Aviso: esta página é apresentada em inglês. Os nossos textos legais estão disponíveis apenas em inglês e em português do Brasil; ainda não existe uma versão em português europeu.
Responsável pelo tratamento: Bhapi.
Encarregado de Proteção de Dados (EPD/DPO): dpo@bhapi.io
Effective: 31 July 2026 · Version: privacy@2026.3
Pending counsel review: the wording of this notice is an engineering draft derived from what the software actually does. It has not been reviewed or approved by legal counsel.
Bhapi (“we”, “us”, “our”) operates the bhapi.ai platform. Which role we hold depends on whose data it is:
If you have an account, the Privacy tab of your account settings shows the role recorded for it, and states plainly whether that role has actually been recorded or is only the role presumed from your account type. Where it has not been determined, it is shown as undetermined rather than assumed.
Data Protection Officer: dpo@bhapi.io
| Category | Examples | Purpose |
|---|---|---|
| Account data | Email, display name, account type, hashed password | Account creation and authentication |
| Guardian contact | The parent/guardian email used to request and record consent | Obtaining and recording verifiable guardian consent |
| Date of birth | Used to set the age tier and the consent threshold | Age-appropriate permissions and consent gating |
| AI interaction metadata | Platform name, timestamp, session duration | Usage monitoring and safety analysis |
| AI conversation content | The text of prompts and responses captured from monitored AI tools | Safety classification and guardian review |
| Risk events | Flagged content categories, severity, PII indicators | Child safety alerting |
| Social content | Posts, comments and attached media the child publishes | Publishing the content and screening it for safety |
| Direct messages | The text of messages the child sends and receives | Delivering the message and screening it for safety |
| Creative content | Prompts and generated output from the creative tools | Delivering the feature and screening output for safety |
| Media uploads | Photos and video the child uploads | Storing the file and screening it for CSAM and other harm |
| Device activity | Screen-time totals, app usage and location check-ins | Screen-time limits, schedules and location safety features |
| Billing data | Subscription plan, payment status (card details held by Stripe) | Subscription management |
Group membership (parent-child relationships and roles) and LLM spend data (API costs, provider, token counts) are also recorded, for access control and budget alerting respectively.
We follow the principle of data minimisation. To be precise about what that does and does not mean:
/capture/content endpoint they are stored encrypted (Fernet). Storage does not depend on the content having been flagged as risky.| Data type | Retention period | How it is deleted |
|---|---|---|
| AI interaction records (platform, time, session) | 12 months | Permanently deleted by the daily retention job |
| Risk events and safety classifications | 12 months | Permanently deleted by the daily retention job |
| Content excerpts from flagged interactions | 12 months | Permanently deleted by the daily retention job |
| Conversation summaries for guardians | 12 months | Permanently deleted by the daily retention job |
| Safety alerts and notification history | 24 months | Permanently deleted by the daily retention job |
| Compliance audit trail entries | 36 months | Permanently deleted by the daily retention job |
| Sign-in sessions | 8 days | Permanently deleted by a scheduled cleanup job |
| AI spend records | No fixed period set | Deleted when the account or member is erased |
| Consent records | No fixed period set | Kept as evidence of the lawful basis for processing |
| Account data | No fixed period set | Deleted when the account or member is erased |
| Content linked to a mandatory-reporting incident | No fixed period set | Held under legal hold; duration not yet determined |
The periods above are the platform defaults. A group administrator can shorten some of them, subject to regulatory minimums; the live values for your group are shown in Settings > Privacy.
When you delete your account, all associated data is deleted immediately via cascading soft-delete, except where retention is required by law.
Under GDPR, you have the following rights:
To exercise these rights, use the compliance features in your dashboard or email contactus@bhapi.io. We respond within 30 days.
Bhapi processes children’s data for safety monitoring purposes. We comply with:
Monitoring cannot begin until the guardian has provided consent for the specific child member. Consent can be withdrawn at any time, which immediately stops data processing for that member.
All Bhapi user data is hosted in the European Union (Frankfurt, Germany) on cloud infrastructure operated by our provider, encrypted at rest.
VERTEX_AI_LOCATION, which
currently defaults to us-central1 in the United States, and the
conversation-summary and image-safety providers listed in Section 9 are also
United States services. The “Receives child content?” column in
Section 9 shows which of these apply.The table below is generated from the service integrations present in our code, so it lists who can actually receive data rather than a summary written by hand. The last column states plainly whether the provider receives content your child wrote.
| Provider | Purpose | Data shared | Receives child content? |
|---|---|---|---|
| Stripe | Subscription billing and payment processing. | Account holder email, subscription plan and payment status. No child data and no AI conversation data. | No |
| SendGrid (Twilio) | Delivery of transactional email: parental-consent notices, safety alerts, reports and account mail. | Recipient email address, the child's display name, and the summary text of a safety alert (risk category and the classifier's reasoning). | No |
| Twilio SMS | SMS delivery of critical and high-severity safety alerts. | Recipient phone number, the child's display name and a brief description of the risk that triggered the alert. | No |
| Google Cloud (Vertex AI) | Safety classification of AI conversations — deciding whether a conversation shows self-harm, grooming, bullying or other risk. | The text of the child's AI conversation, sent for classification. Processing region is set by VERTEX_AI_LOCATION and currently defaults to us-central1 (United States). | Yes |
| Anthropic | Generating the plain-language conversation summary a guardian reads in the dashboard. | The full decrypted text of the child's AI conversation, plus the platform name. Verbatim quotes selected by the model are stored back onto the conversation summary. | Yes |
| Microsoft PhotoDNA | Mandatory child sexual abuse material (CSAM) detection on uploaded images, run before any other moderation. | Uploaded image URLs and perceptual image hashes. | Yes |
| Hive / Sensity | Detection of deepfake and manipulated images and video. | The media file or its URL submitted for analysis. | Yes |
| Yoti | Age and identity verification used to verify a parent's consent. | The verifying adult's identity document and selfie, and the returned age/identity assertion. | No |
| Cloudflare (R2, Images, Stream) | Storage, resizing and transcoding of uploaded photos and video. | The uploaded media file itself and its object key. | Yes |
| Sentry | Application error monitoring. | Stack traces, request paths and user/tenant identifiers attached to an error. Not a content pipeline. | No |
| Google, Microsoft and Apple (sign-in) | Single sign-on for adult account holders who choose it. | The signing-in adult's email address and provider account identifier. Children do not sign in through these providers. | No |
| LLM billing APIs (OpenAI, Anthropic, Google, Microsoft, xAI) | Reading the account's own LLM spend so budget alerts can be raised. This is the billing/usage API only — it is a different integration from the safety and summarisation calls listed separately above. | The account's own API credentials and aggregate usage/cost figures. | No |
| Expo push notification service | Delivering push notifications to the parent and child mobile apps. | Device push token, the child's display name and the alert headline. | No |
| Browser push services (Google, Mozilla, Apple) | Delivering a browser push notification for a safety alert. The destination is whichever push service the guardian's own browser supplied when it subscribed, so there is no fixed hostname. | The encrypted notification payload: the alert headline and the child's display name. | No |
| School information systems (Clever, ClassLink, Canvas, PowerSchool) | Importing a school roster when the school connects its student information system. Deprecated per the 2026-05-03 pivot and off unless the school configures it. | Student name, school email, grade level and guardian email. | No |
| Australian eSafety Commissioner | Statutory complaint reporting in the Australian lane (deprecated market; off unless configured). | The reported content reference and incident metadata. | Yes |
| Render | Cloud hosting and the managed PostgreSQL/Redis that store the platform's data. | All platform data, including stored AI conversation content, encrypted at rest in the Frankfurt (EU) region. | Yes |
CSAM reporting: when our system detects suspected child sexual abuse material, the content is blocked and the incident is recorded for human review. Automated transmission to the NCMEC CyberTipline is implemented in code but switched off pending a legal decision on the reporting destination — no data is sent to NCMEC today.
The second table adds where each recipient sits, and covers two further groups: the biometric processors used for age and identity checks, and the recipients we must disclose even though there is no consent switch for them.
| Provider | Purpose and data shared | Where it is sent |
|---|---|---|
| Stripe | Payment processing for subscription billing. Receives the guardian's billing information only, not the child's data. | api.stripe.com (US / EU) |
| SendGrid (Twilio) | Email delivery for safety alerts, reports and account notifications. May include the child's display name. | api.sendgrid.com (US) |
| Twilio SMS | SMS delivery for urgent safety alerts. May include a brief risk description. | api.twilio.com (US) |
| Google Cloud (Vertex AI) | Content safety analysis (text toxicity, image safety, video). Processes AI conversation content for risk scoring. | aiplatform.googleapis.com (US (us-central1 default)) |
| Anthropic | Generating the plain-language conversation summary a guardian reads in the dashboard. The full decrypted text of the child's AI conversation, plus the platform name. Verbatim quotes selected by the model are stored back onto the conversation summary. | api.anthropic.com (US) |
| Microsoft PhotoDNA | Mandatory child sexual abuse material (CSAM) detection on uploaded images, run before any other moderation. Uploaded image URLs and perceptual image hashes. | api.microsoftmoderator.com (US) |
| Hive / Sensity | Deepfake detection. Processes media shared in AI conversations to detect manipulated images and videos. | api.thehive.ai, api.sensity.ai (US / EU) |
| Yoti | Age and identity verification. Processes identity documents and a facial-liveness capture — the guardian's when verifying parental consent, and the member's when age verification is run against a member. | api.yoti.com (UK / EU) |
| Cloudflare (R2, Images, Stream) | Storage, resizing and transcoding of uploaded photos and video. The uploaded media file itself and its object key. | r2.cloudflarestorage.com, api.cloudflare.com, imagedelivery.net (Global (Cloudflare)) |
| Sentry | Application error monitoring. Stack traces, request paths and user/tenant identifiers attached to an error. Not a content pipeline. | sentry.io, ingest.sentry.io (US / EU) |
| Google, Microsoft and Apple (sign-in) | Single sign-on for adult account holders who choose it. The signing-in adult's email address and provider account identifier. Children do not sign in through these providers. | oauth2.googleapis.com, accounts.google.com, www.googleapis.com, login.microsoftonline.com, graph.microsoft.com, appleid.apple.com, admin.googleapis.com (US) |
| LLM billing APIs (OpenAI, Anthropic, Google, Microsoft, xAI) | Reading the account's own LLM spend so budget alerts can be raised. This is the billing/usage API only — it is a different integration from the safety and summarisation calls listed separately above. The account's own API credentials and aggregate usage/cost figures. | api.openai.com, cloudbilling.googleapis.com, management.azure.com, api.x.ai (US) |
| Expo push notification service | Delivering push notifications to the parent and child mobile apps. Device push token, the child's display name and the alert headline. | exp.host (US) |
| Browser push services (Google, Mozilla, Apple) | Delivering a browser push notification for a safety alert. The destination is whichever push service the guardian's own browser supplied when it subscribed, so there is no fixed hostname. The encrypted notification payload: the alert headline and the child's display name. | unknown (browser-supplied endpoint) |
| School information systems (Clever, ClassLink, Canvas, PowerSchool) | Importing a school roster when the school connects its student information system. Deprecated per the 2026-05-03 pivot and off unless the school configures it. Student name, school email, grade level and guardian email. | api.clever.com, nodeapi.classlink.com, canvas.instructure.com, powerschool.example.com (US) |
| Australian eSafety Commissioner | Statutory complaint reporting in the Australian lane (deprecated market; off unless configured). The reported content reference and incident metadata. | api.esafety.gov.au (AU) |
| Render | Cloud hosting. All data is stored encrypted on servers in the Frankfurt (EU) region. | api.render.com (EU (Frankfurt)) |
| Yoti (yoti_liveness) | Age and identity verification — facial-liveness capture and identity-document images. | api.yoti.com |
| Microsoft PhotoDNA (photodna) | Detection of known child sexual abuse material — perceptual hash or URL of the uploaded image. | api.microsoftmoderator.com |
| Hive (hive_image) | Sexual-content and violence classification before publication — URL of the uploaded image. | api.thehive.ai |
| Hive (hive_deepfake) | Manipulated-media (deepfake) detection — URL of images and video shared in monitored conversations. | api.thehive.ai |
| Sensity (sensity_deepfake) | Manipulated-media (deepfake) detection — URL of images and video shared in monitored conversations. | api.sensity.ai |
| Google Cloud AI (google_vision) | Content safety classification — conversation content and media. | Google Cloud AI (Vision / Video Intelligence) |
| LLM providers (OpenAI, Anthropic, Google, Microsoft) | Synchronisation of AI spend data. API credentials and usage totals only, no conversation content. | Provider spend/billing APIs (US) |
| Cloud infrastructure (Render / Google Cloud) | Hosting and storage of platform data. | Render, Frankfurt (EU) / Google Cloud |
Some of these providers process biometric or biometric-adjacent data (face liveness, identity documents, image and video analysis, perceptual hashing). Child-safety scanning for known illegal material cannot be switched off.
We never sell personal data. We never share children’s data with advertisers.
We use a single session cookie (bhapi_session) for authentication. This cookie is:
We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
We protect your data with:
Every version of this notice carries a version identifier and an effective date at the top of the page, and the same values are published in machine-readable form at /legal/versions. When the notice changes we publish it as a new version with a new identifier and effective date. The version in force when parental consent was collected is recorded against that consent record.
We do not send an email when a version changes: no such notification is built. Check the version and effective date at the top of this page for the notice currently in force.
Data Protection Officer: dpo@bhapi.io
For privacy inquiries: contactus@bhapi.io
For general support: contactus@bhapi.io