Legal
Privacy
What is held about your family, which companies receive it, how long it is kept, and how to get a copy or have it removed.
Last updated 16 September 2026
The short version
You hold the account. Your child does not. Everything Kwechi knows about your child, an adult in your family typed in.
Almost nothing of your family's crosses to another family, and the database is what stops it, not the screens. There are exactly two deliberate exceptions, both about a published template, and both are set out below under "The two things that do cross to another family". Your child, your photographs, your recordings, your logs and your notes are not among them.
There is no advertising here, no tracking code and no analytics product. Nothing about your family is sold or shared with a data broker. We have never installed one.
Four companies hold part of your family's data, because the product cannot run without them: Supabase holds it, Vercel serves the pages, Anthropic answers when you ask the AI for something, and Resend sends the daily email.
Four more see a request without holding anything of yours. When a card carries a video or a picture, your browser fetches it from wherever it lives — Google for a YouTube still or player, the Wikimedia Foundation, Project Gutenberg or the Internet Archive for a picture or a book cover. They see your address and which page you are on, before you click anything. And when you tap a word in the reading view, Kwechi's own server asks the Wikimedia Foundation's dictionary for it, so the word travels but your address does not.
What each one gets is set out below, by name.
What Kwechi holds
About you
Your email address and your password, held by the sign-in service — Kwechi's own code never sees your password. Your name, and a display name and photograph if you add them. Your language, your time zone. Which family you belong to and in what role. When you last signed in.
If you invited another adult, their email address. An invitation nobody accepted is removed thirty days after it expires; an invitation that was accepted keeps the address on the record indefinitely, because nothing clears it.
If you turned on notifications, an address for each device you turned them on for, and a label you can read ("iPhone, Home Screen app").
Your family's name, your home languages, and — if you filled it in — where your family comes from. That last one is information about ethnic origin, and it is worth saying so out loud rather than burying it in a list.
About your child
His first name. His Igbo name, if he has been given one. His due date, which Kwechi asks for at the start, and his date of birth once you enter it. His sex. A photograph, if you add one. His languages and time zone. Free-text notes you write.
Then everything the product is for: his archetype and its weights, the philosophy you wrote and the beliefs you recorded, his plan and his timetable, his routines — when he sleeps, eats, naps and plays — what has been done and what has not, milestone notes you have ticked, language practice, training logs, and any badges or progress.
Some of those records are about his body. Training logs can carry how hard a session felt, whether something hurt and where, his mood, and how long he slept beforehand. There are places to record an injury, a physician's note, and height and weight. Those are health records about a child. They stay inside your family, and they are never sent to the AI.
What your family puts in
Voice recordings of your family saying words in your own language, with the speaker's label and dialect. Photographs. Notes. Files attached as evidence against a piece of work. Library items you add yourself.
Recordings can be of people who do not have an account here — a grandparent saying a word. Their voice is personal information about them, and you should have their agreement before you record it.
A child's surname, which can be stored here
There is no surname column on a child's record. But the founder's own set-up tool writes a child's full legal name into the free-text notes field, so a child's surname can be stored here, in notes, if someone types it there. It would be untrue to tell you that Kwechi never holds a child's surname, so we are not telling you that.
Who can see it inside your family
Roles decide it, and the database enforces the roles.
- An owner or a parent sees everything in the family. The person who created the family has the final say on the philosophy.
- A guardian has a parent's day-to-day editing rights: the archetype's weights, the schedule, the routines, the logs, the library, and a child's details. They cannot retire or delete a child's profile — that is the owner's and a parent's. They cannot write the philosophy or file a change to it.
- A carer records what happens: training and practice sessions, work marked done, milestone notes, the family's own recordings and words. They cannot change the archetype, cannot change the routines, and cannot change or delete a child's profile.
- A viewer reads.
Two qualifications worth having before you hand a role out. A guardian is a wide role — the weights, the schedule, the routines and the logs are all theirs; a carer is the narrow one. And the philosophy is kept off a guardian's screens by the interface. It is not hidden from them at the database level, so somebody determined, working outside the screens, could read it.
The two things that do cross to another family
Both are about the one archetype published as a platform template — the founder's own — and both were built on purpose, so the page will not describe them as accidents.
- A published template's philosophy can be read by any signed-in adult. The rule that hands out an archetype row makes an exception for a template published platform-wide, and the philosophy travels inside that row. If your family ever publishes a template, whatever you wrote as its philosophy is readable by every other family on Kwechi.
- The beliefs flagged for a template can be read by any signed-in adult, and are copied into the family that clones it. A belief marked "include in template", attached to a published platform template, is readable across families by design — so that a parent can see what they are about to receive — and the copying routine writes your words for that belief into their family: the belief itself, how to apply it, and the instruction it gives the AI.
Nothing else crosses. Not a child, not a photograph, not a recording, not a note, not a training log, not a progress record, not a belief you did not flag for a template, and not a philosophy on an archetype you did not publish. A family cannot publish its own template today — the database refuses it without an administrator — so today this describes exactly one archetype, the founder's.
Which companies receive it, and exactly what
Supabase — the database, the files and the sign-in
Everything above is stored here: the database, the private file stores, and the accounts. It runs on Amazon's servers in Northern Virginia, in the United States. If you live outside the United States, your family's data is still kept there.
Vercel — hosting
The app runs on Vercel, so every request you make passes through it: your IP address, your browser, the page you asked for, and your sign-in cookie. Vercel sees this the way any website's host sees it. No error-reporting or analytics package is installed on top of it.
Anthropic — the AI, when you ask it something
When Kwechi asks the AI for something, the request carries your child's first name, an internal identifier, his age in months (or roughly how many whole months until he is due), the phase he is in, the language pair, the strongest of his archetype weights, the philosophy you wrote, word for word (only when the person asking is the family's owner or a parent — a guardian's request does not carry it), up to twenty of your beliefs word for word, the date you asked on, and whatever you typed in your own words.
When you ask UGO a question, it also carries a small, chosen slice of your family's own record — never all of it, and never more than two of these at once: his timetable for that stretch of days and his sleep routines; the titles and minutes of the modules Kwechi would offer him at his age, with the last few blocks you marked done or skipped and their dates; the titles of the library items shelved for his age; or the names of the subjects, disciplines and character traits your family uses. Which slice is chosen is decided by what you asked, in code, before anything is sent, and the done-or-skipped blocks travel only with the module slice they belong to. If UGO thinks another slice would have helped, it says so and you press the button; nothing widens on its own. There is also a handful of counts — how many children are in the family, how many blocks are on today, how many library items sit in his age band — so that UGO does not describe a product you do not have. If you did not name a child on the question, none of the per-child parts are read at all, and UGO is told they were not read rather than being handed a zero.
It does not carry his surname, his date of birth, his due date, your address, a photograph or a health note. No clinical record of his goes: his training logs, his growth measurements, his injury notes and his load warnings are not among the things this request is built from, and the names of those columns are refused by name if anything ever tries to add one. That is partly the point — UGO can say honestly that it is not looking at your child's medical record, because it is not. That is not a sentence on a page: the code copies the permitted fields one at a time, and then a second check walks every block of your family's record that is about to be sent and refuses to send it if a forbidden field is anywhere inside it. The due date is refused as well as the date of birth, on the ground that it is the same fact stated in advance — and so is anything the same fact in another unit, such as weeks or days until he is due. A test feeds it a record stuffed with exactly those fields and proves none of them arrives.
One honest consequence of telling the AI what today is. Before he is born, the request carries today's date and roughly how many whole months are left. Those two together narrow his expected arrival to about a fortnight. That is less than the due date and more than nothing, and it is why the months are rounded rather than given in weeks or days.
The caveat you should have, and it is the one that matters most. That protection covers the named fields — the columns Kwechi reads from. It does not read your free text. If you type a surname, an address, a school, or a health detail such as "he has eczema" into a belief, into the philosophy, or into a message to the AI, it goes, word for word, because that is exactly what those boxes are for and Kwechi does not censor what you wrote about your own child. Nothing inspects it. So the paragraph above is a promise about your child's record, not about your own sentences: write in them what you want the AI to know, and nothing you would not.
Kwechi sends nothing to anyone for training a model. There is no such feature, no such export and no such setting. What Anthropic does with a request once it has it — including how long it keeps it — is governed by Anthropic's own terms, not by Kwechi, and this page will not make a promise on another company's behalf.
Resend — the daily email
If the daily email is on, Resend receives your email address, a subject line containing your child's first name, and a message body carrying his first name, his Igbo name, the day's plan and the Igbo phrase, plus your unsubscribe link. Resend therefore holds a child's first name tied to a parent's address, in its own logs. The daily email is not anonymous and we will not describe it that way.
An invitation email carries the invitee's address, your name, the family name and the link. It carries nothing about a child. How long Resend keeps either is set by Resend's own terms.
Google, in three separate ways
- Sign-in, only if you chose to sign in with Google. Google learns that you signed in and returns your email address and profile name.
- YouTube, when a card has a video. The still picture on the card is loaded straight from Google's servers when the page opens, before you click anything — so Google sees your IP address, your browser and the page you are on before you have decided to watch. Pressing play then loads Google's player. The player runs on the privacy-enhanced domain; Google says that mode stops views of an embedded video influencing what you are shown on YouTube. That is Google's description of Google's product, not something Kwechi can see or verify, and it does not mean nothing is sent. On play, Google receives your IP address, your browser, the video, the page you came from and what you did with the player, and if you are signed in to Google in that browser it knows who you are.
- Translation, which does not happen when you use the app. Google's translation service was called by the founder's own command-line tool while preparing the curriculum, on Kwechi's own module titles and summaries. No family data has ever gone to it, and the app does not call it.
The Wikimedia Foundation, Project Gutenberg and the Internet Archive
These hold nothing about your family. They see a request from your browser, the same way Google does for a YouTube still, and one of them receives a word you tapped.
- Pictures and book covers load from where they live. A card's picture can sit on the Wikimedia Foundation's servers, and a book's cover on Project Gutenberg's; one item's picture sits on the Internet Archive's. Those load when the page opens, before you click anything, so that server sees your IP address, your browser and the page you are on. Kwechi does not copy them onto its own servers, and that choice — which is about not rehosting other people's work — is the reason your browser has to ask them directly.
- A word you tap in the reading view goes to the Wikimedia Foundation's dictionary. Tapping a word in a book asks Wiktionary what it means. The request is made by Kwechi's own server, not by your browser, so what travels is the word and not your address. Wikimedia sees a word; it does not see who asked or which child is reading. If the word is already in your family's own list, nothing is sent at all.
Your browser's push service
If you turned on notifications, the message itself is encrypted end to end before it leaves, so Apple, Google, Mozilla or Microsoft carry ciphertext and cannot read the notification. What the service does see is which device it is for.
And nobody else
The list above is the whole list. There is no advertising network, no analytics, no customer-tracking tool, and no second AI vendor — Anthropic is the only model this product calls, and there is no code in it that calls another.
Cookies, and what stays in your browser
One cookie that matters: your sign-in session. Without it you would sign in on every page.
Your own browser also remembers a few small preferences on your own device — the theme you chose, the text size you read at, whether read-aloud mode is on, where you got to in a book, and a reading timer. They stay on that device. They never reach us and never reach anyone else.
How it is kept
All of it travels over encrypted connections. The file stores are private: nothing is served from a public address, and a photograph or a recording is reached only through a link that expires after ten minutes and is made fresh each time the page loads.
The child-mode PIN is stored only as a salted hash. Invitation links are stored only as a hash, so the link in the email exists nowhere in the database. Your password is never seen by this application at all.
One person can reach everything: the founder, through the database's own dashboard. There is no technical control that stops him and it would be dishonest to imply there is. The key that bypasses the security rules is used in exactly two places, both on the server, and is never in anything your browser downloads.
If something is exposed
Nothing here is a promise about how good the security is. This is what would happen if it failed.
You would be told. The founder is the only person who could find out, and there is no support desk between him and you. He would write to every adult in an affected family, say what was reached, when, and what it means for your child's records, and say what he had changed so it could not happen again.
How fast: within a few days of him knowing, not weeks, and sooner if the exposure is still open. That is an intention, not a contractual term. There is no monitoring product watching for this, so a breach could be found late.
How long it is kept
Very little expires on its own, and you should know which is which.
- Rate-limit counters: two days.
- An unused AI answer: one hundred and eighty days. A re-used one is kept indefinitely, and cached translations are kept indefinitely. Kwechi keeps the whole request beside the answer — the assembled context described above, and your question in your own words — for the same period and for the same reason: it is what proves the answer was not made up, and it is what lets the same question cost nothing the second time.
- An invitation nobody accepted: removed thirty days after it expires. An invitation that was accepted: kept, address and all, with nothing to clear it.
- A copy of your family you asked for: seven days, then Kwechi removes it. The file you downloaded is yours and is not touched.
- Everything else is kept until somebody deletes it, and you can, from Settings.
There is also a change history. Kwechi records before-and-after snapshots of changes to thirteen tables, including a child's profile, the archetype, the beliefs, the training logs, the routines and the milestone notes. It is deliberately not attached to the family record, so a record that changes were made survives the family being deleted — which is what proves a deletion happened.
The before-and-after contents are dropped after twenty-four months, leaving when, which table, what action and which columns differed: a line that is no longer about a person. At the moment a family is deleted its history is reduced further, to when, which family, which table and what action — no name, no date of birth, no note, not even who did it. No row is ever deleted, because a gap in a trail proves nothing.
The files go too, and they go first
A deletion removes the files before the rows, and the database enforces that order: it re-checks every folder and every named file, and refuses to delete a single row while one object is still there. The order matters because the rows are what say where the files are. Take the rows away first and the files can never be found again.
One thing to know beside it. Deleting a single voice recording marks the record deleted and leaves the audio; only deleting a child profile or the whole family sweeps the files.
Getting a copy, or getting it deleted
Both are in Settings, under Your data, and neither goes outside your family for permission. What each one asks for is a role, and the two parts below say which.
A copy
If you are the owner or a parent, one button produces one file holding your family's record: your children's records, the archetype and every version of the philosophy you have written, your beliefs in your own words, the plan as it was laid, the training logs, the milestone notes, your words — and the actual audio of your own voices, not links to them. It opens without Kwechi and without a password.
It is written twice on purpose: once as data a machine can read, once as documents a person can. It is never emailed — a link to a whole family record sitting in an inbox for a week is the one place things get forwarded by accident — so you download it here, over a link that lasts ten minutes and is made fresh each time you press it. Kwechi keeps the file for seven days and then removes it.
What it does not contain, and your copy says so itself. Kwechi's own lesson text, and the books and videos that were never ours to give you: those are named, dated and linked instead, with their licences, so you can fetch them from where they actually live. Nobody's password, invitation link or notification address, because a working credential in a downloaded file is a risk handed over for no benefit. And if you are a parent rather than the owner, not the change history, which Kwechi lets only the person who created the family read.
A guardian or a carer cannot take a copy. Helping with the day is not the same thing as taking the record away.
Deletion
- Retiring a child profile takes him out of every list, the calendar and the daily email, and stops a plan being generated. Nothing is destroyed, there is no time limit on changing your mind, and one click brings all of it back. The owner or a parent can do it.
- Deleting a child profile permanently can only follow a retirement, is the owner's alone, needs his first name typed, and waits thirty days. What stays is your family, your archetype, and everything you wrote about how he should think — which becomes a belief about your family rather than about him, because nothing you write is ever removed.
- Deleting the family is the owner's alone, needs the family's name typed, and waits thirty days. Every other adult sees it on their own Your data page from the moment it starts, and that page is the notice: tell them yourself as well. Each of those adults may ask once for more time. While it waits, nothing else in the family can be deleted or retired — not a recording, not a milestone note, not a photograph, not a belief — and the owner and any parent can still take a copy. The owner can call it off at any point up to the moment the purge actually starts.
- Backups. Deleting removes it from the live database and from the file stores. The database platform keeps its own backups on its own schedule, which Kwechi does not set. So "deleted" means deleted now, and out of backups within that window, and this page does not put a number on a window it does not control.
Two things you can also do yourself: turn the daily email off, in one click, from the link at the bottom of it; and remove a device's notifications from Settings.
Your child specifically
Kwechi collects information about a child from an adult, never from the child. There is no child-facing screen in this product, no child login, and no way for a child to type anything into it.
If that changes — a child mode, a child talking to the AI, a recording of a child's voice — it becomes a different question in law, and this page will be rewritten before the feature ships, not after.
Kwechi knows your child's exact date of birth. That means there is no version of this in which we can claim not to have known his age.
When he is thirteen, and when he is eighteen
A linked login inside your family account may be offered from about thirteen; the database holds that floor and nothing below it can sign in. If it is built, the teenager will be told plainly what the adults in the family can see.
At eighteen, nothing happens automatically. Kwechi runs to twenty-five, so a person's entire recorded upbringing sits inside an account their parent controls long after they are an adult. There is no screen that hands it over, takes a copy for them, or deletes it on their word. Ask, and it is done by hand, by the same person who handles everything else here.
If the adults in a family stop agreeing
Separation, a death, a fallen-out grandparent. The mechanics are worth knowing before they matter, because they are blunter than most products' and none of them is softened by a screen.
- The owner has the final say, and can end the family for everyone. It takes thirty days, every other adult sees it on their own page, each of them may ask once for more time, and nothing else in the family can be deleted or retired while it waits. Deleting the owner's own account does not end the family: the database refuses that until the family is handed over or deleted properly.
- The owner cannot be removed, and can hand the family over from a screen. The new owner gets the final say; the old owner stays as a parent. That is also the thing a family should do before it needs it: if one adult loses their mailbox, a second adult who can take ownership is the only thing that saves the record, because a password reset and an address change both go to the mailbox that is gone.
- The owner can remove another adult, and anybody may leave. Removal ends their access in the same moment — the database, the files and every screen. It destroys nothing they wrote: their training logs, their recordings and their words stay, under their name, because the record belongs to the child's upbringing and not to whoever typed it. The owner can bring them back at any time. Kwechi does not tell them; that is the family's to do.
- Every parent has an independent copy — a guardian, a carer and a viewer do not. An adult who is the owner or a parent can export the whole family record without asking the person they are leaving, and the screen tells them to do it before they go. The other roles are refused, and the leaving screen tells them so plainly rather than pointing them at a button they cannot press.
Nothing in this product decides between two adults who disagree. What it gives them is thirty days and a copy in each parent's hands, rather than one irreversible click.
If Kwechi stops
One person builds and runs this. It is fair to ask what happens to your child's record if he stops, becomes ill, or sells it.
There is no escrow, no successor and no arrangement with anybody to keep it running or to hand it over. What there is is the export: one file, complete, that opens with no Kwechi and no password. That is precisely what it is for. If your family's record matters to you, take a copy now, and take another one from time to time.
What Kwechi does not do
- There is no company, no registered address and no named privacy contact, so every remedy on this page ends at an address that has not been published.
- Deleting one voice recording leaves the audio file. Only deleting a child profile or the whole family sweeps the files.
- "Deleted" means out of the platform's own backups on the platform's own schedule, which Kwechi does not control and does not put a number on.
- A parent's copy carries no change history, which only the person who created the family may read.
- An accepted invitation keeps the invitee's email address, with nothing to clear it.
- Changing the address you sign in with needs your password, so an account that only signs in with Google cannot use that screen, and there is no screen that adds a password to one. The remedy the product offers is a second adult who can take ownership — the stronger one in any case, because a password reset goes to the same mailbox you have lost.
- How long Anthropic and Resend keep what they receive is set by their terms, not by Kwechi's.
- The philosophy is hidden from a guardian by the screens, not by the database.
- No monitoring product watches for a breach, so one could be found late.
- Nothing happens automatically when a child turns eighteen, and nothing decides between two adults who disagree.
- There is no escrow or successor if Kwechi stops, and nothing takes a copy for you.
How to check this page
- Tenancy and roles:
0002_identity.sqlhelper functions, and each table's own policies. - What a carer may and may not do:
is_family_contributor()in0002_identity.sqlagainst thechild_profilespolicies in0006_children.sql, which gate onis_family_editor(). - The two cross-family reads: the select policy on
archetypesin0007_archetypes.sql, and0023_invite_preview_and_template_beliefs.sql, whose own header explains why it exists. - What a copy carries into another family:
clone_archetypein0007_archetypes.sql, including theparent_beliefsinsert. - The guardian gap on the philosophy: the header of
0024_family_authority.sql, which states it. - What reaches the AI:
packages/ai-tutor/src/redact.ts,types.ts,prompt.ts, andsupabase/functions/ai-generate/schedule-context.tsfor the timetable and sleep routines. - The proof that nothing forbidden reaches it:
packages/ai-tutor/src/redact.test.ts. - The daily email:
supabase/functions/daily-notifications/. - The YouTube still picture loaded before any click:
packages/content-aggregator/src/youtube.ts, used byapps/web/src/components/media/youtube-player.tsx. - The other pictures loaded before any click:
apps/web/src/components/media/media-rows.tsxwithapps/web/src/lib/media/addresses.ts, against the addresses insupabase/seed/library.*.sql. - The word sent to Wiktionary, from the server:
apps/web/src/lib/vocabulary/lookup.tsandpackages/content-aggregator/src/sources/wiktionary.ts. - Private buckets and ten-minute links:
0017_storage.sql,apps/web/src/lib/data/storage.ts. - That files go before rows:
complete_deletion_purge()in0054_purge_and_audit_retention.sql, which re-lists every prefix and refuses while an object remains, and the worker that removes them insupabase/functions/purge-deletions/. - What expires automatically:
nightly_maintenance()in0018_cron.sql, rewritten by0054. - The change history's retention:
reduce_audit_log()andreduce_audit_for_family()in0054, andplatform_settings.audit_retention_months. - What a copy carries and what it leaves out:
packages/shared-types/src/export-classification.mjs, with the test that stops a future migration quietly adding a table to it insupabase/tests/27_family_export.mjs. - That one family's copy holds nothing of another's:
apps/web/src/lib/data-rights/export/isolation.test.ts, which seeds two families and asserts over every byte of the file. - Who may take a copy:
is_family_principalin0051_data_rights_schema.sql, which is the owner or a parent and nobody else. - That changing the sign-in address re-authenticates, and refuses a Google-only account:
changeEmailActioninapps/web/src/lib/account/actions.ts. - That deleting the owner's account no longer deletes the family: the
on delete restrictonfamily_accounts.owner_user_idin0051_data_rights_schema.sql, besideprevent_owner_removal()in0002_identity.sql.transfer_family_ownership()is hardened in0052_member_lifecycle.sqland called by/settings/family/ownership. - Who may remove, restore, leave or change a role: the four functions in
0052_member_lifecycle.sql, proved bysupabase/tests/25_member_lifecycle.mjs. - That an accepted invitation keeps the address:
accept_family_invite()in0004_signup_invites.sqlsetsaccepted_atand leavesemail;nightly_maintenance()deletes only invitations withaccepted_at is null.
How to reach us
Kwechi publishes no address to write to. Every remedy described on these pages — taking a copy of your family’s data, having it deleted, making a complaint, asking for something to be taken down, withdrawing consent to a recording, or reporting that the product scheduled something it should not have — is described here in full and cannot be started by post or by email until one is.
If you are using Kwechi, the route that exists is the person who gave you access: he built it, he runs it, and there is nobody else. Two of these need no address at all, and they depend on your role in the family: a copy of your family’s record is the owner’s and a parent’s to take, from Settings under Your data, without asking anybody; deleting the family is on the same page and is the owner’s alone. A guardian, a carer or a viewer has neither, and asks the owner or a parent.
If you came here to send a copyright notice or to ask what is held about a child, the procedure on these pages is what will happen, and an address will be published here before Kwechi opens to a second family.