Privacy Notice
This Privacy Notice explains how Decentre Studio Limited collects, uses, stores, and shares personal information when you use Pathfinder. Controller: Decentre Studio Limited. Privacy contact: jessejr@decentre.io.
What we collect
Account and identity: your Google account identifier (UID), email address, and display name, received when you sign in via Firebase. We do not access Gmail, Calendar, or Drive.
Plan and application data: your shortlist of courses and apprenticeships, plan structure, application status, key dates, and any draft content you create within Pathfinder.
Chat data: the content of your messages and Pathfinder’s responses, retained in a bounded conversation window to provide context. Chat turns are processed by our AI provider.
Billing data: if you hold a paid subscription, your Stripe customer reference, subscription tier, and entitlement state. We do not store your full card number.
Usage and audit data: bounded technical logs covering session events, API request metadata, and audit records required by our governance posture.
How we use it
| Purpose | Lawful basis |
|---|---|
| Account authentication and session management | Contract |
| Delivering your application plan | Contract |
| Running the AI chat lane | Contract |
| Draft support | Contract |
| Deadline and task tracking | Contract |
| Parent or advisor read-only view | Consent |
| Pilot communications | Consent or Contract |
| Security, abuse prevention, audit | Legitimate interests |
| Legal compliance | Legal obligation |
What we don't do
- We do not monetise your data. We do not sell it, license it, or use it for advertising — yours or anyone else's.
- We do not monitor your activity beyond what is needed to run Pathfinder. We do not track what other apps, websites, or services you use.
- We do not profile you for purposes outside your application plan.
Children and young people
During this controlled live phase, Pathfinder is available only to users aged 16 or over. If you are under 16, do not create an account, use the service, or submit personal information. Users aged 16 or 17 receive higher privacy defaults; any future under-16 support requires a separate approval gate.
Young-person and under-16 explanation
Pathfinder is designed to be understandable for students, not only adults. The short version is: we use your account, plan, chat, deadline, billing, and safety/audit data to run Pathfinder and protect the service. We do not sell your data, use it for advertising, or use it for purposes outside your application plan.
For this controlled live phase, Pathfinder is 16+ only. If you are under 16, you should not create an account or send personal information to Pathfinder. Parent or guardian permission is not a bypass for under-16 use unless a later under-16 launch gate is separately approved and published.
Parent and advisor visibility
A parent, guardian, advisor, or operator may only see a role-scoped Pathfinder view if their account is linked and the relevant consent or visibility rule allows it. These views are designed to be thinner than the student view. They may show plan status, dates, account or billing actions, and agreed summary information, but they should not expose private chat content or unrelated personal details unless the product explicitly says that sharing is enabled.
Pathfinder records and checks visibility rules before showing parent or advisor views. If a visibility or consent setting changes, Pathfinder should use the latest Pea-owned policy state rather than browser-only settings.
Processors we use
| Processor | Role |
|---|---|
| Google / Firebase | Authentication, app hosting, Firestore |
| Google Cloud Platform | Server infrastructure, Cloud SQL, API hosting |
| AI provider (OpenRouter / LLM) | Processing chat turn inputs and outputs |
| Stripe | Payment processing and subscription management |
For AI processing, OpenRouter is a routing layer and the selected model provider may also process the prompt and response. Before real student prompts are approved, we record the current OpenRouter logging/settings posture and the selected downstream provider's retention and deletion posture in the processor register.
How long we keep data
| Data | Retention |
|---|---|
| Account identity | Account duration + 12 months |
| Plan and application data | Account duration + 12 months |
| Chat conversation history | Rolling 6-month window |
| Draft content | Until deleted, or account closure + 12 months |
| Policy acceptance records | 3 years |
| Session and audit logs | 12 months |
| Billing records | 7 years (legal obligation) |
Your rights
- Access — ask for a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete information.
- Erasure — ask us to delete your data (subject to legal retention requirements).
- Restriction — ask us to limit how we use your data.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests.
- Withdraw consent — withdraw consent at any time where processing is consent-based.
To exercise any right: jessejr@decentre.io. We respond within one calendar month. You can also complain to the ICO at ico.org.uk or 0303 123 1113.
Contact
Decentre Studio Limited · jessejr@decentre.io · decentre.io