1. Data we collect
We collect the following data to operate the Mothership family assistant:
• **Account data**: Name, email address, and profile image from your Clerk account.
• **Messages & threads**: Text messages you send to the AI assistant and the AI's responses.
• **Memories**: Summaries of conversations stored to personalise future responses.
• **Optional photo metadata**: If you upload a JPEG or TIFF image with embedded EXIF data, we may read its timestamp and location metadata to create a short timeline or memory summary.
• **Scout observations**: Proactive insights generated from your connected integrations (email, calendar, health).
• **Integration tokens**: OAuth access tokens for connected services (Google, Apple Health, etc.), stored encrypted.
• **Cost and usage**: Token counts and estimated cost per AI request for billing purposes.
• **Audit logs**: Records of significant actions (tool executions, approvals, deletions).
2. How we use your data
Your data is used exclusively to provide the Mothership service to your family:
• Responding to your questions and requests via the AI assistant.
• Proactively surfacing relevant observations via the Scout system.
• Enabling family coordination features (shared threads, parental controls).
• Turning optional uploaded-photo metadata into lightweight timeline or memory summaries. We only read exact photo location from files you choose to upload, and any future device-photo access would require explicit permission.
• Billing and abuse prevention.
We do **not** use your data for behavioural advertising, sell it to third parties, or use it to train AI models.
3. Retention periods
• **Messages & threads**: Retained until you delete them, then hard-purged after 30 days.
• **Memories**: Retained until deleted or expired, then hard-purged after 30 days.
• **Optional photo metadata summaries**: Retained with the memory or timeline entry they enrich; removing the underlying memory or upload removes that enrichment as well.
• **Scout observations (adults)**: Retained for 90 days, then automatically deleted.
• **Scout observations (children under 13)**: Retained for 7 days, then automatically deleted (COPPA).
• **Audit logs**: Retained for 90 days.
• **Integration tokens**: Deleted immediately on revocation.
4. Children's privacy (COPPA)
Mothership includes features designed for families with children under 13:
• Children under 13 cannot self-register. A parent must add them to the family.
• Scout observations for children are automatically deleted after 7 days.
• Parents can configure content filters and topic restrictions for child accounts.
• Destructive AI actions for child accounts require explicit parent approval.
• We do **not** engage in behavioural advertising targeting children.
5. Your rights (GDPR)
If you are in the EU/EEA or UK, you have the following rights:
• **Right to access**: Request a full export of your family data at any time from Settings → Privacy.
• **Right to erasure**: Delete your account and all associated data. A 30-day recovery window applies, after which deletion is irreversible.
• **Right to portability**: Data exports are provided in JSON format.
• **Right to rectification**: Update your profile information via Settings → Account.
To exercise these rights, visit [Settings → Privacy](/settings/privacy) or contact us at privacy@mothership.app.
6. Cookies
Mothership uses a single first-party session cookie managed by Clerk for authentication purposes. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.