Privacy
Collect less. Explain clearly. Protect carefully.
This notice explains the public pilot site and the invite-only Family Digital Defence member area. Payment remains disabled until the controller and provider details are finalised.
Pilot draft · Last updated 25 August 2026
Status and controller
The marketing and interest-registration pages are public. The member Control Hub and operations area are allowlisted technical pilots, not open self-service products. The legal operating entity, registered address and public privacy contact have not yet been confirmed. No public payment or partner activation should occur until those details and the final processor schedule are published at the point of collection.
What we collect
The pilot may hold the signed-in adult’s name and email, UK nation, household age bands, generic device labels and broad device types, selected concerns, setup actions, consent records, pilot membership status and structured support categories. The Control Hub also stores connection status, supported capabilities, desired protection mode, provider-accepted internet rules, last check-in, control-command history and safe security-alert metadata.
Information relating to children
Age bands, device categories and selected concerns can still relate to children even without names. They are used to register authorised devices, determine compatible control coverage and shape the parent’s setup actions. Parents should use generic labels, explain controls in an age-appropriate way and avoid entering names or incident details. The pilot does not make automated decisions about a child.
What we deliberately do not collect
We do not ask for third-party account passwords, security codes, recovery phrases, children’s full names, dates of birth, schools, private messages, intimate images, contacts, a detailed browsing history or precise location through the Family Digital Defence portal. Any provider payload fields containing passwords, password hashes, salts or raw breach-source text are deliberately discarded.
Why information is used
Account and household information is used to provide the requested pilot, keep the setup checklist, answer support requests, protect the service from misuse and prepare any future membership. These purposes are expected to rely on steps requested before a contract, performance of a contract, legitimate interests in operating a secure low-data service and legal obligations as applicable. Optional marketing relies on separate consent and can be withdrawn.
Assessment results
The public safety check is calculated in the browser. Raw answers and the resulting readiness score are not sent to or stored by the pilot database.
Breach monitoring
The launch design requires a one-time verification before a family email can be monitored. The lower-cased address is converted to a SHA-256 hash for the breach provider; the portal can retain only a masked display value and the hash needed to match a callback. A callback stores an exposure reference, event date and safe breach metadata. Notification text on the phone is generic, with details available after sign-in.
Hosting, recipients and future providers
The pilot uses OpenAI Sites and Cloudflare-hosted application and database infrastructure. The member area and operations view use separate email allowlists; a normal pilot account is not an operations administrator. No outsourced assistant has portal access during this checkpoint. Control D and Enzoic are the recommended launch candidates, but no live customer processing begins until commercial terms, a processor agreement, UK transfer safeguards, exact API permissions and test-device acknowledgement are complete. Family Digital Defence will not ingest underlying child messages or images.
Children’s privacy
The parent or authorised device owner must explain controls in an age-appropriate way. Controls must not be installed covertly. The launch service does not offer location tracking.
Retention
Automated retention is not yet enabled. Before inviting external pilot families, the operator must activate a schedule covering unactivated interest records, inactive portal accounts, support cases and consent audit records. A signed-in pilot user can request deletion now; the request is identity-verified before records are removed.
Cookies and sign-in
Only essential hosting and sign-in storage is intended for the public site and invite-only member pilot. No advertising or behavioural-analytics cookies are knowingly used. A separate cookie notice and consent mechanism must be added if optional analytics are introduced.
Your rights and contact route
UK data-protection rights can include access, correction, deletion, restriction, objection and complaint to the Information Commissioner’s Office. Signed-in pilot users can create a data-export or deletion request through Member Support. A public privacy email and postal address will be added before wider access.