Legal

Privacy Policy

Last updated July 4, 2026 · Effective July 4, 2026

Our commitments, in plain terms
  • We never read, store, or transmit the content of your child's AI conversations. Ever.
  • We track only which AI platforms are used, for how long, and at what time of day.
  • We never sell your data or your child's data to any third party.
  • We never use your data to train AI models — ours or anyone else's.
  • We never show your child advertising of any kind.
  • You can delete all your data at any time, and we will delete it within 7 days.
Section 1
What we collect
Plain English: We collect usage signals only — which platforms, when, and how long. Nothing about what was said.

Parent account information

When you create an account, we collect your email address, a hashed password, and your payment details (processed by Paddle — we do not store your card number). We use your email to send weekly reports and product updates. You can unsubscribe from product updates at any time.

Child profile information

You create a profile for each child with a first name and age group (6–10, 11–13, or 14–17). We do not collect a child’s email address, phone number, last name, school, location, or photo.

AI usage events

Our browser extension records usage events each time your child visits an AI platform. Each event contains:

  • A hashed (anonymous) child identifier
  • The domain of the AI platform visited (e.g. character.ai)
  • Session start timestamp and duration in seconds
  • Whether the browser tab was active or in the background
  • Device type (desktop or laptop)

That is the complete data we collect about your child. No page content. No typed text. No search queries. No conversation transcripts.

Product usage data

We collect standard product analytics — which features parents use, how often, error logs — to improve the product. This data is not associated with child profiles.

Section 2
What we never collect
Plain English: This is the list that matters most. Read it once.
Conversation content
What your child types to, or receives from, any AI platform
Screenshots or screen recordings
We never capture images of your child's screen
Keystrokes or clipboard content
We do not log what is typed anywhere on the device
Location data
We never request or infer geographic location
Biometric data
No voice, face, fingerprint, or other biometric information
Social media or messaging content
We monitor AI platforms only — not Snapchat, Instagram, TikTok, or messages
Non-AI browsing history
The extension only activates on AI platform domains
Child's email, phone, or full name
Child profiles contain only a first name and age group
Section 3
How we use data
Plain English: Your data powers your weekly report. That's the primary use. Everything else is secondary.

Usage events collected from your child’s devices are used to:

  • Generate your weekly digest email showing AI usage by platform and time of day
  • Detect behavioral patterns (e.g. late-night usage, homework displacement, emotional support frequency) and explain what they may mean
  • Send real-time alerts when a new AI platform is accessed for the first time
  • Identify potential crisis signals and direct you to appropriate resources

Your parent account data (email) is used to send your weekly report, notify you of alerts, and send occasional product updates (you can opt out of product updates at any time from your account settings).

We do not use your data or your child’s data to train any machine learning models, build advertising profiles, or make automated decisions that have legal or similarly significant effects on you or your child.

Section 4
Children's privacy (COPPA)
Plain English: Parents are always the account holders. Children under 13 are covered by COPPA. We comply strictly.
COPPA Compliance

The Children’s Online Privacy Protection Act (COPPA), as amended effective June 23, 2025, requires us to obtain verifiable parental consent before collecting personal information from children under 13. Our product is designed so that the parent — not the child — is always the account holder. All child data flows through the parent’s account, and a parent creates and controls every child profile. This satisfies COPPA’s consent requirement.

What this means in practice

A child never creates their own account. A parent sets up every child profile, and — if a parent chooses to enable it — creates a Family Code and PIN their child uses to sign into their own view of the app. That view lets a child add a short note (an emoji and up to 200 characters) to their own usage, confirm their weekly report, set a personal usage goal, or let their parent know they’d like to talk. This is a real, if narrow, collection of information directly from a child, and we treat it accordingly:

  • Enabling a child’s own login is an affirmative choice a parent makes, on top of the account-level consent already given when the parent’s account was created.
  • Everything a child submits — notes, goals, weekly confirmations, the “I want to talk” flag — is visible to the parent’s account by design. Nothing a child writes is ever hidden from the parent who owns the family, and a parent can delete any of it at any time.
  • Note text is capped at 200 characters, and the app warns (without blocking) a child if their note looks like it contains a phone number or email address.
  • We do not use anything a child writes for advertising, profiling, or AI training, for any child regardless of age.

The 2025 COPPA amendments

The updated COPPA rule (effective June 23, 2025) added specific requirements for AI training data. We comply: we do not use data associated with child profiles to train any AI model, and we do not share child usage data with any third party that would use it for AI training. This applies to all children, not only those under 13.

Transparency with your child

During onboarding, we prompt parents to tell their child that the extension is installed and what it monitors. We provide age-appropriate language for that conversation. We believe monitoring done transparently is healthier for the parent-child relationship than covert surveillance, and we have designed the product accordingly.

Section 5
Data sharing
Plain English: We do not sell data. We share only with infrastructure providers who process data on our behalf, under strict contracts.

We do not sell personal information. We do not share personal information with advertisers, data brokers, or any third party for marketing purposes.

Infrastructure providers

We use the following service providers, each processing data only on our documented instructions:

  • Supabase — database and authentication hosting (US East region)
  • Paddle — payment processing and merchant of record. Paddle is the data controller for payment card information and billing tax details; we do not store your card number.
  • Resend — transactional email delivery (weekly digests, alerts)
  • Sentry — error logging for the browser extension and dashboard. Error logs do not contain child usage event data.

Legal requirements

We will disclose information if required by law, court order, or to protect the rights and safety of our users or the public. We will notify you of any such request, to the extent permitted by law, before responding.

Business transfers

In the event Lenerin is acquired or merges with another company, your data would transfer to the acquiring entity. We will notify you before any such transfer and ensure the acquiring entity is bound by commitments materially equivalent to this policy. If you do not accept the new terms, you will be able to delete your account and data before the transfer takes effect.

Section 6
Data retention
Plain English: Usage events are kept for 12 months so you can see trends. After that, they are deleted automatically.

Child usage events

Usage events are retained for 12 months from collection, then permanently deleted. You can trigger deletion earlier at any time from your account settings.

Parent account data

Your account information is retained for as long as your account is active. When you delete your account, all associated data — including all child profiles and usage events — is permanently deleted within 7 days.

Backups

We maintain encrypted database backups for up to 30 days. After you delete your account, your data may persist in backups for up to 30 additional days before being purged from backup storage.

Section 7
Security
Plain English: Standard encryption everywhere. We take this seriously because our users are children.

All data is encrypted in transit using TLS 1.3. All data is encrypted at rest using AES-256. Access to production systems is restricted to engineering personnel, protected by multi-factor authentication, and logged.

Usage events transmitted by the browser extension do not include any personally identifiable information — only a hashed child identifier that cannot be reversed to a real name without access to your parent account.

We conduct security reviews before each major release. If you discover a security vulnerability, please report it to security@lenerin.com. We will respond within 48 hours and credit responsible disclosures.

No method of data transmission or storage is 100% secure. In the event of a data breach that affects your account, we will notify you within 72 hours of discovery, as required by applicable law.

Section 8
Your rights
Plain English: Access, correct, export, or delete your data at any time. We respond within 30 days.

You have the right to:

  • Access: Request a copy of all data we hold about you and your child profiles
  • Correct: Update or correct inaccurate information in your account
  • Delete: Permanently delete your account and all associated data
  • Export: Receive your usage data in a portable format (JSON or CSV)
  • Object: Object to specific processing of your data
  • Withdraw consent: Cancel your subscription and close your account at any time

Most of these actions are available directly from your account settings. For requests that require our assistance, email privacy@lenerin.com. We will respond within 30 days.

EU and UK residents

If you are located in the European Union or United Kingdom, you have additional rights under the GDPR and UK GDPR, including the right to lodge a complaint with your local data protection authority. Our legal basis for processing your personal data is performance of a contract (providing the service you signed up for). We offer an EU data residency option on request.

California residents

Under the California Consumer Privacy Act (CCPA), you have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information. To exercise your rights, email privacy@lenerin.com.

Questions about this policy?

Email us at privacy@lenerin.com. We read every message and respond within 2 business days. For urgent matters related to your child’s safety, include “urgent” in your subject line.

Lenerin · Privacy Policy · Last updated July 4, 2026