Safeguarding first. Always.

Some of the young people using this are placed away from home for their own safety. The product is shaped around that fact rather than adjusted for it afterwards. This page is the detail, and the second half is the part most products leave out.

  • Registered with the Information Commissioner’s Office
  • Data protection impact assessment on file
  • Row level security on every table holding a child’s record
  • Independent penetration test before any real record exists

How a young person’s privacy is protected.

No public link ever identifies a child
Public pages — the house tour, this site — carry nothing about an individual young person. A personalised guide opens only through a link that is single-use, short-lived and revocable, and the link redirects before the guide renders so the code never reaches the address bar or the browser history.
Every failure looks the same
A link that never existed, one that expired, one that was used and one that was revoked all show the same page with the same words. Guessing at links tells you nothing, including whether a guide for that child was ever made.
Every read of a record is logged
Who looked, at what, and when. The log can be added to and never edited or deleted, by any role, including ours.
Personal data is held in the United Kingdom
The database and the application both run in UK regions. Images and static files are served from an edge network and contain no personal data.
Staff cannot read a young person’s journal
Not the key worker, not the registered manager, not a system administrator. There is no role with a read path, because a private space somebody can be persuaded to open was never private.
Nothing is measured inside the private space
No word counts, no time spent, no number of entries. A chart showing a child wrote nine times over a bad weekend is still information about that child.
The young person can read the log themselves
Not through a form and a four week wait. There is a screen in their own app listing who opened something on their record, what it was and when. Safeguarding entries are held back, and the screen says so and says how to ask. Nobody is told that they looked.

What OKAYiT does not do.

Staff are trained on these. Young people are told these. So they are published here too, in the same words, because a limit that only appears in a training pack is a limit that can quietly be dropped.

  • It does not read what a young person writes

    No sentiment analysis, no keyword flagging, no risk scoring, no summarising, no AI reading a journal entry looking for concern. A pattern is a reason for a conversation with a person, not an event in a system.

  • There is no messaging and no chatbot

    No adult can message a child through OKAYiT, and there is no AI companion to talk to. Both were removed in August 2026 and they are not coming back. A young person in care should be routed towards a trusted adult, not away from one.

  • It does not reward use

    No streaks, no badges for checking in, no notification asking where they have been. Engagement mechanics are coercive with someone who did not choose to be here.

  • It does not replace a single person

    It is a way in to the people already there. If the app is the most supportive thing in the house, something has gone wrong that software will not fix.

This is the single most important design decision in the product, and it looks like a technicality until you picture the house.

A young person opens their welcome guide from a link. If that link simply showed the guide, the code would sit in the address bar and in the browser history of whatever device they used. On a shared house tablet, the next young person to pick it up is one tap from a page about somebody else.

So the link does not show anything. It checks the code once, sets a short-lived cookie tied to that one session, and sends the browser somewhere else. By the time the guide appears, the code is gone from the address bar, gone from history, and was never sent to anything the page loads.

A link that has been forwarded, screenshotted, or left in a browser on a shared device opens nothing.

Data protection, plainly.

We collect only what the product needs to work. We do not sell data, ever.

Personal data is stored and processed in UK regions. Images and static files come from an edge network and contain nothing personal.

Every table holding a young person’s record has row level security on it, so access is decided by the database and not only by the application asking nicely.

You can ask what we hold about a young person, ask for it to be corrected, and ask for it to be deleted. A request from a young person themselves gets the same answer as one from a manager.

Got a safeguarding question?

Ask the awkward one. It is the one we most want to answer.