Privacy Policy
Effective date: May 25, 2026 · Version 2026-05-25
This Privacy Notice for YCJW FBA LLC (operator of the ParentWhisperservice) — referred to in this notice as “we”, “us”, or “our” — describes how and why we collect, store, use, and share (“process”) information when you use our services (“Services”), including when you:
- Visit our website at https://parentwhisper.app;
- Create a ParentWhisper account and use it to record your voice, generate bedtime stories about your child, and play those stories back; or
- Engage with us in other related ways, including any sales, marketing, or events.
Reading this notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have questions or concerns, please contact us at support@parentwhisper.app.
1.Summary of key points
This summary highlights the most important points of our Privacy Notice. Each topic is covered in full detail further down the page.
- What we collect
- — Your account email and password (or Google account), the voice recording you upload for cloning, your child's first name and age band, the concerns you ask us to address in a story, and the stories we generate for you.
- What we do not collect
- — Your child's voice. Your child's full name, address, or any other contact information. We do not knowingly collect any personal information directly from a child under 13.
- How we use it
- — To run your account, generate and play back your bedtime stories, prevent abuse, comply with the law, and improve the Service. We never sell your information, and we do not show advertising.
- Who we share with
- — Service providers that help us operate (Supabase, Stripe, OpenAI, Cartesia, ElevenLabs, Google). Each is listed by name below.
- Your rights
- — You may access, correct, download, or delete the information we hold about you at any time. If you are in California, you have additional rights under the CCPA.
- How to reach us
- — Email support@parentwhisper.app or write to YCJW FBA LLC, c/o Republic Registered Agent Inc., 3400 Cottage Way, Ste G2, Sacramento, CA 95825.
2.What information do we collect?
Information you give us directly
- Account information
- — Email address and password when you create an account directly. If you sign in with Google, we receive your name, email address, profile picture, and Google account identifier — only what Google's standard OAuth profile scope returns.
- Parent voice recording
- — An audio recording (typically 60–120 seconds long) that you submit so we can build a synthesized version of your voice. This recording is forwarded to our voice-cloning provider (Cartesia, or ElevenLabs for legacy accounts) and is not retained on our own servers after the clone is created. The resulting clone is stored under a provider-issued voice ID linked to your account.
- Child profile
- — Your child's first name (or nickname) and a coarse age band (2–3, 4–5, 6–7, or 8–10). We do not ask for your child's last name, date of birth, photo, address, or any other identifier.
- Story input
- — Short text (or a transcribed voice note) describing what is on your child's mind — for example, “scared of the dark” or “fought with her brother today.”
- Generated story content
- — The story text our language model produces from your inputs, and the audio segments we synthesize in your cloned voice. Both are stored against your account so you can play them back later.
- Settings & preferences
- — Default story language, default reading speed, child-name-in-story toggle, monthly story counter, voice slot assignments, and similar account-level settings.
- Billing information
- — When you subscribe, Stripe collects your payment card details, billing address, and tax information on our behalf. We never see or store full card numbers — Stripe returns a tokenized customer reference, which is what we keep.
- Support and feedback
- — If you email us, the contents of your message and any attachments.
Information collected automatically
- Device & log data
- — Standard server logs from your visits, including IP address, browser user agent, the pages you request, timestamps, and error traces. We retain this for 30 days for security and abuse-prevention purposes.
- Cookies
- — A small number of strictly-necessary cookies to keep you signed in and to protect form submissions against cross-site request forgery (CSRF). See the Cookies section below.
- Usage events
- — Coarse counters such as “stories generated this month” that we use to enforce your subscription's monthly quota.
Sensitive information we deliberately do not collect
- Your child’s voice or any audio recorded by or about your child.
- Government identifiers (SSN, driver’s license, passport), biometric identifiers other than your own voice clone, health information, precise geolocation, or background-check data.
- Information from a person whom we have actual knowledge is under 13 years of age — see our COPPA Disclosure for details.
3.How do we process your information?
We process your information to:
- Create and manage your account — authenticate you, store your settings, and let you sign in across devices.
- Provide our core service — record and clone your voice, generate personalized bedtime stories from your inputs, synthesize those stories in your cloned voice, and play them back.
- Process payments — bill you for your subscription via Stripe and provide invoices.
- Enforce abuse and safety limits — screen story prompts for content that should not be turned into a story (for example, indications of self-harm or abuse) and route to appropriate referrals; enforce the monthly story quota included with your subscription.
- Comply with law — respond to lawful requests from courts, regulators, and law enforcement, and meet our tax and consumer-protection obligations.
- Communicate with you — send transactional messages (confirmations, password resets, trial-ending reminders), and, if you have opted in, occasional product updates.
- Improve the Service — analyze aggregate, de- identified usage patterns to understand which features parents actually use.
We will never use your information to:
- Train any third party’s general-purpose AI model.
- Profile your child for advertising.
- Sell your data to data brokers.
4.What legal bases do we rely on?
We process your information only when we have a valid legal basis to do so. Depending on the activity, we rely on one or more of:
- Consent
- — When you click “I agree” at signup, when you upload your voice recording for cloning, and when you submit a story prompt.
- Performance of a contract
- — To deliver the Service you signed up for and to bill you for it.
- Legitimate interests
- — To prevent abuse, secure our infrastructure, and analyze aggregate usage — balanced against your privacy interests, with technical and organizational safeguards in place.
- Legal obligation
- — To comply with applicable law, including tax law and COPPA.
- Vital interests
- — Where an exceptional case — such as a credible safety concern surfaced by a screening signal — requires action to protect the life or physical safety of a child.
You may withdraw consent at any time by deleting the underlying content (e.g., removing a voice slot to revoke the cloning consent, or deleting a story) or by deleting your account. See Review, update, or delete your data.
6.How do we use voice recordings?
Voice cloning is the heart of our service, so we want to be specific about how this data flows:
- What you record — when you set up a voice slot, the browser captures roughly 60–120 seconds of you reading a sample script. The audio is converted to a WAV file in your browser.
- Where it goes — the WAV file is uploaded directly from our servers to Cartesia (or, for legacy accounts, ElevenLabs). The provider trains an Instant Voice Clone model and returns a voice ID.
- What we keep — the voice ID, a label you choose (Mom, Dad, etc.), and the language you recorded in. We do not keep the raw WAV file on our servers after the clone succeeds.
- What our provider keeps— Cartesia and ElevenLabs each retain the recording and the resulting model on their infrastructure for as long as the voice ID exists in your account. When you delete a voice slot, we call the provider’s delete-voice endpoint to remove both.
- Synthesis — when we narrate a bedtime story, we send the story text and the voice ID to the same provider. The audio comes back as MP3 segments and is stored in encrypted Supabase Storage, served to your browser via short-lived signed URLs that expire automatically.
7.How do we use third-party AI providers?
ParentWhisper relies on third-party AI models to generate stories and screen prompts for safety. These providers act as our subprocessors and are listed under Sharing above.
- Story generation— short prompts (your concern text, plus your child’s first name and age band) are sent to OpenAI for English stories and to Google’s Gemini API for Korean stories. The provider returns generated text. We do not opt into any setting that would allow the provider to use this text to train their general models. Each provider’s standard enterprise agreement prohibits such training.
- Safety classification— the same concern text is passed through OpenAI’s Moderation API and through a lightweight classifier we built on top of it. This is how we detect prompts that should be referred to a hotline rather than turned into a story.
- Voice-note transcription — when you tap the microphone icon to dictate a concern, the audio is sent to OpenAI Whisper for transcription. The original audio is discarded after transcription succeeds.
- Speech synthesis — see Voice cloning above.
10.How long do we keep your information?
- Account
- — Until the parent deletes their account.
- Voice clone
- — Until the parent re-records (replaced) or deletes the voice slot. The voice clone is hosted with the synthesis provider; deleting the slot triggers an API call to remove it.
- Voice sample (raw recording)
- — The original ~90-second voice recording is uploaded to the synthesis provider during cloning. We do not retain a copy on our own servers after the clone succeeds.
- Stories
- — Until the parent deletes the story. Each story's audio segments live in encrypted Supabase Storage and are served via short-lived signed URLs.
- Child profile / concern text
- — The first name and age band of the child are stored on the children record. Concern text is stored on each story record. Both are deleted with the account or with the individual story.
- Server logs
- — Server logs that may contain a parent's user-id and request metadata are retained for 30 days for security and abuse-prevention purposes, then automatically rotated out.
- Billing records
- — Billing records (invoices, subscription history) are retained by Stripe for the period required by U.S. tax and financial-record regulations (currently 7 years).
When the retention period for a category lapses, we delete the data or anonymise it so it can no longer be associated with you or your child.
11.How do we keep your information safe?
We implement organisational and technical safeguards designed to protect your information, including:
- TLS (HTTPS) for all traffic between your browser, our servers, and our subprocessors.
- Encryption at rest for the database (Supabase Postgres) and for audio files (Supabase Storage).
- Row-level security policies in the database that restrict every parent to only their own rows — even our own server-side code must authenticate as that parent to access their data.
- Short-lived signed URLs for audio playback (no public buckets, no permanent URLs).
- Least-privilege access for our team. Administrative actions are logged.
- Strict separation between billing data (held by Stripe) and application data (held by us).
No system is perfectly secure. If a breach occurs that affects your information, we will notify you and the appropriate authorities as required by applicable law.
12.Information from minors (COPPA)
ParentWhisper is operated by adults, for adults. The Service is offered only to users who are at least 18 years old. We do not knowingly collect personal information directly from any user under 13 years of age.
We do, however, process limited information about children — specifically, the child’s first name (or nickname) and age band that a parent provides, and any concerns the parent describes — so we can generate personalised bedtime stories. Under the Children’s Online Privacy Protection Act (COPPA), this is treated as personal information of a child collected with verifiable parental consent. By providing this information to us, you confirm that you are the parent or legal guardian of the child described.
Our complete COPPA disclosure — including the categories of children’s information we collect, how we use it, and the controls available to parents — is published at https://parentwhisper.app/coppa.
13.Your privacy rights
Depending on where you live, you may have one or more of the following rights regarding the personal information we hold about you:
- Access — request a copy of the personal information we hold about you.
- Correction — request that we correct any inaccurate or incomplete information.
- Deletion — request that we delete your account and all associated personal information.
- Portability — receive an export of your data in a structured, commonly used, machine-readable format.
- Restriction — request that we limit the processing of your information in certain circumstances.
- Objection — object to certain processing activities, including processing based on legitimate interests.
- Withdraw consent — withdraw consent at any time where we are processing on the basis of consent.
- Lodge a complaint — complain to your local data-protection authority.
To exercise any of these rights, email support@parentwhisper.app. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.
14.Controls for Do-Not-Track features
Most web browsers and some mobile operating systems include a Do-Not-Track (“DNT”) feature. Because no industry standard for honouring DNT signals has been finalised, we do not currently respond to them. That said, we do not engage in any cross-site tracking, so the practical effect is the same: we do not track you across other websites.
15.California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your personal information.
Categories we collect
- Identifiers — email address, account identifier, IP address.
- Customer records — name (if you provide it via Google sign-in), billing details (held by Stripe).
- Internet activity — pages requested, features used.
- Audio data — your voice recording for the purpose of cloning your voice.
- Inferences — none. We do not build profiles or infer characteristics from your data.
Sources
All categories above are collected directly from you, except IP address and request metadata which are collected automatically by our servers when you use the Service.
Sale / sharing
We do not sell personal information, and we do not share personal information for cross- context behavioural advertising, as those terms are defined under the CCPA. We have not done so in the preceding 12 months.
Your CCPA rights
- Right to know what we collect and how we use it.
- Right to delete your personal information.
- Right to correct inaccurate personal information.
- Right to opt out of sale/sharing (n/a — we do neither).
- Right to non-discrimination for exercising your rights.
- Right to limit use of sensitive personal information (n/a — we use your voice recording only for the cloning purpose you authorised).
To exercise these rights, email support@parentwhisper.app. You may also designate an authorised agent to make a request on your behalf; we will require written authorisation and may verify the agent’s identity.
16.Updates to this notice
We may update this notice from time to time. When we do, we will change the “Effective date” at the top of this page and, if the changes are material, we will notify you by email (to the address associated with your account) and ask you to re-accept the updated notice the next time you sign in. Older versions are available on request.
17.How to contact us
If you have questions or comments about this notice, you may:
- Email us at support@parentwhisper.app; or
- Write to us at: YCJW FBA LLC, Attn: Privacy, c/o Republic Registered Agent Inc., 3400 Cottage Way, Ste G2, Sacramento, CA 95825.
For data-protection inquiries specifically, our point of contact is reachable at support@parentwhisper.app.
18.How can you review, update, or delete the data we collect from you?
Most of your data is editable from inside the app:
- Account — change your email, password, and communication preferences in Settings. Delete your account from the same page.
- Child profile— edit or delete your child’s first name and age band from Settings.
- Voice clones — re-record, replace, or delete any voice slot from Voice setup. Deleting a slot calls our provider’s delete-voice endpoint to remove the clone on their side as well.
- Stories — delete any individual story (text + audio) from your Library.
- Data export — request a copy of everything we hold about you by emailing support@parentwhisper.app.
When you delete your account, we delete the rows we hold for you and call our subprocessors to delete the corresponding records on their side. Some information may be retained where law requires (billing records, in particular, are subject to the 7-year retention described above).
9.Social logins (Google)
If you choose to register or sign in with Google, we receive the information that Google’s standard OAuth profile scope returns to us — your email, your display name, your profile picture URL, and a Google account identifier we use to recognise you on subsequent sign-ins.
We do not request, and Google does not share, any additional information unless you grant additional scopes. We use this information only to create and manage your account. You can disconnect the link at any time from your Google account’s security settings.