Privacy Policy

Last updated: 25 May 2026

1. Introduction

PlayFirst is a digital platform designed for speech-language and allied health professionals. PlayFirst provides tools for therapy planning, documentation support, AI-assisted drafting, parent collaboration, activity generation, progress tracking, and related workflow support.

This Privacy Policy explains how PlayFirst collects, uses, stores, shares, transfers, protects, and deletes personal information.

This Privacy Policy applies to:

  • PlayFirst Full
  • PlayFirst Lite
  • The PlayFirst website
  • Parent/caregiver portal functionality
  • AI-assisted features
  • Subscription and payment systems
  • Support and communication services

By using PlayFirst, you acknowledge that you have read and understood this Privacy Policy.

2. Product Distinction: PlayFirst Full vs PlayFirst Lite

PlayFirst Full

PlayFirst Full is a clinical documentation and workflow platform that may store:

  • therapist account information;
  • child/client profiles;
  • therapy notes;
  • assessment information;
  • generated reports;
  • generated activities;
  • parent portal content; and
  • related workflow information.

PlayFirst Full is designed for responsible clinical data handling and is built around the core privacy requirements of:

  • South Africa's Protection of Personal Information Act (POPIA);
  • the Australian Privacy Principles (APPs);
  • the New Zealand Privacy Act 2020;
  • relevant GDPR and UK GDPR principles where applicable.

PlayFirst Full is intended for professional use by therapy professionals in:

  • South Africa;
  • Australia;
  • New Zealand;
  • the United States;
  • the United Kingdom; and
  • Ireland.

PlayFirst Full is designed with HIPAA-aware privacy and security principles in mind and incorporates safeguards commonly associated with privacy-conscious healthcare software, including consent confirmation workflows, audit logging, secure authentication, access controls, secure infrastructure, and data minimisation practices. However, PlayFirst Full is not currently marketed as HIPAA compliant and does not currently operate under a Business Associate Agreement (BAA) chain.

PlayFirst Lite

PlayFirst Lite is a separate stateless AI workspace designed around:

  • de-identification;
  • data minimisation; and
  • temporary processing.

PlayFirst Lite is designed so that clinical inputs and AI outputs are not intentionally stored in a PlayFirst-controlled database.

PlayFirst Lite is intended for de-identified use only.

Users must not submit:

  • Protected Health Information (PHI);
  • identifiable client information; or
  • unnecessary identifying personal information

into PlayFirst Lite.

PlayFirst Lite is designed around HIPAA Safe Harbor de-identification principles, but it is not marketed as HIPAA compliant.

3. Who We Are

PlayFirst is operated by:

PlayFirst
Email: michaela@playfirstapp.com
Website: https://www.playfirstapp.com

For privacy-related requests or concerns, contact:

Privacy / Information Officer: michaela@playfirstapp.com

4. Important Privacy Principles

PlayFirst is designed around the following principles:

  • collect only the minimum information reasonably necessary;
  • encourage therapists to minimise identifying information;
  • provide user-controlled access;
  • provide deletion and export functionality;
  • maintain secure infrastructure and authentication controls;
  • maintain transparency regarding third-party processing;
  • support responsible clinical data handling.

PlayFirst does not sell personal or client data.

PlayFirst only shares data with trusted service providers where necessary to:

  • operate the platform;
  • secure the platform;
  • process payments;
  • deliver emails;
  • provide AI functionality; or
  • support core infrastructure.

5. Information We Collect

5.1 Therapist Account Information

We may collect:

  • name;
  • email address;
  • practice or clinic name;
  • country;
  • subscription details;
  • billing information;
  • authentication information;
  • optional professional registration details.

5.2 Child / Client Information (PlayFirst Full)

Therapists may enter:

  • first name;
  • initials;
  • nickname;
  • age or age range;
  • interests;
  • strengths;
  • communication style;
  • therapy goals;
  • assessment observations;
  • progress notes;
  • generated reports;
  • generated activities;
  • language samples;
  • parent portal information;
  • parent/caregiver contact details where added by the therapist.

PlayFirst strongly encourages therapists to use only the minimum information necessary.

5.3 Session Notes and Reports

Therapists may create or store:

  • session notes;
  • SOAP notes;
  • assessments;
  • recommendations;
  • reports;
  • generated therapy activities;
  • parent summaries;
  • AI-assisted outputs.

5.4 Technical and Usage Information

We may collect:

  • login timestamps;
  • IP addresses or hashed IPs;
  • browser and device information;
  • security logs;
  • failed login attempts;
  • audit logs;
  • usage metrics;
  • subscription status;
  • payment references.

5.5 Payment Information

Payments are processed through third-party payment providers.

PlayFirst does not store full payment card details.

6. Information We Do Not Intentionally Collect

PlayFirst discourages users from entering:

  • unnecessary identifying information;
  • full names where not needed;
  • addresses;
  • ID numbers;
  • medical aid numbers;
  • social security numbers;
  • unnecessary family details;
  • unnecessary sensitive personal information.

PlayFirst Lite users must not submit:

  • PHI;
  • identifiable client information; or
  • unnecessary identifying information.

7. Data Minimisation Guidance

PlayFirst includes in-app guidance encouraging therapists to:

  • use first names, initials, or non-identifying nicknames where possible;
  • avoid unnecessary identifying details;
  • focus notes on therapy observations and goals;
  • avoid storing unnecessary family or personal information.

Suggested best practices include avoiding:

  • surnames;
  • addresses;
  • school names;
  • ID numbers;
  • medical aid numbers;
  • unnecessary parent contact information.

Therapists remain responsible for deciding what information is entered into the platform.

8. Why We Process Information

We process information:

  • to provide the PlayFirst service selected by the therapist;
  • to support therapy documentation and workflow functionality;
  • to provide AI-assisted drafting and generation tools;
  • to manage accounts and subscriptions;
  • to provide parent portal functionality;
  • to provide customer support;
  • to maintain platform security and integrity;
  • to investigate suspicious activity or security incidents;
  • to comply with legal, operational and regulatory obligations.

9. Consent and Therapist Responsibilities

Therapists are responsible for:

  • obtaining appropriate consent or authority from the client, parent or legal guardian;
  • ensuring that information entered into PlayFirst is lawful and appropriate;
  • complying with applicable privacy laws and professional obligations;
  • maintaining their own clinical and consent records.

PlayFirst does not obtain client or guardian consent directly on behalf of therapists.

Before creating child/client profiles, therapists are required to confirm:

"I confirm that I have obtained appropriate consent or authority from the client, parent or legal guardian to create this profile and process this client's information in PlayFirst."

PlayFirst may store:

  • consent confirmation;
  • timestamp;
  • consent version;
  • therapist account reference;
  • related audit log entries.

10. AI Features and AI Providers

PlayFirst uses artificial intelligence to assist with:

  • report generation;
  • parent summaries;
  • therapy activity generation;
  • GLP support;
  • documentation support;
  • workflow drafting.

AI outputs:

  • may contain inaccuracies;
  • may contain omissions;
  • may not always be clinically appropriate;
  • must be professionally reviewed before use.

Therapists remain responsible for all final clinical decisions and documents.

AI Providers

PlayFirst may use third-party AI providers through Emergent's LLM proxy, including:

  • OpenAI;
  • Anthropic.

Emergent has confirmed that its LLM proxy acts as a pass-through and does not log or retain prompt/output content.

However:

  • zero data retention is not currently enabled for the pooled LLM key used through Emergent;
  • AI providers may temporarily retain API data for abuse monitoring, security or legal purposes under their own terms;
  • AI providers state that API data is not used to train their models by default unless users opt in or provider terms state otherwise.

Users should avoid entering unnecessary identifying information into AI tools.

11. Parent / Caregiver Portal

Parent portal access is controlled by the therapist.

Therapists decide:

  • whether to invite a parent/caregiver;
  • what information is shared;
  • which notes or activities are visible.

Parents/caregivers may access:

  • shared activities;
  • shared goals;
  • shared notes;
  • therapist-approved content.

Parents/caregivers do not automatically receive access to:

  • all clinical notes;
  • all reports;
  • all assessment data.

Therapists are responsible for ensuring that they have appropriate consent before sharing information through the parent portal.

12. International Processing and Data Residency

PlayFirst uses cloud-based infrastructure and service providers that may process or store data outside the user's country, including in the United States.

This may include:

  • hosting infrastructure;
  • database hosting;
  • AI processing;
  • analytics;
  • payment processing;
  • email delivery;
  • security tooling.

PlayFirst currently uses Emergent-managed infrastructure with default data residency in the United States.

PlayFirst does not currently guarantee region-specific hosting or dedicated EU-region infrastructure.

Users are responsible for ensuring that their use of PlayFirst is consistent with their own professional and legal obligations.

13. Third-Party Service Providers and Subprocessors

PlayFirst may use third-party service providers including:

  • Emergent.sh;
  • OpenAI;
  • Anthropic;
  • MongoDB Atlas;
  • Cloudflare;
  • Paystack;
  • Resend;
  • analytics providers;
  • security providers.

These providers may process limited information where necessary to operate the service.

PlayFirst maintains a subprocessor register and vendor documentation where available.

14. Security Measures

PlayFirst applies reasonable technical and organisational safeguards including:

  • HTTPS/TLS encryption;
  • encrypted databases;
  • hashed passwords;
  • access controls;
  • restricted administrative access;
  • audit logging;
  • login protection measures;
  • backup systems;
  • monitoring and security tooling.

However:

  • no online system can be guaranteed completely secure;
  • users remain responsible for maintaining secure passwords and device security.

15. Audit Logging and Monitoring

PlayFirst may maintain audit logs relating to:

  • login events;
  • failed login attempts;
  • profile creation;
  • deletion requests;
  • exports;
  • parent portal access;
  • administrative actions;
  • security events.

Audit logs are maintained for security, compliance and operational purposes.

16. Retention and Deletion

PlayFirst retains information:

  • while accounts remain active;
  • while profiles remain active;
  • while required for operational, security or legal purposes.

Users may:

  • delete child/client profiles;
  • delete notes;
  • export data;
  • request account deletion.

Deleted data is removed from active systems.

Deleted data may remain temporarily in secure backups until routine backup expiry.

17. Your Rights

Depending on your country and applicable law, users may have rights including:

  • access;
  • correction;
  • deletion;
  • export/portability;
  • objection or withdrawal of consent where applicable.

Users may contact PlayFirst regarding privacy requests.

Some information may be retained where required for:

  • legal purposes;
  • security purposes;
  • fraud prevention;
  • backup systems;
  • operational integrity.

18. Regional Privacy Positioning

South Africa

PlayFirst is designed around the core privacy principles of POPIA and supports privacy-conscious handling of personal information by therapy professionals.

Australia

PlayFirst is designed around the core principles of the Australian Privacy Principles and supports responsible handling of therapy-related information.

New Zealand

PlayFirst is designed around the core principles of the New Zealand Privacy Act 2020 and supports privacy-conscious handling of therapy-related information.

United States

PlayFirst Full is not marketed as HIPAA compliant and does not currently operate under a BAA chain.

PlayFirst Lite is intended for de-identified use only.

United Kingdom and Ireland

PlayFirst applies transparency, data minimisation, access control and security practices designed around GDPR-style privacy principles where applicable.

19. Privacy Breaches and Security Incidents

PlayFirst maintains an internal breach response process.

Where required by applicable law, PlayFirst may:

  • investigate suspected incidents;
  • notify affected users;
  • notify relevant regulators.

20. Changes to This Privacy Policy

PlayFirst may update this Privacy Policy from time to time.

Updated versions will be posted on the website or inside the platform.

Continued use of the platform after changes are published may constitute acceptance of the updated policy.

21. Contact

For legal or privacy-related matters contact: michaela@playfirstapp.com

Website: https://www.playfirstapp.com