo is an independent business and an independent controller for the payment transaction, including billing, tax, fraud checks, refunds and chargebacks, under its own privacy policy and buyer terms. Card and bank details are entered on Dodo's secure checkout; we never receive or store full payment card details. We receive and keep order, subscription and status records (such as plan, amount, currency, provider references and renewal dates) so we can give your account the access you paid for.
9. Service providers we use
- Supabase — authentication, database and backend storage.
- Our hosting and content delivery platform — serving the site and its assets.
- Dodo Payments — payments as Merchant of Record.
- Google Translate — not loaded at all unless you use it. No request is made to Google when the site is simply opened in English. The translation engine is fetched only after you press the Translate control, or on later pages if you have already chosen a language and that preference is still active, in which case page text is sent to Google for display translation.
We do not add advertising networks, data brokers or cross-site tracking pixels.
10. Why we use your data, and on what basis
- To provide the service and your account — performing our contract with you.
- To fulfil purchases, licences and school access — performing our contract with you.
- To keep the service secure and prevent fraud or misuse — our legitimate interests.
- To answer support requests — our legitimate interests, and performing our contract.
- To meet legal, tax and accounting obligations — legal obligation.
We have not installed website analytics. If we ever add optional analytics, it will be off until you positively agree and the storage page will genuinely control it.
11. What we do not do
- We do not sell or rent personal information.
- We do not run targeted or behavioural advertising.
- We do not profile children or make automated decisions with legal effects about you.
12. International processing
We operate a global service, and our providers may process and store data in countries other than yours, including the United States and the European Union. Where personal data moves between countries we rely on our providers' contractual data protection commitments and take reasonable steps to keep the protection consistent with this policy.
13. How long we keep things
- Account and access records — while your account exists, so your purchases keep working.
- Order, subscription and tax records — for as long as accounting and legal obligations require, typically several years.
- Support messages — while needed to resolve your request and keep a reasonable service history.
- Technical and security logs — short operational periods set by our providers.
- Browser storage — until you clear it in your browser.
14. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to our use of your personal data, to receive a copy in a portable form, and to complain to your data protection authority. Contact us through the support page and we will respond within the time your law allows. Deleting an account removes access to purchased content; some transaction and legal records must be retained even after deletion.
15. Security
We use reasonable technical and organisational measures — encrypted connections, hashed passwords, server-side access checks, row-level database access rules and least-privilege admin access. No online service can promise perfect security, but we take this seriously and will act quickly if something goes wrong.
16. Changes
We may update this policy. The "last updated" date above will change, and material changes will be highlighted in the product.