Skip to main content
Prifio

Prifio

Prifio Privacy Notice

This is a draft

We are still settling some details. Where one isn’t settled yet, you’ll see “(to be confirmed)”.

Version 0.7 · 2026-10-06 · Status: Draft for founder review

0.7: everything the export holds, and what it leaves out; how long each kind of record is kept; how we correct what's wrong; your name, product news, the do-not-email list, birth month and year, Stripe's US storage and the password check, described as they are.

This notice explains what Prifio collects about you and your family, why, and what you can do about it. It's written for the grown-ups — the guardians who hold the account. There's also a much shorter version written for children: Prifio, Explained for You.

What this notice covers

  1. Who we are
  2. The short version
  3. What we collect and why
  4. Our lawful bases
  5. Who processes data for us
  6. International transfers
  7. Retention — how long we keep things
  8. Your rights
  9. Children's information
  10. Cookies and similar storage
  11. Complaints
  12. Changes to this notice

1. Who we are

Prifio is a trading name of SectorSMART Ltd, a company registered in England & Wales, company number 17047477, registered office 95 Carlton Meadows, Llay, Wrexham, LL12 0QW. SectorSMART Ltd is the "controller" of the personal data described in this notice — the organisation legally responsible for deciding how and why it's used.

We are registered with the Information Commissioner's Office (ICO), the UK's independent regulator for data protection. (to be confirmed)

We haven't appointed a separate Data Protection Officer. Instead, the founder is the single named contact for every privacy question, request or concern:

  • Email: (to be confirmed)

Use that address for anything in this notice, including exercising any of the rights in section 8.

2. The short version

If you read nothing else on this page, read this.

  1. Your child never has an account. Only grown-ups (guardians) do.
  2. We store the minimum we possibly can about your child, and section 3 lists every single item we hold — there is no hidden extra.
  3. We never sell or share your family's data with anyone, for any reason.
  4. There are no adverts anywhere in Prifio. Not now, not later.
  5. There's no tracking and no analytics in the parts of Prifio your child uses.
  6. You can see what your child did in Prifio, the day after: notes written in advance by people, never a score. Your child is told, in words they can understand, that the people who look after them can see it.
  7. Your family's data is hosted and processed in the UK and the EU. The one exception, once paid plans exist, is our payment processor — section 6 says what goes where.
  8. You can export your family's data, or delete your account, yourself, at any time.
  9. If your child has two guardians, they stand as equals. Neither can see into a home the child isn't part of, and deleting one guardian's account never deletes the child's record while the other guardian remains.
  10. We'll tell you whenever something that matters about how we handle your data changes.
  11. If you're ever unhappy, you can complain to us, and then to the ICO.

3. What we collect and why

About you, the guardian

WhatWhy we need it
Email addressTo create your account, sign you in, and reach you about your family's account.
Your nameThe name you give when you sign up, so our support team can recognise your account if you contact us. Nobody else sees it — not even the other guardians in your family.
PasswordStored using argon2id, a strong one-way scrambling method. Nobody at Prifio — including us — can read your password back. It exists only to prove it's you.
Two-factor authentication details (optional)Only if you choose to add an extra layer of sign-in security. (Passkeys are not offered yet.)
Where you're signed inFor each browser you sign in on: a label like "Safari on iPad", the first part of its network address, and when you signed in and last used it — so you can see and sign out your devices, and so we can email you when a new one signs in. Never the browser's key: we keep only a scrambled form of it.
The emails you chooseWhether you want occasional product news — news about Prifio, such as new stages and features, sent only if you turn it on and confirm by email. It's off unless you turn it on. (A weekly summary is planned but not offered yet; when it is, it will never name your child or say what they did.)
A do-not-email entry, if there is oneIf an email to you bounces or is reported as spam, or you ask us to stop all email (section 8), we stop emailing your address and note why. We keep that note even after your account is deleted, so that we never write to the address again — your opt-out has to stick. If you asked us to stop, it lasts until you ask us to start again.
Legal-role claimThe role you tell us you hold in relation to the child — for example, parent or legal guardian. We record what you tell us in good faith; Prifio does not investigate or adjudicate family law, and never gives one guardian authority over another.
Billing referenceOnce paid plans exist (they don't yet — the beta is free), a reference from our payment processor, Stripe. Your card details are never seen, stored, or handled by Prifio directly — Stripe takes those.
A suspension, if there is oneOnly if we suspend your account for misuse (our Terms, section 5): when we did it, and the reason, which we email to you. A person decides, never an automated system. We remove both when the suspension is lifted.

Everything above is needed to provide the service, except two-factor authentication and product news, which are entirely optional.

If we invite you to the beta

While Prifio is tried out with a few families, creating an account needs an invitation. If we invite you, we keep your email address with the invitation, so that we can send it to you and check, when you sign up, that you are using the address it was sent to. The link in it works once, for that address only, for 14 days, and we keep only a scrambled form of it. When it is used, we note which account used it, and our records show it was used and from which network, as they do for other account events (section 7). We delete the invitation 30 days after it is used, withdrawn or out of date. If you delete your account, the invitation it was created from goes with it at once; any others we sent to your address go within the same 30 days. A guardian's invitation to join their family lets you sign up in the same way; nothing more is kept for that.

About your child

You, the guardian, give us this information directly when you set up your child's profile. None of it is collected from your child, and your child never fills in a form or answers a question themselves.

This is the complete list. Nothing else about your child is ever collected.

WhatWhy we need it
NicknameSo your child's world can greet them personally. It never has to be their legal name.
Badge choiceA picture your child picks to represent themselves. Purely decorative.
Age bandSo the content and pace fit your child. At beta launch there's one band, Egin (ages 4–5); more arrive as Prifio grows to cover ages 4–16.
Birth month and yearSo we can move your child on to the right stage when later stages arrive, without asking you again. For now every child is in one stage, Egin, so nothing uses them yet. We never store a full date of birth, anywhere.
World stateThe save of your child's world — which journeys they've helped with — so it's there when they come back.
Learning evidenceWhat your child did in an activity: which activity, the choices they made in order (for example 12, then 2), whether the hint was shown, and the date — never the time of day. We show it to you the day after, with our interpretation, how confident we are, and a suggested next step, written in advance by people — never a score, mark or grade, and never made up by AI. It waits a day so that it can never tell another guardian's home when your child played.

We don't collect, and will never ask you for: your child's photograph, school, home address, location, or anything written freely about them in their own words.

Devices you set up for your children

Your child never has an account. When you set up a tablet for your children, the tablet keeps its own key, and we store only a scrambled copy of it, the family it belongs to, which guardian set it up, and the dates it was set up, signed out and stops working (after a year). We don't record anything about the device itself — not its name, type or location, and not when it is used. Like every account event, setting it up is recorded with the first part of the network address it was set up from (section 7). Every guardian is emailed when a device is set up, and any guardian can sign out every device at once. We don't record which device, or which home, your child played in. (Like every website, our hosting provider keeps routine logs of requests for a short time, for security; a save from a tablet shows up there as a request, with its time. We never use those logs to see when your child plays.)

Technical information

  • Error reports. When something breaks, our error-monitoring tool (Sentry, hosted in the EU) captures a technical report so we can fix it. It's configured to scrub personal data before anything is stored.
  • Security logs. Records of sign-ins and similar account-security events, so we can detect abuse and keep accounts safe. See section 7 for how long these are kept. (Not yet in use: error monitoring will be added before launch, and this notice will be updated before it is.)

4. Our lawful bases

Under UK GDPR, we need a lawful basis for everything we do with personal data. Here's ours.

[PROPOSED, pending DPIA confirmation]

What we doLawful basis
Providing the Prifio service — accounts, your child's world, learning evidence, supportContract — necessary to provide the service you've signed up for.
Keeping Prifio secure — abuse detection, fraud prevention, security logsLegitimate interests — protecting our systems and your family, balanced against your rights. Our assessment of that balance is recorded in the DPIA.
Suspending an account that breaks our Terms — decided by a person, and you are told whyContract (the Terms you agreed to), and legitimate interests — keeping families and the service safe.
Inviting you to the beta, when you have asked to join itContract — steps you asked us to take before you sign up.
Sending product news, if you turn it on and confirmConsent — you can withdraw it at any time, from your email settings or the link in every one.
Checking a new password against passwords seen in data breachesLegitimate interests — keeping your account safe. Section 5 says what is sent, which is nothing that identifies you.

We don't use your data, or your child's, for any purpose beyond these. We don't use profiling or automated decision-making that has a legal or similarly significant effect on you or your child — in fact, we don't profile children at all, in any form (see section 9).

5. Who processes data for us

We use a small number of specialist providers to run Prifio. We don't hand your data to anyone beyond this list, and none of them may use it for their own purposes.

CategoryProviderRegionWhat for
Hosting & computeVercelLondon (UK)Runs the Prifio application.
DatabaseNeon (Postgres)London (UK)Stores your family's data.
Transactional emailAWS SESLondon (UK)Sends account and service emails. No tracking pixels, ever.
Error monitoring (planned — not yet in use)SentryEUTechnical error reports only, personal data scrubbed before storage.
PaymentsStripeUnited States, with UK safeguards (section 6)Processes card payments once billing launches. Card details never reach Prifio.
Password checkHave I Been Pwned (Pwned Passwords)GlobalWhen you choose a password, we check it hasn't appeared in a data breach. We send only the first five characters of a scrambled form of it (a SHA-1 hash) — never the password, never anything that identifies you — and compare the answer here.

Each provider will have a data processing agreement with us before it holds any family's data. (to be confirmed)

Beyond the providers listed above, Prifio loads no third-party scripts, fonts, or trackers of any kind.

6. International transfers

By design, we don't route your family's data outside the UK and EU. Every provider above that holds it was chosen because it offers a UK or EU hosting region, and that's where we've configured each one to run.

The exception is our payment processor. Once paid plans exist (the beta is free), Stripe will hold your name, email address and payment details in the United States, under the UK's safeguards for international transfers (the International Data Transfer Addendum to Stripe's data processing agreement). Your child's information never goes to Stripe. (to be confirmed)

One narrow, honest caveat: like most cloud platforms, our hosting provider (Vercel) runs some background "control-plane" systems — the infrastructure that manages deployments and configuration, not your family's data — on global infrastructure with US defaults. Your family's actual data lives in our database in London, and the application itself runs from London. We treat the control-plane point as a watch item, not a gap, and it's recorded in our internal risk documentation (the DPIA and processor register).

7. Retention — how long we keep things

The headline schedule:

WhatHow long
Your account and your child's profile, while activeFor as long as your account stays open.
Audit logs (records of significant account and security events, with the network each came from)24 months — except a few that are the record of something still here, while your account is open: who added each child's profile (while the profile exists), support's removal of a profile you added (while the family exists), and your acceptance of our Terms and your confirmation of product news; and who approved the Welsh children see (kept with it).
Where you're signed in90 days after a browser was last used.
Links we email you (to confirm your address or reset your password)30 days after they are used or run out.
An invitation to join a familyOne never accepted: 30 days after it is cancelled or runs out. One accepted: while both your accounts exist — it records who brought whom into the family, which we need to answer a safeguarding concern. Either way, deleted with your account.
A request to delete your account that you withdrew30 days.
A suspension's date and reasonOnly while the suspension stands — until it is lifted or the account is deleted; we review every suspension at least every three months. The audit log records that it happened, but not the reason's words.
An invitation to the betaDeleted 30 days after it is used, withdrawn or out of date.
Webhook payloads (technical event records from providers like our payment processor)90 days
Deleted accountsErased 14 days after you ask us to delete (section 8), except: a do-not-email entry, if your address has one (section 3); the audit log's entries about your account, with the network each came from — they no longer name you, but carry the reference number your account had, and each goes when it is 24 months old, as everyone's do; any other invitation to the beta we sent your address, which goes within 30 days (section 3); and our backups, which hold a copy for up to 30 days — if we ever restore one, we erase your account from it again before it is used.
Financial records6 years, because HMRC requires it.

This is the headline version. The full retention schedule, covering every category of data we hold, is at docs/compliance/retention.md.

8. Your rights

Under UK GDPR you have a set of rights over your own data, and over your child's, as their guardian. In plain words:

  • See what we hold (access). Use the export tool in your account, any time — no need to ask us first. It gives you everything we hold about you and your child, in two formats: a JSON file (complete and machine-readable) and a readable HTML page (open it like a webpage). That includes where you're signed in, your two-step and email choices, the links we emailed you, invitations to the beta and to a family, a subscription with Stripe's references for it, deletion requests, and the record of what you did and what was done to your account — with the network on what you did yourself, never on what our staff or anyone else did. One download holds the latest 5,000 entries of that record, and the latest 100 links we emailed you; if there are more, it says so, and we'll send you the rest. It also lists what it leaves out, and why: your password, two-step secret and recovery codes (we hold only scrambled forms, and even those would weaken your account), failed attempts to sign in and requests to reset your password (anyone who types your address can make one, and each holds the network of whoever made it; we keep them for 24 months to look into attacks), when our staff looked at your account (ask us, and we'll tell you, unless that could put a child at risk), and anything about another person. One thing waits a day: what your child did today is added to the export the next day, so that an export doesn't tell another home when your child played. The export says the last day it covers, and nothing is held back for longer than that. One thing can still show that your child played: the save of their world (which journeys they've helped with) changes when they play, so two exports taken some time apart show that your child played in between — not when, or in whose home.
  • Correct it (rectification). If anything's wrong, tell us. Once we've checked it's you, through your account, we can correct your child's nickname or birth month and year, your name, or the role you hold in the family; each correction is recorded, and when a child's details are corrected every guardian in the family is emailed (except one whose account we have suspended, who is told nothing of the family meanwhile).
  • Delete it (erasure). Delete your account from your account settings whenever you like. We hold it for 14 days in case you change your mind, then it's permanently and completely erased.
    • If your child has two guardians, deleting one guardian's account never deletes the child's profile or world while the other authorised guardian remains. The child's world stays exactly as it was.
  • Take it with you (portability). The same export tool covers this — your data, in a format you can move elsewhere.
  • Ask us to pause (restriction). If you dispute something we're doing, ask us to restrict processing while we sort it out, and we'll tell you what we can pause. We can stop every email to your address — the security ones too, such as the email that your password changed, so we'll agree that with you first — and we'll tell you before it starts again.
  • Object. You can object to processing we base on legitimate interests (section 4); tell us why and we'll consider it.
  • Withdraw consent. For product news, turn it off any time in your email settings, or use the link in every one — nothing else about your account changes.
  • Automated decisions. These rights don't come up in practice, because we don't make automated decisions about you or your child that have a legal or similarly significant effect, and we don't profile children at all.

To exercise any of these, email us (section 1). We'll normally respond within one month.

If your account is suspended, these rights still stand: you can't sign in, but you can email us for a copy of your data, or to have your account deleted.

If you can't sign in — you've lost access, or your account is suspended — ask us, and we'll check it's you. We can then email a link to your data to the address your account has already confirmed, never to another address. The link works once, within three days; if you use two-step verification it asks for your code as well; and our admin tools never show what's in it. We can also start your account's deletion, with the same 14 days to change your mind, and cancel a deletion we started if you ask. We email you whenever we do any of these, so you'd know if anyone asked in your name — which is also why we can't do them for an address that was never confirmed.

9. Children's information

The ICO's Children's Code (the Age Appropriate Design Code) sets out how services used by children should treat their data. Here's what that means in practice at Prifio:

  • High privacy by default. The most protective settings apply automatically. Your child never has to configure anything.
  • No profiling. We don't build a behavioural profile of your child, ever, in any form.
  • No nudge techniques. Nothing in Prifio is designed to keep your child engaged for longer than they want to be, or to pull them back in. No streaks, coins, leaderboards or timers exist anywhere in the product — this is a settled decision, checked automatically on every change we make (tests/policy/child-safety.test.ts). Sessions end naturally, when your child is done.
  • Minimisation. We only ever collect the short list in section 3. Nothing more, ever, without updating this notice first.
  • A notice your child can understand. There's a separate, much shorter explainer, written and voiced for a four- or five-year-old: Prifio, Explained for You.
  • Your child is told what you can see. You can read what your child did in each activity. On a tablet you've set up for them, your child's own explainer says, in Welsh, that the people who look after them can see what they did there (the Children's Code, standard 11). In the free taster nothing is recorded, so it isn't said.
  • Your child's privacy matters too. Children have a right to privacy of their own (the UN Convention on the Rights of the Child, article 16). The notes are there to help you help them learn, like a note home from a teacher. Please use them that way, and talk with your child about what they've been doing rather than checking up on them.

10. Cookies and similar storage

This is everything Prifio stores on your devices, or on a device you set up for your children. Nothing else is stored, and the list is checked automatically every time we change Prifio (tests/policy/storage-inventory.test.ts).

NameWhat kindWhat it's forHow long it lasts
prifio_sessionCookieKeeps you signed in.Until you sign out, after 12 hours unused, or after 30 days at most.
prifio_childCookieOn a device you set up for your children: the device's key to their world. It's only ever sent to the children's part of Prifio.It works until a guardian signs the device out, or for a year at most; a signed-out tablet may keep the useless key until the year is up.
prifio.cwm.soundStored in the browserOn your children's device, and only after someone presses the sound button: remembers whether sound is on or off on that device. It holds nothing else.Until it's cleared in the browser.
pf-shell-refreshedStored in the browser, for one tabOn guardian pages: stops a page from reloading itself over and over if your connection drops part of a request, and stops one account's details showing after someone else signs in.Deleted when you close the tab.

Each item is needed for Prifio to work the way you've asked it to, or remembers a choice someone made by pressing a button. None of it is used to track anyone, and there are no advertising cookies, analytics or third-party trackers. UK law only requires a cookie banner when a site stores things that aren't needed for the service you asked for. We don't, so there's nothing to ask your permission for, and nothing to click through.

11. Complaints

We hope you never need to, but if you're unhappy with how we've handled your family's data, tell us first: (to be confirmed). We'll do our best to put it right.

If you're still not satisfied, you have the right to complain to the Information Commissioner's Office (ICO), the UK's independent regulator for data protection:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113

12. Changes to this notice

This notice is versioned — the version number and date are always at the top. When we make a material change (anything that actually affects what we do with your family's data), we email every guardian to tell them directly, rather than quietly updating the page.

Version log

VersionDateChange
0.12026-07-27Initial draft for founder review.
0.22026-10-05Devices set up for your children; learning evidence described as it is now recorded.
0.32026-10-05What you can see about what your child did (notes the day after, never a score) and what your child is told about it (Children's Code standard 11); every cookie and stored item listed (it had said one cookie, but the device cookie arrived with 0.2); an export adds each day's activities the next day. No family had an account when this changed. From the beta, a change like this is emailed to every guardian (section 12).
0.42026-10-05If we suspend an account for misuse: what we keep (when, and the reason we email you), why, and for how long. No family had an account when this changed.
0.52026-10-06If you can't sign in: how we send you your data (a one-time link to your confirmed address) or start your deletion when you ask us. No family had an account when this changed.
0.62026-10-06If we invite you to the beta: what we keep with the invitation (your email address), why, on what basis, and for how long (30 days after it is used, withdrawn or out of date). Also: this page's version line now matches this log (it still said 0.3). No family had an account when this changed.
0.72026-10-06The export now holds everything we hold about you, and says what it leaves out and why; how long sessions, emailed links, family invitations and withdrawn deletion requests are kept, and the audit log's exceptions; how we correct what's wrong, and what pausing means. Described as they are: your name (seen only by our support team), where you're signed in, product news and its consent, the do-not-email list (kept after deletion), birth month and year (kept for later stages; nothing uses them yet), that two exports taken apart can show that your child played in between, Stripe's storage in the United States, and the password check. Also: the weekly summary is no longer offered (nothing sent it); setting up a tablet is recorded with the network it was set up from; other beta invitations to your address go within 30 days of your account; processing agreements are to be signed before the first family, not "in place"; a signed-out tablet may keep its useless key until the year is up. Removed: "language choice", which we never stored. The export's record of what you did shows a network only on what you did yourself, leaves out attempts anyone could make, and holds the latest 5,000 entries (more on request); it also holds the links we emailed you, invitations to the beta and Stripe's references. What an erasure leaves (the do-not-email entry, and the audit log's entries until they are 24 months old), said as it is. What we can pause on a restriction request: every email, the security ones too, by agreement — and that stop is on the do-not-email list until you ask us to lift it. What an erasure leaves includes other beta invitations to your address (up to 30 days) and our backups (up to 30 days). The latest 100 links we emailed you are in the export, the rest on request. No family had an account when this changed.