Privacy policy

Plain English first, the formal bits after. This policy covers the Fincho app at app.fincho.co.uk and this website. It is written for parents and for students aged 11 to 18, so it avoids legal shorthand where it can.

1. The promise

Parents do not see what a student says to Pip. Not the messages, not a summary of them, not a mood score derived from them. This is not a setting; it is how the product is built. The parent dashboard, the weekly report to parents, and anything a connected app (such as ChatGPT or Claude) can read are generated from activity data only: days used, time spent, tasks completed, practice results, and grades from uploaded reports. A parent’s data export never contains conversation content. The student is told this in plain words when they set up their login.

The one exception is safety: Pip is a study companion, not a counsellor. If a student writes about being unsafe or in serious distress, Pip gives a one-line pointer to Childline (0800 1111) and suggests talking to a trusted adult. Pip does not counsel and does not alert parents.

2. Who we are

The data controller is Cogria Ltd, a company registered in England and Wales (company number 17019182). Contact: [email protected]. We are a small company run by parents of secondary school children; there is no separate data protection officer, and the same address reaches the people who run the service.

3. What we collect and why

Data Why we use it Legal basis
Account details: names, email, a hashed password, role (parent or student) To run your account and sign you in Contract
A parent’s phone number (optional, later) WhatsApp notifications the parent switches on Consent
School facts: school, year or stage, subjects and awarding body, timetable, term dates To plan around the student’s real week Contract
Uploads: photos or PDFs of timetables, reports and marked work, plus what Pip read from them To turn paper into plans, grades and weak spots the student can act on Contract
School work the student reports: homework, tests, scores, mistakes and patterns Practice that targets real gaps Contract
Plans, check-ins, daily reflection and optional mood The core of the product: plan, do, tick off Contract
Study sessions: when the app was open, active or idle Habit metrics for the student and parent. No screen recording; keystrokes are counted, never stored Legitimate interests (running the service as described)
Conversations with Pip and the short profile Pip keeps about how the student learns Answering, planning, marking; remembering what works for this student. Students can see and delete every profile item Contract
Model usage: token counts and cost per request Running and paying for the service Legitimate interests
Notifications sent and read Not sending the same thing twice Legitimate interests
Connected-app reads (which app, when, which summary) So parents can see and revoke what their apps read Contract
Payment: Stripe customer and subscription identifiers, plan status Billing, once the beta ends. Card details never touch our servers Contract
Server logs: IP address, browser, request path, errors, kept 30 days Security and debugging Legitimate interests

We do not use the data for advertising, we do not sell it, and we do not build profiles for anyone other than the student’s own learning.

4. Children

Students are 11 to 18. A student account can only be created from a link a parent generates inside their own account, so a parent always knows the account exists and can close it. We follow the ICO’s Age Appropriate Design Code in the way the product is built: privacy by default, no nudges to share more, no location, no advertising, and plain-language explanations at the point they matter (the student sees the chat promise before choosing a password).

Pip only talks about learning. Off-topic conversation is politely redirected. Emotional worries get one acknowledging sentence and, where serious, a signpost to Childline; that is the whole of it.

5. Who processes the data for us

We use a small number of processors, each under their standard data-processing terms:

  • Hosting: a virtual private server we control. During the beta it is in Hong Kong; before public launch it moves to the European Union.
  • AI models: messages to Pip (and the documents it reads for you) are sent to OpenAI (OpenAI, L.L.C., USA), which processes the text to produce a reply. OpenAI does not train on data sent through its API. We send no account identifiers with the text.
  • Email: Resend (USA).
  • File storage: Cloudflare R2.
  • Payments: Stripe, once billing is switched on. Stripe is a controller for the card data it collects.
  • Connected apps you choose: if a parent connects ChatGPT, Claude or another tool through our connector, that tool receives the summaries it asks for under the parent’s own agreement with that provider. Disconnecting in Family settings stops it immediately.

Some of these providers are outside the UK. Where data leaves the UK we rely on the safeguards in the provider’s data-processing terms (the UK International Data Transfer Addendum or an adequacy decision). This paragraph will be checked by a solicitor before public launch.

6. How long we keep it

  • Everything in a family account is kept while the account exists. The parent who set up the family can delete it at any time in Family settings, which deletes every member’s login and every student’s data at once; any live subscription is cancelled first. Uploaded files are removed from storage in the same step.
  • Backups are kept for 30 days and then overwritten, so deleted data can persist in a backup for up to 30 days.
  • Server logs: 30 days.
  • Model-usage records are kept for accounting without any message content.
  • Pip’s memory items expire on their own when they stop being relevant, and a student can delete any item immediately.

7. Your rights

Under UK GDPR you can ask for a copy of your data, corrections, deletion, restriction, or to object to processing based on legitimate interests. Two things are built in:

  • Download: a parent can download the family’s data from Family settings (no conversation content); a student can download everything of theirs, conversations included, from their own settings.
  • Delete: the parent who set up the family can delete the whole account; a student can delete any memory item.

For anything else, email [email protected]. We answer within one month. If you are unhappy with our answer you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.

Students can exercise these rights themselves where they are old enough to understand them, which for this service we take to be all of our users; a parent can act for a child in either case.

8. Cookies

The app uses one session cookie to keep you signed in, and nothing else. This marketing site sets no cookies and runs no analytics scripts.

9. Security

Passwords are hashed, connections are encrypted, and each family’s data is separated by account in the database. Access to production is limited to the people who run the service. If a breach ever affects you we will tell you and the ICO within the legal deadlines.

10. Changes

We will email the parent account about material changes and keep the date at the top of this page current. Earlier versions are available on request.

Last updated 7 September 2026. This policy describes how the beta works today and will be reviewed with a solicitor before public launch.

Updated 7 September 2026