Privacy Policy

Introduction

Point Holdings, LLC dba The Pivot Point™ ("we," "us," "our," or "Company") operates the Kindled Heart™ platform ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. This policy complies with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq., and the FTC's implementing regulations.

Important Notice for Parents/Guardians: Kindled Heart™ is designed for youth ages 15-24. If your child is under 13, parental consent is required before they can use this service. If your child is 13-17, we encourage you to review this policy with them.

Age of Users and Parental Consent

Kindled Heart™ is intended for users ages 15 and older. We comply with COPPA as follows:

  • Users 13 and Under: We do not knowingly collect personal information from children under 13 without verifiable parental consent. If we become aware that a child under 13 has created an account without parental consent, we will delete their account and all associated data immediately.
  • Users 13-17: For users ages 13-17, we collect parental contact information and obtain verifiable parental consent before allowing account creation. Parents may review, update, or request deletion of their child's information at any time.
  • Users 18 and Older: Users 18+ can create accounts without parental consent.

Information We Collect

We collect the following types of information:

Information You Provide Directly:

  • Account information (email address, name)
  • Profile information (nickname, age range, pronouns, situation context, personal goals)
  • Daily mood check-ins and emotional state data
  • Chat messages and conversations with AI peer support companion
  • Journal entries and personal reflections
  • Resource bookmarks and usage patterns
  • For users 13-17: Parent/guardian email address and contact information

Information Collected Automatically:

  • Device information (browser type, operating system, device ID)
  • Usage data (pages visited, features accessed, time spent in app)
  • IP address and general location information
  • Session cookies for authentication and security

How We Use Your Information

We use the information we collect for the following purposes:

  • Provide, maintain, and improve our mental health support services
  • Deliver personalized AI-powered peer support conversations
  • Detect and respond to crisis situations for user safety (crisis detection)
  • Communicate with you about your account and service updates
  • Monitor and analyze usage patterns in aggregated, de-identified form for service improvement
  • Comply with legal obligations and enforce our Terms of Service
  • For users under 18: Communicate with parents/guardians about account activity if needed for safety

Crisis Detection and Safety

To ensure user safety, we automatically scan chat messages and journal entries for crisis-related keywords and concerning patterns. When potential crisis indicators are detected:

  • A crisis flag is created in your account
  • You receive supportive resources and crisis helpline information (988 Suicide & Crisis Lifeline)
  • For users under 18, we may notify parents/guardians if immediate safety concerns are identified
  • Staff members may be alerted to provide appropriate support

This crisis detection is performed solely for your safety and in accordance with our duty of care to protect vulnerable users.

Data Sharing and Disclosure

We do not sell, rent, or share your personal information with third parties for marketing purposes. We may disclose information in the following circumstances:

  • Legal Requirements: When required by law, court order, or government request
  • Safety and Crisis: To emergency responders or parents/guardians when there is an immediate safety concern
  • Service Providers: To trusted partners who help us operate the service (subject to confidentiality agreements)
  • Aggregated Data: We may share de-identified, aggregated data for research and service improvement

Data Retention and Deletion

We retain your personal information only as long as necessary to provide our services and comply with legal obligations. You have the right to request deletion of your account and all associated data at any time. Upon deletion:

  • Your account will be deactivated immediately
  • All personal information will be deleted within 30 days
  • De-identified, aggregated data may be retained for research purposes
  • For users under 18, parents/guardians may request deletion on behalf of their child

Your Privacy Rights

You have the following rights regarding your personal information:

  • Right to Access: Request and review all personal information we hold about you
  • Right to Correct: Request correction of inaccurate or incomplete information
  • Right to Delete: Request deletion of your account and all associated data
  • Right to Opt-Out: Opt out of certain data uses (except those necessary for service operation)
  • Right to Data Portability: Request a copy of your data in a portable format
  • Parental Rights (COPPA): For users under 13, parents may exercise all rights on behalf of their child

To exercise any of these rights, please contact us at [email protected] with your request.

Data Security

We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption in transit (HTTPS/TLS protocol)
  • Encryption at rest for sensitive data
  • Secure authentication and session management
  • Regular security audits and vulnerability assessments
  • Access controls and employee confidentiality agreements

However, no method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Third-Party Links

Kindled Heart™ may contain links to third-party websites and resources. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.

COPPA Compliance Statement

Kindled Heart™ complies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 without verifiable parental consent. For users ages 13-17, we obtain parental consent before account creation and provide parents with access to their child's information. If you believe we have collected information from a child under 13 without proper consent, please contact us immediately at [email protected].

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date. Your continued use of Kindled Heart™ following such changes constitutes your acceptance of the updated Privacy Policy.

Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our privacy practices, please contact us:

Email: [email protected]

Mailing Address:
Point Holdings, LLC dba The Pivot Point™
[Your Mailing Address]

Response Time: We will respond to all privacy inquiries within 30 days.

Last Updated: 3/31/2026

This Privacy Policy is effective as of the date listed above and complies with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq., and the FTC's implementing regulations (16 CFR Part 312).