FamilyGPT ("we," "our," or "us") operates the FamilyGPT application and website. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. We are committed to protecting the privacy of all our users, especially children.
When you create an account, we collect your name, email address, and password (stored securely using industry-standard hashing). We use this to authenticate you and manage your family account.
Parents provide their children's first name, age, and optional interests when adding them to the platform. Children authenticate using simple login codes — no email or password is required from children.
We store conversation messages between children and the AI assistant. This data is used to provide the chat service, enable parental monitoring, and improve response quality through memory features. Children can enter free-text chat content that may include personal details they choose to share.
When uploads are enabled by a parent, children may submit images or PDFs for help. We process the image or extracted PDF text to check safety and answer the child's question.
We collect basic usage information such as message counts, session activity, and feature usage to enforce usage limits and improve our service.
We use your data to provide AI chat services tailored to your child's age and your family's values, enforce content moderation, and enable parental controls.
All messages are processed through our content moderation system to ensure age-appropriate interactions. Flagged content is stored for parental review.
With parental consent, we extract and store key facts from conversations (interests, preferences, learning style) to personalize the AI's responses for each child.
We may send you email notifications about flagged content, account security, or important service updates. You can control notification preferences in your settings.
FamilyGPT is designed for use by children under the direct supervision and consent of their parents or legal guardians. Only parents can create accounts and add children to the platform.
We collect only the minimum information necessary to provide our service. Children do not provide email addresses, phone numbers, or other personal contact information.
We do not use children's data for advertising purposes. We do not serve ads to children. We do not build advertising profiles based on children's activity.
Parents have full visibility into their children's conversations, can review flagged content, manage content filters, and delete their children's data at any time.
HTTPS/TLS protects data in transit. Parent passwords and password-reset tokens are hashed before storage. Child login codes and session tokens are stored as database credentials rather than one-way hashes.
Our application and database are hosted on secure cloud infrastructure with industry-standard security practices, access controls, and monitoring.
Access to user data is strictly limited. Parents can only access their own family's data. Children can only access their own conversations.
We will never sell, rent, or trade your personal information or your children's data to third parties for marketing or advertising purposes.
Chat messages, uploaded images, and extracted PDF text are sent to OpenAI to generate responses and run content-safety checks. Per-child OpenAI web search is enabled by default when configured and may use Bing grounding; parents can disable it. FamilyGPT disables provider-side response storage for these requests.
Messages, image bytes or extracted PDF text may be processed by moderation services to ensure safety. This processing is automated and used solely for content safety purposes.
When configured, Langfuse receives operational AI metadata such as model, call type, timing, and token usage for service diagnostics. Prompt and response recording is disabled for this telemetry path, and stable child, family, and conversation identifiers are excluded.
FamilyGPT stores diagnostic AI-call logs containing up to 10,000 characters of the full system prompt, recent chat context, and generated response. These logs may include serialized image bytes and child, family, and conversation identifiers. Administrative access is restricted, and there is no automatic retention schedule.
Google and Apple verify parent identity credentials and may return provider IDs, email, name, and profile image. Stripe and Apple process subscription payments. Amazon Simple Email Service delivers account and safety notifications.
The website does not load Google Analytics, Umami, or Microsoft Clarity scripts. These analytics and session replay scripts are disabled across public, parent, and child routes.
We may disclose information if required by law, court order, or to protect the safety of our users, particularly children.
Parents can review all conversation history, flagged content, and stored memories for their children through the parent dashboard.
Parents control content filter strictness, blocked categories, custom blocked words, and daily usage limits.
Parents can update their children's profiles, clear conversation memories, and modify family values and guidelines at any time.
Parents can request deletion of their family's data by contacting us at privacy@familygpt.chat. Account-linked database records are removed through the account deletion path. Separately stored diagnostic AI-call logs and uploaded files are not removed automatically, so request those records before deleting the account.
We retain your data for as long as your account is active and as needed to provide our services.
Account deletion removes the account-linked family, children's profiles, conversations, and memories from the application database. Separately stored diagnostic AI-call logs and uploaded files are not removed automatically.
We do not publish a verified fixed backup-retention period. If infrastructure backups contain deleted data, removal follows the configured backup lifecycle.
If you have questions about this privacy policy or our data practices, please contact us at privacy@familygpt.chat.
To request access to, correction of, or deletion of your data, email us at privacy@familygpt.chat with your account email address.
We may update this privacy policy from time to time. We will notify registered users of material changes via email. The "Last Updated" date at the top of this page indicates the most recent revision.