Toy Chest
Placeholder copy. Real legal text comes from Termly Pro and is commissioned pre-launch (PROVISIONING.md). This template scaffolds the structure; do not treat it as binding.
Legal

Privacy policy

Toy Chest’s user is the parent. The child does not log in, consent, or interact with the service. We keep the least we can about the child: a first name (optional), the month and year of birth, and an optional note about what they are working on, used only to pitch play ideas and shelves to the right age.

You are the controller of the information you enter about your child; we process it on your behalf. The service is not intended for use by children.

Birth month, never the date

Birth month and year only — deliberately NOT the full date of birth. We need to compute the child’s age in months for age-aware features; we do not need the day. This is a meaningful privacy posture and a non-negotiable design constraint.

Storing a child’s full date of birth — combined with their name, photo, family identifiers, and developmental notes — would create a richly identifying record we have no legitimate need for. Age in months is sufficient for every age-aware feature in the product. The day is information we do not collect, do not store, and cannot leak.

If a parent enters ‘May 2025,’ the app computes ‘currently 12 months’ and updates monthly. That is enough.

Who handles data for us

These companies process data on our behalf:

  • Neon (the database)
  • Cloudflare R2 (uploaded photos and book files)
  • Lemon Squeezy (billing; they are the merchant of record)
  • Anthropic (drafts descriptions and play ideas; does not train on your data)
  • Resend (email we send you)
  • Upstash Redis (rate-limit counters; no personal data)
  • Sentry (error reports)
  • PostHog (a handful of server-side product events such as “account created”; no cookies, no page tracking)
  • Vercel (hosting)
  • A print partner, only when you order a printed book

Your rights, and deleting your chest

From Settings you can export everything you have written (as a PDF and as JSON) or delete your chest. Deletion works like this: for 30 days the chest is hidden and can be restored by signing in; on the 30th day we permanently delete the household, its children, toys, notes, shelves, wishlist, uploaded photos and book files, cancel any subscription, and remove your email from our lists. If you belong to no other household, your sign-in is deleted too. Error reports and server logs age out on their own within 30 days.

You can also ask us for a copy of your data, or for its deletion, by email, under the GDPR or the CCPA.