Privacy Policy

Last updated: 8 September 2026

1. Introduction

ParentWise ("we", "our", or "us") provides a day-to-day helper for parents: Child Hub, Curiosity, Play, and Learn. This policy explains how we collect, use, disclose, and safeguard personal data when you use the Service. We process personal data under the General Data Protection Regulation (GDPR) and related EU/UK rules, and we provide AI-interaction notices under Article 50 of the EU AI Act.

2. Data Controller

ParentWise is the data controller for personal data processed through the Service. Contact: privacy@parentwise.co.

TODO(legal): registered legal entity name, company number, and postal address.

TODO(legal): EU representative and Data Protection Officer (if required).

3. Information We Collect

3.1 Information You Provide

  • Account Information: Email address, name, and authentication credentials.
  • Profile Information: Parenting style preferences and other profile details you choose to provide.
  • Child Information: Names, ages or dates of birth, personality traits, challenges, helpers, contacts, activities, and related Child Hub fields that you enter.
  • Special-category (health) data: Fields in child_medical (conditions, medications, allergies, immunizations, measurements, clinician and insurance details, emergency notes) and files you upload to the child-documents storage bucket, which may include medical documents. This data is stored for your records and caregiver summaries. It is not sent to the AI model. Writes require a separately recorded explicit consent (purpose child_medical, with timestamp and policy version).
  • Chat and generation data: SOS messages, Play filters and outputs, Curiosity topics and follow-ups.
  • Payment Information: Processed by Stripe. We do not store full payment card numbers.

3.2 Automatically Collected Information

  • Usage Data: Session information, feature usage, and rate-limit counters needed to operate the Service.
  • Device Information: Browser type, operating system, and similar technical data.
  • Cookies and similar technologies: Strictly necessary cookies always; analytics tags (Google Tag Manager GTM-P23232KF / Google Analytics G-Y6R7N8K0HQ, Vercel Speed Insights) load only after you accept non-essential cookies. See the Cookie Policy.

4. Legal Basis for Processing (GDPR)

  • Contract (Art. 6(1)(b)): Creating an account, storing child profiles you enter, generating SOS/Play/Curiosity content, and providing paid features you subscribe to.
  • Consent (Art. 6(1)(a)): Non-essential cookies/analytics; optional marketing if we add it later.
  • Explicit consent (Art. 9(2)(a)): Special-category health data in child_medical and related document uploads. Consent is recorded with a timestamp and policy version and can be withdrawn. Without it, medical fields cannot be written.
  • Legitimate interests (Art. 6(1)(f)): Security, fraud prevention, and keeping the Service reliable.
  • Legal obligation (Art. 6(1)(c)): Where we must retain or disclose data to comply with law.

TODO(legal): confirm the legitimate-interest balancing test and any additional bases for children's data.

5. How We Use Your Information

  • To provide personalised parenting guidance through AI features (SOS, Play, Curiosity, and Learn)
  • To create and manage your account and Child Hub records
  • To process payments and subscriptions via Stripe
  • To operate, secure, and debug the Service
  • To communicate about the Service, security, and support
  • To comply with legal obligations

6. Data Sharing and Disclosure

We do not sell your personal data. Conversations and child data are disclosed to processors who help us run the Service. That is required for AI generation, hosting, payments, and (if you consent) analytics. The previous claim that this data is "never shared with third parties" was incorrect and is withdrawn.

6.1 Actual AI data flow

Browser → Supabase (Auth, Postgres, Edge Functions; region: eu-west-1, project xztzvzwlyfceexwkphaw) → ParentWise edge function (chat, play, or curiosity) → contracted model provider (primary, with automatic fallback on 5xx/timeout). TODO(legal): confirm the production primary and fallback provider identities and whether they retain prompts or use them for training.

The outbound model payload includes child age, personality traits, stated challenges, helper notes where present, and conversation or topic text. The child's real name is replaced with a stable non-identifying token before the model call. The token is re-substituted to the display name in the app when you view the result. Medical fields from child_medical are not included in the model payload.

TODO(legal): confirm whether the contracted model providers retain prompts, and whether they are used to train models. Until confirmed, assume processors may process prompts to fulfil the request and apply their own retention policies.

7. Subprocessors

The following organisations process personal data on our behalf. TODO(legal): executed DPAs / Standard Contractual Clauses for each processor.

ProcessorPurposeData categoriesRegion
SupabaseApplication database, authentication, edge functions, and file storage (including the child-documents bucket)Account data; child profiles; conversations; Child Hub records (including child_medical); uploaded documents that may include medical files; usage logsEU (eu-west-1); project xztzvzwlyfceexwkphaw
Contracted model providers (primary and fallback)Generate SOS, Play, Curiosity, and Learn model outputs via ParentWise edge functionsPrompts and conversation text; child age, personality traits, and stated challenges; pseudonymised child reference tokens (not the child's real name)TODO(legal): confirm the production primary and fallback provider identities, processing regions, and whether prompts are used for training
OpenAIText-to-speech for user-initiated read-aloud of generated contentText the parent chooses to read aloud (may include restored child names if the parent plays AI output after client-side re-substitution)TODO(legal): confirm OpenAI TTS processing region
StripeSubscription checkout, billing, and customer portalPayer identity, email, payment method tokens, subscription status. ParentWise does not store full card numbersTODO(legal): confirm Stripe account region / data localisation
Google Tag Manager (container GTM-P23232KF) and Google Analytics (G-Y6R7N8K0HQ)Marketing and usage analytics, loaded only after cookie consentDevice and usage data, pages viewed, cookie identifiers. Not child profiles or chat content from our application databaseTODO(legal): confirm Google Ads/Analytics transfer mechanism
VercelWeb hosting and optional Speed Insights performance telemetryRequest metadata, performance metrics; Speed Insights loads only after cookie consentTODO(legal): confirm Vercel deployment region

8. International Data Transfers

Some processors above may process data outside the European Economic Area. TODO(legal): list transfer tools actually in place (SCCs, adequacy decisions, or UK IDTA) per processor. We will not invent those instruments here.

9. Data Retention

Account deletion is available in the product and removes the auth user and associated application rows we can reach. TODO(legal): backup, log, payment, and processor retention periods — do not treat "30 days" as a confirmed figure.

10. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data.
  • Right to Rectification: Request correction of inaccurate data.
  • Right to Erasure: Request deletion of your personal data.
  • Right to Restrict Processing: Request limitation of processing your data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent, including special-category medical consent and analytics cookies. Withdrawal does not affect processing already carried out.

To exercise these rights, contact privacy@parentwise.co. TODO(legal): statutory response period and identity-verification process.

11. Data Security

We use HTTPS, authentication, and row-level security on application tables so that a signed-in parent can normally only access their own rows. No method of transmission over the Internet is 100% secure.

12. Children's Privacy and AI transparency

The Service is for parents and guardians. There is no child login. Information about children is provided by the parent to personalise guidance. SOS, Play, Curiosity, and Learn surfaces display a persistent notice that the user is interacting with an AI system (EU AI Act Art. 50).

We minimise data sent to model providers: the child's real name is not included in outbound model calls. Age, personality, and stated challenges still are, because they are used to tailor output.

TODO(legal): confirm age threshold copy (under 16 vs Member State variations) and parental-responsibility wording.

13. Supervisory Authority

If you are in the EU/EEA you may lodge a complaint with your local Data Protection Authority. TODO(legal): lead supervisory authority if one is designated.

14. Changes to This Policy

We may update this Privacy Policy. Material changes will be posted on this page with an updated date. TODO(legal): whether email notice is required for material changes.

15. Contact Us

Questions about this policy: privacy@parentwise.co