Safety & Trust

Written for the person who has to say yes

You're vetting a tool that touches young people's data. Good. This page is the plain-English version of everything you need to check, and our Privacy Policy has the rest.

The short version
First names + points. That's the student record. Hosted on Supabase, EU region. No student-to-student contact of any kind. Delete everything, any time, yourself.
What we collect
Student first name (or nickname), so leaders know who's who.Points, streaks and coins the engagement record.Session answers what they typed during a study, visible to leaders.Leader accounts name, church email, role. Adults only.
What we never collect
No photos. There is no photo upload in the student schema at all.No dates of birth. We don't need them, so we don't ask.No contact details. No student emails, phone numbers or addresses, anywhere.This isn't a policy promise. The fields don't exist. We can't lose what we never collect.
Where it lives

Supabase, EU region. UK GDPR applies. Your church is the data controller; we're the processor, and we'll sign the paperwork that says so.

How moderation works

Students can only respond to what a leader presents. No open chat, no DMs, no student-to-student messaging, so the surface for misuse simply isn't there.

If you leave

Export your studies, delete your church, and every student record goes with it. No retention games, no "contact support to delete".

Still have questions? Good.

Bring your safeguarding lead. We'll walk through the data model on a call before you commit to anything.

Request a Pilot →Privacy Policy →