Reading mode

Reading mode is a display preference. It uses a system font and gives words and lines more room.

Privacy Policy

Last updated: 15 July 2026

This Policy explains how ReInvent U handles personal information. We designed it around a simple rule: collect what the learning experience genuinely needs, keep family and coaching data off marketing surfaces, and make sharing a deliberate choice.

1. Who is responsible

ReInvent U is operated by Mango Dog Pty Ltd, ABN 33 628 425 481 and ACN 628 425 481, based in New South Wales, Australia. For a privacy request or complaint, email george@reinventu.work or use our contact form and choose Privacy or Support.

2. Information we collect

Parent and account information

  • name, email address, authentication identifier, household membership, timezone, and communication choices;
  • assessment answers, family profile, purchases, seats, refunds, support messages, account activity, and the version and server timestamp of the parent or guardian's 13+ learner attestation; and
  • payment status and transaction identifiers from Stripe. We do not receive or store full card numbers; and
  • if a parent expressly selects the optional paid-access SMS backup, the mobile number they enter in Stripe Checkout and the version and time of that recovery-only choice.

Learner information

  • chosen first name, age band, interests, provisioned seat, and learning preferences;
  • mission progress, project choices, coach interactions and transcripts, direction and check records, uploaded build artifacts, links, screenshots, demo recordings, and feedback;
  • short press-to-record voice clips when a parent or guardian has specifically enabled voice coaching;
  • capability state, evidence review state, pauses, support needs, and the next-step recommendations the Service creates; and
  • technical and safety classifications needed to reject schoolwork completion, malware, abuse, or unsafe content.

We do not ask for or intentionally collect a learner's date of birth to establish eligibility. Please do not provide a child's full legal name, exact birth date, school, home address, health information, or other sensitive information unless we specifically ask for it and explain why it is necessary.

Device, security, and attribution information

  • IP address, browser and device information, timestamps, request logs, security signals, and essential session-cookie data;
  • when a parent explicitly enables browser notifications, a pseudonymous push endpoint, browser-generated encryption keys, family timezone, quiet hours, delivery attempts, and opt-out state;
  • page and product events needed to operate and improve the Service; and
  • campaign and referral parameters, such as UTM tags, when a visitor arrives through a marketing link.

3. Why we use information

  • provide the assessment, report, purchased learning experience, account, coaching, progress, evidence record, verification, and support;
  • bind each learner and purchase to the right household and prevent access across families;
  • send requested reports, access messages, receipts, Parent Briefs, safety notices, and other service communications;
  • send one optional recovery-only SMS when paid Season access remains unclaimed after one hour; the number is never used for marketing;
  • deliver an optional generic browser alert when a family build ships, without putting a child's name, build, evidence, coach content, or private access link on the lock screen;
  • send optional educational or marketing follow-up only where the recipient has chosen it, and honour unsubscribe choices;
  • detect abuse, protect children and other users, investigate incidents, and maintain evidence integrity;
  • measure product quality and attributable funnel performance using the minimum data needed; and
  • meet legal, accounting, tax, dispute, and regulatory obligations.

4. Family privacy and visibility

The parent or guardian is the household account holder. They can see seat status, mission progress, shipped artifacts, evidence states, Parent Briefs, and information needed to supervise and support the experience. A parent does not automatically receive a transcript of every coaching conversation. We may surface a limited excerpt or contact the parent where needed to explain a build decision, resolve an access issue, protect someone, or address serious misuse.

Learner information is never used to target advertising to the learner. Marketing tags are not loaded on private account, coaching, report, payment-success, access-token, or verification-management pages. Public sharing uses a first name only and requires the household's sharing choice; a share link can be revoked.

5. AI processing and automated recommendations

Relevant inputs may be sent to contracted AI providers to generate coaching, classify a request, review a build, summarise a session, or suggest a next step. We aim to send only the context needed for that task and configure providers for business processing where available. Do not submit information you are not authorised to share.

Voice coaching is optional and off unless a parent or legal guardian specifically enables it. A learner must press Record for each clip. The clip is sent to our configured regional AI service to create a transcript, held only in memory for that request, and then discarded by ReInvent U; we retain the transcript with the private coach history. We do not use voice clips to identify a person, create a voiceprint, or target advertising. Text coaching remains available when voice is not enabled.

The Service uses software to calculate assessment profiles, recommend project difficulty, flag possible schoolwork or unsafe content, and organise progress. These outputs guide the learning experience; they do not decide admission, employment, credit, insurance, health care, or another person's legal rights. A person can challenge an output through Support, and an authorised human controls consequential evidence and account actions.

6. Cookies, analytics, and marketing choices

Essential cookies keep a signed-in session secure and remember necessary product state. Optional marketing measurement is off until a visitor makes a choice on an eligible public marketing page. Refusing optional measurement does not block the assessment, report, purchase, or product. A visitor can change that choice later.

Refusing or withdrawing optional measurement takes effect immediately in that browser through a first-party denial marker, including when the preference request cannot be completed. New checkouts from that browser then suppress optional server-side advertising conversion output. Enabling that output requires a separate signed, HttpOnly first-party consent receipt; a browser-submitted checkout field cannot grant consent.

On the free family assessment, we may use a first-party pseudonymous receipt to keep pre-registered experimental wording consistent and count at most one relevant action. The receipt expires after seven days, contains no email, assessment answers, child details, or advertising identifier, and is not disclosed to an advertising platform. Global Privacy Control and Do Not Track signals disable this measurement. The assessment provides a direct “Do not measure this visit” control that removes the receipt; the assessment remains fully available.

First-party product events are our operational source of truth. Browser-submitted events cannot declare a purchase, revenue, identity, capability, or other authoritative outcome; those events come from trusted server records. We do not sell personal information.

7. Email and communication choices

Entering an email to request a report authorises that report and related service delivery. Optional follow-up is a separate choice. Every commercial email includes an unsubscribe mechanism, and we continue to send only messages that are necessary to operate an account or fulfil a purchase after a marketing opt-out. A parent can also contact us to change household communication preferences.

Browser notifications are off by default and the browser asks permission only after a parent taps the enable control. The parent can set family quiet hours and turn notifications off from the paid family space or browser. Turning them off does not stop the separate Parent Brief service email.

8. When we share information

We disclose information only as reasonably necessary to:

  • infrastructure and authentication providers, including Google Cloud and Firebase;
  • payment providers, including Stripe;
  • email providers, including Mailgun;
  • SMS providers, including Twilio, only for an optional parent-authorised paid-access recovery message;
  • browser push services selected by the parent's browser, which receive the pseudonymous endpoint and an encrypted, generic notification;
  • AI and content-processing providers used for the specific coaching, safety, review, transcription, or generation task;
  • people the household chooses through a public or private share link;
  • professional advisers and authorities where reasonably needed to comply with law, protect a person, investigate fraud or abuse, or establish legal rights; and
  • a successor organisation in a genuine business transaction, subject to appropriate confidentiality and this Policy.

We do not allow providers to use family information for their own direct marketing.

9. Overseas processing

Our providers may process information outside Australia, including in the United States and other countries where their infrastructure or support teams operate. We select established providers, limit the data and purpose, and take reasonable steps to require appropriate protection. Contact us if you want more detail about a provider used for a particular feature.

10. Retention, archives, and deletion

  • Account, purchase, tax, fraud, and dispute records are retained for the periods required for those purposes.
  • Raw security logs and transient demo data are kept only as long as needed for security and operation.
  • Family live events expire after 30 days and browser-notification delivery records after seven days. Disabled push subscriptions are removed or pruned when no longer operationally needed.
  • Optional Season SMS recovery records, including the encrypted destination and opaque access link, expire after 30 days. Stripe and Twilio keep their own transaction records under their terms and legal obligations.
  • Coaching transcripts and progress records are retained while the account or learning record is active and then reviewed against operational, safety, and legal needs. Press-to-record voice clips are not stored by ReInvent U after transcription.
  • Evidence records and archival snapshots are designed to remain available after a subscription or Season ends because portability is part of the product. The learner or parent may still request deletion; we will explain any limited record we must retain.
  • Revoking a share link removes public access without requiring deletion of the underlying private record.

11. Security

We use access controls, server-managed sessions, encrypted transport, signed capability links, payment-webhook verification, family ownership checks, provider credential controls, monitoring, and testing appropriate to the Service. No online service is risk-free. If a breach is likely to cause serious harm, we will investigate and notify affected people and regulators as required.

12. Your choices and rights

You can ask us to:

  • provide access to personal information we hold about you or a child you are authorised to represent;
  • correct inaccurate information;
  • export the learner's evidence record in an available portable format;
  • delete information, subject to limited legal, safety, fraud, and transaction-retention requirements;
  • revoke a public share link or change consent and communication choices; or
  • review an automated profile, classification, or recommendation.

We may need to verify identity and household authority before acting. We will respond within the period required by applicable law and explain if we cannot complete all or part of a request.

13. Children and young people

The family product is intended for young people aged 13 and over under a parent- or guardian-managed account. We do not knowingly offer independent accounts to children under 13. If we learn that we collected a younger child's information without appropriate parental involvement, we will restrict and delete it as appropriate.

The family assessment and each First Ship Weekend and Season checkout require a parent or legal guardian to confirm that every included learner is age 13 or older. We store the attestation version and a server-generated timestamp. We do not collect a date of birth for this check.

We apply child-centred defaults: minimal collection, no learner-targeted advertising, private-by-default work, clear sharing controls, parent-managed seats, age-appropriate explanations, and a learner's involvement in decisions about their work. As at 15 July 2026, Australia's Children's Online Privacy Code remains an Exposure Draft. The Office of the Australian Information Commissioner says the final Code must be registered by 10 December 2026. We will review this Policy and the product against the final Code when it is published and before applicable obligations take effect.

14. Complaints

Send the details to george@reinventu.work or choose Privacy on the contact form. We will acknowledge the complaint, investigate it, and explain our response. If an Australian privacy complaint is not resolved, you may contact the Office of the Australian Information Commissioner.

15. Changes

We may update this Policy as the product, providers, or law changes. We will post the new date and take reasonable steps to notify account holders before a material change that affects how family information is used.