GROWXP Back to the site
Privacy and data · last updated 29 July 2026

What we store, and what we refuse to store

GrowXP is a motivation system used by families with children, so this page is written to be read, not to be survived. It covers two separate things: this website with its waiting list, and the GrowXP product used by families in the closed pilot. Where the law is named, we mean the EU General Data Protection Regulation (GDPR, including Article 8 on children) and Russian Federal Law No. 152-FZ on Personal Data.

In short

1. Who is responsible

GrowXP is built and run by its author as a closed, non-commercial pilot: no company sits behind it yet, no money changes hands, and nobody is paid to look at your data. In the language of the law that author is the “operator” (152-FZ) and the “controller” (GDPR). Before GrowXP opens beyond the pilot, the operator's full legal identity will be named on this page — that is a promise with a date attached to it, not a formality we hope you skip.

Everything about data — questions, corrections, deletion, complaints — goes to [email protected], and is answered from the same address. There is no phone line and no bot for this on purpose: a written request leaves a trail both sides can point at.

2. This website and the waiting list

The pages of growxp.me are static. Opening them creates no account, sets no cookie, and stores nothing in your browser. Our web server keeps ordinary technical logs — which page was requested, when, and with what response code — and they rotate away automatically after a few megabytes. The site is published through a tunnel, so the address our server records as the caller is the tunnel's, not your device's; the company that operates that tunnel does see your real address, and is named below.

If you switch on notifications

Pressing “Notify me” asks your browser for permission. If you allow it, your browser — not us — creates a push subscription with the push service that browser uses (Google for Chrome and Edge, Mozilla for Firefox, Apple for Safari). We then store what that subscription consists of:

Push address (endpoint)A long URL at your browser vendor's push service. It identifies a browser installation, not a person: no name, no email, no phone number, no IP address.
Two public keysGenerated by your browser so that only your browser can decrypt the notification we send.
Browser language, time zone, user-agentSo that we can send the announcement at a sane local hour and know which browsers we are dealing with. Nothing else is derived from them.

Purpose: to send you one notification when we start gathering the next test group. Legal basis: your consent — GDPR Art. 6(1)(a), and Art. 9 of 152-FZ. Pressing the button is that consent; this page is the information it is based on.

Withdrawing it is one press. The same button, now reading “You are on the list”, turns the subscription off: your browser cancels it and we mark our copy as deleted. You can also revoke notification permission in your browser's site settings at any time — we find out at the next send, when the push service reports the address as gone, and drop it.

How long we keep it: until you turn it off, or until the announcement has been sent and the waiting list has served its purpose — whichever comes first. Addresses that the push service reports as dead are deactivated automatically.

This site is for adults. The waiting list is meant for parents and teachers. Please do not switch notifications on a child's device.

Third parties on this website

We serve the fonts and the page's own JavaScript from growxp.me itself — deliberately, so that reading this page tells no advertising company anything about you. There is no Google Fonts request, no CDN, no analytics, no tracking pixel, no session recording. Two third parties remain, and both are structural rather than optional:

3. The product: what a family's account contains

This section applies only to families in the closed pilot — people who received an invitation and started using GrowXP inside Telegram. If you are only reading the website, none of it concerns you.

Parents and teachersThe Telegram account id and the display name Telegram gives us, plus the role (parent, mentor) and, for a mentor, which subjects they are allowed to award for.
The childThe name or nickname the parent types in, an optional persona title, the chosen theme, and an age band such as “8–10”. We deliberately do not store a date of birth. If the child has their own Telegram account, its id — that is how the app knows whose dashboard to show.
What the child didThe award ledger: which activity, on which track, when, the weight applied, and which adult confirmed it. This is the substance of the product, and it is append-only by design — history is never rewritten behind a child's back.
BehaviourThe weekly “shield” state — intact, broken, repaired — in neutral wording, with no score attached, kept deliberately separate from the award ledger. Whatever note an adult adds when a shield breaks or is repaired is stored as free text. A parent can also mark a day as a sick day so it does not count as a missed one; that record is a date with no reason attached.
Wishes and prizesThe wishlist the child fills in themselves, and which milestones unlocked what.
HomeworkThe task text from a mentor, their comments to the parents, and photographs uploaded by the child or the mentor. They are meant to show completed work: every upload is re-encoded on our server, which strips camera metadata including any location. Nothing technically stops a child from photographing themselves instead, and the photo is forwarded to the parents and that mentor as a Telegram message with the child's first name in the caption — so treat it as a message, not a private file.
The parent advisorIf parents use the built-in AI advisor, their chat with it — one thread per family, visible to both parents.
Deep profiling (optional)If a family uses it: the parent's answers, the child's own answers and clarifications, and the generated motivation profile and report.

What we never ask for. No date of birth — an age band is enough. No address, no phone number, no school name, no email for a child, no location, no contact list, no fingerprinting. There is no field anywhere in the system for a diagnosis and the product never asks a family to declare one: GrowXP is built with ADHD in mind and says so openly, but it runs on an age band, a first name and a list of what the child actually did. Wording that would read like a diagnosis is deliberately kept out of what the child and the parents see.

Where health nevertheless appears

Two honest exceptions, because pretending otherwise would be worse than admitting them:

Under GDPR Art. 9 and Art. 10 of 152-FZ this is special-category data. The honest status today is that the system gives it no separate storage regime and asks for no separate consent — it is ordinary text in an ordinary field. We would rather write that down than let you assume otherwise.

Legal basis. For a parent using the product: performance of the service they asked for, and their consent. For a child's data: the consent of their parent or legal guardian — GDPR Art. 6(1)(a) with Art. 8, and Art. 9 of 152-FZ, which likewise requires the legal representative's consent for a minor.

4. Children, specifically

Everything here follows one rule: a child is not a customer we acquire, they are a person their parent brought in.

5. What leaves our server

6. Where the data lives and who can reach it

The database is a single file on a server we rent and administer ourselves — no third-party cloud database, no data warehouse, no analytics copy. Homework photos sit next to it on the same disk. Access is limited to the operator; nobody is employed to browse family data, and nobody outside has an account. Technical logs may briefly contain a Telegram account id — for example when someone unknown writes to the bot — and they rotate away on their own within megabytes.

Backups run daily. They are kept for two weeks on the server, and a copy is pulled to a machine the operator controls, where it is kept for thirty days before it is deleted. That copy is the reason a deletion request takes up to a month to disappear everywhere, and we would rather you knew the number than trusted a word like “promptly”.

We will not pretend this is a bank. It is a small self-hosted service run carefully by one person, and the honest summary of its security is “few moving parts, and nothing sent anywhere it does not have to go”. Two things are on the list before GrowXP opens beyond the pilot: encrypting those backup archives at rest, and naming the server's jurisdiction on this page. Both are named here rather than left for you to discover.

7. Deleting data and ending it

Write to [email protected] and say what should go: one photo, one profiling session, a child's whole record, or the entire family. Here is how it actually works, so that nothing surprises you:

If the pilot ends, we will tell the families in it, and their data will be deleted or handed to them, whichever they prefer.

8. Your rights

Whatever regime applies to you, the practical answer is the same: write to [email protected]. You can ask us to show you what we hold, correct it, delete it, stop using it, or hand it over in a machine-readable form. You can withdraw a consent you gave, and doing so is never made harder than giving it was. If you believe we have handled your data badly, you may also complain to your data-protection authority — in the EU, the supervisory authority of your country; in Russia, Roskomnadzor.

We answer requests within 30 days. If we cannot identify what belongs to you — a push address, for instance, carries no name — we will say so plainly rather than guess.

9. Changes to this page

The date at the top is the date of the last change. This page lives in the same repository as the product, so its history is versioned along with the code. If a change makes our handling of data materially wider, we will say so on the site rather than quietly edit this text.