Privacy Policy
At Project Legacy, protecting your family’s privacy is our highest priority. We handle information about children and adults in a household, and voice recordings. This policy describes what we actually collect, where it is stored, and who can reach it.
Current status: Project Legacy is available through the App Store and Google Play. Some of the protections described below are already built; others are commitments we are still implementing. Where that distinction matters, we state it plainly rather than describing a planned safeguard as though it were finished.
1. The Data We Collect
To provide personalized guidance and educator video sessions through the legacy-mobile-app and legacy-facility-app, we collect:
- Account Information: Parent/Guardian name, email, phone number, and billing details.
- Child Profiles: Your child’s name, date of birth, and dysregulation patterns, provided by you as the parent or guardian with your consent at registration. Correction (August 28, 2026): an earlier version of this policy said we do not store a child’s legal full name. That was inaccurate — the quantitative-analysis engine that personalizes guidance derives its values from the full name and date of birth you provide, so we do collect and store them. We have corrected the claim rather than leave it standing. The app’s interface displays a short name of your choosing. We do not collect government-issued IDs or Social Security numbers for any child. See our Children’s Privacy Policy for detailed child data practices.
- Names and Dates of Birth Used for Quantitative Analysis: The quantitative-analysis engine that personalizes guidance derives its values from the names and dates of birth you provide for the people in a dyad. These are used to compute the quantitative analysis and to generate guidance for your family.
- Educator Session Records: Session logs, the educator’s session notes, and behavioral friction scores.
- Content You Write or Keep: Where you edit a guidance draft (such as a monthly letter) or save words that worked for your family, that content is stored so it can be shown back to you. It is private to your household.
- Device Identifiers: Our subscription provider (RevenueCat) and payment processor (Stripe) use device identifiers on your phone — to keep your subscription state correct across reinstalls, and for payment fraud prevention. These identifiers are not used for advertising.
2. Voice Cloning Data & Acoustic Calibration
Project Legacy uses proprietary AI to generate acoustic co-regulation models from a person’s voice. Because a voice clone can say things its owner never said, we treat voice as the most sensitive category of data we hold, and we restrict it accordingly.
- Whose Consent Is Required: A voice may only be cloned with the express consent of the person whose voice it is. An account holder cannot consent on another adult’s behalf. Where a voice belongs to someone other than the account holder — for example a spouse, co-parent or partner — that person must provide their own consent before any calibration sample is used, and they may withdraw it at any time without needing the account holder’s agreement. This is enforced by the system, not only by policy: consent is recorded against the voice itself, naming the speaker and the relationship they agreed to, and audio cannot be generated in a voice that has no live consent for that relationship. Where consent is missing or has been withdrawn, the system refuses to use the voice.
- Who Can Create One: Voice cloning is available only on paid plans. Accounts on the free tier cannot calibrate or generate a cloned voice at all.
- Encryption & Storage: Baseline audio samples provided to calibrate the Voice Engine are encrypted at rest and in transit, and are stored in Google Cloud Storage inside a restricted service perimeter.
- Restricted Usage: A voice clone is used strictly and exclusively to generate personalized co-regulation and repair audio within the relationship the consenting speaker agreed to. That means audio addressed to their own child, or to a spouse or partner in a dyad they have joined. It is never used to address a person outside that relationship, never used for marketing, and never used to generate speech on a topic unrelated to co-regulation.
- Generation Records: We keep a record of every utterance generated in a person’s voice — what was said, when, and in which relationship. Any person whose voice has been cloned may request their complete generation history, and we can produce it. This record is kept even if consent is later withdrawn, so that withdrawing does not erase your ability to see what was said while it was active.
- No External Training: We never sell voice data, and we never use an acoustic signature to train public Large Language Models (LLMs) or external commercial APIs. A voice model is used only for the individual who consented to it.
- Revocation & Deletion: Consent may be withdrawn at any time, and withdrawal takes effect immediately — generation in that voice stops at once, across every relationship it was granted for. This right belongs to the speaker, independently of whose account the clone sits under, and exercising it does not require that account holder’s involvement or agreement. During closed beta, contact us to receive your revocation link; automatic delivery of that link to speakers is not yet in place.
3. Dyadic Alignment & Telemetry
As part of our NeuroSymbolic AI operations, the system tracks “dyadic alignment” — the behavioral friction scores and progress matrices between a parent and child over time.
This telemetry is stored in a managed Google Cloud SQL database inside a Google Cloud VPC Service Controls perimeter, which restricts the underlying storage, database and compute services from being reached from outside that boundary. Data is encrypted at rest and in transit, and reaching the application requires an authenticated session.
We want to be precise about what we do not do. We do not operate a separate analytics warehouse, and we do not pass your records through a de-identification pipeline — because your records are not exported to a downstream analytics system in the first place. Telemetry is stored in order to serve it back to you and to the educator assigned to your household. An earlier version of this policy described a Cloud Data Loss Prevention de-identification stage; that description did not match how the system works, and we have removed it rather than leave an inaccurate claim standing.
Quantitative-analysis and telemetry data is processed by AI models running inside our own Google Cloud project. It is not sent to third-party model providers, and it is not used to train publicly available models.
Guidance history and your educator. From August 28, 2026 onward, the system keeps a record of which guidance items were served to your household (for example, which situations you asked the guidance shelf about). This record exists so that the educator assigned to your household can prepare for a paid video session by seeing what self-serve help you have already received, instead of spending the session rediscovering it. It is visible only to you and to your household’s assigned educator — no other staff member can view it. Guidance use before that date was not recorded.
4. Data Sharing & Third-Party Infrastructure
We do not sell your personal data, and we do not share it for advertising. We share information with:
- Assigned Educators: The Resonance System Educator who runs your household’s video sessions.
- Google Cloud Platform: Hosting, database, file storage, secret management, speech synthesis, and the AI models that generate co-regulation guidance. This is where your data lives.
- Live Session Provider: Where you use a live educator video session, the audio and video are carried by Daily.co. Session media passes through their infrastructure.
- Payment and Subscription Providers: Stripe for payment processing, and RevenueCat for mobile app-store subscriptions. Card details are handled by the payment provider; we do not store card numbers.
- Legal Compliance: When legally mandated by a valid subpoena or court order.
Contractual data-protection terms with these providers, including any Business Associate Agreements required where protected health information is involved, are being reviewed and put in place as part of our path to general availability. We are not asserting that every such agreement is already executed.
5. Your Rights & Data Deletion
You may request a complete and permanent deletion of your account, voice clones, child alias profiles, and dyadic telemetry at any time by visiting our Data Deletion Portal.
If your voice has been cloned on someone else’s account — for example a partner’s — you hold these rights over your own voice model directly. You may request its deletion without needing that account holder’s involvement. As noted in section 2, the self-service path for a speaker who is not the account holder is still being built; until it ships, contact us and we will action the request.
6. Changes to This Policy
When we correct or expand this policy we update the date at the top. Where a previous version described something inaccurately, we say so in the text rather than quietly editing it out, so you can see what changed and why.