Privacy Policy
Last updated: 24 February 2026
1. Data Controller
Bhapi (“we”, “us”, “our”) operates the bhapi.ai platform.
We are the data controller responsible for your personal data.
Data Protection Officer: contactus@bhapi.io
2. Data We Collect
| Category | Examples | Purpose |
| Account data | Email, display name, account type, hashed password |
Account creation and authentication |
| Group membership | Parent-child relationships, roles |
Access control and family/school/club structure |
| AI interaction metadata | Platform name, timestamp, session duration |
Usage monitoring and safety analysis |
| Risk events | Flagged content categories, severity, PII indicators |
Child safety alerting |
| Content excerpts | Partial AI prompts/responses when risk-flagged (detected personal identifiers masked) |
Guardian review of safety concerns |
| Spend data | LLM API costs, provider, token counts |
Budget monitoring and alerts |
| Billing data | Subscription plan, payment status (card details held by Stripe) |
Subscription management |
3. Lawful Basis for Processing
- Contract (GDPR Art. 6(1)(b)): Account data, billing, and service delivery.
- Legitimate interest (GDPR Art. 6(1)(f)): Safety monitoring of children’s AI usage
where the guardian has enrolled the child. We have conducted a balancing test confirming
that the child’s safety interest outweighs the privacy intrusion, given our data
minimisation measures.
- Consent (GDPR Art. 6(1)(a)): Processing of children’s data requires
verifiable guardian consent, enforced per jurisdiction (see Section 7).
- Legal obligation (GDPR Art. 6(1)(c)): Consent records, audit logs, and data
retention as required by COPPA, GDPR, and LGPD.
4. Data Minimisation
We follow the principle of data minimisation:
- Raw AI prompts and responses are not stored by default.
- Only content flagged by our safety engine is retained, and detected personal
identifiers within it (such as emails, phone numbers, ID and card numbers, and
postal addresses) are automatically masked before it is stored.
- Content excerpts are automatically deleted after 12 months.
- We collect only the minimum data necessary for each stated purpose.
5. Data Retention
| Data Type | Retention Period |
| Risk events and content excerpts | 12 months |
| Audit log entries | 24 months |
| Account data | Until account deletion |
| Consent records | Until withdrawal + 6 months |
| Spend records | 12 months |
| Session tokens | 24 hours (auto-expiry) |
When you delete your account, all associated data is deleted immediately via cascading
soft-delete, except where retention is required by law.
6. Your Rights (Data Subject Rights)
Under GDPR, you have the following rights:
- Access (Art. 15): Request a copy of your personal data.
- Rectification (Art. 16): Correct inaccurate personal data.
- Erasure (Art. 17): Request deletion of your personal data (“right to be forgotten”).
- Portability (Art. 20): Receive your data in a machine-readable format (ZIP export).
- Object (Art. 21): Object to processing based on legitimate interest.
- Restrict processing (Art. 18): Request limitation of processing.
- Withdraw consent (Art. 7(3)): Withdraw consent at any time without affecting
the lawfulness of prior processing.
To exercise these rights, use the compliance features in your dashboard or email
contactus@bhapi.io. We respond within 30 days.
7. Children’s Data
Bhapi processes children’s data for safety monitoring purposes. We comply with:
- COPPA (US): Verifiable parental consent required for children under 13.
- GDPR Article 8 (EU): Parental consent required for children under 16.
- LGPD Article 14 (Brazil): Parental consent required for children under 18.
- Australian Privacy Act: Parental consent required for children under 16.
Monitoring cannot begin until the guardian has provided consent for the specific child member.
Consent can be withdrawn at any time, which immediately stops data processing for that member.
8. International Transfers and Data Location
All Bhapi user data is hosted in the European Union (Frankfurt, Germany) on cloud
infrastructure operated by our provider, encrypted at rest.
- All user data (including data for users in Brazil and other regions) is stored in
EU data centres in Frankfurt. Bhapi does not operate data centres in other regions.
- Where a cross-border transfer of personal data is necessary, we rely on Standard
Contractual Clauses (SCCs) approved by the European Commission and, for Brazilian
personal data, on the international-transfer mechanisms permitted under the LGPD.
9. Third Parties
| Provider | Purpose | Data Shared |
| Stripe | Subscription billing | Email, subscription plan (no AI data) |
| SendGrid | Transactional email | Email address, display name |
| LLM providers (OpenAI, Anthropic, Google, Microsoft) |
Spend data synchronisation | API credentials only (no user content) |
| Cloud infrastructure (Render/GCP) | Hosting |
All data (encrypted at rest, DPA in place) |
We never sell personal data. We never share children’s data with advertisers.
10. Cookies
We use a single session cookie (bhapi_session) for authentication. This cookie is:
- HttpOnly: Not accessible to JavaScript.
- Secure: Only transmitted over HTTPS in production.
- SameSite=Lax: Protected against CSRF attacks.
We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
11. Security
We protect your data with:
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- LLM API credentials encrypted with Fernet/Cloud KMS
- bcrypt password hashing
- Rate limiting and brute-force protection
- Multi-tenant data isolation
- Annual penetration testing by CREST-certified providers
- Immutable audit logging
12. Changes to This Policy
We will notify you of material changes via email and update the “Last updated”
date. Continued use of the platform after notification constitutes acceptance.
13. Contact
For privacy inquiries: contactus@bhapi.io
For general support: contactus@bhapi.io