This policy explains what ChildScribe collects, how we use it, and what controls you have. We wrote it in plain language because legal documents shouldn't require a law degree.
When you create a ChildScribe account, we collect your name, email address, and payment information (processed securely by Stripe — we never see or store your full card number). You also provide basic family profile details: your child's first name, age, and any preferences that help the interviewer ask better questions.
During interviews, your voice is transcribed in real time, and we keep the resulting text transcripts — never the audio itself. If you upload photos to accompany journal entries, we store those as well. The journal entries themselves — generated from your interview transcripts — are also retained as part of your account.
We also collect standard device and usage data: your device type, operating system, app version, session timestamps, and general interaction patterns (such as how often you start interviews or view journal entries). This helps us understand how the product is used so we can improve it. We do not collect precise geolocation data, and we do not use third-party analytics trackers.
Your data exists for one purpose: to provide the ChildScribe service to your family. We use your interview transcripts to generate journal entries and compile memory books. Your family profile helps the AI interviewer ask relevant, thoughtful follow-up questions — if your child is six and loves dinosaurs, the interviewer knows that context.
We use aggregated, anonymized usage patterns to improve the product — for example, understanding which interview lengths lead to the best journal entries, or which prompts help parents feel most comfortable. This analysis never involves reading individual transcripts.
We do not use your data for advertising. We do not sell your data. We do not share your data with data brokers. We do not use your family's interviews, transcripts, photos, or journal entries to train machine learning models — not ours, and not anyone else's. Your stories are yours.
ChildScribe uses AI at two stages: the live voice interview and story generation. During an interview, your voice streams over an encrypted connection to OpenAI's realtime API, which transcribes your words as you speak and generates the interviewer's spoken replies. Your raw audio is used only to power that live conversation — ChildScribe's own servers never receive or store it. What we keep is the text transcript.
To turn transcripts into journal entries, chapters, and memory books, our AI engine sends transcript text to Anthropic's Claude API. Anthropic processes that text solely to return a response to ChildScribe. Under Anthropic's commercial API terms, your inputs and outputs are not used to train, improve, or fine-tune their models.
We chose providers whose commercial API terms prohibit using customer data for model training — this is true of both Anthropic and OpenAI's API platform. We will notify you if there are any material changes to how your data is processed by our AI providers.
ChildScribe is designed for families with children ages 3 through 12, and we take our obligations under the Children's Online Privacy Protection Act (COPPA) seriously. Children do not create accounts, do not have login credentials, and do not interact with ChildScribe directly. Parents and legal guardians are the sole account holders, and all data collection requires the active participation and consent of a parent.
The information we store about children is limited to what parents choose to provide: a first name (or nickname), an age or birth year, and the content of interviews and journal entries that reference them. We do not collect children's email addresses, phone numbers, physical addresses, photos taken by children, or any direct identifiers beyond what a parent voluntarily shares during interviews.
Parents have full control over their children's data at all times. You can review, edit, or delete any information about your child from within your account. If you delete your account, all data associated with your children is permanently removed within 30 days. If you believe we have inadvertently collected information from a child without parental consent, please contact us immediately at support@legacyscribegroup.com and we will delete it promptly.
All ChildScribe data is stored on servers located in the United States. All data transmitted between your device and our servers is protected by TLS (Transport Layer Security) encryption, and access to the systems where your transcripts, photos, and journal entries live is restricted to the small number of people who operate the service.
Our infrastructure runs on established US-based cloud providers — DigitalOcean hosts the application and database, and Fly.io runs the AI engine that turns transcripts into journal entries. We implement role-based access controls and automated monitoring for unauthorized access attempts, and we keep server software and dependencies up to date.
No system is perfectly secure, and we are honest about that. But we build ChildScribe as if our own children's data were in it — because it is. If we ever become aware of a security breach affecting your data, we will notify you within 72 hours with a clear description of what happened, what data was involved, and what steps we are taking.
You have the right to access all data we hold about you and your family. From your account, you can view every journal entry (and the interview transcript behind it), photo, and piece of profile information associated with your account. There is nothing hidden and no data we collect that you cannot see.
You have the right to obtain a copy of your data at any time. From your account settings, you can download an export of your data — your journal entries and family profile information as structured JSON, plus every photo in its original file format — and any memory books you have purchased remain available as PDF downloads. Your data is not locked into our platform.
You have the right to delete your account and all associated data. Account deletion is available right from your account settings — you confirm with your password, and that\'s it. No emails to support, no retention tricks. When you delete your account, deletion of your data — transcripts, journal entries, photos, and profile information — from our live systems begins immediately, and residual copies in our routine infrastructure backups expire within 30 days, after which your data is irrecoverable.
If you are a resident of California, the European Union, the United Kingdom, or another jurisdiction with specific privacy rights, you may have additional rights including the right to correct inaccurate data, restrict processing, or lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at support@legacyscribegroup.com.
While your account is active, we retain your transcripts, journal entries, photos, and profile information for as long as you maintain your subscription. This data is what makes ChildScribe useful — it allows the interviewer to build on past conversations and enables you to compile memory books that span months or years.
We never store your interview audio, so there is no audio retention policy to manage. Your voice is transcribed in real time during the conversation, the audio is used only to power that live session, and only the text transcript is kept. There are no recordings of your voice on our servers to review, retain, or delete.
When you cancel your subscription, you retain read-only access to your data. If you subsequently delete your account, all data — transcripts, journal entries, photos, memory books, and profile information — is deleted from our live systems right away, and residual copies in our routine infrastructure backups expire within 30 days. We do not retain anonymized or aggregated versions of your individual data after deletion.
If we make changes to this privacy policy, we will notify you via email at the address associated with your account at least 30 days before the changes take effect. We will also post the updated policy on this page with a revised effective date.
For material changes — such as new categories of data collection, new third-party data processors, or changes to how we use AI — we will provide a clear summary of what changed and why. We will never quietly alter this policy and hope no one notices. If a change would meaningfully affect your family's privacy, you will know about it, and you will have time to export your data or close your account before the change takes effect.
If you have questions about this privacy policy, want to exercise your data rights, or have concerns about how your information is handled, we want to hear from you.