Privacy policy
What Lamplight collects, which companies receive it, how long we keep it, and how you delete it.
1. The short version
- You, the parent or guardian, hold the account. Children do not have accounts and never enter anything into the app.
- To make a story we send some of what you enter to two companies that work for us: Anthropic writes the story text, and Inworld makes the voice copy and the audio. Each receives only what it needs, listed below.
- We do not sell your information, show ads, or use third-party analytics or tracking tools.
- Your voice recording and voice copy are deleted when you delete the voice or the account, and on a published schedule if the account goes quiet.
- You can export or delete everything from Settings in the app, at any time.
2. What we collect
About you, the account holder
- Sign-in details: your email address, or the identifier Apple or Google gives us when you sign in with them.
- The date and time you confirmed you are 18 or older, and the date and time you agreed to the data permission screen that names our AI vendors.
- Your plan (free, Plus, or Pro), your story credits, and a ledger of how credits were granted and used.
- If you allow notifications, a device push token so the app can tell you when audio is ready. [confirm: the app currently uses local notifications only; the push token field exists in the database but is unused]
About your child, entered by you
- A nickname and an age band (2 to 3, 4 to 5, 6 to 8, or 9 and up).
- Likes, things to leave out of stories, and the usual story length.
- People, pets, and toys who may appear in stories, each with a name and a relation (for example "Grandmother" or "Stuffed rabbit").
- What the child is working on: up to two topics from a fixed menu or written by you, and an optional "today" note for tonight's story.
Do not enter last names, school names, or addresses in free-text fields. The app asks you not to, and it also scrubs known names, street addresses, and school names from free text before anything is sent to the story model.
Your voice
- A recording of you reading a short passage (about 30 seconds), used to make a voice copy.
- A separate recording of you saying your name and your permission out loud (the spoken consent line).
- The voice copy itself, which is made and held by Inworld and referenced by an identifier in our database.
- A consent record: the name you gave for the voice owner, the version of the voice release you agreed to, and the date.
Voice recordings and voice copies are treated as biometric identifiers (voiceprints) under the laws of several states. See section 8 and the voice release.
Stories
- Each story's title, summary, text, parent note, and audio file, plus which child and voice it was made for, its length, whether you marked it a favorite, and the model and voice provider used.
- Reports you send about a story: the reason, your note, and a snapshot of the story text so the report can be read after the story is deleted.
What we do not collect
- Nothing from the child. There is no child account, no microphone use while a story plays, no input during listening, and no tracking of listening.
- No location, contacts, photos, or advertising identifiers.
- No third-party analytics or tracking software. The counts we need to run the business come from our own database.
- The microphone is used only on the voice recording screen.
3. Who receives what
We use a small number of companies to run the app. Each receives only what is listed here.
| Company | What it does | What it receives |
|---|---|---|
| Anthropic | Writes and reviews the story text (the Claude models, through Anthropic's API). | Your child's age band, likes, leave-outs, the topic being worked on, and any today note or custom topic text. It does not receive your child's nickname or the names of people, pets, or toys: each is swapped for a placeholder before sending and put back afterwards. It does not receive your voice. |
| Inworld | Makes the voice copy and turns story text into audio. | Your voice recording, and the finished story text, which includes the nickname and names you entered because the voice has to say them. Inworld stores the voice copy until we delete it. What Inworld may do with the voice sample beyond making the copy: [confirm: the spec notes Inworld's voice license covers improving its services, from a secondary source, and that zero retention is a paid add-on; verify on Inworld's current terms and state it here in plain words] |
| Supabase | Hosts our database, file storage, and server functions. | Everything in section 2, stored in a private project in the United States (us-east-1). Audio files sit in private storage reached only through short-lived signed links. |
| RevenueCat | Tracks subscription status across Apple and Google. | An app user identifier and purchase and subscription events from the App Store or Google Play. It does not receive child profiles, voice, or stories. [confirm the identifier used and whether it is tied to your email] |
| Apple and Google | Handle sign-in (if you choose it) and all payments. | Payment details stay with Apple or Google. We never see your card. |
| Expo | Builds the app and can deliver push notifications. | A push token, if push notifications are enabled. [confirm: unused until the app stores push tokens] |
| Vercel | Hosts this website. | Ordinary web server request logs for this site. The app's data does not pass through this site. |
We do not sell personal information, and we do not share it with anyone else except as required by law. [confirm wording on legal requests and any business transfer clause]
4. How we use it
- To write a story for your child and read it in the voice you recorded.
- To keep your library, favorites, and offline copies working.
- To manage your plan and credits.
- To review reports about stories and improve the safety rules the story model follows. Reports are read by a person.
- To answer support requests.
We do not use your voice, your child's profile, or your stories to train AI models, and we do not use them for advertising.
5. How long we keep it
This is the retention schedule the app enforces.
| Data | Kept until |
|---|---|
| Voice recording and voice copy | You delete the voice or the account. Also deleted automatically after 90 days without a story on a free account, or 12 months after a paid plan lapses. You can record again at any time. |
| Spoken consent recording | Deleted with the voice. |
| Consent record (owner name, release version, date; no audio) | 3 years after the voice or account is deleted, as our record that permission was given. |
| Today notes | 30 days. |
| Stories, audio, child profiles, topics | You delete them or the account. |
| Report snapshots | Kept after the story is deleted so the report can be reviewed. If you delete the account, the snapshot is unlinked from any account identifier. [confirm a time limit for report snapshots; the spec sets none] |
| Deletion log | A record that a deletion ran, with no personal data in it. |
| Account and sign-in details | You delete the account. |
6. Your choices
- Export. Settings, Export my data. You get a file with your child profiles, topics, and story text.
- Delete a voice. Voices, then delete. This removes the recording and the voice copy from our systems and from Inworld.
- Delete a story or a child profile. From the library or the profile screen.
- Delete everything. Settings, Delete everything. Details are on the delete account page, including how to ask by email.
- Report a story. From the player. You can ask for the story to be removed from your library at the same time.
- Notifications. Controlled in your phone's settings.
Residents of some states have additional rights to access, correct, or delete personal information, and to know whether it is sold or shared. We do not sell or share it. To exercise any right, email brian@emptybar.llc from the address on your account. [confirm which state privacy laws apply at launch and the response timeline]
7. Security
- Every database table is protected so that an account can only read and write its own rows.
- Audio and voice recordings are in private storage and are reached through signed links that expire.
- The story model never sees real names; they are swapped for placeholders before sending.
- The voice copy at Inworld is labelled with an opaque identifier, not a name.
- Vendor API keys are held on the server, never in the app.
8. Voice recordings and state biometric laws
A voice recording used to make a voice copy is a biometric identifier (a voiceprint) under laws in Illinois, Texas, Washington, and other states. Before we capture one, the app shows the voice release on its own screen and records your written agreement (a checkbox, with the release version and date stored) and your spoken agreement (the consent line at the start of the recording).
- We use the voiceprint only to read stories inside your account.
- We never sell, lease, or trade it, and no one outside your account can use it.
- We keep it only as long as the schedule in section 5 says, which is within one year of the purpose ending in every case, and we destroy it on request at any time.
- Another person's voice may be added only when that person reads and agrees to the release themselves and records the consent line on your phone. No audio files can be uploaded. No one under 18 may be recorded.
[confirm: Illinois statute text was not verified in the spec's research; a lawyer should confirm this section meets BIPA's written-release and public-retention-policy requirements, or decide whether to block Illinois at signup]
9. Children
Lamplight is for adults. We do not knowingly collect information from anyone under 18, and children do not use the app. The information you enter about your child is given by you, the parent or guardian, and is handled as described on the children page.
10. Changes
When this policy changes, the effective date at the top changes with it, and the app will ask you to review it again if the change affects what we collect or share. [confirm how changes are announced]
11. Contact
Empty Bar LLC
18202 Minnetonka Boulevard
Deephaven, MN 55391
Legal and privacy: brian@emptybar.llc
Support: support@emptybar.app