First Followers Privacy Policy
Publication status: Published September 22, 2026. Timeframes identified as targets remain planning estimates, as explained below.
Effective date: September 22, 2026 Draft revised: September 21, 2026
Devon Allary personally operates First Followers ("First Followers," "we," "us," or "our"). First Followers is a family faith-learning service for parents or legal guardians and children approximately 7–12 years old. This policy explains how the First Followers iPhone and iPad application, our first-party backend, and related support services (collectively, the "Service") collect, use, disclose, retain, and protect personal information. The adult prelaunch website and waitlist have a separate privacy notice. Joining the waitlist does not give permission to collect information from a child in the app.
The Service is initially intended for families in the United States and Canada. It is directed in part to children under 13. We therefore design the Service on the assumption that the U.S. Children's Online Privacy Protection Act and Rule ("COPPA") apply. We also follow applicable Canadian privacy requirements, including the federal private-sector principles and, for Quebec users, Quebec's private-sector privacy law.
1. Who operates First Followers
The operator responsible for personal information handled through First Followers is:
- Legal name: Devon Allary
- Business name: First Followers
- Mailing address: 1502 rue Noel Lareau, Chambly, Quebec J3L 5M7, Canada
- Telephone: +1 514-601-6435
- Privacy email: devonallary1@gmail.com
- Privacy Officer: Devon Allary
This operator is the contact responsible for all parent and privacy inquiries, including inquiries about service providers that maintain children's information for us.
2. The parent account and the child experience
An adult parent or legal guardian creates the household, signs in, accepts the parent privacy notice, provides verifiable parental consent, creates each child profile, and pairs a child device. Children do not create an email account or supply payment details.
The Service supports indirect communication within a family: a guardian assigns lessons and prayer invitations, a child completes activities or shares a note, and the guardian reviews available work and manages Screen Time. Submitted lesson answers and drawings, shared notes, quiz results, requests for help, completion information, progress summaries, approvals, and Screen Time records may be visible to authorized guardians in the same household. Guardian-approved feedback is shown to the child where that feature is available. Comments labelled as parent-only are kept in the guardian experience.
This sharing does not make a child's work public or send it to other families, churches, or schools. Only adults with lawful authority over that child may be given guardian access. Possession of a device or membership in an Apple family group does not by itself establish that authority.
The private prayer journal is a separate feature, described in section 3.6. It is not included in ordinary guardian lesson reports. First Followers is not a counselling, emergency, or professional confidential-advice service.
3. Information we collect
We collect only information reasonably necessary to provide and secure the Service.
3.1 Adult and household information
We may collect:
- the stable account identifier supplied by Sign in with Apple;
- an Apple private-relay or other email address, if the adult elects to provide it;
- consent records, including the notice version, consent version, acceptance time, and revocation status;
- household membership, preferred language and time zone, curriculum settings, selected Christian tradition or denominational lens, notification settings, and parent-configured lesson and reward rules;
- normalized App Store subscription information, such as product identifier, subscription status, purchase and expiry times, transaction identifiers, renewal state, and fraud-prevention digests; and
- information the adult includes in a support, privacy, or legal request.
We do not receive the adult's complete payment-card number. Apple processes App Store payments under Apple's own terms and privacy practices.
3.2 Child profile and learning information
Information supplied by the adult or generated when a child uses the Service may include:
- a nickname, broad age band (7–8, 9–10, or 11–12), optional avatar, preferred language, curriculum pathway, and approval policy;
- assigned lessons, lesson interactions, quiz answers and results, completion status, and progress evidence;
- written answers and drawings submitted for lesson review, including drawing captions, and optional notes the child chooses to share with the guardian;
- lesson start and completion times, reported active lesson duration, attempts, requests for help, and question-level learning results;
- guardian review decisions, reasons for an override, parent-only comments, and guardian-approved child feedback;
- guardian-authored prayer invitations and the child's completion acknowledgement;
- a minimized evaluation or parent-facing summary of an answer, including source-based learning tags and whether a parent reviewed or changed a draft;
- rewards, approvals, Screen Time minutes issued or used for a First Followers reward, and technical enforcement status; and
- notification preferences and whether an assignment, approval, or reward event occurred.
Written answers, drawings, shared notes, prayer invitations, and review comments can contain personal or sensitive information even when we do not ask for it. Before sharing, the child interface explains who can see the submission. Please avoid including an address, phone number, school, full name, or another person's private information. A nickname or encryption does not make all associated records anonymous.
Curriculum selections and lesson responses may reveal or suggest religious beliefs. We treat this as sensitive information and use it only to provide the family-selected faith-learning experience, obtain guardian review, maintain progress selected by the guardian, and meet legal or security obligations. We do not use it for advertising.
3.3 Device, pairing, notification, and security information
We may collect:
- a random installation identifier, cryptographic public key and credential digest, pairing status, last service contact, and Apple Family Controls authorization status;
- family-device names, personal/shared-device mode, linked child profiles, protected profile-access credentials, and device-level Screen Time settings and usage totals;
- a short-lived pairing-code digest (not the reusable plain code);
- an Apple Push Notification service token, encrypted at rest, together with device role, notification environment, locale, time zone, and notification preference;
- request identifiers, IP address and basic network metadata processed by our servers or hosting provider, timestamps, app version, operating-system major version, response status, and content-free error or security events; and
- normalized App Store verification records needed to provide subscription access and prevent one purchase from being claimed by unrelated households.
Push payloads contain only an event type, an opaque record identifier, approved localization keys, and Apple's standard sound instruction. They do not contain a child's nickname, lesson title, answer, reflection, score, selected app, or Screen Time minutes.
3.4 Apple Screen Time selections
When a guardian uses Apple's Family Controls picker, Apple represents selected apps, categories, or websites with privacy-protecting opaque tokens. First Followers uses those tokens only to apply the rules the guardian chooses. We do not use them for advertising or analytics, attempt to reverse them into a list of installed apps, or collect a child's general Screen Time history. A relay copy is kept only long enough to deliver and acknowledge the rule; the active selection remains on the relevant guardian and child devices until the guardian replaces or deletes the rule.
3.5 Information we do not ask children to provide
The child experience does not request a child's surname, exact birth date, email, telephone number, home address, school, precise location, contacts, photos, voice, health information, government identifier, or advertising identifier. We do not offer public profiles, child-to-child messaging, open chat, or public posting of a child's answers. Unrequested personal information can nevertheless appear in user submissions; we handle it under this policy.
3.6 Local private prayer journal
Cloud journal sync is disabled for this release. The journal stores encrypted entries on the child's device and excludes its storage directory from device backups. A passphrase or recovery code unlocks the journal; a guardian account or profile PIN does not. Anyone with that recovery information may be able to read it. Journal entries do not appear in guardian lesson reports. We cannot recover entries without the needed secret. Disconnecting a device does not itself erase its local journal. Use the journal's device controls to delete it.
Existing encrypted server vaults, if any were created during testing, remain subject to profile/account deletion and an operator inventory before launch. Sync must not be enabled until its notice, consent, parental access, deletion, and retention design has been reviewed and approved. Encryption does not remove parental rights.
4. How we use information
We use personal information to:
- authenticate the adult and create the household;
- obtain and record parent notice and consent;
- create and pair child profiles and devices;
- deliver age-appropriate lessons and family-selected curriculum;
- send submitted child work and shared notes to authorized guardians for review;
- deliver guardian prayer invitations and approved feedback to the linked child, under the visibility rules in section 3.6;
- calculate or record lesson completion, parent decisions, progress evidence, and rewards without rating a child's faith, sincerity, morality, or spiritual worth;
- apply, reconcile, and safely clear guardian-selected Screen Time rules;
- verify subscriptions, restore purchases, and prevent fraud or duplicate claims;
- deliver optional service notifications;
- provide support, respond to access/deletion requests, and correct errors;
- protect the safety, integrity, and availability of the Service; and
- meet legal obligations and establish, exercise, or defend legal claims.
We do not use a child's information to build advertising profiles, serve behavioural advertising, train public or third-party AI models, or make decisions about the child's faith or character.
5. Parental notice and consent
Before collecting personal information through a child profile or device, we provide a direct parent notice explaining the information, purposes, providers, retention and choices. Our normal verification method is email-plus: the adult enters their email in the parent app, reads the notice and follows a personal link to confirm parental authority, the processing described and the Terms. The link expires after seven days. Opening it alone does not grant permission. We record the exact notice version and the parent's response, then schedule a confirming email approximately 24 hours later with withdrawal instructions. No ID upload, signed form or payment is required for this normal flow. A signed form may be offered as an assisted alternative after agreeing a secure return process with the operator.
Accepting the Terms, signing in or passing an on-device parental gate does not by itself provide this separate permission. Cloud journal sync and optional product analytics are disabled. Optional notifications have separate controls. We obtain new permission before materially changing previously approved child-data practices.
If permission is incomplete after seven days, the contact and setup data collected only to obtain it become due for deletion by the next successful cleanup. The target for clearing overdue setup records is 24 hours. This does not delete a separately subscribed adult waitlist record. The permission process must be active before new child collection is enabled.
6. When we disclose information
We do not sell personal information. We do not share personal information for cross-context behavioural advertising, targeted advertising, or data-broker use. We do not display third-party advertising in the Service.
We disclose only what is necessary in these situations:
6.1 Within the authorized household
Authorized guardians can receive the child's submitted lesson records, answers and drawings while retained, shared notes, progress information, prayer completion, approvals, and Screen Time records. The child interface makes this visibility clear before sharing. Parent-only review comments are not child messages. The private journal follows section 3.6. Guardians should protect any copies they download or share outside the Service; we cannot erase copies held outside our control.
6.2 Operators and service providers
These are the providers used for the current setup. Devon Allary is the single contact for all parent inquiries about our handling of child information, including provider processing. The links below identify the providers and their public privacy contacts; they do not certify completion of our contract or cross-border review.
| Organization | Role and information | Privacy contact |
|---|---|---|
| Devon Allary | Operates First Followers and handles parent support and privacy requests | Contact details in section 1 |
| Apple Inc. and Apple Canada Inc. | Apple sign-in, purchases, push notifications and Screen Time platform functions | Apple privacy contact |
| Google Cloud Canada Corporation; Google LLC | Google Cloud Run hosts the API in Montréal; Firebase serves the website and permission page. Google LLC also provides the operator’s Gmail support inbox | Google Cloud entities and addresses; Google privacy contact |
| Supabase Pte. Ltd. | Managed PostgreSQL database in Canada (ca-central-1); stores account, household, learning and device records and applicable database backups | privacy@supabase.com; provider information |
| Plus Five Five, Inc. (Resend) | Adult permission and confirmation emails; adult email address, notice, permission link and delivery records. Email data is processed in the United States | privacy@resend.com; provider information |
| Cloudflare, Inc. | Domain/DNS services and forwarding incoming privacy email to the operator’s Gmail inbox; routing and network metadata | dpo@cloudflare.com; provider information |
Support is handled directly by Devon through Gmail; there is no separate help-desk vendor. Do not email children’s answers, drawings or journal entries. Resend receives adult transactional messages, not child lesson records. Cloudflare and Gmail handle the content adults choose to send for support. Before enabling child collection, we must confirm provider agreements, restricted purposes, security assurances and applicable cross-border assessments. We remain responsible for processing performed on our behalf.
6.3 No child answers to third-party AI at launch
At the publication date, First Followers does not send a child's nickname, free-text answer, drawing, shared note, journal, learning record, device data, or Screen Time selection to OpenAI, ElevenLabs, or another third-party generative-AI provider. We may use generation tools internally to help create general lesson media from staff-authored content that contains no user personal information.
We will not enable third-party AI processing of a child's information unless we first complete a child-privacy review, update this policy and the direct parent notice, identify the provider and exact data disclosed, obtain separate explicit and verifiable parent permission when required, and contractually prohibit model training and impose approved deletion limits.
This restriction also applies to AI-generated learning reports. Removing a name or raw answer does not necessarily make a child-linked learning record anonymous.
6.4 Legal, safety, and business events
We may disclose information when reasonably necessary to comply with law or valid legal process; protect a child, user, or other person from a credible safety threat; investigate fraud or security incidents; or establish or defend legal claims. If our business is reorganized, financed, sold, or transferred, information may be reviewed or transferred under confidentiality and only in accordance with applicable law. We will not transfer children's information to a successor for materially different purposes without the notice and consent required by law.
7. Retention and deletion schedule
We retain information only for its stated purpose. These are the selected launch limits. Seven-day text cleanup and 365-day learning/inactivity sweeps exist in the current implementation. Items labelled “target” or “planning” are reasonable operational estimates, not verified provider guarantees or permission to retain data longer than necessary. The scheduled active-database sweep runs hourly; overdue records are removed by the next successful run. Failure monitoring and manual follow-up are required.
| Information | Purpose | Retention or target |
|---|---|---|
| Pending permission contact/setup | Obtain permission | 7 days to complete permission; then due for cleanup, with a target of 24 hours to clear overdue records |
| Submitted answers, drawings and copied response prose | Short-term parent review | 7 days from trusted server receipt; earlier on a valid deletion request |
| Guardian review text, shared lesson notes and prayer invitations/acknowledgements | Family communication | 7 days from the review decision or the last edit to that note or invitation; copied child response text may be removed sooner with its source |
| Minimized completions, learning reports and old assignments | Recent learning progress | 365 days from the relevant record timestamp; sooner with profile or household deletion |
| Child profile and device settings | Operate the active child profile | While active; removal starts after 365 days without profile updates or recent learning activity; target active-system purge within 30 days of a verified deletion request |
| Local private journal | Private writing on the child’s device | No server collection or cloud sync. Local entries remain until deleted on the device; no automatic age-based local deletion. See the local deletion instructions below |
| Screen Time operational history and unacknowledged rule-relay data | Apply and troubleshoot parent-selected controls | Planning targets: history 365 days; relay data within 24 hours after acknowledgement or 7 days if unacknowledged. These category-specific limits still require end-to-end verification; active device rules remain until replaced or removed |
| Pairing codes | Pair a device | Code expires after 10 minutes; expired digest and content-free result removed after 30 days |
| Installation credentials and push tokens | Authenticate devices and deliver optional notifications | Revoke on device/profile/household removal; target purge within 30 days. A hash-only clear-restrictions record can remain for 30 days to let an old device remove restrictions |
| Terminal notification records and routine technical logs | Delivery reliability and troubleshooting | 30-day target; the active-database notification sweep uses record creation time |
| Security and audit records | Abuse prevention and account accountability | 365 days; a documented incident or legal obligation may justify an isolated minimum record for longer |
| Optional product analytics | No current collection | Disabled in this release; any future enablement requires its own notice and retention terms |
| Adult subscription and transaction evidence | Subscriptions, refunds, accounting and legal obligations | Active subscription, then only as needed for a documented obligation, with a planning ceiling of 7 years; otherwise erased with the account. No raw child responses or full card details in retained financial evidence |
| Adult support correspondence | Resolve and follow up on the request | Target: 12 months after closure, or earlier when no longer needed; longer only for a documented legal obligation |
| Encrypted provider backups | Disaster recovery | Target rolling expiry within 30 days. Actual provider backup expiry is not yet verified; this is not a completed-erasure guarantee. Reapply deletion records before returning a restored backup to service |
Deletion requests, local copies and backups
Our target is to complete active-system deletion within 30 calendar days after a verified request. Account access and device credentials are revoked when deletion begins; ordinary queued purges can finish sooner. We will explain a delay or a legally required exception. The backup target is separate and has not yet been verified with the provider.
For a local journal, open the journal on the child's device and use its delete-entry controls, or lock it and choose the option to erase the journal, then confirm. Repeat on every device holding a copy. Use Apple Settings > General > iPhone/iPad Storage > First Followers > Delete App to remove the app and its local data; Offload App preserves data and is not deletion. Erase separately any exported files or screenshots. We cannot remotely erase a device that never reconnects or copies held outside our control.
Removing the app does not delete the household or cancel an Apple subscription. Use Parent Settings for profile or household deletion and Apple's subscription settings to cancel billing. The local private journal is not uploaded and has no server retention period. It is excluded from the app's device backup directory. Do not enable cloud sync under this notice.
When a documented legal obligation requires longer retention, we isolate the minimum record, restrict its use and delete it when the obligation ends. We do not keep child records indefinitely simply because nobody asks for deletion.
8. Parent and user choices and rights
Subject to identity verification and applicable law, a guardian may:
- review the personal information collected from their child;
- correct the child profile or challenge a learning interpretation;
- request deletion of a submitted response or drawing, shared note, report item, stored journal information, child profile, or household;
- revoke consent and refuse further collection or use of the child's information;
- request a portable copy of information associated with the household;
- disable notifications in First Followers and in Apple device settings; and
- withdraw optional analytics consent without losing paid core functionality.
Use Parent Settings > Privacy and consent record in the app or contact devonallary1@gmail.com. We will acknowledge a request within 10 days and respond within the period required by applicable law. We may take proportionate steps to confirm that the requester is the account holder and the child's guardian. We do not charge for a routine request.
The current in-app consent-withdrawal action closes the household and starts account deletion. For a request concerning one child or one optional feature, contact us first so we can handle that scope. Withdrawing optional permission does not require giving up unrelated core features. Revoking permission for necessary processing may end the affected child's online participation. When the household is deleted, we revoke child credentials and issue a time-limited clear-restrictions response so the child device can fail open rather than remain blocked.
A child who has a privacy question should ask their parent or guardian to contact us. We will provide an age-appropriate explanation and involve the guardian as required.
9. Security
We use safeguards appropriate to the sensitivity of family and child information, including encrypted network connections; encryption of push tokens at rest; cryptographic installation credentials; Apple Keychain or protected device storage for local credentials; role- and household-scoped access; minimized push payloads; rate limits; restricted logs; and deletion controls. We require relevant providers to maintain comparable safeguards and operate a written child-data security, retention, incident-response, and provider-review program.
No security method is perfect. If we discover a breach that creates a legal duty to notify, we will notify affected users and regulators as required by applicable law.
10. Storage and processing locations
First Followers is operated from Quebec, Canada. The current API and permission service run in Montréal, and the Supabase database uses the Canadian ca-central-1 region. Resend stores email data in the United States. Firebase website delivery, Apple services, Cloudflare routing and the Gmail support inbox may process information in Canada, the United States and other countries used by their published service networks. We do not promise that all processing stays in Quebec or Canada. Foreign privacy laws and government-access rules may differ. The required provider and cross-border assessments must be completed before child collection is activated; a Canadian database region alone does not establish compliance.
11. U.S. and Canadian privacy information
United States and COPPA
For a child under 13, the guardian has the rights described in section 8, including the right to review or delete the child's information and refuse further collection or use. We do not condition a child's participation on disclosing more personal information than is reasonably necessary for the activity. We provide direct notice and obtain verifiable parental consent before collection unless a narrow legal exception applies.
Regardless of whether a state privacy statute applies to us, we do not sell personal information or share it for targeted or cross-context behavioural advertising. We do not respond differently to browser "Do Not Track" signals because the app and our public legal pages do not use cross-site tracking; where a legally recognized opt-out-preference signal applies to a future website, we will honour it as required.
Canada
Canadian users may request access and correction, ask how information has been used or disclosed, withdraw consent subject to legal or contractual limits, and complain to our Privacy Officer. We seek parent or guardian consent for a person unable to provide meaningful consent and, absent exceptional circumstances, treat children under 13 that way. In Quebec, we obtain parent or parental-authority consent for a minor under 14 as required by law.
If our Privacy Officer does not resolve a concern, a person may contact the Office of the Privacy Commissioner of Canada or the applicable provincial regulator, including Quebec's Commission d'accès à l'information. We encourage contacting us first so we can investigate promptly.
12. Changes to this policy
We may update this policy as the Service, providers, or law changes. We will post the new version with its effective date. Before a material change to the collection, use, or disclosure of child personal information previously approved by a guardian, we will give the guardian a new direct notice and obtain renewed consent when required. We will not retroactively use child information for a materially different purpose without the permission required by law.
13. Contact us
For questions, complaints, access, correction, export, deletion, or consent withdrawal, contact:
Devon Allary — Privacy Officer 1502 rue Noel Lareau, Chambly, Quebec J3L 5M7, Canada devonallary1@gmail.com +1 514-601-6435