FAMILY PILOT · UPDATED 6 SEPTEMBER 2026
Your family’s information
What this pilot stores
Learn with Susie stores your verified parent email, sign-in records and family membership; parent details; child nickname, date of birth, country and avatar; optional learning notes; private uploaded work; reviewed library material; lesson plans, answers and requests for help; recorded visits; parent-created education reports; and feedback you choose to provide. The parent manages this information. Use only information you have the right to share.
Where it goes
Cloudflare hosts the application and stores records in D1 and private files in R2. Cloudflare Email Sending delivers requested sign-in links. Your email provider also processes those messages. Files are accessible through authenticated parent requests, not public file links.
AI content generation
When a parent selects Create AI activity pack, OpenAI receives only a topic and theme from our fixed catalogue and the number of cards requested. We do not send names, exact ages or birthdays, emails, profile notes, child answers, questions, history, files, visits or report content. The app adds personal context and saves learning records inside Cloudflare. Generated material can be inaccurate: parents must review it before publishing it to their child.
OpenAI requests use store:false. This does not mean Zero Data Retention: provider security and abuse-monitoring rules still apply to the generic content request. We have not enabled personal-data AI features such as uploaded-work interpretation or child chat. Any future change requires an updated notice and appropriate provider arrangements.
Parent and child spaces
The child has a restricted session for one profile. Parent notes, sibling details, report controls and account information are not included in child responses. Parents can see saved learning answers and help requests. Switching to child mode ends this browser’s parent session. Returning to parent tools in that browser requires a fresh email sign-in. Parents can instead create a one-use link for a separate child device and keep their own parent session. These links expire after 15 minutes and open only the chosen child’s four-hour session. Creating a replacement cancels the previous unused link. Parents can end child device access remotely; signing out everywhere also ends their child sessions. We store a hash of the link, its expiry and issuing session, not the original link.
Adult-only image test
Chris and Gemma can separately test a reviewed, non-personal image and generic question from their fictional demo family. This sends the displayed image and question to OpenAI under standard API retention with store:false; Zero Data Retention is not enabled. No image is added to a child’s history by this test. Real minors’ data and images containing people must not be submitted. This test uses adult review, not automated person detection.
Garden and visit discoveries
Parents prepare activities and approve them for their child. Children save written observations and, only when the parent enables photos for that child, optional photographs. Photos remain in the private family library unless a parent explicitly prepares and approves a non-personal image for AI checking. Children cannot send photos directly to AI. Photos are resized in the browser and EXIF location metadata is removed. Avoid photographing people or private details. Turning photos off prevents new uploads but does not delete existing images. Parents verify completed work; only verified discoveries enter report drafts. Deleting an activity removes its written answers; its photos remain in the library until separately deleted. Existing report snapshots are not rewritten by deleting source work.
Parent image checks and monthly treats
Parents can send a reviewed non-personal image and question to the OpenAI API. Each submission requires confirmations covering faces, people, identifying information and standard retention. Declaring people blocks sending. These are human checks, not automatic face detection. Zero Data Retention is not enabled. No child profile or learning history accompanies the image. Optional monthly treat targets, recorded lesson time and child sign-in dates stay in Cloudflare. Lesson time is an estimate of visible, recently active use; it is not a measure of attention. Rewards are hidden from the child when disabled.
Reports and your choices
Education reports are drafted in this app, using the dates and observations you choose. They highlight recorded participation and achievements. They exclude private profile notes, visit notes and sessions marked as off days or excluded. You can edit the draft, approve it, download Word or PDF, and decide whether to share it. Nothing is automatically sent to a local authority. Downloads are separate copies you control.
Keeping and removing records
Test learning records remain until deleted. Library notes, sessions, visits and reports have delete controls. Deleting a child removes their linked learning records; original uploaded family files become unassigned and can be deleted separately in the library. Deleting a source visit or session does not rewrite an already saved report: edit or delete that report separately. Deleting a file removes it from active R2 storage. Provider backups and operational security records may have separate retention periods.
Sign-in and essential cookies
We use a secure essential parent session cookie for up to seven days, a child session for up to four hours, and a short-lived cookie protecting email links. Expired authentication records are cleaned in bounded batches. No advertising tags or optional analytics cookies are installed. The unlisted pilot link can be forwarded; email verification and server permissions protect family accounts.
Questions and feedback
Contact the person who gave you the pilot link for account-removal requests or privacy questions. This is an early family pilot; do not rely on it for safeguarding, medical advice or a formal educational assessment.
Parent sign-inChild topic requests
A child may type a learning idea for their parent. The original request, parent notes and unpublished drafts stay in Cloudflare and are not sent to OpenAI. The parent selects a fixed catalogue topic for generic teaching cards, or writes their own material. A second, explicit approval is needed before teaching cards and questions appear in the child’s space. Requests are included in the family export and can be deleted by the parent. Deleting a request does not delete its published lesson or learning evidence; those can be removed in Sessions.