Privacy
The short version
The guardian holds the account for anyone under 18, and we collect nothing about a teen until their guardian has consented. We keep teen details deliberately minimal. We do not read your teen’s sessions. We do not sell data, and we do not use it for advertising. You can have everything deleted.
What we collect
- From the guardian: name, email address and password for the account, the consent records you sign, and payment details, which are handled by Stripe. Full card numbers never touch our systems.
- From the teen (only after guardian consent when under 18): first name, age band, suburb-level location, their questionnaire answers (interests, equipment, honest hours), and an email address for their own login.
- From the journey: brainstorm transcripts, the decisions made at each step, the business brief, and the sales the family logs.
How we use it
- To run the product: the research run, the brainstorms and the step-by-step plan all need the profile and journey content to work.
- To keep guardians informed: every brainstorm transcript is emailed to the guardian when the session ends, and safety alerts name the topic of a blocked message without quoting the teen.
- To keep teens safe: every message is checked by our safety system before it goes anywhere.
- To improve FirstGrand: we use counts and numbers only, never the content of anyone’s session. The next section says exactly what that means.
Do we read your teen’s sessions? No.
Nobody at FirstGrand reads a teen’s conversations to improve the product. We do not do it, and we do not ask for permission to do it. We used to offer an optional box for “anonymised excerpts” and we have removed it, because taking the name off a teen’s words does not really make them anonymous. A teenager in a named suburb, selling something particular to a club they belong to, is recognisable from the story alone.
To make FirstGrand better we use aggregate, non-identifying information instead. That means numbers, not words:
- How many research runs and brainstorms happen, and how many finish.
- What they cost us to run, and how long they take.
- Quality scores from our own testing, which runs against a small set of example journeys we wrote ourselves, with the consent of the family in them. Never yours.
- What broke: error rates and failures.
None of that includes anything your teen typed. There is no button anywhere in our systems that pulls a real family’s conversation into our testing, and our test suite fails if anyone tries to add one.
There is one exception, and it is about safety, not product. If the safety system blocks a message, we store a short piece of that blocked message (up to 500 characters) and someone at FirstGrand may read it, so we can check the safety system is working properly and act if a teen looks to be at risk. That applies only to messages that were blocked, never to the rest of the conversation. The guardian is told the topic of a blocked message, and their teen is not quoted back to them.
Separately, a guardian can always read their own teen’s transcripts. They are emailed when a session ends, and they are in Guardian corner. That is a guardian seeing their own child, which is the whole point, and it is not us reading anything.
Who processes it for us
We use a small set of service providers, each for one job: Stripe (payments), Supabase (database), Vercel (hosting), Anthropic (the AI provider that powers the research and the brainstorms), and Resend (email, including the transcript emails to guardians). Journey content is sent to the AI service only as needed to run your journey.
Deletion
The guardian can request deletion of the whole family account from Guardian corner. The account deactivates straight away, the data purge follows, and we email confirmation when it is done.
Contact
Questions about your data: contact address to be confirmed before launch.