Draft. Not legally reviewed. Not binding on anyone.
This page is a placeholder. It describes how AngelLink is intended to work so that the people writing the real document have somewhere to start. No lawyer has read it, no organization has approved it, and it creates no agreement between you and anybody. Every value shown in square brackets is still missing and must be filled in by a person.
It carries no date, because dating it would imply a review that has not happened. Do not rely on anything here.
Legal · draft
Privacy Policy (draft)
What AngelLink records about you, who can read it, and for how long.
1.Who is responsible
Two organizations hold information about you, and they do different things.
- Your youth organization decides who joins, who supervises whom, who may read which conversations, and what happens after a concern is raised. Under data protection law it is normally the controller — the one that decides why your information is used.
- AngelLink, operated by [Company legal name] of [Registered address], runs the software and stores the data on that organization’s behalf — normally the processor.
Which of us is which for any given piece of information is [Controller and processor split — to be confirmed by counsel]. It matters, because it decides who you make a request to. Until it is settled, ask your organization first.
2.What we collect
- Who you are. Your name, your email address or phone number, the organization and group you belong to, and your role in it.
- Your age, or your age band. Needed to work out whether consent is required before you can take part.
- Everything you send. Message text, images and files, who you sent them to, and when. Including messages you later delete.
- Consent records. Who gave consent for a young person to take part, when, and for what.
- What the system flagged. Messages picked up by automatic scanning, the category of concern, and what a supervisor did about it.
- An audit trail. A tamper-evident record of actions taken in the service — who read a conversation, who changed a setting, who suspended an account.
- Technical records. Sign-in times, device and browser information, and IP addresses, kept to keep accounts secure.
We do not collect location, contacts, or anything from your device beyond what is listed here. We do not buy information about you from anyone else.
3.Why we collect it
- To let you send and receive messages — the service you asked for.
- To let approved leaders supervise conversations between adults and young people.
- To spot signs that a young person may be at risk, and put them in front of a person who can act.
- To keep a record that can be relied on later, if a concern turns into an investigation.
- To keep accounts secure and to stop abuse of the service.
The legal basis for each of these, and which of them rest on a legal obligation rather than consent, is [Lawful basis per purpose — to be confirmed by counsel].
We do not use your messages to advertise to you, we do not sell them, and we do not use them to train a general-purpose AI model.
4.Your messages are not private
Most privacy policies exist to reassure you that your data is kept confidential. This one has to tell you something different, and it belongs near the top rather than in a clause at the end.
Conversations on AngelLink are monitored. Approved leaders in your organization can read them. Deleting a message does not erase it. Messages are scanned automatically for signs of harm.
In detail:
- Leaders can read your conversations without asking you and without telling you at the time. Their reading is itself recorded in the audit trail.
- Messages cannot be edited once sent.
- Deleted messages are kept. Deleting removes a message from the conversation you can see. It stays in a deleted-message log that leaders can review.
- Automatic scanning runs on every message, not only on ones somebody has reported.
- Chat closes outside set hours, and the fact that you tried to send something is recorded even when the message cannot be delivered then.
This is the whole point of the product. Youth organizations use it precisely so that an adult cannot have a hidden conversation with a child. If that is not what you want, do not send it here.
5.Who can see what
- You see your own conversations and your own account details.
- Leaders approved for a conversation see that conversation, its attachments, its deleted messages and its audit trail.
- Supervisors see the same, plus the queue of concerns the system has flagged in the groups they are responsible for.
- The organization’s owner sees membership, roles, consent records and configuration for their own organization.
- Guardians, where their organization has switched this on, get view-only access. What exactly a guardian can see is [Guardian visibility scope — to be confirmed].
- Other organizations see nothing of yours. Each organization’s data is isolated from every other, and that isolation is enforced by the database itself rather than by application code remembering to check.
- We — the people who run the platform — manage accounts, organizations and configuration. Our design commitment is that platform staff have no route to read the content of a young person’s conversations. Where we genuinely need access to fix a fault, it is [Support access procedure — to be confirmed].
We also share information where the law requires it, or where there is a safeguarding duty to report a concern to the police or a child protection agency. Those duties differ by country: [Mandatory reporting duties].
Companies that help us run the service — hosting and email delivery — process information on our behalf under contract. Automatic scanning is not on this list, because it is not done by anyone else: it runs on our own servers. The list of them is [Sub-processor list — not yet compiled].
6.Automatic scanning
Messages are checked automatically for six things, and this is the complete list: a request to keep the conversation secret or to delete it; a suggestion to move to another app where nobody is watching; an exchange of a phone number, address or other personal contact detail; arranging to meet away from the organization’s activities; a request for photographs; and language suggesting the person writing may be at risk of harming themselves. The checking is done by matching known patterns of words, on our own servers. Your child’s messages are not sent to any other company to be checked, and no artificial-intelligence service reads them.
A flag notifies a supervisor. It does not, on its own, suspend anyone, contact a guardian, or contact the authorities. A person decides what happens next.
The scanning is imperfect in both directions. It flags ordinary conversations that happen to use worrying words, and it misses real concerns expressed in words it does not recognise. Treat it as a prompt to look, never as a verdict.
Whether any of this counts as automated decision-making that gives you additional rights is [Automated decision-making assessment — to be confirmed].
7.How long we keep it
Honest answer: the periods below have not been set. Each needs a decision from the organization and its legal advisers, because a safeguarding record kept too briefly is useless in an investigation and one kept too long is its own risk.
- Messages and attachments: [Message retention period — to be confirmed]
- Deleted-message logs: [Deleted-message retention period — set per organization]
- Audit trail: [Audit retention period — to be confirmed]
- Consent records: [Consent record retention — to be confirmed]
- Account details after an account closes: [Account retention after closure — to be confirmed]
- Sign-in and technical records: [Technical log retention — to be confirmed]
We will not invent a number here to make the page look finished. Until these are decided, assume material is retained rather than deleted.
8.People under the age of majority
Most of the young people using this service are minors, so their position is set out separately rather than left to be inferred.
- Consent comes first. Where the law requires a guardian’s consent, a young person cannot take part until that consent is recorded. If we do not know how old someone is, we assume consent is required and keep them blocked.
- The threshold varies. The age at which a young person can agree on their own behalf differs by country and province. Each organization sets its own, within the floor for its jurisdiction: [Consent age threshold — to be confirmed by counsel].
- Young people are told they are being watched. A young person using this service should know, in words they understand, that leaders can read their conversations and that deleting a message does not erase it. Explaining that is the organization’s job at enrolment, and the service says so too.
- Only what is needed. We do not ask young people for information the service does not need.
9.Guardians
A parent or guardian may be given view-only access, if the organization has switched it on. View-only means exactly that: a guardian can read, and cannot send messages or take part.
Guardians can normally ask to see what is held about their child, ask for corrections, and withdraw consent for their child to take part. Today a guardian withdraws consent by asking the organization to record the withdrawal; the organization must act on that request.
Withdrawing consent takes effect the moment it is recorded. It is worth being exact about what it does and does not do:
- No new messages, in either direction. From that moment nobody can send the young person a message, in any conversation they are part of — and they cannot send one either.
- The guardian who withdrew stops seeing the conversations. The condition is checked every time a conversation is opened, so the next read returns nothing. There is no overnight job and no queue.
- Messages already exchanged stay, and stay readable to the people who were in them. The young person can still open those conversations, and so can the adults who were already in them. The organization has to be able to review what was said, and a withdrawal is one of the moments a review is most likely to be needed.
- The consent record itself stays, showing that consent was given and when it was withdrawn. Nothing is erased.
A guardian’s rights are not unlimited. Where a young person is old enough to have their own privacy interest, or where sharing a conversation with a guardian would itself put the young person at risk, the organization may decline. How that judgement is made is [Guardian access exceptions — to be confirmed by counsel].
10.Your rights, and their limits
Depending on where you live, you can normally ask to:
- see what is held about you;
- correct it if it is wrong;
- get a copy in a portable form;
- object to some uses of it;
- complain to a data protection regulator.
There is one limit, and it is real rather than a formality, so it is stated rather than glossed.
You cannot generally have safeguarding records erased on request. Messages, deleted-message logs and the audit trail are kept even when someone asks for them to go.
The reason is that this material may be the evidence of a concern about a child, and the person asking for it to be deleted may be the person it is evidence about. A system where a record can be erased by whoever is most motivated to erase it is not a safeguarding system.
The legal basis for refusing erasure in this specific case, and how far it extends, is [Erasure exemption — to be confirmed by counsel]. This is one of the open questions a lawyer must settle before this policy stops being a draft.
11.How to make a request
Start with your own organization — contact its safeguarding lead or administrator. They hold the relationship with you and can act on most requests directly.
If they cannot help, or the request is about the platform itself, write to [Privacy contact — name and email].
We will need to be reasonably sure who you are before we hand over personal information, which may mean asking you to confirm something only you would know. We aim to respond within [Response time — to be confirmed].
If you are not satisfied you can complain to the data protection regulator where you live: [Regulator — depends on jurisdiction].
12.Where information is stored
Information is stored with [Hosting provider and region].
If your organization operates in more than one country, your information may be held outside the country you are in. Whether that is lawful for your country, and what safeguards would apply, is [Cross-border transfer arrangement — unresolved]. This is a known open question, not an oversight, and it needs an answer before any organization outside [Primary operating country] is brought on.
13.Security
The service is built so that each organization’s data is separated from every other’s at the database level, so that the audit trail cannot be altered without the tampering being detectable, and so that passwords and invitation links are stored only as one-way hashes and never in a form anyone could read back.
Those are design properties, not a certification. We have not been independently audited, we have not had a penetration test, and we make no claim to hold any security certification. When that changes this section will say which standard, who assessed it, and when.
If there is a breach affecting your information, we will notify the affected organizations and, where the law requires it, the regulator and you, within [Breach notification timeframe — to be confirmed].
15.Changes to this policy
We may change this policy. Where a change materially affects you we will give notice before it takes effect.
This version carries no date and no version number on purpose. A date would say somebody reviewed it, and nobody has.
16.Who to contact
About your own information or your child’s: your youth organization, first.
About the platform: [Privacy contact — name and email], or write to [Registered address]. Whether a data protection officer must be appointed, and who it would be, is [Data protection officer — to be confirmed by counsel].
This service is intended to operate under [Applicable regulation — to be confirmed by counsel]. We make no claim to be compliant with any particular regime until someone qualified has assessed it and said so.
The rules for using the service are in the terms of service, which is also a draft.