SafeMentor Privacy Policy
Status: February 2026
In this privacy policy, we inform you about the processing of personal data when using the SafeMentor App, the Parent Dashboard, and the associated AI services. Protecting children's privacy is our top priority. We follow the 'Privacy by Design' and 'Privacy by Default' principles and adhere to international best practices for child safety (such as KOSA and AADC) to ensure a safe learning environment. SafeMentor is intended exclusively for children up to the age of 15. Consent for data processing is therefore granted exclusively by the legal guardians.
1. Controller and Contact
Responsible for data processing is: Lighthouse Engineering Architecture S.L., Av Lluc 58, BJ, 07300 Inca, Spain, CIF B56925043. Email: privacy@safementor.app. The data protection controller is Andreas Greif, Mühlenstr. 3, 78176 Blumberg. privacy@safementor.app.
2. Data Categories and Collection Purposes
We only collect data that is strictly necessary for the provision of our services:
- • Registration Data (Parents):• Purpose: Name and address: Tax law obligation (§ 14 UStG - Invoicing) Phone number: SMS verification Email: Contract processing and Parent Dashboard access Payment data: Contract processing • Legal basis: Art. 6 (1) (b) GDPR (Performance of a contract).
- • Child Profile Data:Pseudonym and birth month of the child. • Purpose: Age-appropriate adaptation of AI responses and verification of parental consent according to Art. 8 GDPR.
- • Interaction Data and 'Project Memory':Chat content, questions asked, generated answers, and project progress (e.g., Python code). • Purpose: Continuity in the learning process. • Legal basis: Art. 6 (1) (b) GDPR.
- • Automatically Collected Information:IP address, browser type, operating system, and device usage data. • Purpose: Debugging and statistical evaluation to improve our services. • Legal basis: Art. 6 (1) (f) GDPR (Legitimate interest).
3. Special Feature: AI Processing and Intent-Routing
SafeMentor uses various AI models that are automatically selected depending on the request: • Before we transfer data to external AI interfaces (currently OVHcloud), it is cleared of personal identifiers as far as possible. • Every input from the child is first analyzed by a specialized classifier. This checks in real-time whether it is a factual learning question or a safety-relevant request. • Depending on the detected topic, the request is forwarded to the appropriate module to guarantee an educationally valuable and safe response. • Content is automatically checked for threat situations (e.g., grooming, bullying, self-endangerment, violence). In case of acute danger, a report is sent to the Parent Dashboard and, if necessary, also via email or SMS. **Safety Monitoring & Parent Dashboard:** • If a safety-relevant concern of lower urgency is detected (Yellow Flag), we inform the legal guardians about the general topic area and the detected reason, to enable an educational exchange in the family. • If acute threat situations are detected (Red Flag, e.g., signs of self-endangerment, abuse, violence, or other safety-relevant incidents), parents are notified immediately. In these cases, parents are also provided with a factual, non-verbatim summary of the relevant situation so that they can fulfill their supervisory and protective duties. The legal basis for Yellow/Red Flag monitoring is based on Art. 6 (1) (f) GDPR (Legitimate interest in protecting children from danger) **Balance of Interests:** • Our interest: Fulfillment of child protection duties (§§ 1631, 1666 BGB) • Interest of parents: Exercise of the duty of supervision • Interest of the child: Protection from serious dangers (violence, abuse, suicide) IMPORTANT: The Red Flag system is used exclusively for protection against serious dangers. It is NOT used for trivial behavior monitoring. Examples of Red Flags: ✓ Concrete suicide announcements ✓ Indications of abuse ✓ Serious threats of violence ✗ NOT: Swearing, normal arguments, bad grades. For children aged 14 and over: The child is informed about the safety monitoring function in an age-appropriate manner. If dangers are identified, the child itself is first encouraged to speak with parents/trusted persons before being automatically informed (except in case of acute danger to life).
3a. AI Models and Providers
STANDARD REQUESTS: • Provider: OVHcloud • Location: EU (France) • Usage: General learning questions, simple tasks COMPLEX TASKS: • Provider: OVHcloud, extended context processing • Location: EU servers • Usage: Mathematical problems, complex explanations, requests flagged as safety-relevant SAFETY-CRITICAL: • Dual-Check: Two independent classifiers check in parallel • Purpose: Compliance with safe answers when hazardous situations are detected The AI models used are checked for child safety and are subject to strict GDPR requirements (Data Processing Agreement according to Art. 28 GDPR). The specific provider may change as part of technical development; an up-to-date overview is always available in our list of subprocessors. IMPORTANT: Processing takes place exclusively on EU servers. No training data is created from child chats.
3b. Storage Architecture and Data Location
SafeMentor uses a hybrid storage model to protect privacy: **LOCAL STORAGE (on the child's device):** • Full chat histories: AES-256 encrypted, only on the device and only during the session. • Chat summaries: Created after the session and automatically deleted after 7 days • Project Memory: Local database for project progress (e.g., code snippets, details about a project). Project stores are deleted after 30 days of inactivity. **SERVER-SIDE STORAGE (encrypted in EU data centers):** • Yellow and Red Flag summaries: Context summaries for the Parent Dashboard (max. 30 days) • Account data: Registration information, payment data IMPORTANT: Full chat protocols never leave the child's device. Only pseudonymized requests are transmitted to servers for AI processing. In case of device loss, local data is protected by device PIN/biometrics. Remote deletion via the Parent Dashboard is possible.
4. Disclosure to Third Parties and EU Data Processing
SafeMentor processes ALL data exclusively within the European Union. We have deliberately chosen an EU-only architecture to ensure the highest data protection standard for children.
4a. Sub-processors (EU Servers)
We only pass on data to carefully selected partners for contract fulfillment:
| Category | Provider | Location | Purpose | Legal Basis |
|---|---|---|---|---|
| Hosting & Backend | Google Cloud | EU (Belgium) | Server infrastructure | DPA according to Art. 28 GDPR |
| AI Inference and Reasoning | OVHcloud | EU (France) | Generate AI answers | DPA according to Art. 28 GDPR |
| Hosting Frontend | Vercel Inc. | EU (Frankfurt) | Server infrastructure | DPA according to Art. 28 GDPR |
| Payment Processing | Mollie B.V. | EU | Credit card payments | DPA according to Art. 28 GDPR |
| Database Hosting & Backend | Supabase Ireland Ltd. | EU (Frankfurt) | Storage of user accounts (parents), chat summaries, project data | DPA according to Art. 28 GDPR |
| SMS Authentication | Twilio | EU (Ireland) | Parent authentication | DPA according to Art. 28 GDPR |
Although Vercel Inc. is headquartered in San Francisco (USA), data processing for SafeMentor takes place exclusively on servers in Frankfurt, Germany. Vercel has contractually committed to: • Not transfer data outside the EU • Not grant access to US employees to EU server data • Inform SafeMentor immediately in case of official requests. Additional protection: All sensitive data (chat content) is end-to-end encrypted before being stored on Vercel servers, so that Vercel itself has no access to plain text data. Twilio Inc. is also headquartered in the USA, but SafeMentor uses Twilio's European infrastructure in the Ireland region (IE1) for parent authentication. This ensures that the primary processing and storage of authentication data (such as mobile numbers and verification codes) takes place within the EEA. Twilio has committed through a Data Processing Addendum (DPA) and supplementary technical measures to: • Carry out the storage and processing of personal data primarily on servers within the EU. • Ensure an adequate level of data protection by applying EU Standard Contractual Clauses and certification under the EU-U.S. Data Privacy Framework. • Limit access to data by US entities to the absolute minimum necessary for technical operation. • In case of government requests, proceed according to internal transparency guidelines and protect the interests of SafeMentor. **Technical details on OVHcloud:** • Legal entity: OVH SAS (France) • Data centers: France (primary) • Certifications: ISO 27001, SOC 2 Type II • Data residency: All data remains in EU data centers • Training prohibition: NO customer data is used for model training • Retention: Requests are deleted immediately after processing
4b. No Third Country Transfers
IMPORTANT: There is NO data transfer to countries outside the EU/EEA. All data processing is subject exclusively to the GDPR.
4c. Data Processing Agreements (DPA)
All sub-processors have been carefully selected in accordance with Art. 28 GDPR and have concluded legally compliant data processing agreements with SafeMentor. These include in particular: • Bound by instructions of the controller • Confidentiality obligations of all employees • Technical and organizational measures (TOMs) • Support for data subject rights • Obligation to report data breaches immediately • Deletion obligations after contract end
4d. Current List and Change Notices
A constantly updated list of all sub-processors with contact details can be found at: /en/subprocessors In case of changes (e.g., new provider), you will be informed in good time (at least 30 days in advance) by email. You then have the right to object to the commissioning.
4e. No Sale of Data
We NEVER sell data to third parties. Neither for advertising, marketing, nor for any other purposes. Your data and the data of your children are processed exclusively for the provision of our services.
5. Cookie Policy
We use technically necessary cookies to enable functions such as login. You can block cookies via your browser. **TECHNICALLY NECESSARY COOKIES (without consent):** • Session Cookie: Maintaining the login (Duration: until end of session) • CSRF Token: Protection against attacks (Duration: 24 hours) You can adjust your cookie settings at any time or block cookies in general in your browser. Please note that if technical cookies are deactivated, functionality may be limited. We do NOT use third-party cookies (Google Analytics, Facebook Pixel, etc.).
6. Storage Duration
Personal data is stored only as long as necessary for the purposes or as required by legal deadlines.
| DATA TYPE | RETENTION PERIOD | LEGAL BASIS |
|---|---|---|
| Account Data (Parents) | Until contract end + 10 years | § 147 AO (Retention requirement) |
| Chat Summaries (normal) | 7 days | Art. 6 (1) (b) GDPR |
| Project Memory | 30 days after last use | Art. 6 (1) (b) GDPR |
| Yellow/Red Flag Summaries | 30 days (automatic deletion) | Art. 6 (1) (f) GDPR (Child protection) |
| Full Chat Protocols | Never stored server-side | Privacy by Design |
IMPORTANT: Red flag summaries are deleted after 30 days even if the hazard situation persists. This serves to protect the child's privacy. For ongoing concerns, we recommend professional support (e.g., family counseling) instead of technical permanent monitoring. **Account Deletion:** Upon termination, all personal data (except tax-relevant documents) will be completely deleted within 30 days.
7. Your Rights (Data Subject Rights)
Under the GDPR, you (and your child) have the right to access, rectification, erasure ('right to be forgotten'), restriction of processing, data portability, and the right to lodge a complaint with a supervisory authority. Requests must include proof of identity.
8. Data Security
We use state-of-the-art TLS/SSL encryption. Access to the Parent Dashboard is protected by multi-factor authentication. In case of security incidents, we inform the authorities in accordance with legal regulations.
9. Automated Decision Making and Profiling
SafeMentor uses AI-based automated processing in the following areas:
- • INTENT CLASSIFICATION:• Purpose: Assignment of the request to different safety levels and the corresponding AI model responses • Logic: AI model with corresponding prompts • Legal consequence: No disadvantageous effects for the child
- • YELLOW/RED FLAG RECOGNITION:• Purpose: Protection against dangers (violence, abuse, suicide) • Logic: Rule-based system + AI classifier (dual-check for critical cases) • Legal consequence: Immediate parent notification • IMPORTANT: This is NOT a fully automated decision within the meaning of Art. 22 GDPR, since the final decision on protective measures lies with the parents.
10. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the General Data Protection Regulation (GDPR). **Note on Jurisdiction:** As the responsible body under data protection law, we are subject to the supervision of the supervisory authority responsible for our headquarters or the authority relevant for the main location of our data processing. However, you can also address your complaint to the data protection authority in the EU Member State where you live, work, or where the suspected violation occurred. A list of supervisory authorities with contact details can be found at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
11. Voluntariness of Data Provision
The provision of your personal data is neither legally nor contractually required. You are also not obliged to provide us with personal data. Contractual obligations or the possibility to conclude contracts do not exist. **Consequences of non-provision:** Failure to provide your personal data merely means that you cannot use our services. You will not suffer any further disadvantages from this. **Mandatory fields and optional information:** As part of registration and use, we mark mandatory fields whose entry is required for the conclusion of the contract and the provision of our services (e.g., email address of parents, date of birth of the child). All other information is voluntary and can be omitted without adversely affecting the possibilities of use.
12. Withdrawal of Your Consent
Insofar as the processing of your personal data is based on consent (Art. 6 (1) (a) GDPR), you have the right to withdraw this consent at any time for the future. The lawfulness of the processing carried out based on the consent until the withdrawal remains unaffected by this. **Effects of Withdrawal:** The withdrawal of your consent may mean that certain functions of SafeMentor based on this consent (e.g., the use of certain AI models or more detailed analyses) can no longer be used or can only be used to a limited extent. The core functionality of the platform generally remains intact as long as other legal bases (e.g., fulfillment of contract, Art. 6 (1) (b) GDPR) support the processing. **How You Can Withdraw:** You can withdraw your consent informally with effect for the future. Please send your withdrawal to: By email: privacy@safementor.app By post: Lighthouse Engineering Architecture S.L., Av Lluc 58, BJ, 07300 Inca, Spain. For security and clear identification, we ask you to provide the email address with which you are registered with SafeMentor in your withdrawal statement.
13. Data Protection Impact Assessment (DPIA)
SafeMentor will, where necessary, conduct a Data Protection Impact Assessment (DPIA) in accordance with Art. 35 GDPR after completion of the pilot phase, to assess the risks to the rights and freedoms of children. **Reason for the DPIA obligation:** The processing includes: • Systematic monitoring (Red Flag monitoring) • Processing of sensitive data of children (under 16 years old) • Automated decision-making (intent routing, safety classification)
- • TECHNICAL PROTECTIVE MEASURES ALREADY IN PLACE:• Privacy by Design architecture (local storage of full texts) • AES-256 encryption of all sensitive data • Pseudonymization before transmission to AI providers • End-to-end encryption (TLS 1.3) • Automatic deletion after 7/30 days
- • ORGANIZATIONAL PROTECTIVE MEASURES ALREADY IN PLACE:• Strict access control (multi-factor authentication) • Regular security audits (every 6 months) • Training of all employees on child protection & GDPR • Emergency plan for data breaches