1. Who We Are
Canopy Families is a service of Mackie AI Enterprises Limited (company number 17107639), registered in England & Wales.
ICO registration number: ZC110311
Contact: [email protected]
2. Our Commitment to Children's Privacy
We do not sell children's personal data or use it for advertising. We design children's pages with high-privacy defaults and keep optional website analytics off those pages.
This policy explains what the service actually collects, why it is needed, who receives it, and the controls available to families. Children also see a shorter explanation before starting a learning chat.
3. What Data We Collect
Parent and guardian accounts:
- Name, email address, authentication records, notification choices, and account settings
- Subscription plan and Stripe customer or subscription references; Canopy does not store full card details
- Feedback, parent-advisor prompts, router-assistant prompts, and support communications you choose to send
Children's profiles (created by parent or guardian only):
- Display name, school year group, account identifier, and a protected PIN where used
- Learning subjects, session times, message content, AI replies, message counts, and safety flags
- Approved-device security records, including an opaque device token hash, device name, and last-seen time
- Parent-configured schedules and safety settings
Home-network protection (full-access plan): router or device details, DNS configuration identifiers, service settings, connection status, and DNS analytics such as blocked domains and query totals supplied by NextDNS.
Technical and website data: service logs, IP-derived request information, browser or device type, consent preferences, and — only after opt-in and never on children's pages — website analytics and anonymous performance measurements such as route, network speed and Web Vitals.
Security and abuse-prevention data: Cloudflare Turnstile runs only on parent registration, sign-in and password-change verification. It receives security signals needed to distinguish people from automated traffic, including network and IP information, browser and operating-system characteristics, the Canopy hostname and site key, challenge timing, interaction, and outcome. Canopy does not send names, email addresses, passwords, form entries, user communications, or child learning content to Turnstile. For selected child-access endpoints, Canopy converts the endpoint's existing security credential — such as a device, approval, or link token, or a child reference — into a secret-keyed, one-way identifier before short-lived rate-limit counters are sent to Upstash. Raw credentials, identifiers, IP addresses, PINs, and form contents are not stored in that rate-limit database.
We do not request biometric data or store full payment-card details. A message and the automated safety flag applied to it may reveal or infer health or wellbeing information. We treat that information as especially sensitive.
4. Why We Process Information
Depending on the activity, we rely on providing the service requested by the parent or guardian, our legitimate interests in operating a secure and useful family service, compliance with legal obligations, or consent for optional analytics. We assess children's interests and rights before relying on legitimate interests.
We rely on our legitimate interests to authenticate users, prevent automated account abuse, enforce proportionate rate limits, and protect the service. Turnstile and Upstash are strictly necessary security controls and do not depend on optional analytics consent.
Parent or guardian approval is required before a child profile is created, but it is not treated as a blanket legal basis for every later use of a child's information. Where safety analysis reveals or infers health information, an additional UK GDPR Article 9 condition and appropriate safeguards are required.
You can withdraw optional analytics consent at any time using the Analytics settings control. Parents can request deletion or object to other processing by contacting [email protected].
5. How We Use Data
- To provide age-appropriate AI learning experiences tailored to your child
- To save learning sessions and give parents or guardians the oversight described in the service
- To run automated content-safety checks, record flags, and send parents safety alerts
- To authenticate users, approve devices, prevent misuse, and operate network protections
- To distinguish automated abuse from genuine parent account access and limit repeated requests to security-sensitive child-access endpoints
- To administer subscriptions, respond to feedback, and provide requested support
- To measure and improve non-child pages when a visitor has opted in to analytics
We do not use children's data for advertising. Automated safety classification is used to protect the child and support parent oversight, not to target content or promotions.
6. Data Sharing
We do not sell or rent personal data. Information is disclosed only where needed to operate the service, process payments, deliver requested communications, protect a child or another person from serious harm, or comply with law.
- Child and parent prompts are sent to Anthropic's commercial API to classify or generate responses
- Parents can view their child's saved sessions and flagged messages in the authenticated dashboard
- A generic safety-alert email is sent through Resend; it does not contain the child's name or message content
- DNS requests and analytics for connected full-access families are processed by NextDNS
- Cloudflare receives only the security signals required for Turnstile, while Upstash receives secret-derived identifiers and short-lived counter state for distributed rate limiting
- Account, hosting, payment, and optional analytics providers receive the limited data needed for their functions
We review provider roles, contracts, security measures, sub-processors, and international-transfer safeguards. Some providers may also act as independent controllers for limited activities such as payment fraud prevention or their own legal obligations.
7. Service Providers and Recipients
The following providers are present in the current implementation:
- Supabase — authentication and database hosting. Privacy information
- Vercel — application hosting, delivery, service logs, consent-gated Web Analytics, and consent-gated Speed Insights performance measurements. Privacy notice
- Anthropic — AI safety classification and child or parent AI responses through the commercial API. Privacy centre
- Resend — transactional and safety-alert email delivery. Privacy policy
- Stripe — checkout, subscriptions, billing portal, and payment fraud controls. Privacy policy
- NextDNS — DNS filtering and DNS analytics for families using home-network protection. Privacy policy
- Google — Google Tag Manager and tags it delivers, only after analytics opt-in and never on child-facing routes. Privacy policy
- Cloudflare — Turnstile bot protection on parent registration, sign-in and password-change verification. It receives the limited security signals described above, but Canopy does not send it the form fields entered into our service. Cloudflare's Turnstile Privacy Addendum says it acts as our processor when protecting Canopy and as a controller when it uses Turnstile signals to improve its bot-detection capabilities. Turnstile privacy addendum
- Upstash — short-lived distributed rate-limit counters keyed by secret-derived identifiers for selected Canopy API endpoints. Privacy policy
We update this list when the implemented provider set changes materially.
8. Data Retention
Account, profile, conversation, device, and safety data: currently retained while the family account is active so the service and parent dashboard can operate. An account-deletion request enters a controlled deletion queue after a 24-hour cooling period. Our worker removes directly controlled account data from the application database, Supabase authentication, and any linked NextDNS profile, with retries if a step fails.
Short-lived access records: child magic links expire after 15 minutes and pending device approvals after 10 minutes. Expired link and approval records are removed after seven days, and PIN-attempt records after 30 days.
Turnstile challenges: challenge tokens expire after five minutes and can be validated only once. Cloudflare's retention of Turnstile security signals and aggregated service analytics is governed by its Turnstile Privacy Addendum and Privacy Policy.
Abuse-prevention counters: Upstash rate-limit keys expire with their ten-minute enforcement windows. Canopy disables Upstash rate-limit analytics and sends only a scoped HMAC identifier, counter state, and expiry — not a raw IP address, account or child identifier, account content, PIN, device credential, approval credential, or link token.
Provider copies and backups: follow the provider's applicable retention and backup cycle. For example, Anthropic states that standard commercial API inputs and outputs are deleted from its backend within 30 days unless a different agreement, safety enforcement, or legal requirement applies.
We are formalising a field-level retention schedule and deletion runbook. Until that work is approved and automated, we will not claim that active-account child conversations are deleted on a shorter fixed timetable.
9. Your Rights and Your Child's Rights
As a parent or guardian, you have the following rights under UK GDPR in relation to both your own data and your child's data held by us:
- The right to access all data we hold
- The right to correct inaccurate or incomplete data
- The right to request complete erasure (“right to be forgotten”)
- The right to restrict processing
- The right to withdraw consent at any time without affecting prior lawful processing
- The right to data portability
To exercise a right, contact us at [email protected]. Rights depend on the circumstances and lawful basis. We normally respond within one calendar month and will explain if an extension or exemption applies.
10. ICO Registration
Mackie AI Enterprises Limited is registered with the Information Commissioner's Office under registration number ZC110311.
If you have concerns about how we handle your data that we have not resolved to your satisfaction, you have the right to lodge a complaint with the ICO at ico.org.uk.
11. Changes to This Policy
We will notify all registered parents and guardians of any material changes to this policy by email before they take effect. We will never make retroactive changes that reduce your rights or protections.
The date at the top of this page reflects when this policy was last updated.