Avviso: questa pagina è mostrata in inglese. I nostri testi legali sono al momento disponibili solo in inglese e in portoghese (Brasile); non esiste ancora una traduzione in italiano.

Titolare del trattamento: Bhapi.

Responsabile della protezione dei dati (DPO): dpo@bhapi.io

Privacy Policy

Effective: 31 July 2026 · Version: privacy@2026.3

Pending counsel review: the wording of this notice is an engineering draft derived from what the software actually does. It has not been reviewed or approved by legal counsel.

1. Data Controller and Data Operator Roles

Bhapi (“we”, “us”, “our”) operates the bhapi.ai platform. Which role we hold depends on whose data it is:

If you have an account, the Privacy tab of your account settings shows the role recorded for it, and states plainly whether that role has actually been recorded or is only the role presumed from your account type. Where it has not been determined, it is shown as undetermined rather than assumed.

Data Protection Officer: dpo@bhapi.io

2. Data We Collect

CategoryExamplesPurpose
Account dataEmail, display name, account type, hashed passwordAccount creation and authentication
Guardian contactThe parent/guardian email used to request and record consentObtaining and recording verifiable guardian consent
Date of birthUsed to set the age tier and the consent thresholdAge-appropriate permissions and consent gating
AI interaction metadataPlatform name, timestamp, session durationUsage monitoring and safety analysis
AI conversation contentThe text of prompts and responses captured from monitored AI toolsSafety classification and guardian review
Risk eventsFlagged content categories, severity, PII indicatorsChild safety alerting
Social contentPosts, comments and attached media the child publishesPublishing the content and screening it for safety
Direct messagesThe text of messages the child sends and receivesDelivering the message and screening it for safety
Creative contentPrompts and generated output from the creative toolsDelivering the feature and screening output for safety
Media uploadsPhotos and video the child uploadsStoring the file and screening it for CSAM and other harm
Device activityScreen-time totals, app usage and location check-insScreen-time limits, schedules and location safety features
Billing dataSubscription plan, payment status (card details held by Stripe)Subscription management

Group membership (parent-child relationships and roles) and LLM spend data (API costs, provider, token counts) are also recorded, for access control and budget alerting respectively.

3. Lawful Basis for Processing

4. Data Minimisation and What We Store

We follow the principle of data minimisation. To be precise about what that does and does not mean:

5. Data Retention

Data typeRetention periodHow it is deleted
AI interaction records (platform, time, session)12 monthsPermanently deleted by the daily retention job
Risk events and safety classifications12 monthsPermanently deleted by the daily retention job
Content excerpts from flagged interactions12 monthsPermanently deleted by the daily retention job
Conversation summaries for guardians12 monthsPermanently deleted by the daily retention job
Safety alerts and notification history24 monthsPermanently deleted by the daily retention job
Compliance audit trail entries36 monthsPermanently deleted by the daily retention job
Sign-in sessions8 daysPermanently deleted by a scheduled cleanup job
AI spend recordsNo fixed period setDeleted when the account or member is erased
Consent recordsNo fixed period setKept as evidence of the lawful basis for processing
Account dataNo fixed period setDeleted when the account or member is erased
Content linked to a mandatory-reporting incidentNo fixed period setHeld under legal hold; duration not yet determined

The periods above are the platform defaults. A group administrator can shorten some of them, subject to regulatory minimums; the live values for your group are shown in Settings > Privacy.

When you delete your account, all associated data is deleted immediately via cascading soft-delete, except where retention is required by law.

6. Your Rights (Data Subject Rights)

Under GDPR, you have the following rights:

To exercise these rights, use the compliance features in your dashboard or email contactus@bhapi.io. We respond within 30 days.

7. Children’s Data

Bhapi processes children’s data for safety monitoring purposes. We comply with:

Monitoring cannot begin until the guardian has provided consent for the specific child member. Consent can be withdrawn at any time, which immediately stops data processing for that member.

8. International Transfers and Data Location

All Bhapi user data is hosted in the European Union (Frankfurt, Germany) on cloud infrastructure operated by our provider, encrypted at rest.

9. Third Parties

The table below is generated from the service integrations present in our code, so it lists who can actually receive data rather than a summary written by hand. The last column states plainly whether the provider receives content your child wrote.

ProviderPurposeData sharedReceives child content?
StripeSubscription billing and payment processing.Account holder email, subscription plan and payment status. No child data and no AI conversation data.No
SendGrid (Twilio)Delivery of transactional email: parental-consent notices, safety alerts, reports and account mail.Recipient email address, the child's display name, and the summary text of a safety alert (risk category and the classifier's reasoning).No
Twilio SMSSMS delivery of critical and high-severity safety alerts.Recipient phone number, the child's display name and a brief description of the risk that triggered the alert.No
Google Cloud (Vertex AI)Safety classification of AI conversations — deciding whether a conversation shows self-harm, grooming, bullying or other risk.The text of the child's AI conversation, sent for classification. Processing region is set by VERTEX_AI_LOCATION and currently defaults to us-central1 (United States).Yes
AnthropicGenerating the plain-language conversation summary a guardian reads in the dashboard.The full decrypted text of the child's AI conversation, plus the platform name. Verbatim quotes selected by the model are stored back onto the conversation summary.Yes
Microsoft PhotoDNAMandatory child sexual abuse material (CSAM) detection on uploaded images, run before any other moderation.Uploaded image URLs and perceptual image hashes.Yes
Hive / SensityDetection of deepfake and manipulated images and video.The media file or its URL submitted for analysis.Yes
YotiAge and identity verification used to verify a parent's consent.The verifying adult's identity document and selfie, and the returned age/identity assertion.No
Cloudflare (R2, Images, Stream)Storage, resizing and transcoding of uploaded photos and video.The uploaded media file itself and its object key.Yes
SentryApplication error monitoring.Stack traces, request paths and user/tenant identifiers attached to an error. Not a content pipeline.No
Google, Microsoft and Apple (sign-in)Single sign-on for adult account holders who choose it.The signing-in adult's email address and provider account identifier. Children do not sign in through these providers.No
LLM billing APIs (OpenAI, Anthropic, Google, Microsoft, xAI)Reading the account's own LLM spend so budget alerts can be raised. This is the billing/usage API only — it is a different integration from the safety and summarisation calls listed separately above.The account's own API credentials and aggregate usage/cost figures.No
Expo push notification serviceDelivering push notifications to the parent and child mobile apps.Device push token, the child's display name and the alert headline.No
Browser push services (Google, Mozilla, Apple)Delivering a browser push notification for a safety alert. The destination is whichever push service the guardian's own browser supplied when it subscribed, so there is no fixed hostname.The encrypted notification payload: the alert headline and the child's display name.No
School information systems (Clever, ClassLink, Canvas, PowerSchool)Importing a school roster when the school connects its student information system. Deprecated per the 2026-05-03 pivot and off unless the school configures it.Student name, school email, grade level and guardian email.No
Australian eSafety CommissionerStatutory complaint reporting in the Australian lane (deprecated market; off unless configured).The reported content reference and incident metadata.Yes
RenderCloud hosting and the managed PostgreSQL/Redis that store the platform's data.All platform data, including stored AI conversation content, encrypted at rest in the Frankfurt (EU) region.Yes

CSAM reporting: when our system detects suspected child sexual abuse material, the content is blocked and the incident is recorded for human review. Automated transmission to the NCMEC CyberTipline is implemented in code but switched off pending a legal decision on the reporting destination — no data is sent to NCMEC today.

The second table adds where each recipient sits, and covers two further groups: the biometric processors used for age and identity checks, and the recipients we must disclose even though there is no consent switch for them.

ProviderPurpose and data sharedWhere it is sent
StripePayment processing for subscription billing. Receives the guardian's billing information only, not the child's data.api.stripe.com (US / EU)
SendGrid (Twilio)Email delivery for safety alerts, reports and account notifications. May include the child's display name.api.sendgrid.com (US)
Twilio SMSSMS delivery for urgent safety alerts. May include a brief risk description.api.twilio.com (US)
Google Cloud (Vertex AI)Content safety analysis (text toxicity, image safety, video). Processes AI conversation content for risk scoring.aiplatform.googleapis.com (US (us-central1 default))
AnthropicGenerating the plain-language conversation summary a guardian reads in the dashboard. The full decrypted text of the child's AI conversation, plus the platform name. Verbatim quotes selected by the model are stored back onto the conversation summary.api.anthropic.com (US)
Microsoft PhotoDNAMandatory child sexual abuse material (CSAM) detection on uploaded images, run before any other moderation. Uploaded image URLs and perceptual image hashes.api.microsoftmoderator.com (US)
Hive / SensityDeepfake detection. Processes media shared in AI conversations to detect manipulated images and videos.api.thehive.ai, api.sensity.ai (US / EU)
YotiAge and identity verification. Processes identity documents and a facial-liveness capture — the guardian's when verifying parental consent, and the member's when age verification is run against a member.api.yoti.com (UK / EU)
Cloudflare (R2, Images, Stream)Storage, resizing and transcoding of uploaded photos and video. The uploaded media file itself and its object key.r2.cloudflarestorage.com, api.cloudflare.com, imagedelivery.net (Global (Cloudflare))
SentryApplication error monitoring. Stack traces, request paths and user/tenant identifiers attached to an error. Not a content pipeline.sentry.io, ingest.sentry.io (US / EU)
Google, Microsoft and Apple (sign-in)Single sign-on for adult account holders who choose it. The signing-in adult's email address and provider account identifier. Children do not sign in through these providers.oauth2.googleapis.com, accounts.google.com, www.googleapis.com, login.microsoftonline.com, graph.microsoft.com, appleid.apple.com, admin.googleapis.com (US)
LLM billing APIs (OpenAI, Anthropic, Google, Microsoft, xAI)Reading the account's own LLM spend so budget alerts can be raised. This is the billing/usage API only — it is a different integration from the safety and summarisation calls listed separately above. The account's own API credentials and aggregate usage/cost figures.api.openai.com, cloudbilling.googleapis.com, management.azure.com, api.x.ai (US)
Expo push notification serviceDelivering push notifications to the parent and child mobile apps. Device push token, the child's display name and the alert headline.exp.host (US)
Browser push services (Google, Mozilla, Apple)Delivering a browser push notification for a safety alert. The destination is whichever push service the guardian's own browser supplied when it subscribed, so there is no fixed hostname. The encrypted notification payload: the alert headline and the child's display name.unknown (browser-supplied endpoint)
School information systems (Clever, ClassLink, Canvas, PowerSchool)Importing a school roster when the school connects its student information system. Deprecated per the 2026-05-03 pivot and off unless the school configures it. Student name, school email, grade level and guardian email.api.clever.com, nodeapi.classlink.com, canvas.instructure.com, powerschool.example.com (US)
Australian eSafety CommissionerStatutory complaint reporting in the Australian lane (deprecated market; off unless configured). The reported content reference and incident metadata.api.esafety.gov.au (AU)
RenderCloud hosting. All data is stored encrypted on servers in the Frankfurt (EU) region.api.render.com (EU (Frankfurt))
Yoti (yoti_liveness)Age and identity verification — facial-liveness capture and identity-document images.api.yoti.com
Microsoft PhotoDNA (photodna)Detection of known child sexual abuse material — perceptual hash or URL of the uploaded image.api.microsoftmoderator.com
Hive (hive_image)Sexual-content and violence classification before publication — URL of the uploaded image.api.thehive.ai
Hive (hive_deepfake)Manipulated-media (deepfake) detection — URL of images and video shared in monitored conversations.api.thehive.ai
Sensity (sensity_deepfake)Manipulated-media (deepfake) detection — URL of images and video shared in monitored conversations.api.sensity.ai
Google Cloud AI (google_vision)Content safety classification — conversation content and media.Google Cloud AI (Vision / Video Intelligence)
LLM providers (OpenAI, Anthropic, Google, Microsoft)Synchronisation of AI spend data. API credentials and usage totals only, no conversation content.Provider spend/billing APIs (US)
Cloud infrastructure (Render / Google Cloud)Hosting and storage of platform data.Render, Frankfurt (EU) / Google Cloud

Some of these providers process biometric or biometric-adjacent data (face liveness, identity documents, image and video analysis, perceptual hashing). Child-safety scanning for known illegal material cannot be switched off.

We never sell personal data. We never share children’s data with advertisers.

10. Cookies

We use a single session cookie (bhapi_session) for authentication. This cookie is:

We do not use tracking cookies, analytics cookies, or third-party advertising cookies.

11. Security

We protect your data with:

12. Changes to This Policy

Every version of this notice carries a version identifier and an effective date at the top of the page, and the same values are published in machine-readable form at /legal/versions. When the notice changes we publish it as a new version with a new identifier and effective date. The version in force when parental consent was collected is recorded against that consent record.

We do not send an email when a version changes: no such notification is built. Check the version and effective date at the top of this page for the notice currently in force.

13. Contact

Data Protection Officer: dpo@bhapi.io

For privacy inquiries: contactus@bhapi.io

For general support: contactus@bhapi.io