Trust / Working draft

Privacy, with the edges still visible.

This page describes information the Briarhush app currently receives and stores through its account, enquiry, waitlist, story, memory, consent, and privacy-request flows. It is a readable draft, not final legal terms.

Information currently received

The categories below reflect fields used by the current app flows. Some submissions can contain sensitive family information, including child details, memories, and photographs.

  • Accounts and authentication. Account name and email, password credential data in the account record, and session records with expiry and token fields. Sessions may also include optional IP address and user-agent fields. These records support account creation, sign-in, active sessions, and protected account or admin access.
  • General enquiries. The contact flow stores a name, email address, and message so Briarhush can review and respond.
  • Studio enquiries. The studio intake stores a contact email, business type, offer, audience, deliverables, budget, references, selected package or template values, source, and timestamps.
  • Mascot licensing enquiries. The licensing flow stores contact and company name, email, selected mascot, usage channels, territory, duration, and related enquiry fields in the quote-request record. It also records the status of a confirmation email sent through the installed email proxy.
  • Waitlist signups. The waitlist flow stores an email address and creation timestamp, records consent metadata when supplied, and sends the configured welcome email. Waitlist addresses are not rendered as a public list.
  • Personalised story requests. The story flow stores a parent or guardian email, child first names and ages, interests, occasion, story length, budget, tone, optional dedication, consent timestamp, and optional reference-photo storage metadata. A reference photo is uploaded through the existing R2 proxy. The route sends a confirmation email to the submitter and an internal notification.
  • Memory submissions. Memory-book intake stores family name, contact email, occasion, memory details, medium and book preferences, optional dedication, photo URL references, consent timestamp, and delivery or email status. Memory-film intake stores family name, occasion, contributor count, media-count range, delivery window, contact email, and confirmation-email status.
  • Consent and privacy requests. A privacy request includes a request type, contact email, and optional details; the database records its status and timestamps. Consent records can include scope, notice version, subject email, resource type or ID, accepted timestamp, and creation timestamp.

How the information is currently used

The confirmed operational purposes are to:

  • create accounts, sign users in, maintain sessions, and protect account or admin access;
  • review and respond to general, studio, mascot licensing, story, and memory enquiries;
  • review the creative details needed for a requested story, keepsake, film, or licensing conversation;
  • send confirmation, welcome, and internal review emails through the installed email proxy;
  • record the consent metadata associated with a submission; and
  • receive and review requests to access or delete submitted information.

This draft does not state that Briarhush sells information, uses it for advertising or profiling, or shares it for purposes beyond these confirmed app flows.

Private submission content

Story, child, memory, photo, licensing, and project-enquiry submissions are operational records for the requested service. They are not rendered on public pages, and the public app does not provide a list of submitted records. Admin project and privacy-request views are protected by the installed requireAdmin() guard.

This page describes the current product behavior; it does not make an absolute promise of confidentiality, security, non-disclosure, or deletion.

Retention and deletion requests

The current code records creation timestamps and, where applicable, processing or email status. The owner-approved retention setting is currently unset, so no retention period has been approved and this draft does not invent one. There is also no approved legal response timeline or service-level promise for a request.

To ask about access to or deletion of information, use the existing Contact page, which includes the current request path. Requests are recorded for owner review; submitting one does not mean deletion is automatic or guaranteed by a particular date.

Owner and legal review markers

The following decisions remain open and are intentionally not presented as settled terms:

  • retention periods, deletion handling, and any legal response timelines;
  • legal bases for each intake and the wording for children’s data and guardian consent;
  • storage, email, R2 photo-storage, analytics, and other vendor or processor language;
  • international storage or transfer details;
  • the official legal entity and controller details; and
  • the final access and deletion request process.

The consent-gated Meta Pixel and the framework visitor beacon are separate implementation behaviors. Their vendor, analytics, and legal wording still needs review, so this page does not make a blanket claim about optional analytics or consent coverage.

Contact Briarhush

Questions, corrections, or privacy requests can be started through the Contact page or by emailing briarhush@polsia.app.