What we store, and what we refuse to store
GrowXP is a motivation system used by families with children, so this page is written to be read, not to be survived. It covers two separate things: this website with its waiting list, and the GrowXP product used by families in the closed pilot. Where the law is named, we mean the EU General Data Protection Regulation (GDPR, including Article 8 on children) and Russian Federal Law No. 152-FZ on Personal Data.
In short
- This website sets no cookies, runs no analytics, and loads nothing from third-party servers — fonts and scripts are served from our own domain.
- If you switch on notifications, we store one thing: the push address your browser generates, plus your browser language, time zone and user-agent string. No name, no email, no account.
- We send exactly one notification — when the next test group opens. Press the button again and the subscription is deleted.
- A child never signs themselves up. Children enter the product only through an invitation issued by their own parent.
- Ask us and we delete a child's or a family's data. Today the operator does it by hand — there is no self-service button yet, and we say so rather than imply one.
- We do not sell data, do not run ads, and do not profile anyone for marketing.
1. Who is responsible
GrowXP is built and run by its author as a closed, non-commercial pilot: no company sits behind it yet, no money changes hands, and nobody is paid to look at your data. In the language of the law that author is the “operator” (152-FZ) and the “controller” (GDPR). Before GrowXP opens beyond the pilot, the operator's full legal identity will be named on this page — that is a promise with a date attached to it, not a formality we hope you skip.
Everything about data — questions, corrections, deletion, complaints — goes to [email protected], and is answered from the same address. There is no phone line and no bot for this on purpose: a written request leaves a trail both sides can point at.
2. This website and the waiting list
The pages of growxp.me are static. Opening them creates no account, sets no cookie, and stores nothing in your browser. Our web server keeps ordinary technical logs — which page was requested, when, and with what response code — and they rotate away automatically after a few megabytes. The site is published through a tunnel, so the address our server records as the caller is the tunnel's, not your device's; the company that operates that tunnel does see your real address, and is named below.
If you switch on notifications
Pressing “Notify me” asks your browser for permission. If you allow it, your browser — not us — creates a push subscription with the push service that browser uses (Google for Chrome and Edge, Mozilla for Firefox, Apple for Safari). We then store what that subscription consists of:
| Push address (endpoint) | A long URL at your browser vendor's push service. It identifies a browser installation, not a person: no name, no email, no phone number, no IP address. |
| Two public keys | Generated by your browser so that only your browser can decrypt the notification we send. |
| Browser language, time zone, user-agent | So that we can send the announcement at a sane local hour and know which browsers we are dealing with. Nothing else is derived from them. |
Purpose: to send you one notification when we start gathering the next test group. Legal basis: your consent — GDPR Art. 6(1)(a), and Art. 9 of 152-FZ. Pressing the button is that consent; this page is the information it is based on.
Withdrawing it is one press. The same button, now reading “You are on the list”, turns the subscription off: your browser cancels it and we mark our copy as deleted. You can also revoke notification permission in your browser's site settings at any time — we find out at the next send, when the push service reports the address as gone, and drop it.
How long we keep it: until you turn it off, or until the announcement has been sent and the waiting list has served its purpose — whichever comes first. Addresses that the push service reports as dead are deactivated automatically.
This site is for adults. The waiting list is meant for parents and teachers. Please do not switch notifications on a child's device.
Third parties on this website
We serve the fonts and the page's own JavaScript from growxp.me itself — deliberately, so that reading this page tells no advertising company anything about you. There is no Google Fonts request, no CDN, no analytics, no tracking pixel, no session recording. Two third parties remain, and both are structural rather than optional:
- Cloudflare — our domain and the tunnel that publishes the site run through it, so Cloudflare handles the connection itself and sees the request and the IP address it came from, as any network provider on the way does. We chose it because the alternative was exposing a home machine to the open internet.
- Your browser's push service (Google, Mozilla or Apple) — appears only if you switch notifications on, and only because a web notification physically travels through it. It receives your push address and an encrypted message it cannot read.
3. The product: what a family's account contains
This section applies only to families in the closed pilot — people who received an invitation and started using GrowXP inside Telegram. If you are only reading the website, none of it concerns you.
| Parents and teachers | The Telegram account id and the display name Telegram gives us, plus the role (parent, mentor) and, for a mentor, which subjects they are allowed to award for. |
| The child | The name or nickname the parent types in, an optional persona title, the chosen theme, and an age band such as “8–10”. We deliberately do not store a date of birth. If the child has their own Telegram account, its id — that is how the app knows whose dashboard to show. |
| What the child did | The award ledger: which activity, on which track, when, the weight applied, and which adult confirmed it. This is the substance of the product, and it is append-only by design — history is never rewritten behind a child's back. |
| Behaviour | The weekly “shield” state — intact, broken, repaired — in neutral wording, with no score attached, kept deliberately separate from the award ledger. Whatever note an adult adds when a shield breaks or is repaired is stored as free text. A parent can also mark a day as a sick day so it does not count as a missed one; that record is a date with no reason attached. |
| Wishes and prizes | The wishlist the child fills in themselves, and which milestones unlocked what. |
| Homework | The task text from a mentor, their comments to the parents, and photographs uploaded by the child or the mentor. They are meant to show completed work: every upload is re-encoded on our server, which strips camera metadata including any location. Nothing technically stops a child from photographing themselves instead, and the photo is forwarded to the parents and that mentor as a Telegram message with the child's first name in the caption — so treat it as a message, not a private file. |
| The parent advisor | If parents use the built-in AI advisor, their chat with it — one thread per family, visible to both parents. |
| Deep profiling (optional) | If a family uses it: the parent's answers, the child's own answers and clarifications, and the generated motivation profile and report. |
What we never ask for. No date of birth — an age band is enough. No address, no phone number, no school name, no email for a child, no location, no contact list, no fingerprinting. There is no field anywhere in the system for a diagnosis and the product never asks a family to declare one: GrowXP is built with ADHD in mind and says so openly, but it runs on an age band, a first name and a list of what the child actually did. Wording that would read like a diagnosis is deliberately kept out of what the child and the parents see.
Where health nevertheless appears
Two honest exceptions, because pretending otherwise would be worse than admitting them:
- The sick day above is a fact about a child's health, even though we store only a date and never a reason. A list of such dates is what it is, and we treat it as sensitive.
- The advisor chat is free text, and the assistant will ask a parent about a child's particulars when they matter to the advice. Whatever a parent writes there — including a diagnosis, if they choose to mention one — is stored as ordinary text and, like the rest of that chat, is sent to the AI provider described below. Nothing in the product needs it: if you would rather it did not exist anywhere, do not type it there.
Under GDPR Art. 9 and Art. 10 of 152-FZ this is special-category data. The honest status today is that the system gives it no separate storage regime and asks for no separate consent — it is ordinary text in an ordinary field. We would rather write that down than let you assume otherwise.
Legal basis. For a parent using the product: performance of the service they asked for, and their consent. For a child's data: the consent of their parent or legal guardian — GDPR Art. 6(1)(a) with Art. 8, and Art. 9 of 152-FZ, which likewise requires the legal representative's consent for a minor.
4. Children, specifically
Everything here follows one rule: a child is not a customer we acquire, they are a person their parent brought in.
- No self-signup. A child cannot create an account. They join only with an invitation code issued by their own parent inside the family, and they can only ever interact with the adults that parent invited. There is no discovery, no public profile, no friends, no leaderboard against strangers, no messaging with anyone outside the family circle.
- A teenager's own answers stay theirs — from the parents. In the optional profiling flow a 14-plus child answers on their own device, and the raw answers are not handed to the parents: they receive the conclusion, not the transcript. That is enforced by the API rather than by good intentions — the internal profile is never sent to any client at all. The limit of the promise is stated to the teenager on the screen where they agree to answer: the model does read what they write, because that is what generates the profile.
- No advertising, ever. No ads are shown, no profiles are built for marketing, no data is sold or shared with schools, advertisers or data brokers. There is no business model in which that would be tempting: the product is a paid service to parents or it is nothing.
- Minimum data by design. The whole product runs on an age band, a first name and a list of what the child actually did. That is not a privacy gesture, it is the design: the system rewards effort, and effort is all it needs to know.
5. What leaves our server
- Telegram. The bot and the app live inside Telegram, so messages, buttons and uploaded photos pass through Telegram's infrastructure and are subject to Telegram's own privacy policy. A copy of an uploaded homework photo also remains in Telegram, on purpose: it is our insurance if the server's disk is lost.
- An AI provider, if the AI features are used. Three things send text to a large language model: the optional deep profiling, the advisor chat for parents, and the mini-tests in the child's profile. What goes out is the answers themselves, the child's age band, and — for the advisor and the mentor's advisor — the child's first name, along with track names, recent award reasons and the notes adults have written. The parent advisor also composes a weekly summary on its own, without being asked, for every family that has a child. Every family in the pilot today is taking part in building GrowXP — the author's own family and the people helping to make the thing work, not customers being served. On that footing the AI features run through the author's own account with the provider, which is a channel for testing. Admitting the first family from outside that circle is the condition for moving them to a provider channel whose terms forbid training on what we send; the provider will be named here when that happens. It is a condition, not a hope.
- Cloudflare carries the connection, as described above — and unlike our own server, it does see the IP address your request came from.
- Google's font service, in the app. The dashboard inside Telegram still loads its typefaces from Google, so Google learns the IP address of the device that opens it. We removed that from this website — the fonts you are reading now come from our own server — and the app is next in line.
- Nothing else. No analytics, no crash reporting, no advertising or marketing tools, no session recording, no third-party integrations of any kind. Those are absent from the code, not merely disabled.
6. Where the data lives and who can reach it
The database is a single file on a server we rent and administer ourselves — no third-party cloud database, no data warehouse, no analytics copy. Homework photos sit next to it on the same disk. Access is limited to the operator; nobody is employed to browse family data, and nobody outside has an account. Technical logs may briefly contain a Telegram account id — for example when someone unknown writes to the bot — and they rotate away on their own within megabytes.
Backups run daily. They are kept for two weeks on the server, and a copy is pulled to a machine the operator controls, where it is kept for thirty days before it is deleted. That copy is the reason a deletion request takes up to a month to disappear everywhere, and we would rather you knew the number than trusted a word like “promptly”.
We will not pretend this is a bank. It is a small self-hosted service run carefully by one person, and the honest summary of its security is “few moving parts, and nothing sent anywhere it does not have to go”. Two things are on the list before GrowXP opens beyond the pilot: encrypting those backup archives at rest, and naming the server's jurisdiction on this page. Both are named here rather than left for you to discover.
7. Deleting data and ending it
Write to [email protected] and say what should go: one photo, one profiling session, a child's whole record, or the entire family. Here is how it actually works, so that nothing surprises you:
- By hand, by the operator. There is no “delete my account” button in the product yet. A deletion request is carried out manually and confirmed back to you in writing. That is the limitation of a one-person pilot, and building the tool that does it properly is the next thing on the list.
- Some things you can already remove yourself: a homework photo before the task is submitted, a wishlist item, a profiling session from the admin panel.
- The award ledger is append-only while an account exists — that is the point of the product, because a child's earned experience must not be quietly editable, not even by a parent. Deleting a family removes its ledger along with everything else; erasing a single episode from it is not something the system can do.
- Backups lag. Data deleted today survives in backup archives for up to two weeks on the server and up to thirty days in the operator's copy, then goes with them.
- Telegram keeps its own copies. Because the product lives inside a messenger, notifications and homework photos are also ordinary Telegram messages in the chats of the parents and the mentor. Deleting our copy does not reach into their chat histories — those are theirs to clear, and Telegram's policy governs them.
If the pilot ends, we will tell the families in it, and their data will be deleted or handed to them, whichever they prefer.
8. Your rights
Whatever regime applies to you, the practical answer is the same: write to [email protected]. You can ask us to show you what we hold, correct it, delete it, stop using it, or hand it over in a machine-readable form. You can withdraw a consent you gave, and doing so is never made harder than giving it was. If you believe we have handled your data badly, you may also complain to your data-protection authority — in the EU, the supervisory authority of your country; in Russia, Roskomnadzor.
We answer requests within 30 days. If we cannot identify what belongs to you — a push address, for instance, carries no name — we will say so plainly rather than guess.
9. Changes to this page
The date at the top is the date of the last change. This page lives in the same repository as the product, so its history is versioned along with the code. If a change makes our handling of data materially wider, we will say so on the site rather than quietly edit this text.