Talent IQ Privacy Policy
Talent IQ is a parent-controlled discovery companion. This policy describes exactly what the product collects, how it is processed, who processes it on our behalf, and how you remove it. It describes the app as actually built — nothing more.
1. Summary of our commitments
- We do not sell personal information, and we never sell children's personal information.
- There is no advertising in Talent IQ and no targeted advertising to children.
- There are no public child profiles, no leaderboards, no child-to-child or stranger messaging, and no location sharing.
- Child profiles are created and controlled by a parent or legal guardian.
- AI-generated observations are qualitative patterns only — never IQ scores, diagnoses, clinical assessments, or fixed career predictions.
- You can export all of your account data as JSON and delete any child's data or your entire account at any time.
2. Who we are
Talent IQ ("Talent IQ", "we", "us") provides the Talent IQ AI Companion web application. For personal data processed through the service, Talent IQ acts as the data controller and the parent account holder is our customer. Contact us at privacy@talentiq.app.
3. Parent accounts and authentication
Accounts are for adults only. When you sign up with email or with Google sign-in we store your email address, an account identifier, an optional display name, and authentication metadata (such as sign-in timestamps and session tokens) needed to keep you signed in. Passwords are handled by our authentication provider and are never stored by us in readable form. Sign-in is required for every parent-only area of the app.
4. Child profiles and child data categories
A parent creates each child profile. We deliberately ask for the minimum: a nickname (a real name is not required), an age or age band, a language preference, and a few interests. We do not ask for a child's full legal name, address, school, phone number, email address, or photograph of the child, and Talent IQ's AI is instructed not to request or retain such identifying details if a child volunteers them.
Linked to a child profile, we store:
- Conversations — the text of AI conversation sessions and each turn within them.
- Talent Signals and observations — qualitative pattern states (Emerging Pattern, Frequently Observed, Worth Exploring, Not Enough Evidence Yet) together with the evidence excerpt and source that supports each one.
- Longitudinal memory — accumulated pattern history over time so the app can show change across weeks and months.
- Discovery Journal entries and child reflections saved from activities.
- Parent Notes written by you about your child.
- Challenge activity — which challenges were started or completed and any response saved with them.
- Together Time sessions — the shared parent-child prompts and responses in that flow.
- Reports and report snapshots — generated summaries, kept as point-in-time snapshots so past reports remain accurate.
All of this data is scoped to a single child profile inside a single parent account. The app enforces per-account isolation at the database level, so one family's data is never visible to another, and one child's history is never mixed into another child's context.
5. How AI processing works
Talent IQ's conversational intelligence runs server-side. Your browser never holds an AI provider credential. When a conversation turn, Parent Mode question, Together Time turn, report, challenge recommendation, or signal extraction is requested, our server sends the relevant context — the current message, a limited window of recent turns for that child, the child's age band, existing qualitative patterns, and relevant notes — to OpenAI, which processes it and returns a structured response.
Safety rules run before and after every generation. The AI does not evaluate answers as right or wrong, does not diagnose, does not label, and does not predict a fixed future for a child. Observations are always presented as one of the four qualitative states above, backed by the evidence that produced them.
If the AI service is unavailable, the app falls back to a local rules-based conversation mode. In that mode no content leaves our infrastructure for AI processing.
6. Voice: transcription and spoken responses
Voice mode is off unless a parent enables it. When a child or parent records audio, the audio bytes are sent from the browser to our server, forwarded to OpenAI's speech-to-text service, and the resulting text is returned. For spoken replies, the text of an AI response is sent to OpenAI's text-to-speech service and the returned audio is streamed back to the browser for playback.
We do not store audio. Recorded audio and generated speech are held only in memory for the duration of the request; there is no audio storage bucket, and no audio file is publicly addressable. Only the resulting transcript text — and any observations derived from it — is saved to your account, exactly as if it had been typed.
7. Conversation Credits and payments
AI usage is metered in Conversation Credits. We keep a server-side ledger recording your monthly included allowance, purchased credit balance, each usage or refund transaction, the operation type it relates to, and the timestamp. This ledger is a billing and abuse-prevention record; it does not contain conversation content.
Credit purchases are processed by Stripe. Card numbers, CVC codes, and full payment instrument details are entered with and handled by Stripe — Talent IQ never receives or stores full card details. We store only what we need to reconcile a purchase: the pack purchased, the amount and currency, the payment status, and Stripe's transaction reference. Stripe processes this data as an independent payment processor under its own privacy policy.
8. Service providers (and why this is not selling)
We use a small number of vendors that process data strictly on our instructions, only to deliver the service, and with no right to use it for their own purposes:
- Lovable Cloud (Supabase) — database, authentication, and application hosting infrastructure where your account data is stored.
- OpenAI — AI text generation, speech-to-text, and text-to-speech, as described above.
- Stripe — payment processing for credit purchases.
- Google — only if you choose Google sign-in, to authenticate you.
Disclosure to a service provider for these purposes is not a sale or a cross-context behavioural "share" under laws such as the CCPA/CPRA. We do not sell personal information, we do not sell or share children's personal information for any purpose, and we do not disclose personal information to advertising networks or data brokers. We may disclose data if legally compelled, or to protect the safety of a child or another person.
10. Children's privacy, COPPA and parental consent
Talent IQ is designed for children to use with a parent's involvement, and only through a parent-created profile. Children do not create accounts, cannot sign in independently of the parent account, and cannot make purchases.
For families in the United States, we operate consistently with the Children's Online Privacy Protection Act (COPPA). By creating a child profile you provide verifiable parental consent, as the account holder, for the collection and use of that child's information described in this policy. We collect only information reasonably necessary for the discovery activity, we do not condition a child's participation on disclosing more than is necessary, and we do not use children's information for advertising, profiling for marketing, or any behavioural targeting.
As the parent you may, at any time: review the information stored for your child, export it, refuse to permit further collection by disabling features or deleting the profile, and require deletion of everything already collected. Detailed analytics are visible in Parent Mode only; Child Mode shows encouragement and activity, never analysis.
11. Parental control over child data
The parent account holder controls every child profile: which features are enabled (including voice, uploads and journal saving), what is saved, what is deleted, and who sees it. Only the signed-in parent account can access its own children's data. Talent IQ has no feature that exposes a child profile publicly or to another user.
12. Export, deletion and your rights
In Settings you can, at any time:
- See an inventory of exactly what is stored for each child, by category and count.
- Export all your data as a downloadable JSON file containing your account data and each child's conversations, observations, notes, journal entries, activity and reports.
- Delete one child's data — this permanently removes that profile together with its conversations, turns, observations and evidence, signal memory, journal entries, reflections, parent notes, challenge completions, Together Time sessions, reports and snapshots. Other children are unaffected.
- Delete all Talent IQ data in your account while keeping the login.
- Delete your account entirely — this removes every child profile, all history and evidence, and your sign-in credentials, and signs you out immediately.
Deletions are permanent and cannot be undone, so export first if you want a copy. Depending on where you live, you may also have rights of access, correction, portability, restriction, objection, and complaint to a supervisory authority (for example under the GDPR or UK GDPR), and rights to know, delete, correct and opt out of sale or sharing (for example under the CCPA/CPRA — noting that we do not sell or share personal information). The tools above satisfy most of these directly; for anything else write to privacy@talentiq.app and we will respond within the period required by applicable law. We will not discriminate against you for exercising a privacy right.
Where the GDPR applies, our legal bases are: performance of our contract with you (providing the service), your consent (for a child's participation and for optional features such as voice), our legitimate interests (security, abuse prevention, service reliability), and legal obligation (billing records). Our infrastructure and AI providers may process data in the United States; where required, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent mechanism.
13. Retention
We keep child and family data for as long as your account remains active, because the product is explicitly longitudinal — the value comes from recognising patterns over months. We do not apply an automatic expiry to conversations, observations or reports; you decide when they go.
When you delete a child profile or your account, the associated records are removed from our live systems immediately and cascade to every linked record. Encrypted infrastructure backups may retain a copy for a short rolling window before being overwritten. Audio is never retained. Billing and credit-ledger records may be kept, in a form disconnected from conversation content, where we are legally required to retain financial records.
14. Security
Data is transmitted over TLS and stored in a managed database with row-level security policies that scope every record to its owning parent account, enforced by the database itself rather than only by application code. AI and payment credentials are stored as encrypted server-side secrets and are never present in the browser or in our source code. Parent-only routes are gated behind authentication, AI operations are authenticated, ownership-checked and rate limited server-side, and operational logs exclude conversation content. No system is perfectly secure, but we design for least exposure and minimum collection.
15. What Talent IQ is not
Talent IQ is a discovery companion — not a therapist, doctor, psychologist, diagnostic tool or school examination. Nothing the app produces is an IQ score, a test result, a ranking against other children, a clinical assessment, or a prediction of what a child will become. Outputs are qualitative observations with visible supporting evidence, intended to start family conversations. They should never be used to make medical, educational placement or diagnostic decisions.
16. Changes to this policy
This page carries a version number and effective date at the top. When we make a material change we will increment the version, update the dates, and — where the change materially affects how a child's data is handled — notify the parent account holder and obtain consent again where the law requires it.
17. Contact
Privacy questions, data requests and complaints: privacy@talentiq.app. You can also review the in-product controls on the Safety & Privacy page and manage export and deletion in Settings.