Privacy Policy

Last updated: May 1, 2026

LearnManager helps parents and guardians set up learning activities for children. This policy explains what we collect, why we collect it, how we share it, and how parents can access or delete it.

Who Uses LearnManager

LearnManager is parent-led. Children do not create accounts, provide contact information, or manage billing. A parent or guardian creates the family setup, provides child learning context, assigns activities, and controls deletion.

Information We Collect

  • Account and identity data: A Supabase anonymous user ID is created when you start using the app. If you claim the account with Sign in with Apple, we may receive your Apple account identifier, email address, and name if Apple shares them.
  • Child profile data: Parents provide a child first name or nickname, declared age or age band, optional interests, selected learning goals, and parent-friendly goal level answers. We do not ask children to create accounts.
  • Learning activity data: We store assigned activities, generated activity content, activity progress, completion status, answer results, and activity usage needed to show progress and prepare future learning work.
  • Generation inputs: When a parent requests generated content, we process the parent prompt, selected goal metadata, child nickname, declared age, interests, learning history summaries, and uploaded media only when the parent explicitly attaches it.
  • Support data: If you contact support or use in-app feedback, we collect the message, optional email address, optional screenshot, diagnostic ID, app version, and authenticated user ID.
  • Technical data: We process device type, operating system, app version, IP address via Cloudflare, security logs, crash reports, performance diagnostics, and other diagnostic data needed to run and protect the service.
  • Billing data: Stripe processes payment method details. LearnManager stores Stripe customer, subscription, checkout, invoice, and entitlement records needed to manage paid access and cancellations.

The v1 iOS TestFlight build does not request App Tracking Transparency permission, does not access IDFA, and does not register push notification tokens. Production push notifications are disabled for v1.

How We Use Information

  • Create and maintain anonymous or claimed parent accounts.
  • Prepare age-aware reading and early math activities.
  • Let parents assign, play, save, remix, and review activities.
  • Track progress needed for parent-visible learning history.
  • Operate billing, quota, account recovery, and deletion flows.
  • Respond to support requests and diagnose product issues.
  • Detect abuse, protect the service, and comply with law.

We do not sell personal information, do not share child data with advertisers, and do not use child data for behavioral advertising.

AI Processing

LearnManager uses Anthropic Claude through our Cloudflare and Supabase backend to generate and review learning activities. Only fields needed for the requested activity are sent for generation: child nickname, declared age or age band, interests, selected goal template, parent-friendly level, parent prompt, learning history summaries, and uploaded media only when the parent attaches it.

We do not send parent email, Apple ID, billing data, Stripe IDs, support messages, raw analytics identifiers, exact birth dates, or unrelated child profile fields to the generation provider.

Service Providers

We share data with service providers that process it for us under contractual confidentiality and security obligations.

ProviderPurposeDataLocation
SupabaseAuthentication, PostgreSQL database, Edge Functions, and storageAccount IDs, profiles, child records, goals, activities, support rows, and app dataUnited States, AWS us-east-1
CloudflareWorkers, generated activity runtime, public activity pages, edge security, and IP routingActivity requests, generated web activity files, IP address, and operational logsGlobal edge network
AnthropicClaude activity generation and child-safety reviewLimited generation inputs and generated outputs described in this policyUnited States
SentryCrash reporting and performance diagnosticsCrash, performance, app version, device, and scrubbed diagnostic contextUnited States / global processing
StripeCheckout, subscriptions, invoices, tax, and payment supportParent billing and subscription records; Stripe does not receive child learning profiles from usUnited States / global processing

PostHog product analytics are disabled for the v1 iOS TestFlight build. If we enable product analytics later, we will keep child names, parent emails, raw IDs, prompt text, answer text, billing identifiers, support bodies, and tokens out of analytics payloads.

Children's Privacy

We comply with the Children's Online Privacy Protection Act (COPPA) and applicable child privacy laws. Parents provide consent by setting up a child profile and confirming they are allowed to manage learning activities for that child. Parents can review, correct, or delete child data by using in-app settings or by contacting us.

We do not knowingly collect contact information directly from children under 13, do not let children create accounts, do not show behavioral ads, and do not sell or share child information with advertisers.

Retention and Deletion

  • Anonymous and claimed account records are kept until account deletion or as needed for support, security, and legal duties.
  • Child profiles, goals, assignments, activity history, generated activities, and uploaded media are deleted or de-identified when the parent deletes the account, except records we must retain for legal, tax, fraud-prevention, or audit reasons.
  • Active Stripe subscriptions are cancelled immediately during server-backed account deletion. Payment and tax records may be retained by Stripe and by us as required by law, typically up to seven years.
  • Support requests are redacted or retained only as needed to investigate issues, maintain safety, and comply with legal duties.
  • Diagnostic and security logs are kept only as long as needed to operate, debug, secure, and improve the service.

Your Rights

Depending on where you live, including under GDPR and California privacy laws, you may have these rights:

  • Access a copy of personal data we hold about you or your child profile.
  • Correct inaccurate account, child profile, or support information.
  • Delete your account in the app or ask us to delete child data.
  • Request a portable export of personal data where legally required.
  • Object to or restrict certain processing where legally required.
  • Appeal or contact us about California, GDPR, COPPA, or GDPR-K rights.

To exercise these rights, use the account deletion flow in the app or contact privacy@learnmanager.ai. We may need to verify your identity before fulfilling a request.

Security

We use HTTPS, database access controls, row-level security, least-privilege service keys, private storage controls, monitoring, and deletion workflows designed to protect family learning data. No online service can guarantee perfect security, but we work to reduce risk and respond quickly to issues.

International Transfers

LearnManager and our providers may process data in the United States and other countries where our providers operate. Where required, we rely on appropriate contractual safeguards for international transfers.

Changes

We may update this policy as the product changes. If a change is material, we will provide notice in the app, by email when available, or on this page before the change takes effect where required.

Contact

Privacy requests: privacy@learnmanager.ai

General support: support@learnmanager.ai