Privacy at Still Here
Last updated: July 2026
Still Here is built for young people. Privacy matters to us — especially for teens under 18. This page explains, in plain English, what we collect, why, and the choices you have.
Who we are
Still Here is operated by Still Here Youths (SHY), an Australian not-for-profit youth organisation. We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).
What we collect
- Account info: display name, email, age range, state, school year (all optional except email).
- Learning progress: lessons completed, habits tracked, journal entries (private to you).
- Content you post: posts, DMs, event invites, bookings, donation pledges.
- Ember AI conversations: messages you send to our AI companion. Used to provide replies; not sold or used to train external models.
What we DON'T do
- We do not sell your data. Ever.
- We do not run ads.
- We do not share data with third parties except our secure infrastructure providers (Supabase for the database, Lovable AI Gateway for Ember).
If you're under 18
You can use Still Here without a parent account. If a parent asks for a copy or deletion of your data on your behalf, we'll verify with you first before acting — because your voice matters.
Safety-first exceptions
If Ember AI or a moderator detects an imminent risk to life, we will surface Australian crisis hotlines (Kids Helpline, Lifeline, 13YARN, 000) immediately. In extreme cases where a young person's safety is at risk, we may report to police or child safety authorities as required by Australian law.
Your rights
You can request a copy or deletion of your data at any time by emailing privacy@stillhereyouths.org. We'll respond within 30 days. If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC).
How we secure your data
- Passwords are hashed and salted by our identity provider — never stored in plain text.
- Personal information (email, phone) is encrypted in transit (TLS) and at rest by our managed infrastructure.
- Our engineering practices are guided by OWASP recommendations and the ASD Essential Eight mitigation strategies (as design goals, not certifications).
- We comply with the Notifiable Data Breaches scheme and will notify affected users and the OAIC where required by law.
- The platform is designed to WCAG 2.2 AA accessibility goals.
Australian legal framework
Our practices are informed by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Online Safety Act 2021 (Cth), and guidance from the eSafety Commissioner. See /trust for a fuller breakdown.
Contact
Questions? hello@stillhereyouths.org · Privacy: privacy@stillhereyouths.org