Legal

Privacy Policy

Last updated: 17 May 2026

In plain English

We collect only what the app needs to work. We never sell your data. Your family’s information is encrypted, stored in Australia, and under your control. You can delete everything at any time. Children’s data receives the highest level of privacy protection under Australian law.

Super Epic Goals
Operated by Super Epic Group
ACN: 689 548 383 | ABN: 81 689 548 383
Melbourne, Australia

1. Introduction

Super Epic Group (“we,” “us,” or “our”) operates Super Epic Goals (www.superepicgoals.com), a family goal-setting and engagement platform that helps children and their families create goals, reward their efforts, and celebrate their achievements. The platform also includes a suite of engagement and motivational activities (“Epic Tools”) designed to support children's focus, coordination, and self-regulation in a fun, interactive way.

This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our service.

Important - Express Consent Required: Because we collect personal information about children, we require your active, express consent before creating an account. You will be asked to affirmatively agree to this Privacy Policy during the account registration process. Continued use of the platform constitutes ongoing consent to the practices described here.

2. Information We Collect

2.1 Personal Information

We collect the following personal information when you create an account:

  • Your name
  • Your email address
  • Your child's name
  • Your child's month and year of birth

2.2 Google Sign-In Information

When you choose to sign in using Google through NextAuth, we may collect:

  • Your Google account name
  • Your Google profile information as permitted by your Google account settings

2.3 Goal and Activity Data

We collect information about:

  • Goals created for your child (including any conditions/goals selected from AI-generated suggestions)
  • Progress tracking data
  • Achievement records
  • Usage patterns within the application

2.4 Goal Wizard (AI) Input Data

When you use our Goal Wizard feature, we temporarily process:

  • Your child's gender (not stored in your profile)
  • Conditions or goal types you specify
  • Short-term or long-term goal preferences
  • Your child's age (derived from birth month/year in your profile)

This information is used solely to generate age-appropriate goal suggestions through our AI system.

2.5 Epic Tools - Engagement and Activity Data

Our platform includes a suite of engagement and motivational activities called “Epic Tools.” When you or your child use these tools, we may collect the following data:

  • Mood Check-in: Mood selection and timestamp — stored so the profile owner can view their mood history over time.
  • Reaction Time: Reaction speed in milliseconds — the top 5 fastest results are stored so the profile owner can track personal bests.
  • Keepy Uppy Ammonitey: Game duration and number of ammonites saved — stored so the profile owner can view their game history.
  • Epic Spinner: Rotations per minute (RPM) and spin count — not stored; data exists only during the active session.
  • Calm Breathing: Guided breathing session progress — not stored; data exists only during the active session.
  • Stopwatch: Elapsed time and lap records — not stored; data exists only during the active session.

Important: Epic Tools are engagement and motivational activities designed to be fun and interactive. They are not medical devices, clinical assessments, or health management tools. Data from Epic Tools is not used to diagnose, treat, or manage any medical or health condition. Where data is stored, it is retained solely so that the profile owner can view their own activity history.

Epic Tools data is never shared with third parties for commercial purposes.

2.6 Technical Information

We may collect technical information including:

  • Device information (we may collect this in the future)
  • Browser type and version
  • Usage analytics and performance data

2.7 Location and IP Address Data

When you create an account, submit a contact enquiry, or sign up for our newsletter, we collect your approximate location by looking up your IP address through a third-party geolocation service (ipapi.co). The data we collect includes:

  • Your IP address
  • Approximate country, region, and city
  • Timezone

We use this information for:

  • Security and fraud prevention (e.g. detecting suspicious registration patterns)
  • Compliance with applicable laws (e.g. determining which privacy regulations apply to your account)
  • Service improvement and analytics in aggregated, de-identified form

This location data is stored with your account record and retained for as long as your account remains active. It is not shared with third parties for commercial purposes. The geolocation lookup is performed server-side using your IP address only - we do not use browser-based geolocation or GPS.

2.8 Push Notification Tokens

When you enable push notifications on your device, we collect your device push token via Firebase Cloud Messaging (FCM). This token is used solely to send you notifications about your child's goals and activity. Push tokens are stored in our database and associated with your account. You can disable push notifications at any time through your device settings.

2.9 Cookies and Similar Technologies

We use cookies to:

  • Maintain your user preferences (such as text size and confetti settings)
  • Keep you signed in to your account
  • Improve your user experience

3. How We Use Your Information

3.1 Primary Purposes

We use your personal information to:

  • Provide and maintain our service
  • Create and manage your family's account
  • Track your child's goals and progress
  • Generate age-appropriate goal suggestions through our AI-powered Goal Wizard
  • Provide engagement and motivational activities through our Epic Tools
  • Send push notifications about your child's goals and activity
  • Customize the experience for your family
  • Communicate with you about your account and our service

3.2 Aggregated Data Analysis

We use goal and Epic Tools data in aggregated, de-identified form to:

  • Understand which types of goals are most commonly “social proofed”
  • Create a database of effective goal types that can benefit other families
  • Improve our service and develop new features
  • Support evidence-based research into effective goal-setting approaches

Important: This aggregated data is de-identified before analysis and cannot be used to identify specific users, children, or families.

3.3 Service Improvement

We may use your information to:

  • Analyze usage patterns to improve our platform
  • Develop new features and functionality
  • Ensure technical functionality and security

3.4 Artificial Intelligence (Goal Wizard)

Our Goal Wizard feature uses artificial intelligence (currently Google's Gemini Flash 2.0, though this may change in the future) to generate personalized goal suggestions. This process:

  • Combines your input (child's gender, desired conditions/goals, time preference) with your child's age
  • Sends this information to our AI service provider to generate age-appropriate goal suggestions
  • Does not store gender information in your profile
  • Only stores condition/goal information if you choose to select and save an AI-generated goal
  • Gives you complete control over which suggestions to accept, modify, or discard

The AI processing occurs in real-time through our third-party AI provider, and you retain full control over what information becomes part of your child's permanent goal record. We may change AI service providers in the future to improve our service.

4. Multi-User Access and Professional Collaboration

4.1 Invited Users

Super Epic Goals allows parents and primary account holders to invite other individuals to access their child's profile. Invited users may include family members, friends, support workers, and healthcare professionals (such as occupational therapists, speech pathologists, or NDIS support coordinators).

4.2 Privacy Levels and Data Visibility

We operate a four-level privacy control system. When you invite a user, you determine which data they can access. By default, invited users have limited visibility. You may grant broader access at your discretion. The levels are:

  • Level 1 - Goals only: Invited users can view your child's active goals and progress.
  • Level 2 - Goals and achievements: Includes goal progress plus celebration and achievement records.
  • Level 3 - Goals, achievements, and Epic Tools data: Includes engagement activity data from tools such as mood check-ins and reaction time results.
  • Level 4 - Full access: Full visibility of all data within the profile, including all Epic Tools activity history.

4.3 Professional Access

Where you invite a professional (such as a therapist, teacher, or support worker) to view your child's profile, you are providing consent for that person to view data within their assigned access level. Invited professionals remain bound by their own professional obligations. Super Epic Group is not responsible for how invited users use or store data they view through the platform.

4.4 Revoking Access

You may revoke an invited user's access at any time through your account settings. Upon revocation, that user will immediately lose access to your child's data on the platform. We do not control any notes or information the invited user may have recorded independently.

5. Information Sharing and Disclosure

5.1 No Third-Party Sharing for Commercial Purposes

We do not sell, trade, or otherwise transfer your personal information to third parties for their marketing or commercial purposes.

5.2 Service Providers

We may share your information with trusted service providers who assist us in operating our platform, including:

  • MongoDB - database hosting with encryption at rest and in transit. Our primary database is located in Australia.
  • Vercel - application hosting and edge network with encryption at rest and in transit. Your requests may be processed at the nearest Vercel edge location, which may be outside Australia (including the United States, Europe, or Asia-Pacific).
  • Firebase (Google, United States) - push notification delivery via Firebase Cloud Messaging. Device push tokens are stored to enable notifications. Subject to Google's Data Processing Addendum.
  • NextAuth - authentication services.
  • Google (United States) - when you choose to use Google Sign-In, and for AI processing through Gemini Flash 2.0 for our Goal Wizard feature. Goal Wizard input data is processed in the United States. This data is not stored by Google for model training purposes and is subject to Google's Data Processing Addendum and applicable privacy commitments.
  • ipapi.co - IP-based geolocation service used to determine your approximate location (country, region, city, timezone) at registration and when submitting contact enquiries. Only your IP address is sent to this service.

All service providers are contractually obligated to keep your information secure and use it only for the specific services they provide to us.

5.3 Legal Requirements

We may disclose your information if required by law or if we believe such action is necessary to:

  • Comply with legal obligations
  • Protect and defend our rights or property
  • Protect the safety of our users or the public
  • Prevent or investigate possible wrongdoing

6. Data Security

6.1 Encryption

All data is encrypted both at rest and in transit through our hosting providers (MongoDB and Vercel).

6.2 Access Controls

We implement role-based access controls so that users only access data relevant to their assigned permission level. Access events are logged to support security monitoring and audit purposes.

6.3 Regular Reviews

We regularly review our security practices and update them as necessary. We work toward alignment with the Australian Cyber Security Centre's Essential Eight mitigation strategies.

7. Data Retention

We retain your personal information:

  • For as long as your account remains active
  • Until you request deletion of your data
  • As required by applicable law

Goal and activity data (including Epic Tools records) is retained for as long as your account is active. When you delete your account, all associated data is permanently removed unless retention is required by law.

When you request data deletion, we will remove your personal information while maintaining your user ID to preserve system functionality and prevent service disruptions.

8. Your Rights and Choices

8.1 Access and Correction

You have the right to:

  • Access the personal information we hold about you and your child
  • Request correction of inaccurate or incomplete information
  • Update your account information at any time

To exercise these rights, contact us at saiful.nasir@superepicgroup.com with the subject line “Privacy Request.” We will respond within 30 days.

8.2 Data Deletion

You can request deletion of your personal data through your account settings. Please note:

  • Your personal information and all associated data will be permanently removed
  • Your user ID may be retained to maintain system functionality
  • This action cannot be undone

8.3 Withdraw Consent

You may withdraw your consent to our collection and use of your personal information at any time by contacting us or closing your account. Please note that withdrawing consent may limit or prevent us from providing some or all of our services to you.

8.4 Cookie Management

You can control cookies through your browser settings, though this may affect your experience on our platform.

9. Children's Privacy

Super Epic Goals is designed for parents and families to use with their children. We take the privacy of children's data seriously, particularly given our platform's use with children who may have autism, ADHD, or related conditions.

Information collected about children (including name, birth month/year, goal data, and Epic Tools data) is:

  • Collected only with express parental or guardian consent, obtained at account creation
  • Used only to provide our goal-tracking and engagement service
  • Treated with the highest level of privacy protection appropriate for children's data
  • Never shared with third parties for commercial purposes
  • Retained for as long as your account is active, and deleted upon account closure

Parents and guardians have full control over their child's information, including who can access it and at what permission level, and can request its deletion at any time.

10. Notifiable Data Breaches

We are subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). In the event of a data breach that is likely to result in serious harm to any individual whose data is involved, we will:

  • Contain the breach - immediately take steps to limit the scope and impact of the breach
  • Assess the breach - determine whether the breach is likely to result in serious harm within 30 days of becoming aware of the incident
  • Notify the OAIC - notify the Office of the Australian Information Commissioner as soon as practicable after forming the view that a notifiable data breach has occurred
  • Notify affected individuals - notify all individuals whose information was involved and who are at risk of serious harm, providing details of the breach and recommended steps they should take

If you believe your data may have been compromised, please contact us immediately at saiful.nasir@superepicgroup.com with the subject line “Data Breach Report.”

11. International Data Transfers

11.1 Data Location

Our primary database (MongoDB) is located in Australia. Your stored data (account information, goals, activity records) resides in Australia.

11.2 Edge Processing

Our application is hosted on Vercel, which uses a global edge network. Your requests may be processed at the nearest Vercel edge location, which could be in Australia, the United States, Europe, or Asia-Pacific, depending on your geographic location. This processing is transient — your persistent data remains stored in our Australian database.

11.3 Cross-Border Disclosure - Google (United States)

When you use our Goal Wizard feature, input data (child's gender, conditions/goals, time preferences, and age) is sent to Google's Gemini AI service, which is processed on servers located in the United States. We take the following steps to protect this data:

  • We have in place a Data Processing Addendum with Google that governs the use of this data
  • Google has committed that this data is not used to train AI models
  • The data transmitted is limited to the minimum necessary to generate goal suggestions

Before using the Goal Wizard, you will be notified that data is processed overseas and given the option to proceed or decline.

11.4 Firebase (United States)

Push notification tokens are processed through Firebase Cloud Messaging (operated by Google) in the United States. This is limited to your device token and notification content. Subject to Google's Data Processing Addendum.

11.5 International Users

If you access our service from outside Australia, your information may be transferred to and processed in Australia (where our database resides) and may transit through other countries via our edge network and service providers. By using our service, you consent to these transfers.

We apply the same privacy protections to all users regardless of location. We do not currently claim compliance with GDPR (EU), CCPA (California), or other non-Australian privacy frameworks, but we handle all personal information in accordance with the Australian Privacy Principles, which provide robust privacy protections for all users.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do:

  • We will post the new Privacy Policy on this page
  • We will update the “Last Updated” date at the top of this policy
  • For significant changes - particularly those affecting how we handle children's data - we will notify you via email and require you to re-consent before continuing to use the platform

13. Privacy Complaints and Contact

13.1 Internal Complaints Process

If you have a concern or complaint about how we have handled your personal information, we encourage you to contact us first so we can attempt to resolve the matter directly.

To make a privacy complaint:

  • Email us at saiful.nasir@superepicgroup.com with the subject line “Privacy Complaint”
  • Describe your concern in as much detail as possible, including the relevant dates and information involved
  • We will acknowledge your complaint within 5 business days and provide a substantive response within 30 days
  • If we need additional time to investigate, we will notify you and keep you updated on our progress

13.2 External Complaints - OAIC

If you are not satisfied with our response, or if you prefer to lodge a complaint directly with a regulatory body, you may contact:

  • Office of the Australian Information Commissioner (OAIC) - for complaints under the Privacy Act 1988 (Cth) and the Australian Privacy Principles: www.oaic.gov.au

13.3 General Contact

For any other questions or requests regarding this Privacy Policy or our data practices:

Super Epic Group
Email: saiful.nasir@superepicgroup.com
Melbourne, Australia

For privacy-related inquiries, please include “Privacy Policy” in your email subject line.

14. Australian Privacy Law Compliance

This Privacy Policy is designed to comply with the following Australian privacy legislation and principles:

  • Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs)
  • Notifiable Data Breaches scheme (Part IIIC, Privacy Act 1988)

While our platform is used by families of children with various needs (including autism, ADHD, and related conditions), the data we collect through Epic Tools does not constitute health information under the Health Records Act 2001 (Vic). Epic Tools are engagement and motivational activities — not clinical assessments, diagnostic tools, or health management instruments. Data from these tools is not used to diagnose, treat, or manage any medical or health condition.

All personal information collected through our platform is handled in accordance with the Australian Privacy Principles with the highest standard of care appropriate for children's data.

15. Dollar Balance Feature - Not Real Money

Super Epic Goals includes an optional “$ (dollar) mode” feature that allows parents to represent a child's earned stickers as a dollar amount. This feature is purely a motivational and tracking tool designed to help older children engage with the concept of earning and saving.

Important: The dollar balance displayed in Super Epic Goals is not real money. It does not represent any actual funds held, managed, or owed by Super Epic Goals or Super Epic Group. The application is not a bank, financial institution, or payment service. No real currency is stored, transferred, or guaranteed by this feature.

Parents and guardians are solely responsible for determining whether and how any represented dollar amounts are honoured in the real world (for example, as pocket money). Super Epic Goals collects and displays the balance figure solely to support the motivational purpose of the feature, and this data is handled under the same privacy protections as all other profile data described in this policy.

This Privacy Policy is effective as of the date listed above and applies to all users of Super Epic Goals.