Privacy Policy

Last Updated: August 28, 2026

At Project Legacy, protecting your family’s privacy is our highest priority. We handle information about children and adults in a household, and voice recordings. This policy describes what we actually collect, where it is stored, and who can reach it.

Current status: Project Legacy is available through the App Store and Google Play. Some of the protections described below are already built; others are commitments we are still implementing. Where that distinction matters, we state it plainly rather than describing a planned safeguard as though it were finished.

1. The Data We Collect

To provide personalized guidance and educator video sessions through the legacy-mobile-app and legacy-facility-app, we collect:

2. Voice Cloning Data & Acoustic Calibration

Project Legacy uses proprietary AI to generate acoustic co-regulation models from a person’s voice. Because a voice clone can say things its owner never said, we treat voice as the most sensitive category of data we hold, and we restrict it accordingly.

3. Dyadic Alignment & Telemetry

As part of our NeuroSymbolic AI operations, the system tracks “dyadic alignment” — the behavioral friction scores and progress matrices between a parent and child over time.

This telemetry is stored in a managed Google Cloud SQL database inside a Google Cloud VPC Service Controls perimeter, which restricts the underlying storage, database and compute services from being reached from outside that boundary. Data is encrypted at rest and in transit, and reaching the application requires an authenticated session.

We want to be precise about what we do not do. We do not operate a separate analytics warehouse, and we do not pass your records through a de-identification pipeline — because your records are not exported to a downstream analytics system in the first place. Telemetry is stored in order to serve it back to you and to the educator assigned to your household. An earlier version of this policy described a Cloud Data Loss Prevention de-identification stage; that description did not match how the system works, and we have removed it rather than leave an inaccurate claim standing.

Quantitative-analysis and telemetry data is processed by AI models running inside our own Google Cloud project. It is not sent to third-party model providers, and it is not used to train publicly available models.

Guidance history and your educator. From August 28, 2026 onward, the system keeps a record of which guidance items were served to your household (for example, which situations you asked the guidance shelf about). This record exists so that the educator assigned to your household can prepare for a paid video session by seeing what self-serve help you have already received, instead of spending the session rediscovering it. It is visible only to you and to your household’s assigned educator — no other staff member can view it. Guidance use before that date was not recorded.

4. Data Sharing & Third-Party Infrastructure

We do not sell your personal data, and we do not share it for advertising. We share information with:

Contractual data-protection terms with these providers, including any Business Associate Agreements required where protected health information is involved, are being reviewed and put in place as part of our path to general availability. We are not asserting that every such agreement is already executed.

5. Your Rights & Data Deletion

You may request a complete and permanent deletion of your account, voice clones, child alias profiles, and dyadic telemetry at any time by visiting our Data Deletion Portal.

If your voice has been cloned on someone else’s account — for example a partner’s — you hold these rights over your own voice model directly. You may request its deletion without needing that account holder’s involvement. As noted in section 2, the self-service path for a speaker who is not the account holder is still being built; until it ships, contact us and we will action the request.

6. Changes to This Policy

When we correct or expand this policy we update the date at the top. Where a previous version described something inaccurately, we say so in the text rather than quietly editing it out, so you can see what changed and why.