← Back to Gentle Connections

Privacy Policy

Gentle Connections respects your privacy and is committed to protecting the sensitive information about your child. This Privacy Policy explains how we collect, use, and safeguard your data.

1. Information We Collect

Information You Provide

  • Account Information: Email address, name (for communication)
  • Child Information: Name, age, grade, diagnosis, school name, medication details, behavioral observations, academic strengths/struggles, interests
  • Handbook Responses: All answers you provide in the questionnaire (sensitive data about your child's ADHD profile, strategies, and needs)

Information We Collect Automatically

  • Usage Data: Pages visited, time spent, interactions (via consent-based Google Analytics, PostHog, and Meta Pixel on public pages)
  • Device Data: Browser type, IP address (for security)
  • Timestamps: When profiles are created, updated, or deleted

2. How We Use Your Information

We use your information to:

  • Generate personalized shadow teacher handbooks
  • Save your progress and profiles securely
  • Send you authentication links and service emails
  • Improve our service (anonymous analytics only)
  • Comply with legal obligations

We NEVER:

  • Sell or share your data with third parties
  • Use your child's data for marketing or advertising
  • Share data with schools or government agencies without your consent
  • Train AI models on your personal information

3. Data Storage & Security

Where Your Data Is Stored

  • Firestore Database: Google Cloud (us-central1 region, encrypted at rest)
  • Generated PDFs: Cloud Storage (encrypted, deleted after download)
  • Backups: Google Cloud automatic backups (encrypted)

Security Measures

  • HTTPS encryption for all data in transit
  • Firebase Authentication (industry-standard OAuth 2.0)
  • Firestore security rules (user data isolation)
  • No passwords stored (magic link authentication)
  • Regular security audits

4. Your Rights & Control

Access & Download

You can download all your data at any time (profiles, handbooks, metadata).

Delete Your Data

You can delete individual profiles anytime. To delete your entire account and all associated data:

  1. Email us at: admin@gentle-rhythm.com
  2. We will permanently delete all your data within 30 days
  3. Deleted data is removed from all backups (may take up to 90 days)

Correct or Update

You can update any information in your profiles at any time within the app.

Opt Out of Analytics

You can decline analytics from the cookie banner at any time. We do not use personal data for analytics — only anonymized usage patterns about page flow and product friction.

5. Children's Privacy (COPPA & GDPR)

Gentle Connections is not intended for children under 13. Parents/guardians provide information about their children, and we collect only the minimum necessary.

COPPA Compliance (US)

  • We do not knowingly collect data from children under 13
  • We require verifiable parental consent to collect information about children
  • By using Gentle Connections, you represent that you are the parent/legal guardian
  • Parents can request deletion of their child's data at any time

GDPR Compliance (EU)

  • We process data only with your explicit consent
  • Your child's data is considered "special category data" (protected characteristics)
  • You have the right to access, correct, delete, or port your data
  • We do not use automated profiling or decision-making
  • We do not share data outside the EU without appropriate safeguards

PDPA Compliance (Singapore)

  • We comply with Singapore's Personal Data Protection Act
  • Data is stored in Google Cloud (compliant with PDPA)
  • You can request data access, correction, or deletion

6. Third-Party Services

We use the following third-party services (all GDPR/COPPA compliant):

Google Cloud (Firebase)

  • Authentication, database, storage
  • Google Privacy Policy

Google Analytics 4

  • Anonymized usage analytics (no personal data)
  • GA4 Privacy Controls

PostHog

  • Consent-based product analytics for page flow and funnel events
  • No handbook answers or sensitive child details are sent
  • PostHog Privacy Policy

Meta Pixel

  • Consent-based marketing attribution on public site pages only
  • No handbook answers or sensitive child details are sent
  • Meta Privacy Policy

Stripe

  • Payment processing (PCI DSS Level 1 certified)
  • Stripe Privacy Policy

Note: We do not use third parties to train AI models or for marketing. Your data is never shared with these services for their own purposes.

7. Data Retention

Data Type Retention Period
Profiles & Handbooks Until you delete (or account deletion)
Email address & auth logs Until account deletion (then 90 days for backups)
Analytics (anonymized) Up to 13 months, depending on provider retention settings
Payment records 7 years (legal requirement)

8. International Data Transfers

Your data is stored in Google Cloud (us-central1). If you are in the EU, we rely on Google's Standard Contractual Clauses and adequacy decisions for lawful transfers.

9. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email. Your continued use of Gentle Connections means you accept the updated policy.

10. Contact Us

Privacy Questions or Data Requests?

Email: admin@gentle-rhythm.com

Response time: 14 days (or as required by law)

Gentle Connections is committed to protecting your family's privacy. If you have any concerns, please reach out immediately. Your trust is our foundation.

Last Updated: June 7, 2026
Effective Date: June 7, 2026
Version: 1.0 (Pre-Launch)
Gentle Connections is a product by Gentle Rhythm Digital Pte. Ltd., 77 High Street, #10-12B High Street Plaza, Singapore 179433. All rights reserved.