Privacy and consent
How we keep children safe, in the same words a parent sees in the app. Recording is audio only, never video, and no note reaches a parent without the teacher checking it.
What every parent agrees to
This is shown once to every parent, on its own screen, before a child can be added. Changing a word means a new version, and every parent sees it again. The version in the app today is 2026-09-v1, and it is titled "Before we begin".
- Your child's classes are recorded as audio only, never video, so the app can write a note about what was taught.
- An AI drafts that note. The teacher checks it before you see it. Nothing about your child is shown to you without a teacher's confirmation, except the note itself if the teacher has not reviewed it within a day, and then it is marked as unreviewed.
- Recordings are deleted 30 days after the class. Notes stay with your child's profile until you delete them.
- You can turn recording off for any class, and you can delete a class, a child, or your whole account at any time from inside the app.
- Your child never has an account and never talks to the AI.
What we collect and why
| Data | Why | Where | How long | Who can see it |
|---|---|---|---|---|
| Parent name, email, timezone | Account and scheduling | Postgres (Supabase) | Account life | The parent; support on request |
| Child first name, birth date, languages at home | The child's profile and age-appropriate content | Postgres | Account life or until the parent deletes the child | The parent; the child's teachers see the first name only |
| Consent records | Proof of consent by version | Postgres | Account life | The parent |
| Classes, schedules, meeting links, invite tokens | Running the classes | Postgres | Class life | The parent; the accepted teacher |
| Sessions | Attendance and the record of what happened | Postgres | Session life | The parent; the class teacher |
| Audio recordings | The audio the transcript is made from | Private recordings bucket in Supabase Storage, region [to confirm] | Deleted 30 days after the class | Only the recorder. No parent, no teacher |
| Transcripts | The text the class note is written from | Postgres | Kept with the child until the child or the class is deleted | Only the recorder, never a parent |
Recording is audio only, never video.
Vendors that touch a class recording
Vexa
The bot vendor, hosted. It sends a bot into the class and holds the audio until the recorder fetches it. [How long Vexa itself keeps a file: to confirm from its terms.]
Deepgram
The transcription vendor. It receives the audio to produce the text. It never receives the child's name, the parent's name, or the meeting link.
Deletion
A parent deleting their account deletes the parent row; every child, consent, class and session under it cascades. Teachers keep their own profile. The deletion runbook is exercised monthly. Audio that belongs to a deleted class, child or account is removed from storage by the recorder's next housekeeping pass, within two hours.
one8nine FZCO, Dubai runs Parhai. Write to hello@parh.ai with any question about your child's data.