Privacy Policy
Version 3.1 · Effective August 23, 2026
Prodigy is a parent-coaching product for the first 36 months. The parent is the user. The child is not. This policy says what we collect, why, who processes it, and how you control it.
1. Who we are
Michael Hodgen operates Prodigy at https://startprodigy.app, using the Hodgen.AI name. Hodgen.AI, LLC, an Idaho limited liability company has not been formed yet. When it is formed, Michael Hodgen may assign this service, this policy, and your account to that company. Contact: mike@hodgen.ai.
2. Information we collect
- Parent account: email, password (hashed by our auth provider), display name, plan, Stripe customer and subscription ids, safety-acknowledgment version.
- Child profile: first name, birth date, notes, traits, milestone observations, activity ratings. Name, notes, traits, and percentiles are encrypted at rest (AES-256-GCM). Birth date is stored as a date so the plan can age with the child.
- Activity log: which cards you marked done, skipped, or got; optional parent notes.
- Caregivers: emails you invite, and the permission you grant (view or edit).
- Optional video (Prodigy plan): a short clip you upload for an educational observation. Stored in a private bucket. Sent to Google Gemini to produce the observation. See Child privacy.
- Coach email: we send the daily and weekly coach to the address on the account unless you unsubscribe.
- Usage analytics: page views and product clicks via PostHog. We do not send child name, birth date, notes, or video to PostHog.
- Safety acknowledgment: which boxes you checked, a SHA-256 hash of your IP (not the IP itself), user-agent, timestamp. No child fields.
- Rate limiting: hashed IP and account id, so a flood cannot burn the AI or billing paths.
We do not collect precise location, contacts, HealthKit data, or full payment card numbers. Stripe processes cards. We never see the full number.
3. How we use it
- To run the account, the day's cards, and the week's plan.
- To rewrite a parent script with xAI Grok. A prompt may include first name, age in months, traits, and a parent note. Grok is not allowed to invent a diagnosis.
- To email the coach and account mail (login, billing, grants).
- To bill through Stripe and keep the plan in sync.
- To invite caregivers you choose.
- To keep the service secure and to keep a record of consent.
We do not sell personal information. We do not share it for cross-context advertising. We do not use family content to train Prodigy's own models. Third-party model providers process a prompt only to return the output we asked for, under their terms.
4. Children's data
The account holder must be 18 or older and the parent or legal guardian. We collect child information from the parent, not from the child. Full detail: Child privacy.
5. Processors
- Supabase (US West): auth, database, private file storage.
- Vercel: hosting and server functions.
- xAI (Grok 4.6): parent-script rewrite, reports, and plan copy.
- Google (Gemini): optional video observation on the Prodigy plan.
- Stripe: subscriptions. We never store full card numbers.
- Resend: transactional and coach email from noreply@hodgen.ai.
- PostHog: product analytics, no child fields.
- Upstash: rate-limit counters.
- fal.ai: demo activity videos from de-identified prompts. No child video.
6. Your rights
- Access: child profile and log are in the app.
- Export: Settings → Your Data → Export all data as JSON.
- Deletion: Settings → Your Data. Type DELETE. This cancels billing and removes the account. Apple requires this path in-app; email is not the only way.
- Email: unsubscribe from coach mail via the link in the footer. Account mail (login, billing) still has to send.
- California residents (CCPA / CPRA): right to know, delete, correct, and opt out of sale or share. Those rights follow the resident, not where the operator is formed. We do not sell or share as those terms are defined. We do not use sensitive personal information to infer characteristics for advertising.
- EEA / UK: if you use Prodigy from the EEA or UK, email mike@hodgen.ai for access, correction, or erasure. The lawful bases we rely on are contract (running the account you asked for) and consent (safety ack, optional video).
7. Cookies
We use a session cookie so you stay logged in, and PostHog may set an analytics cookie. We do not use advertising cookies or a tracking pixel for ads.
8. Safety acknowledgment records
When you accept the safety acknowledgment, we store the version, the boxes you checked, a hashed IP, user-agent, and time. Those records contain no child fields. They survive account deletion (the account id is cleared) so we can show that an adult accepted the risk language.
9. Retention
Account data stays while the account is open. After you delete, we purge the account and child records promptly. Encrypted backups may remain up to 90 days, then rotate out. Stripe keeps billing records as tax law requires. Safety-ack records stay as described in §8.
10. Security
TLS in transit. Row-level security on the database. Service-role keys stay on the server. Child name, notes, traits, and percentiles are field-encrypted. Reports of a vulnerability: mike@hodgen.ai.
Michael Hodgen and anyone working for him on Prodigy may open an account only to fix a problem you asked us to fix, to keep the service running, or as required by law. That access is logged. After Hodgen.AI, LLC, an Idaho limited liability company is formed, that company's people take the same limit.
11. Changes
Material changes will be emailed to the account address 30 days before they take effect, and the version number at the top of this page will change.
Questions? Email mike@hodgen.ai.