Privacy policy
How family accounts, learning progress, device saves and backups are handled.
Updated
Who this policy is for
This policy covers the Brick Buddies family-account website and its separate native iPhone build. It is written for parents, carers and educators. An adult should set up a family account and help children use the app. Use a nickname rather than a full name. Do not enter sensitive information or contact details in a child’s name field.
Family accounts and the information we save
On the website, these records are sent over HTTPS to the family database when you sign in and use the app. They are used to provide your account, restore saves across devices and personalise practice within the selected grade. Family records are not public. Working-pad notes and the current round are temporary and restart on reload.
- Account details: a family username, a salted password hash, a hashed recovery code, sign-in sessions and account creation/update times. We do not require an email address or save your password or recovery code as readable text.
- Child profiles: a name or nickname, optional emoji and generated identifier. Up to 20 child profiles can belong to one family.
- Preferences: grade, number range, round length, answer style, reading preference and other practice settings. The active child is selected separately on each device.
- Learning: the latest 600 practice attempts per child, including skill, question identifier, grade, dates, first-answer result, wrong-attempt count, whether choices were visible, completion and difficulty. Earlier hint use may be present. The app uses this evidence to choose practice and calculate progress.
- Landmarks: earned building steps, collection progress and reset information.
- Transfers: a source-device identifier records whether an old save has already been imported, to prevent duplicate imports.
Device storage, cookies and offline changes
The website keeps a local cache and a queue of changes in browser storage. A necessary HttpOnly session cookie keeps the family signed in for up to 30 days. We use no advertising or analytics cookies.
If a loaded page loses its connection, it can keep queued practice on the device and send it when connected again. Opening or reloading the website needs an internet connection. A save is backed up only after it reaches the server and the backup process copies it.
Signing out removes this browser’s cache for that family after pending changes are saved. Other signed-in devices can retain their own caches. Clearing browser data removes local copies but does not delete the online family account. One tab per browser can edit family progress at a time.
The separate native iPhone build uses app preferences on the device and does not currently sync with the website. The old website addresses also have separate saves. Nothing is imported from them until an adult exports a file and confirms its import into a family. Legacy mistake records are not imported.
Hosting and backups
Fly.io hosts the application and its SQLite database on a persistent volume in Sydney. Litestream copies database changes to a private Tigris backup bucket, configured for Sydney. We target a backup sync every 60 seconds and use daily volume snapshots as an additional recovery source. These are recovery systems, not a guarantee against all data loss or service interruption.
Backup history targets 30 days. Expiry is periodic, and the newest recovery snapshot may remain longer until a replacement exists. Deleted records may therefore remain in restricted backups for a period. Backups are used for recovery, not ordinary access or advertising.
Requests to the hosting services can include IP address, requested URL, browser information, time and diagnostic information. Sign-in abuse controls store short-lived keyed hashes of IP addresses and usernames with attempt counts. App logs avoid passwords, recovery codes and child record contents.
Although the database and backup locations are configured for Sydney, providers use global networking, support and operational systems. Technical information may be processed outside Australia. Provider terms and privacy practices also apply. The old transfer website remains hosted by Cloudflare.
What we do not do
There is no advertising, public child profile, messaging, behavioural analytics SDK or runtime AI/LLM service in the app. We do not sell children’s learning records or share them for advertising or AI training. Public llms.txt and policy pages describe the app; they do not expose private family data.
External resources
Curriculum links open external services with their own privacy practices; the app does not attach saved child profiles or learning records to those links.
Access, export and deletion
- View profiles in Grown-ups → Kids and learning in Grown-ups → Progress. You can add children and change their emoji. Profile names cannot currently be edited.
- Download the family’s progress in Grown-ups → Settings → Your family account. Keep exported files private; they contain children’s names or nicknames and progress.
- Reset landmarks in Settings to clear the selected child’s collection. This does not erase their profile or learning history.
- Delete the entire family account in Settings using the family password. This removes live profiles, learning, landmarks and sessions. Restricted backups expire under the retention described above. Other devices and exported files may still hold copies; clear their website data too.
- There is no individual child-delete or practice-only reset control yet. Contact the operator for help with records we hold.
- Clearing data for an old website or deleting the native app can remove its local saves. Device backups and exports are controlled separately. We cannot remotely recover records that were only saved locally.
Security and retention
Accounts and progress remain until deleted. Learning history is bounded to the latest 600 attempts per child rather than a fixed number of days. Expired sessions and rate-limit records are removed during subsequent authentication requests.
Family accounts use hashed passwords and recovery codes, secure cookies, request validation and family-scoped database access. Authorised operators and hosting providers may access data when necessary to run, secure or restore the service. No system can guarantee complete security.
Children do not have separate passwords or a parent PIN. Anyone using a signed-in browser can switch children, see progress and change settings. Use the device’s screen lock and sign out on shared devices. Browser caches are not a separate encrypted vault.
Keep your family username, password and recovery code safe. Resetting a password with the code revokes existing sessions and produces a new code. There is no email reset. If you lose both the password and recovery code, we cannot promise to restore access.
Contact, requests and complaints
An adult can contact the operator about privacy, access, correction, deletion or a concern. Describe the issue without sending a child’s full name, password, recovery code or unnecessary learning records. If you contact us, we receive the contact details and content you choose to send and use them to answer, investigate or meet applicable obligations.
We retain correspondence only as needed for those purposes and may disclose information where legally required. You can also ask the Office of the Australian Information Commissioner about privacy rights and whether it can handle a complaint.
Changes to this policy
We update this page and its date when the app’s data practices change. Read it before using a new feature that requests additional information.
Operator and contact
Brick Buddies