Brightr
Privacy Policy
Last updated: 28 July 2026
This Privacy Policy explains how Rupert Graham (“Brightr”, “we”, “us”, or “our”) collects, uses, shares, and protects your personal information when you use the Brightr mobile application and related services (together, the “Service”). Brightr is a parenting information and support app. It is designed for adults (parents, caregivers, and expecting parents) and is not directed at or intended for children under the age of 13.
If you do not agree with this Privacy Policy, please do not use the Service. By creating an account or otherwise using the Service, you acknowledge that you have read this Privacy Policy and the associated Terms of Use.
1. Who is responsible for your data
Rupert Graham is the data controller of personal information processed through the Service. You can reach us about privacy matters at privacy@brightr.ai or, for general enquiries, at support@brightr.ai.
2. Information we collect
We collect only what we need to provide the Service. The categories of personal information we process are:
- Account information. Your full name, email address, and a password you choose. When you reset a password or delete your account, we generate a short-lived one-time code and send it to your email.
- Profile information. An optional profile photo and preferences (for example, app theme and language).
- Child information. The name, date of birth, gender, and country you record for each child you add to your account. If you invite a caregiver, partner, or grandparent, we also store the relationship you select and whom access has been granted to.
- Chat content. Questions you send to the in-app AI assistant, the assistant’s responses, and any reports you submit about a response. Reports include the reason you select and a short excerpt of the response.
- Subscription and purchase information. Your subscription status (active, trialing, canceled, expired), plan, renewal date, and the transaction identifier supplied by the App Store or Google Play. We do not receive or store your payment-card details; those are handled directly by Apple and Google.
- Device and technical data. Device type, operating-system version, app version, language, time zone, a random push-notification token (if you enable notifications), and approximate IP-derived region used only to keep the service available and secure.
- Usage data. Which screens you open, which tips or products you tap, errors encountered, and similar product-telemetry events used to operate and improve the Service.
- Communications. Emails you send to us and our replies, plus records of system emails we send you (OTP codes, password-reset codes, account-deletion codes, subscription notices).
We do not collect location, camera, microphone, contacts, calendar, health, or advertising-identifier data. The Service does not display third-party advertising, does not use cross-app tracking, and does not ask for Apple App Tracking Transparency permission.
3. How we use your information
We use your information to:
- Create and secure your account, authenticate you, and keep your session active;
- Personalise daily tips, articles, and product suggestions based on the ages and stages of the children on your account;
- Power the in-app AI assistant with enough context to give relevant answers (your question plus basic details about the selected child);
- Process subscription start, renewal, cancellation, refund, and restore events from the App Store and Google Play;
- Send transactional emails such as sign-up confirmations, OTP codes, password-reset codes, and account-deletion confirmation codes;
- Send push notifications you have opted into (you can disable these at any time in your device settings or inside the app);
- Detect abuse, investigate reported responses, prevent fraud, and respond to security incidents;
- Comply with legal obligations, enforce our Terms of Use, and establish, exercise, or defend legal claims.
4. Legal bases (UK and EU users)
If you are in the United Kingdom, the European Economic Area, or another jurisdiction with similar rules, we rely on the following legal bases:
- Performance of a contract — to provide the core Service you ask us to (account, subscriptions, chat, tips).
- Legitimate interests — to keep the Service secure, to improve it, and to understand aggregated usage. You can object to processing based on legitimate interests as described in the “Your rights” section.
- Consent — for push notifications and for any optional features that clearly ask you first. You can withdraw consent at any time without affecting earlier processing.
- Legal obligations — to comply with tax, accounting, consumer-protection, or law-enforcement requirements.
5. Children and family data
Brightr is intended for adults aged 18 or over (or the age of majority in your location) who are parents, caregivers, or expecting a child. You must be an adult to create a Brightr account.
When you add a child profile, you confirm that you are the child’s parent or legal guardian, or that you otherwise have the authority to provide the child’s information under applicable law. Child profile data is used only to personalise tips, articles, and AI responses for that child. We do not knowingly collect personal information directly from children. If you believe a child has provided personal information to us without adult authorisation, please contact us and we will delete it.
Brightr is not a general audience child-directed service and is not submitted to the App Store Kids Category or Google Play’s Designed for Families program.
6. The AI assistant and medical disclaimer
The in-app AI assistant generates responses using large language models and a curated knowledge base. To produce relevant answers, we send the assistant your question together with basic, non-sensitive context about the selected child (age range, gender, country). We do not send your email, password, payment data, or chat history from other sessions.
Brightr is not a medical service, a diagnostic tool, or a substitute for professional advice. The AI assistant provides general parenting information and educational content only. Always consult a qualified healthcare professional about any medical concern, and contact your local emergency service if you believe your child needs urgent care.
7. Service providers and sub-processors
We rely on a small number of carefully selected providers to operate the Service. We share only the information each provider needs, and each is bound by a data-processing agreement or equivalent contract that restricts their use of your data to the services they provide to us.
- Amazon Web Services (AWS) — EU (Ireland). Application hosting (EC2), media storage (S3 with CloudFront), and transactional email (Simple Email Service).
- MongoDB Atlas — EU (Ireland). Primary database for account, profile, subscription, and chat-report records.
- Anthropic PBC — United States. Provides the underlying language model (Claude) that generates AI-assistant responses. Your question and basic child context are sent for the duration of the request; Anthropic does not use your data to train models for other customers.
- Qdrant — EU. Vector database that helps the assistant retrieve relevant knowledge-base material.
- Google Firebase Cloud Messaging. Delivers push notifications to your device if you enable them. Only an opaque push token is shared.
- Apple App Store (Apple Inc.) and Google Play (Google LLC). Process your subscription purchases, renewals, and refunds. We receive transaction confirmations and subscription-status events; we do not receive your payment-card details.
- Email-deliverability providers used by our transactional email service to send OTP, receipts, and account notices.
We do not sell your personal information, and we do not share it with advertising networks, data brokers, or analytics SDKs that create cross-app profiles.
8. International transfers
The Service is operated primarily from European data centres. Some of our providers — notably Anthropic — are located in the United States. When we transfer personal information outside the United Kingdom or the European Economic Area, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms. You can request a copy of the relevant safeguards by writing to privacy@brightr.ai.
9. How long we keep your data
- Active accounts. While your account is active we retain the information above so we can provide the Service.
- Deleted accounts. When you delete your account, we permanently remove it from our primary database straight away — there is no waiting period and no recovery window. This includes your profile, child profiles, linked caregiver grants, chat reports, device tokens, invitations, notification history, tracker and health records, and product-click logs, together with your AI-assistant profiles and the full history of your AI-assistant conversations. Signing up again with the same email address creates a new, empty account. The one exception is the subscription billing record described below. Backups are overwritten on the standard retention cycle and then purged.
- Subscription records. We retain a minimal record of past subscriptions for as long as required by tax, accounting, and consumer-protection law (typically up to seven years). When you delete your account this record is immediately detached from your identity — it keeps the store transaction reference and amount but is no longer linked to you — and is deleted at the end of that period. We keep it so that a refund, chargeback, or renewal notice from Apple or Google can still be reconciled after your account is gone; deleting your Brightr account does not cancel a store subscription.
- Email suppression. If an email address has bounced or complained, we keep a suppression entry indefinitely to avoid sending to it again.
- Support correspondence. Emails you send us are retained for up to 24 months and then deleted, unless an ongoing matter requires longer retention.
10. How to delete your account
You can delete your account at any time in either of two ways:
- Inside the app. Open Account › Delete Account, confirm with your password, and tap Delete.
- On the web. Visit https://api.brightr.ai/delete-account, enter your email, receive a one-time confirmation code, and submit it with your password.
Deletion immediately removes your profile, linked child profiles, linked caregiver access, chat sessions and reports, saved preferences, and device tokens, as described above. Active App Store or Google Play subscriptions must be canceled separately from your Apple ID or Google Play account settings; deleting your Brightr account does not cancel a platform subscription.
11. Security
We protect your information with industry-standard safeguards:
- All traffic between the app, the backend, and our providers is encrypted in transit using TLS;
- Data is encrypted at rest in our database and object storage;
- Passwords are hashed with bcrypt; we never see or store them in plain text;
- API access is authenticated, rate-limited, and scoped to the logged-in user;
- Administrative access is restricted to a small set of authorised personnel and protected by strong authentication;
- Logs and operational data are retained only as long as needed to keep the Service healthy and secure.
No system is perfectly secure. If you believe your account has been compromised, please contact privacy@brightr.ai immediately.
12. Your rights
Depending on where you live, you have some or all of the following rights in relation to your personal information:
- Access — request a copy of the personal information we hold about you;
- Rectification — ask us to correct information that is inaccurate or incomplete;
- Erasure — ask us to delete your information (see the deletion section above);
- Restriction — ask us to limit how we process your information in certain circumstances;
- Portability — receive a machine-readable copy of information you provided to us;
- Objection — object to processing we base on legitimate interests;
- Withdraw consent — where we rely on your consent, you can withdraw it at any time without affecting earlier processing;
- Lodge a complaint — with the data-protection authority in your country. In the UK this is the Information Commissioner’s Office (ICO); in the EU it is the supervisory authority where you live, work, or believe a breach occurred.
To exercise any of these rights, email privacy@brightr.ai from the address associated with your account. We will respond within the time frames required by applicable law (typically within one month).
13. California residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the CPRA, including the rights to know, delete, correct, and limit the use of sensitive personal information. We do not sell or “share” personal information for cross-context behavioural advertising. To exercise your rights, email privacy@brightr.ai. We will not discriminate against you for exercising a privacy right.
14. Push notifications and in-app messaging
We send push notifications only if you opt in when prompted by your operating system. You can turn them off at any time in your device settings or inside the app. Transactional emails related to account security, subscription, and deletion are sent regardless of notification preferences because they are necessary for the Service.
15. Cookies and similar technologies
The mobile app does not set browser cookies. We use standard mobile-app local storage to keep you signed in, remember preferences, and cache content. Our public web pages (including the account-deletion page) may use strictly necessary cookies to operate. We do not use analytics or advertising cookies.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date at the top. If the change is material, we will also notify you by email, with an in-app banner, or both, before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.
17. Contact
If you have questions, concerns, or requests related to this Privacy Policy, please contact us:
- Privacy & data-protection enquiries: privacy@brightr.ai
- General support: support@brightr.ai
- Data controller: Rupert Graham
Operated by Rupert Graham. Questions about this document can go to support@brightr.ai.