DPIA Summary

Draft v0.1 · Last reviewed 28 June 2026 · ← Back to Security Center

The Short Version

What the DPIA covers

The assessment identifies ten risk areas (R1–R10) across the product, including: processing children's behavioural data via nicknames rather than legal identity; the tension between an immutable, hash-chained ledger and the right to erasure; retention of financial-dispute data in separated-family scenarios; and the two AI features (AI Mentor insights and the family audit) that process minimised behavioural summaries.

The ledger and erasure (Risk R10)

The most detailed risk assessment concerns what happens to ledger data after account deletion. Our conclusion: pseudonymised ledger records (amounts, timestamps, and chore patterns with identifiers stripped) are pseudonymous personal data, not anonymous data — the combination of fields could, in principle, act as a behavioural fingerprint. We deliberately corrected an earlier internal description that overstated this as "anonymised." Mitigations in place: no retained linkage key between the pseudonymised records and any identity, no index on behavioural fields, and a hard 7-year deletion at the end of the retention window (aligned to the UK Limitation Act 1980), enforced by an automated purge job.

Automated decision-making

Neither of Morechard's AI features makes a decision with legal or similarly significant effect on a user. Module unlocking and chore approval are rule-based, not AI-driven; AI-generated insights are informational only and always sit in front of a parent for review, not in place of one.

What's still open

We think a DPO evaluating a pilot deserves to see the gaps as clearly as the coverage:

Requesting the full document

Schools considering a pilot are welcome to request the full internal DPIA draft for their own DPO's review. Email [email protected].