Privacy Policy
Effective date: September 26, 2026
Operator: HavenLabs LLC, 922 E 670 N, Ogden, UT 84404, USA
Contact: support@firesideai.app
Fireside is a family AI assistant. A parent or guardian creates the account, sets the household's values and boundaries, and adds their children. Children then chat with the assistant, and every message and every picture passes through those boundaries before it reaches them.
This policy says what we collect, why, who sees it, how long we keep it, and what you can do about it. We have tried to write it so a parent can read it in five minutes.
The short version
- The parent owns the account. Children never create accounts, never give us an email address, and never agree to anything.
- We collect what the product needs and nothing for its own sake. No advertising, no analytics trackers, no selling or sharing of data for marketing. Ever.
- A child's chat is sent to our AI provider (OpenAI) to be screened and answered. We have applied to have OpenAI hold it for zero days; until that is granted, they hold it under their standard policy (see "Our providers").
- Parents can see what happened, delete a child's history, or delete everything. Deletion is immediate and complete.
What we collect
From the parent, when you sign up
- Your name and email address.
- Your password, stored only as a hash. We cannot read it.
- For each sign-in session: the IP address and the browser or app that signed in. This is standard session security so we can spot a stolen session; it is not used for anything else.
About your household, when you set it up
- The values you choose for each topic (bodies, dating, violence, faith, language, substances, money), any beliefs you describe, and the house rules you write. These are instructions to the assistant and they are stored as you wrote them.
- For each child: a first name (or nickname), an age, and a colour. We do not ask for a child's surname, birthday, photo, school, or anything else.
From a child, while they chat
- The messages the child types, and the assistant's replies.
- Pictures the child asks for, and the pictures that are generated.
- When each message was sent.
A child may type something personal into a chat: a friend's name, what happened at school. We do not ask for it and we do not extract it, but it is part of the transcript, and the transcript is stored and handled as described below.
Automatically, as the product works
- Safety records. For every turn, a record of what the safety layer decided (allowed, guided, redirected, blocked, or crisis), which rule or household setting applied, and whether a parent was notified. These records contain no message text. They are what the Notices page is built from.
- Device records. When you set up a child's phone, a token is created for that phone. We store a hash of it, the label you gave the phone, and when it was last used, so you can see and revoke it.
- Usage counts. For each child, a count of messages and pictures per day; for the household, a running total of what the day's AI use has cost us. Together they keep usage within the plan's daily allowance. Numbers only.
- Server logs. Errors and request paths for keeping the service running. Our logging is written so that message content never appears in a log.
What we deliberately do not collect
- No location. No contacts. No microphone or camera access. The app asks for no device permissions beyond the ones needed to run.
- No advertising identifiers, no analytics SDKs, no third-party trackers, in the app or on the website.
- No data from anyone under 18 except what is described above, through a parent's account.
Why we use it
| Data | Used for |
|---|---|
| Parent name and email | Signing in, verifying your address, password resets, and the safety notices described below. |
| Household values and rules | Shaping every one of the assistant's answers to your children. |
| Children's names and ages | Addressing the child, and setting age-appropriate limits. |
| Transcripts | Answering the child (the assistant needs the recent conversation for context), showing the child their own recent chat, and letting you review it. |
| Safety records | The Notices page; the emails that tell you something needed your attention. |
| Device records | Letting you see which phones are set up and revoke one. |
| Usage counts | Keeping each child's use within the plan's allowance. |
We do not use any of this to train AI models, to build profiles, to advertise, or to measure "engagement". We do not sell it and we do not share it for marketing.
Safety notices to parents
When the safety layer intervenes in a way you should know about (a child tries to talk the assistant out of its rules, a locked protection blocks something, a sensitive topic comes up, or a child says something that suggests they may be in danger) we record it and, for the serious cases, email you. The email says what kind of thing happened and which child; it never contains the child's words. If a child's message suggests they may be at risk of harming themselves, the assistant answers with the 988 Suicide & Crisis Lifeline and encourages them to talk to you, and you are notified.
A child can also report any answer themselves, from the answer itself. A report is recorded the same way, as a safety record without the words, and reaches you as a notice and an email.
Our providers
We run on a small number of services. Each receives only what its job needs.
| Provider | What it does | What it receives |
|---|---|---|
| OpenAI | Screens each message, writes the assistant's reply, reviews and generates pictures. | The child's message and the recent conversation, the household's settings as instructions, and pictures. Also a one-way hash of the household id (never a name or email) so OpenAI can flag abuse without knowing who you are. |
| Neon | Hosts our database. | Everything in "What we collect", encrypted in transit and at rest. |
| Vercel | Hosts the website and the service. | Requests and server logs (no message content). |
| Upstash | Holds the usage counters. | A household id, a child id and a number. |
| Resend | Sends our emails. | Your email address and the text of the email (never a child's words). |
| Apple App Store, Google Play, Expo | Distribute and update the app. | Standard app-store data governed by their own policies; nothing from inside your household. |
About OpenAI specifically. OpenAI's published policy for its API is not to train on what is sent to it, and to keep abuse-monitoring logs for up to 30 days (checked September 26, 2026). We have applied for zero data retention, under which OpenAI keeps nothing after answering. Until it is granted, the product is offered to families with children 13 and older.
How long we keep it
| Data | Kept for |
|---|---|
| Transcripts (messages and pictures) | 90 days, then deleted automatically (a job runs once a day). |
| Safety records (no content) | 12 months, so the Notices page has a history. |
| Account, household settings, children's profiles, device records | As long as the account exists. |
| Sign-in sessions | 30 days from last use. |
| Usage counts | About a day. |
| Server logs | One day, on our host's current plan. |
Delete a child: removing a child's profile deletes their transcripts, safety records and device tokens immediately.
Delete the account: deleting your account (Dashboard, Your account, with your password) deletes the household, every child, every transcript, every safety record and every device, at once. There is no soft delete and no recovery window. Backups held by our database provider expire within seven days.
What parents can do
- See what happened: the Notices page lists every intervention, without the child's words.
- Review a child's chat: from the dashboard, open a child. What you see follows their age: under 13, the whole conversation; 13 to 15, each exchange as a line (when, what it was about, how it was answered) without the words; 16 and over, only the alerts. The child is told the same thing under their own message box.
- Change the rules: values and house rules can be changed at any time and apply to the next message.
- Revoke a phone: a device you set up for a child can be revoked from the dashboard; the phone stops working immediately.
- Delete a child, or delete everything: described above.
- Ask us anything: support@firesideai.app. We answer within 5 business days.
Children
Children do not create accounts and cannot sign up. A child can use the product only on a device a parent has set up, inside a household a parent created. Creating the account and setting up a child is the parent's consent for us to collect, from that child, what is described in "From a child, while they chat", and nothing more.
We collect from a child only what is needed to answer them. We do not ask children for personal information, we do not let the assistant ask for it (sharing contact details or arranging to meet is one of the locked protections), and we never contact a child directly.
A parent can review the information collected from their child, have it deleted, or withdraw consent by deleting the child's profile or the account, at any time, as described above. We will not condition a child's use of the product on providing more information than is needed.
During our pilot the product is offered to families with children aged 13 and older.
Security
Passwords and device tokens are stored as hashes. All traffic is encrypted in transit. Secrets live on the server, never in the app. The safety layer runs on the server, so a modified app cannot turn it off. If we ever discover a breach affecting your data, we will tell you within 72 hours of confirming it.
Changes
If this policy changes in a way that matters, we will email the parent on the account before the change takes effect. The current version is always at firesideai.app/privacy.
Contact
HavenLabs LLC
922 E 670 N, Ogden, UT 84404, USA
support@firesideai.app
See also the Terms of Service.