← Back to Mothership

Privacy Policy

Effective date: 1 January 2026 · Last updated: 13 March 2026

1. Data we collect

We collect the following data to operate the Mothership family assistant: • **Account data**: Name, email address, and profile image from your Clerk account. • **Messages & threads**: Text messages you send to the AI assistant and the AI's responses. • **Memories**: Summaries of conversations stored to personalise future responses. • **Optional photo metadata**: If you upload a JPEG or TIFF image with embedded EXIF data, we may read its timestamp and location metadata to create a short timeline or memory summary. • **Scout observations**: Proactive insights generated from your connected integrations (email, calendar, health). • **Integration tokens**: OAuth access tokens for connected services (Google, Apple Health, etc.), stored encrypted. • **Cost and usage**: Token counts and estimated cost per AI request for billing purposes. • **Audit logs**: Records of significant actions (tool executions, approvals, deletions).

2. How we use your data

Your data is used exclusively to provide the Mothership service to your family: • Responding to your questions and requests via the AI assistant. • Proactively surfacing relevant observations via the Scout system. • Enabling family coordination features (shared threads, parental controls). • Turning optional uploaded-photo metadata into lightweight timeline or memory summaries. We only read exact photo location from files you choose to upload, and any future device-photo access would require explicit permission. • Billing and abuse prevention. We do **not** use your data for behavioural advertising, sell it to third parties, or use it to train AI models.

3. Retention periods

• **Messages & threads**: Retained until you delete them, then hard-purged after 30 days. • **Memories**: Retained until deleted or expired, then hard-purged after 30 days. • **Optional photo metadata summaries**: Retained with the memory or timeline entry they enrich; removing the underlying memory or upload removes that enrichment as well. • **Scout observations (adults)**: Retained for 90 days, then automatically deleted. • **Scout observations (children under 13)**: Retained for 7 days, then automatically deleted (COPPA). • **Audit logs**: Retained for 90 days. • **Integration tokens**: Deleted immediately on revocation.

4. Children's privacy (COPPA)

Mothership includes features designed for families with children under 13: • Children under 13 cannot self-register. A parent must add them to the family. • Scout observations for children are automatically deleted after 7 days. • Parents can configure content filters and topic restrictions for child accounts. • Destructive AI actions for child accounts require explicit parent approval. • We do **not** engage in behavioural advertising targeting children.

5. Your rights (GDPR)

If you are in the EU/EEA or UK, you have the following rights: • **Right to access**: Request a full export of your family data at any time from Settings → Privacy. • **Right to erasure**: Delete your account and all associated data. A 30-day recovery window applies, after which deletion is irreversible. • **Right to portability**: Data exports are provided in JSON format. • **Right to rectification**: Update your profile information via Settings → Account. To exercise these rights, visit [Settings → Privacy](/settings/privacy) or contact us at privacy@mothership.app.

6. Cookies

Mothership uses a single first-party session cookie managed by Clerk for authentication purposes. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

7. Contact

For privacy enquiries, please contact: **privacy@mothership.app**