Privacy policy
Plain English first, the formal bits after. This policy covers the Fincho app at app.fincho.co.uk and this website. It is written for parents and for students aged 11 to 18, so it avoids legal shorthand where it can.
1. The promise
Parents do not see what a student says to Pip. Not the messages, not a summary of them, not a mood score derived from them. This is not a setting; it is how the product is built. The parent dashboard, the weekly report to parents, and anything a connected app (such as ChatGPT or Claude) can read are generated from activity data only: days used, time spent, tasks completed, practice results, and grades from uploaded reports. A parent’s data export never contains conversation content. The student is told this in plain words when they set up their login.
The one exception is safety: Pip is a study companion, not a counsellor. If a student writes about being unsafe or in serious distress, Pip gives a one-line pointer to Childline (0800 1111) and suggests talking to a trusted adult. Pip does not counsel and does not alert parents.
2. Who we are
The data controller is Cogria Ltd, a company registered in England and Wales (company number 17019182). Contact: [email protected]. We are a small company run by parents of secondary school children; there is no separate data protection officer, and the same address reaches the people who run the service.
3. What we collect and why
| Data | Why we use it | Legal basis |
|---|---|---|
| Account details: names, email, a hashed password, role (parent or student) | To run your account and sign you in | Contract |
| A parent’s phone number (optional, later) | WhatsApp notifications the parent switches on | Consent |
| School facts: school, year or stage, subjects and awarding body, timetable, term dates | To plan around the student’s real week | Contract |
| Uploads: photos or PDFs of timetables, reports and marked work, plus what Pip read from them | To turn paper into plans, grades and weak spots the student can act on | Contract |
| School work the student reports: homework, tests, scores, mistakes and patterns | Practice that targets real gaps | Contract |
| Plans, check-ins, daily reflection and optional mood | The core of the product: plan, do, tick off | Contract |
| Study sessions: when the app was open, active or idle | Habit metrics for the student and parent. No screen recording; keystrokes are counted, never stored | Legitimate interests (running the service as described) |
| Conversations with Pip and the short profile Pip keeps about how the student learns | Answering, planning, marking; remembering what works for this student. Students can see and delete every profile item | Contract |
| Model usage: token counts and cost per request | Running and paying for the service | Legitimate interests |
| Notifications sent and read | Not sending the same thing twice | Legitimate interests |
| Connected-app reads (which app, when, which summary) | So parents can see and revoke what their apps read | Contract |
| Payment: Stripe customer and subscription identifiers, plan status | Billing, once the beta ends. Card details never touch our servers | Contract |
| Server logs: IP address, browser, request path, errors, kept 30 days | Security and debugging | Legitimate interests |
We do not use the data for advertising, we do not sell it, and we do not build profiles for anyone other than the student’s own learning.
4. Children
Students are 11 to 18. A student account can only be created from a link a parent generates inside their own account, so a parent always knows the account exists and can close it. We follow the ICO’s Age Appropriate Design Code in the way the product is built: privacy by default, no nudges to share more, no location, no advertising, and plain-language explanations at the point they matter (the student sees the chat promise before choosing a password).
Pip only talks about learning. Off-topic conversation is politely redirected. Emotional worries get one acknowledging sentence and, where serious, a signpost to Childline; that is the whole of it.
5. Who processes the data for us
We use a small number of processors, each under their standard data-processing terms:
- Hosting: a virtual private server we control. During the beta it is in Hong Kong; before public launch it moves to the European Union.
- AI models: messages to Pip (and the documents it reads for you) are sent to OpenAI (OpenAI, L.L.C., USA), which processes the text to produce a reply. OpenAI does not train on data sent through its API. We send no account identifiers with the text.
- Email: Resend (USA).
- File storage: Cloudflare R2.
- Payments: Stripe, once billing is switched on. Stripe is a controller for the card data it collects.
- Connected apps you choose: if a parent connects ChatGPT, Claude or another tool through our connector, that tool receives the summaries it asks for under the parent’s own agreement with that provider. Disconnecting in Family settings stops it immediately.
Some of these providers are outside the UK. Where data leaves the UK we rely on the safeguards in the provider’s data-processing terms (the UK International Data Transfer Addendum or an adequacy decision). This paragraph will be checked by a solicitor before public launch.
6. How long we keep it
- Everything in a family account is kept while the account exists. The parent who set up the family can delete it at any time in Family settings, which deletes every member’s login and every student’s data at once; any live subscription is cancelled first. Uploaded files are removed from storage in the same step.
- Backups are kept for 30 days and then overwritten, so deleted data can persist in a backup for up to 30 days.
- Server logs: 30 days.
- Model-usage records are kept for accounting without any message content.
- Pip’s memory items expire on their own when they stop being relevant, and a student can delete any item immediately.
7. Your rights
Under UK GDPR you can ask for a copy of your data, corrections, deletion, restriction, or to object to processing based on legitimate interests. Two things are built in:
- Download: a parent can download the family’s data from Family settings (no conversation content); a student can download everything of theirs, conversations included, from their own settings.
- Delete: the parent who set up the family can delete the whole account; a student can delete any memory item.
For anything else, email [email protected]. We answer within one month. If you are unhappy with our answer you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
Students can exercise these rights themselves where they are old enough to understand them, which for this service we take to be all of our users; a parent can act for a child in either case.
8. Cookies
The app uses one session cookie to keep you signed in, and nothing else. This marketing site sets no cookies and runs no analytics scripts.
9. Security
Passwords are hashed, connections are encrypted, and each family’s data is separated by account in the database. Access to production is limited to the people who run the service. If a breach ever affects you we will tell you and the ICO within the legal deadlines.
10. Changes
We will email the parent account about material changes and keep the date at the top of this page current. Earlier versions are available on request.
Last updated 7 September 2026. This policy describes how the beta works today and will be reviewed with a solicitor before public launch.
Updated 7 September 2026