Security Disclosure
Last Updated: June 1, 2026We believe in transparency regarding how WonderColor handles data security, particularly given that the app is designed for young children.
Offline-First Architecture
WonderColor's core security feature is its offline-first design. The app does not transmit user artwork, preferences, or any child-related data to external servers. This architectural decision eliminates the risk of remote data breaches for user content.
Local Data Storage
All user-created content is stored in the app's sandboxed local storage directory on the device. This data is not accessible to other apps and is protected by the device's operating system security model.
COPPA Compliance
WonderColor complies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children. There are no features that allow children to share personal information, create public profiles, or communicate with other users.
No In-App Purchases for Children
Any future in-app purchase flows will be gated behind a parental verification step to prevent unauthorized purchases by children.
Vulnerability Reporting
If you are a security researcher and believe you have found a vulnerability in WonderColor, please responsibly disclose it to us at security@scooplabs.tech. We take all reports seriously and will investigate them promptly.
Have questions about this policy?