← Back

Privacy Policy

Effective July 31, 2026 · Black and Yellow Enterprise LLC

Overview

We collect only what we need to run the app. We do not sell your data, we do not run ads, and there is no third-party analytics or tracking software in the app. We comply with COPPA, CCPA, and GDPR.

What We Collect

Account: your email address and a hashed password. Family: the traditions you name as your own, the ones you read as scripture rather than as culture, your family values, how wide a library you asked for, the collections on your shelf, and your time zone. Children: first name, age, reading level and bedtime length, all entered by a parent. Billing: your subscription status — Stripe holds the payment details and we never see the card. Activity: which stories were read, bookmarks, and streaks.

Sensitive Information

The traditions a family names as its own can reveal religious belief, so we treat those answers as sensitive. We ask only so that the shelf leads with the stories your family already reads at home. They are stored on the parent account, never used for advertising, never shared or sold, and you can change or clear them at any time in the app.

What We Do Not Collect

No SSNs, no full card numbers (Stripe handles payments), no GPS location, no biometrics, no advertising identifiers, and nothing collected directly from children under 13.

How We Use Data

To operate your account, deliver stories, decide what appears on your shelf, count reading streaks in your own time zone, and send transactional email such as receipts and password resets. We do not use your data for advertising or for profiling outside the app.

Children's Privacy (COPPA)

Every account is adult-controlled and every child profile is created by a parent. A child profile holds a first name, an age, a reading level and a bedtime length. It is never used for advertising. A parent can edit or remove a child profile, or delete the entire account, from Account Settings inside the app.

Data Sharing

Shared only with the service providers that run the app: Supabase (database and sign-in), Stripe (payments), and Vercel (hosting). Never sold to third parties.

Data Security

TLS/SSL encryption in transit. AES-256 at rest. Passwords hashed with bcrypt. Row-level security in database.

Your Rights

Access, correct, export, or delete your data. You can delete your account and everything stored with it from Account Settings inside the app, which also cancels an active subscription. You can also write to privacy@legendarystories.app, and we respond within 30 days.

Data Retention

Account data deleted within 30 days of account deletion. Payment records retained 7 years for tax compliance.

Contact

Privacy: privacy@legendarystories.app · Legal: legal@legendarystories.app · legendarystories.app/privacy