Skip to main content
PDA Question
How It Works For Parents About Resources Support Download

Privacy Policy

Last Updated: August 22, 2026

Revised Effective Date: September 21, 2026

Summary: This policy explains what information the Services may collect, how it may be used and shared, retention and security, and privacy rights. Review the full policy below.
On this page
  • Information collected
  • How information is used
  • How information is shared
  • Security
  • Retention
  • Your rights
  • Children
  • Contact

Introduction

PDA Question ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how information is handled by our static website (the "Site"), the currently released PDA Question iOS application (the "App"), the backend and AI providers used by the App, and third parties you choose to share information with (collectively, the "Services"). These systems have different data practices, which are described separately below. The Last Updated date records when this document was revised, and the revised policy text takes effect on the Revised Effective Date shown above. Unless a different timeframe is stated, the technical practices described here reflect the practices reviewed on August 22, 2026.

This Privacy Policy is a notice of our data practices, not a request to "accept" the policy as a separate contract. Please review it so you can make informed choices about using the Services and the information you provide.

Information We Collect

The Website

The Site is a static website served through GitHub Pages and its content-delivery infrastructure, including Fastly. The Site has no question-submission form, PDA Question account or registration flow, website checkout or payment processing, or website-based OpenAI generation. PDA Question does not add analytics tools, advertising code, tracking pixels, cookies, or cross-session browser storage to the Site.

The Site uses one browser-session flag to remember that a visitor dismissed the App download banner during the current browser session. The Site does not transmit that flag. GitHub Pages, Fastly, and ordinary network infrastructure may process request metadata such as an IP address, browser or device information, requested page, and request time. Those providers control the details of their logs, including retention and processing locations, under their own terms, policies, and settings.

Site support links use a mailto: flow. Activating a link opens the visitor's chosen mail application or provider; information is sent only if the visitor chooses to send the message. The sender address and message then pass through the sender's mail provider and are received in a Gmail mailbox. Links to Apple or OpenAI websites are also followed only when a visitor chooses to activate them.

The iOS App

The App has no PDA Question registration, username, password, user account, or user-session system. An Apple account may be used by Apple for App Store purchases, and the App evaluates StoreKit entitlement information on the device. The App uses a locally generated device identifier for backend rate and abuse controls, along with application-level technical controls to communicate with the backend. Those controls are not a PDA Question user credential. Local preferences and context also do not create a PDA Question user account.

When you use the App, you may provide or create information including:

  • Questions and Context: The situation or question you enter and structured context used for generation, such as age, speaker, PDA-related context, requested response length, detected themes, and relevant settings or contextual expansion
  • Professional Letters: Information used to generate a requested letter, which may include a child's name, age, grade, pronouns, school, recipient name or title, challenges, strategies, accommodations, situations, and other context you enter
  • Local App Content: History, favorites, Professional Letters and drafts, schedules, settings and context, caches, technical identifiers, diagnostic or operational metadata, and other feature-specific state stored on the device
  • Support and Feedback: Information you choose to send, which may include your email address, message, feedback or suggestion text, and related app, device, operating-system, network, or request metadata

Backend and AI Processing

For eligible App generation requests, the App sends provider-bound content through the PDA Question backend to OpenAI. Depending on the feature, that content includes Question and contextual generation data or the Professional Letter information listed above; it is not limited to "question text." The released App may also send operational security events and make limited automatic service requests when it starts. Those automatic requests do not contain the user's actual question, but they may involve the PDA Question backend and provider infrastructure, including OpenAI, and create normal device, request, security, rate-control, and service-usage metadata.

The backend and its infrastructure process operational information needed to deliver and protect the service, including:

  • A stable device identifier used to apply usage limits, operate the service, and prevent abuse
  • The requester's IP address, request metadata, and temporary security and rate-limit records used to operate the service and prevent abuse
  • Security events and diagnostic or operational metadata about backend and provider activity used to operate and troubleshoot the service
  • Normal Vercel runtime and infrastructure logs, plus temporary server-side operational state held in a managed data store for security and rate limiting
  • Feedback and product-suggestion email metadata processed through Resend and Gmail

PDA Question does not currently include Firebase Analytics, Google Analytics/GA4, Amplitude, Mixpanel, advertising or attribution tools, IDFA tracking, or a crash-analytics provider in the App or Site. Operational security, rate-control, service-usage, email, and infrastructure records are separate from product analytics.

Sensitive Information and Information Not Requested for Ordinary Use

Ordinary Question use does not require a child's name, a government identifier, or other unnecessary identifying detail. Please avoid including Social Security numbers, government-issued identification numbers, or other unnecessary sensitive identifiers in free-text fields. The App has no dedicated government-ID field and does not intentionally request government identifiers for ordinary use. Information you voluntarily enter may nevertheless be processed as part of the submitted content.

  • Child Information: Some features, including Professional Letters, intentionally accept identifying and contextual information needed to generate the requested content. Free-text fields can also contain information you choose to enter.
  • Health or Sensitive Context: Questions, letters, schedules, and other fields may contain health, behavioral, educational, school, or other sensitive context you voluntarily provide.
  • Location: The App does not request precise GPS location. An IP address processed by network and backend infrastructure may indicate an approximate location.
  • Payments: PDA Question does not directly process or receive payment-card numbers. Apple processes App Store purchases and related Apple account and transaction information.

How We Use Your Information

We use the information we collect for the following purposes:

To Provide and Maintain Our Services

  • Send eligible Question and Professional Letter content through the backend to OpenAI and return the requested Understanding, Script, or letter
  • Personalize the App using context and preferences primarily stored on the device
  • Store App History, favorites, letters, schedules, settings, caches, and other feature-specific state locally
  • Troubleshoot technical issues using support, request, security, and diagnostic metadata
  • Use feedback and operational or diagnostic metadata to maintain and improve service reliability

To Communicate With You

  • Respond to your support inquiries and feedback
  • Receive product suggestions and operational reports through our email providers
  • Publish the current Privacy Policy and other supported notices on the Site

To Ensure Security and Prevent Fraud

  • Apply request validation, rate limits, quotas, and abuse controls
  • Review operational security events and request metadata
  • Restrict device or application access when security or abuse controls are triggered

For Legal Compliance

  • Comply with applicable laws, regulations, and legal processes
  • Respond to lawful requests from public authorities
  • Establish, exercise, or defend legal claims

How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following limited circumstances:

Operational Service Providers Selected by PDA Question

We use operational providers to deliver and support the Services, including:

  • OpenAI: The App sends eligible generation content through our backend to OpenAI. Depending on the feature, this can include the Question and structured context or Professional Letter details, including identifying and sensitive information you choose to enter. The backend does not intentionally add the requester's IP address or device identifier to the OpenAI message content, although identifiers typed into submitted content are included.
  • Website and Backend Infrastructure: GitHub Pages and Fastly serve the static Site; Vercel hosts the App backend and may process request metadata and runtime logs; and a managed server-side operational data store holds temporary security and rate-limit records.
  • Email Services: Resend and Gmail process feedback, suggestions, support messages, and related email or request metadata.
  • Apple: Apple provides the App Store, StoreKit purchases, subscription entitlements, restoration, and user-initiated App Store links.

We are responsible for accurately describing our use of these providers and for the provider choices we make. Provider handling, retention, processing locations, and independently controlled practices depend on each provider's applicable terms, policies, account settings, and technical controls, which we do not control in every detail. We do not promise a provider-specific retention period or processing location unless expressly stated here.

AI Generation, Historical Fine-Tuning, and Foundation-Model Training

The App currently uses a developer-created fine-tuned model to generate responses. That historical developer fine-tuning is distinct from processing a current request. Generating an Understanding, Script, or Professional Letter does not itself retrain the model.

PDA Question does not include a separate product workflow whose purpose is to submit current questions, feedback, or generated responses for OpenAI foundation-model training. OpenAI's published API data controls state that API data is not used to train or improve its models unless an organization opts in, and separately address abuse monitoring and endpoint-specific retention. OpenAI's handling of PDA Question API data, including any provider training use and retention, depends on its applicable API terms and policies, PDA Question's organization settings, and any applicable contractual controls. See OpenAI's API data-controls documentation.

Business Transfers

If PDA Question is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. Any supported notice will be posted on the Site or provided as required by applicable law.

Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or subpoena), or to:

  • Comply with legal obligations
  • Protect and defend our rights or property
  • Prevent or investigate possible wrongdoing in connection with the Services
  • Protect the personal safety of users or the public

With Your Consent

We may share your information for any other purpose with your explicit consent.

User-Directed Sharing and External Links

The App lets you choose to copy, export, email, message, or share selected content through the iOS clipboard, Mail, Messages, PDF tools, or system share sheet. These handoffs occur only when you initiate them. Once content is sent to a recipient app, person, or provider, that destination controls its own use and retention.

The App's Helpful Products feature contains tagged Amazon links that you may choose to open. The Site currently contains no Amazon affiliate links. Other Apple, OpenAI, and resource links are also opened only by user action.

Data Security

The Services use technical controls including:

  • Transmission: Site, App-to-backend, and backend-to-provider connections use HTTPS/TLS
  • Request Controls: The backend applies application-level request controls, validation, rate limits, and abuse controls
  • Device Storage: App information is stored in iOS files, preferences, or Keychain storage depending on the data category

Security and backup practices can differ among the services we use. We do not state that every system uses the same encryption-at-rest, access-control, security-assessment, incident-response, or backup configuration.

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security. You use our Services at your own risk.

Data Retention

Retention and deletion differ by data store and feature. The App has no PDA Question account and there is no single account-deletion or all-data-deletion endpoint.

  • History: Question, Understanding, Script, and related History records are stored locally and can be removed individually or through Clear History. Clear History does not remove favorites or every other local App store.
  • Other Local Stores: Favorites, Professional Letters and drafts, schedules, settings and context, caches, the last submitted question, identifiers, and security or feature-specific state have separate retention and deletion behavior. A Professional Letter may exist in both letter history and general History, so deleting one copy does not necessarily delete the other.
  • Device and Security Identifiers: Local device and diagnostic identifiers and some security records may persist until their specific storage is reset or removed through applicable device or app-data controls. The App does not currently provide a single control that deletes information across every local feature and third-party service.
  • Backend AI Requests: The backend processes raw prompts and generated responses only as needed to provide ordinary generation requests; it does not save them in its security and rate-limit store or a separate PDA Question content database. OpenAI processing and retention are governed separately as described above.
  • Rate and Abuse State: Certain temporary server-side security and rate-limit records are configured to expire automatically on schedules that vary by purpose. Actual operational retention may also depend on provider and runtime behavior.
  • Logs and Email: Vercel and other infrastructure logs, OpenAI provider data, and Resend/Gmail messages or metadata are controlled separately and are not removed by local App deletion controls. Retention and backup practices vary by provider, service, and applicable settings.

You may use the available feature-specific deletion controls and may contact us to make a privacy request. A request will be evaluated across the relevant stores and providers, subject to applicable law and available mechanisms; it is not equivalent to deleting a nonexistent PDA Question account.

Privacy Requests and Applicable Rights

Anyone may contact us for reasonable assistance with information associated with them. Depending on what we can identify and retrieve, you may ask us to:

  • Provide access to or a copy of information we hold about you
  • Correct inaccurate information we control
  • Delete information we control
  • Explain available App controls or provider-specific request steps

These voluntary requests are subject to reasonable identity and authority verification and to technical, security, provider, legal, and record-retention limitations. Because PDA Question has no user account and information is split among local App stores, operational systems, providers, and email, we may not be able to identify, retrieve, correct, or delete every item. We will explain what we can reasonably do.

Privacy laws in some jurisdictions may provide additional rights when those laws apply to PDA Question or to particular information. We will review and respond to legally applicable requests as required, but this policy does not claim that a named privacy statute applies solely because a person lives in a particular place.

How to Make a Request

Email PDAQuestionApp@gmail.com with the subject line "Privacy Request" and describe the information or assistance you are seeking. Please do not send unnecessary sensitive information with your initial request. We may ask for additional information reasonably needed to verify your identity, authority, or the records involved.

Children's Information and Adult Use

PDA Question is designed for direct use by adults who are at least 18. An App Store designation such as "Rated 13+" is a storefront content rating and does not change the Terms' 18+ eligibility requirement.

Adults may use the Services to support a child in their family or care and may provide information concerning that child. The current service is consumer and family focused. Professionals may receive or review material that a family chooses to share, but PDA Question is not currently offered to organizations, schools, clinics, agencies, or professional practices for independent submission of client, patient, or student information.

Ordinary Question use does not require a child's name, and we encourage adults to avoid unnecessary identifying or sensitive details. However, users may voluntarily enter identifying or sensitive information in free-text fields, and some features intentionally request information needed for the feature:

  • Professional Letters may request a child's name, age, grade, pronouns, school, challenges, strategies, accommodations, situations, recipient details, and other entered context
  • Question and Professional Letter content is processed through the backend and OpenAI for the generation the adult user requests
  • PDA Question does not verify the accuracy of information entered by a user
  • Deletion is feature- and store-specific; local controls do not automatically remove provider logs, operational state, email, or a separate copy stored in another App feature

If you believe a person under 18 used the Services directly or submitted information, contact us at PDAQuestionApp@gmail.com so we can review the relevant stores, providers, and available steps. Where COPPA or another child-privacy law applies, we will handle the matter as that law requires.

International Processing

PDA Question and its operational providers may process information in the United States and other countries. Data-protection rules and provider practices may differ from those in your country, and the exact processing locations and transfer controls depend on the provider, service, account settings, and applicable requirements.

Where an international-transfer requirement applies to PDA Question or particular information, we will address it as required by applicable law.

Third-Party Links and User-Selected Services

Our Services may contain links to or let you share with third-party websites, services, people, or resources that you choose, including:

  • Apple App Store and OpenAI policy pages linked from the Site
  • Educational resources and articles linked from the Site or App
  • Tagged Amazon Helpful Products links in the App
  • Mail, Messages, the clipboard, and other destinations you select through App sharing tools

After you intentionally follow a link or send content to a destination, that third party controls its own independent handling under its policies and settings. We encourage you to review those practices before providing information. This differs from the operational providers PDA Question selects to deliver the Services, whose roles are described in this policy. We remain responsible for the accuracy of our own disclosures and the provider choices we make, but we do not control every independently operated provider or destination system.

Jurisdiction-Specific Privacy Rights

The sections below summarize potential rights when the named law applies; they do not determine applicability based only on a person's location.

California

If the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), applies to PDA Question and the relevant information, California residents may have rights such as access or knowledge, correction, deletion, portability, opt-out of certain sales or sharing, limits on certain uses of sensitive personal information, and non-discrimination. The existence and scope of a right depend on statutory applicability, definitions, and exceptions.

As a factual description of current practices, PDA Question does not sell personal information and does not currently include advertising, attribution, or cross-site tracking technology in the App or Site.

European Economic Area, United Kingdom, and Switzerland

If the GDPR, UK data-protection law, Swiss data-protection law, or another applicable regime applies to PDA Question and the relevant processing, it may provide rights such as access, correction, deletion, restriction, portability, objection, withdrawal of consent where consent is used, or a complaint to an appropriate authority.

Other Jurisdictions

Other privacy laws may provide additional rights when their scope and requirements apply. You may use the same privacy-request channel described above, and we will evaluate the request under applicable law and available mechanisms.

Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology, applicable requirements, or other relevant circumstances. When we make changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Post the revised policy on the Site
  • State the date when the revised policy takes effect

We may provide additional notice or seek consent where required by applicable law. Continued use does not turn this Privacy Policy into a separate contract or replace consent where consent is legally required.

Do Not Track Signals

Some web browsers and devices may transmit "do not track" (DNT) signals. PDA Question does not currently add advertising or tracking technology to the Site, and the Site does not separately respond to DNT signals.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: PDAQuestionApp@gmail.com
Subject Line: Privacy Inquiry

We will review and respond to inquiries as appropriate and as required by applicable law.

Version dates: This document was last updated August 22, 2026. The revised policy text takes effect September 21, 2026 and describes practices from that date forward.

PDA Question

Calm, PDA-informed educational support for parents and caregivers.

PDAQuestionApp@gmail.com

Product

How It WorksFor ParentsDownloadFor Professionals

Learn

What is PDA?ResourcesAbout

Help

SupportPrivacyTerms
© 2026 PDA QuestionEducational support—not diagnosis, treatment, or emergency services.