ChildScribe
Data & Security

Your family's stories are safe with us.

ChildScribe holds some of the most personal data a family can share -- conversations about their children, in their own words. We built our security around a simple principle: treat every family's data the way we'd want ours treated.

Encrypted everywhere

TLS 1.2+ encrypts every byte that travels between your device and our servers. Every request is scoped to your account — your stories are yours alone.

We never store your audio

Voice interviews are transcribed in real time over an encrypted connection. We keep the text transcript — your raw audio is never saved on our servers.

Zero data selling

We do not sell, rent, or share your family's data with advertisers, data brokers, or AI training pipelines. No third-party analytics trackers, either.

You own everything

Download your journal entries and original photos in a single export at any time, plus every memory book you've purchased. Delete your account right from settings.

Encryption

How we protect your data

Every piece of family data in ChildScribe is encrypted while it travels between your device and our servers using TLS 1.2+ — the same transport encryption standard used by banks and healthcare systems.

Access to stored data is scoped at the application layer: every request is authorized against your account, so no one outside your family — including other ChildScribe users — can read your entries, transcripts, or photos.

Authentication is handled through Laravel's session-based system for the web app, with short-lived tokens for active interview sessions that expire automatically. We enforce secure password requirements and support password reset flows that verify identity before granting access.

Voice & audio

Your voice becomes text — we keep the text

When you have a ChildScribe conversation, your voice streams over an encrypted connection to OpenAI's realtime speech service, which transcribes your words and speaks the interviewer's replies. The audio exists only to power that live conversation — it is never uploaded to or stored on ChildScribe's servers.

Each interview session is authorized with a short-lived, single-session credential that expires automatically. What ChildScribe keeps from the conversation is the text transcript — the words, not a recording.

Because we never store audio, there is no recording of your voice sitting in a database anywhere in ChildScribe. Transcripts and the journal entries generated from them are what persist, protected by the encryption and access controls described above.

AI processing

How AI helps write your stories

Two AI providers power ChildScribe, each with a narrow job. OpenAI's realtime API runs the live voice interview — it transcribes your speech and generates the interviewer's spoken replies. Anthropic's Claude API turns finished transcripts into journal entries, chapters, and memory books.

Both providers' commercial API terms prohibit using customer data to train their models. Your family's conversations are processed to deliver the product, not learned from.

No AI company beyond these two receives your family's conversations, and the infrastructure that hosts and processes them is limited to the providers in our privacy policy. The full list of service providers we use, and what each one sees, is in our privacy policy.

Payment security

Your payment details never touch our servers

All payment processing is handled by Stripe, which is PCI DSS Level 1 certified -- the highest level of payment security certification available. When you enter your card details, they go directly to Stripe's servers. We never see, store, or have access to your full card number.

Stripe handles fraud detection, dispute resolution, and compliance with payment security regulations. Your billing information is completely isolated from your family's interview data -- they live in separate systems with no connection between them.

Data ownership

Your data is yours. Full stop.

You can export your ChildScribe data at any time: a single ZIP containing your journal entries and children's profiles as structured JSON alongside the photos from your journal. Memory books you've purchased download separately as print-ready PDFs. Everything arrives in open formats you can read, archive, or import into other services.

If you decide to leave ChildScribe, you can delete your account directly from your settings page — a password confirmation is the only step. Deletion is real and permanent -- your data is removed from our active database, and backup copies expire within 30 days. We do not keep shadow copies or anonymized versions of your content.

There is no lock-in. We believe that if we make something good enough, you'll want to stay. And if you don't, your stories should leave with you.

Infrastructure

Where your data lives

ChildScribe runs on US-based infrastructure. Our servers, databases, and backups are all hosted within the United States. We do not transfer family data to servers in other countries.

We host with established cloud providers — DigitalOcean for the application and database, Fly.io for the AI engine — and restrict production access to a small number of authorized people.

We keep all server software, dependencies, and libraries up to date, and every change to the product is version-controlled and runs through an automated test suite.

Incident response

What happens if something goes wrong

No company can guarantee that a security incident will never happen. What we can guarantee is how we'd respond. If we ever discover unauthorized access to family data, here is exactly what we will do:

We will notify affected families within 72 hours of confirming the incident, with a clear explanation of what happened, what data was involved, and what we're doing about it. We will not hide behind vague corporate language or delay notification to protect our reputation.

We will engage independent security experts to investigate the root cause, implement fixes, and verify that the vulnerability is closed. We will publish a transparent post-incident report once the investigation is complete.

Security questions or concerns?

If you've found a vulnerability, have a question about how we handle data, or just want to understand our practices better, we want to hear from you.

support@legacyscribegroup.com

Responsible disclosure is welcome. If you discover a security issue, please contact us privately before disclosing it publicly. We commit to acknowledging your report within 48 hours and working with you to resolve it.

Legacy Scribe Group LLC · Last updated May 2026