Privacy Policy — Scout Learning Lab LLC
Effective Date: 2026-07-16 Last Updated: 2026-07-17 2026-07-13: editorial correction of the operator's legal name (Scout Learning Labs → Scout Learning Lab LLC); no substantive change. 2026-07-16: added disclosure of the Site's availability waitlist (email addresses submitted to the parents-and-educators waitlist, stored by our website host Netlify, Inc. — also added to the Subprocessor List); no change to children's-data practices. 2026-07-17: product name updated from Nova to Lantern throughout (branding alignment; the same product, practices unchanged), and transcript retention simplified to the operating mechanism (deleted on your deletion request); no substantive change. Policy Version: 2026-07-16
0. Preface
This Privacy Policy explains how Scout Learning Lab LLC (the "Company," "Scout," "we," "our," or "us") collects, uses, and discloses information when you (i) purchase or use Lantern, our AI tutor hardware product; (ii) use our Lantern Parent companion mobile or web application (the "Parent App"); (iii) interact with our website at lanternlearning.io (the "Site"); and (iv) communicate with our customer support (collectively, the "Products and Services").
Lantern is intended for use by children. Most of our users are under 13. This policy is written for parents and guardians. A child-readable version of the children's privacy section is available at childrens-privacy.md.
If you do not agree to this Privacy Policy, do not use the Products and Services.
By purchasing, downloading, accessing, using, or interacting with our Products and Services, you agree and expressly consent to our collection, use, and disclosure of information as described here, including information about you, your child (the "Supervised Minor"), and any additional adults you authorize to access the Products and Services through your Parent App account (each a "Permitted Adult").
1. Contact
Scout Learning Lab LLC 65 Mission Trail Rd, Woodside, CA 94062 privacy@lanternlearning.io · (310) 962-0091
For COPPA-related inquiries, data access, correction, or deletion requests: privacy@lanternlearning.io. We respond within seven (7) days for COPPA-related requests, and within thirty (30) days for all other privacy requests.
For California-specific privacy rights: see your-privacy-choices.md.
2. Modifications
We may revise this Privacy Policy from time to time. The effective date at the top of this document indicates the last revision. If we modify the policy, we will:
- Update the "Last Updated" date and the policy version stamp.
- Send you an email at the address associated with your Parent App account and/or surface an in-app notification at least thirty (30) days before the change takes effect (sooner if required by law).
- For families with active children's accounts, require re-consent through the Parent App's
Re-consentscreen before the new policy applies to data we collect after the effective date.
If we are required by applicable law to obtain renewed verifiable parental consent before continuing to use already-collected children's information under updated terms, we will pause collection until you complete the re-consent flow.
3. Personal Information We Collect
We collect the following categories of personal information.
3.1 Information you provide
- Identifiers from you (the parent or guardian): name, email address, account password, and billing information.
- Identifiers about your child: first name, age, grade level, and any context notes you choose to provide (such as interests, learning differences, or family goals).
- Verification artifacts: with the active e-signature method, a cryptographic hash of the notice text you signed against, the signing time, and your IP address (we do not retain the typed name itself). If/when we use Kids Web Services (KWS) by Epic Games, KWS collects identity verification data (face scan, government ID, credit card, or knowledge-based authentication); we never receive or store the underlying verification data — only a signed assertion that verification succeeded.
- Sworn affirmation: your statement, made through our consent wizard, that you are the parent or legal guardian of the named child.
- Communications: any content you send us via support email or other channels.
- Waitlist sign-ups: if you join the availability waitlist on our Site (the form is directed to parents and educators), we collect the email address you submit so we can send availability updates. Waitlist submissions are stored by our website host, Netlify, Inc. (see the Subprocessor List); we use them for no other purpose, you can unsubscribe at any time, and we do not knowingly retain waitlist submissions from children.
3.2 Information collected automatically from the Lantern device
- Voice audio (transient): during a session, the device streams the child's spoken audio to OpenAI's Realtime API (model gpt-realtime-2) to power the spoken conversation, and separately to Deepgram to convert speech to text for the reading assessment. OpenAI does not train on API data and retains inputs and outputs for up to thirty (30) days for abuse monitoring before deleting them (its Realtime service also holds up to about one (1) hour of audio to sustain a multi-turn conversation); Deepgram does not retain the audio after transcription. We do not retain raw voice audio in our own cloud, and we never generate a voiceprint or biometric identifier from a child's voice. During reading practice the device keeps a short local recording for same-day quality checks, deleted automatically within a day or two. (Exception: research-cohort families, see §11.)
- Camera frames (uploaded for OCR; local copy ≤7 days): the device captures camera frames of whatever the child shows it (book pages, worksheets, handwriting) and uploads them to Google for text recognition (OCR) so Lantern can read the page. A local copy stays on the device's storage for up to seven (7) days for the on-device retry/QA pipeline, then is deleted. We do not retain the frames in our own cloud.
- Reading transcripts: text transcripts of the session (what the child said + what Lantern said back) are stored on the device's local storage, never in our cloud. Deleted on your deletion request.
- Handwriting analysis: for writing-mode sessions, the device captures images of the child's handwritten work and uploads them to Google for text recognition (OCR); the resulting analysis text is sent to our cloud as part of the session summary. A local copy of the images stays on the device until deleted (an automatic cleanup job is planned but not yet running; the copies are removed when you request deletion of your child's data) and is not retained in our own cloud.
- Session summaries: AI-generated short summaries of how the session went — what topics were covered, what the child practiced, how engaged they were — are sent to our cloud and stored under your Parent App account. These summaries are aggregated metrics and narrative — they do not include verbatim child speech.
- Device telemetry: hardware model, operating system version, software version, network connectivity diagnostics, error logs, and a unique device identifier used to keep the device paired to your account.
3.3 Information collected automatically from the Parent App and Site
- Device and software information of your phone or computer (OS, browser version, screen size).
- Network information (IP address, approximate location derived from IP at the country/state level only).
- Usage information (which screens you viewed, when, how long).
- Your timezone: when you sign in to the Parent App, we detect your device's timezone (an IANA identifier such as
America/New_York) and store it on your parent account. We use it only to schedule your weekly summaries — anchoring the week's generation and the Sunday-evening notification window to your local time. You can have it corrected by emailing privacy@lanternlearning.io. - Push notification token (iOS, only if you enable notifications): a device token issued by Apple that lets us deliver the weekly summary notification to your phone. Stored until you turn notifications off (or revoke the device) or delete your account, and removed when Apple reports the token invalid.
- Cookies and similar technologies — see
cookie-policy.md.
3.4 Information from third parties
- Identity verification result from Kids Web Services (the verification yes/no, transaction ID, timestamp).
- Payment status from our payment processor (Stripe or equivalent) — confirmation that a charge succeeded, not the underlying card number.
- App store information (Apple App Store, Google Play) when you install the Parent App.
3.5 What we do NOT collect
- Last name of your child
- Home address (other than billing address for hardware purchase, used only for shipping)
- Phone number of your child
- School your child attends (unless you voluntarily mention it in context notes — we treat this as optional context)
- Social security numbers
- Social media handles or accounts
- Health, religion, or political affiliation (unless you voluntarily mention them in context notes)
3.6 Sensitive personal information
Some of the categories above qualify as "sensitive personal information" under one or more state privacy laws (CCPA/CPRA in particular):
- Voice audio (treated as biometric data even though transiently held)
- Children's personal information (everything we collect about your child)
We do not sell or share sensitive personal information for cross-context behavioral advertising. We do not use sensitive personal information for any purpose other than providing and improving the Products and Services as described in this policy.
4. How We Use Information
We use information to:
- Provide the core service: run AI tutoring sessions, track reading and writing progress, generate session summaries for the Parent App.
- Personalize the experience: Lantern adapts to your child's reading level, attention patterns, interests (as you provide them), and prior session history. Personalization is on by default; you can turn it off in the Parent App.
- Support the Parent App: show you dashboards and deliver weekly summaries — including, if you enable notifications on iOS, one weekly summary push notification (Sunday evenings, your local time), and nothing else.
- Comply with legal obligations: maintain COPPA-required consent records for seven (7) years, respond to verified parental requests, retain audit logs of consent grants and withdrawals.
- Improve safety and reliability: analyze aggregated, de-identified data to detect bugs, improve speech recognition accuracy, refine our safety guardrails (see
safety.md). - Communicate with you: transactional emails (receipts, account updates, security alerts) and, only if you opt in, marketing emails.
4.1 Improvement and AI training
We do not use children's voice audio, transcripts, session content, or images to train any AI model — neither our own model nor those of our subprocessors. Our subprocessors — OpenAI (voice conversation), Deepgram (speech-to-text), Google (image OCR), and Anthropic Claude (session analysis) — do not train their models on the data we send them: OpenAI does not train on API data by default, and the others' service terms commit them not to train on it.
Exception for research-cohort families: see §11.
5. How We Share Information
We share information with the following categories of third parties:
5.1 Subprocessors providing core service
The Products and Services rely on a small number of carefully selected vendors. Some subprocessors are used by all families; some apply only outside the friends-and-family pilot. The "In scope" column makes this explicit.
| Subprocessor | Purpose | What we share | In scope | Where |
|---|---|---|---|---|
| OpenAI (Realtime API) | Real-time conversational AI (spoken voice) | Voice audio, text prompts | All families | US |
| Google (Cloud OCR) | Text recognition (OCR) from images | Camera frames + handwritten work images | All families | US |
| Deepgram | Speech-to-text transcription for reading assessment | Voice audio (transient, deleted post-transcription) | All families | US |
| Anthropic (Claude API) | Session analysis, profile updates, reading assessment scoring | Session transcripts, aggregated metrics | All families | US |
| Supabase (Postgres + storage) | Cloud database for Parent App | Aggregated metrics, session summaries, account information | All families | US |
| Resend | Transactional email delivery (receipts, magic links, alerts) | Email content + recipient address | All families | US |
| Railway | Application hosting for the consent service, plus hosting for our weekly-summary generation job (a dedicated container that reads children's learning data across the roster to write each family's weekly summary) | Operational logs, environment configuration; children's learning data processed in the weekly generation job | All families | US |
| Apple (Apple Push Notification service) | Delivery of the optional weekly summary notification to the iOS Parent App | Device push token; notification content (your child's first name inside a fixed weekly-summary message — no summary content) | Families who enable notifications | US |
| Kids Web Services (Epic Games) | Verifiable parental consent | Parent email, location | Production only (pilot families use the typed-name e-signature — see §10.1) | US |
| Stripe (or equivalent) | Payment processing for hardware sales | Billing information, payment card data (Stripe holds; we don't see) | Hardware purchasers only (pilot families receive devices on loan; not in scope) | US |
| Sentry or equivalent | Error tracking | Error stack traces, sanitized request context | When enabled — disclosed via subprocessor change notice | US |
A more detailed and continuously-updated subprocessor list is at subprocessors.md.
None of these subprocessors are permitted to use the data we share with them to train AI models, for advertising, or for any purpose other than providing the service to us.
5.1.1 Subprocessor changes
We will notify families at least thirty (30) days before adding a new subprocessor that processes children's personal information, by email to the address on file and via the Parent App. For material changes (a subprocessor handles a new category of children's data, or processes data in a new jurisdiction), we will obtain renewed verifiable parental consent before the change applies to data collected after the effective date.
5.2 Legal disclosures
We may disclose personal information when required by law — including in response to subpoenas, court orders, or other legal process; to protect the rights, property, or safety of Scout, our users, or others; or to investigate fraud or violations of our Terms of Service.
5.3 Business transfers
If Scout is involved in a merger, acquisition, or sale of assets, personal information may be transferred. We will provide notice and, where required, obtain renewed parental consent before transferred information is used under new terms.
5.4 With your consent
We share information for any other purpose only with your explicit consent.
5.5 What we do NOT do
- We do not sell personal information.
- We do not share personal information for cross-context behavioral advertising.
- We do not rent personal information to advertisers, brokers, or analytics aggregators.
- We do not allow our subprocessors to use children's information for their own purposes.
6. Data Retention
| Category | Retention |
|---|---|
| Voice audio (transient) | Not stored in our cloud; processed by OpenAI (deleted within its up-to-30-day abuse-monitoring window) and Deepgram (not retained after transcription) |
| Reading-practice recording (on device) | Deleted automatically within a day or two |
| Camera frames | Uploaded to Google for OCR; local copy ≤ 7 days on device; not retained in our cloud |
| Handwritten work images | Uploaded to Google for OCR; local copy on device until deleted (automatic cleanup planned, not yet running; removed on deletion request); not retained in our cloud |
| Reading audio (research cohort only) | Kept on device while family is in research cohort; deletion completed by our team within 30 days of cohort withdrawal |
| Reading transcripts (on device) | On the device only; deleted on your deletion request |
| Parent account timezone | Until you delete the account |
| Push notification token (iOS, opt-in) | Until you turn notifications off, revoke the device, or delete the account; removed when Apple reports it invalid |
| Session summaries + weekly progress summaries (cloud) | ≤ 730 days from session date (target — automatic age-out planned; deleted sooner on request, within 30 days) |
| Account profile | Until you delete the account |
| Consent records | 7 years (legal retention requirement) |
| Hardware order records | 7 years (tax and warranty) |
| Email backups (transactional) | Kept as evidence of consent-related sends; a family's copies are purged when their deletion request is fulfilled |
| Operational logs (Railway, application logs) | 30 days |
| Error tracking events | 90 days |
When you delete data through the consent dashboard at https://consent.lanternlearning.io or by emailing privacy@lanternlearning.io, your request is recorded immediately and your child's profile is deactivated; we acknowledge COPPA-specific deletion requests within seven (7) days, and our team completes deletion — cloud systems and the Lantern device — within thirty (30) days, with email confirmation. The seven-year consent record retention follows Scout's records-retention policy for COPPA consent records; we retain only the minimum fields needed as evidence of consent and deletion (consent records, audit log, deletion requests, device-pairing records) — not session content or child profile data.
Backup retention. Routine encrypted backups of our cloud database may retain a copy of deleted records for up to thirty-five (35) days from deletion, after which backup copies are also purged. Backup copies are accessible only for disaster recovery; they are not used for any other purpose and are not searchable in the ordinary course of business. If a deletion request requires us to also purge backups before the standard rotation, we will honor that request — contact privacy@lanternlearning.io.
7. Security
We use industry-standard security practices to protect personal information:
- TLS 1.3 in transit, AES-256 at rest
- Encrypted storage for all on-device data (FileVault / macOS Data Protection)
- Two-factor authentication on Parent App accounts (when enabled)
- Service-role keys for Supabase access; row-level security policies for tenant isolation
- HMAC-signed webhook validation for KWS and other inbound integrations
- SOC 2 Type II certified subprocessors only (verified at vendor onboarding and annually)
- Audit logging of consent-changing actions
- Restricted access: production credentials are limited to a small number of authorized Scout engineers, and every production access is logged
For a more detailed security posture description, see security.md.
In the event of a security incident affecting personal information, we will notify affected families within seventy-two (72) hours of confirming the incident, by email to the address on file.
8. Your Rights
You have the following rights with respect to personal information about you and your child:
| Right | How to exercise |
|---|---|
| Access (see what we have) | Consent dashboard (https://consent.lanternlearning.io) → Your data → Generate export, OR email privacy@lanternlearning.io |
| Export (machine-readable copy) | Consent dashboard → Your data → Generate export → emailed as JSON + CSV |
| Correction | Email privacy@lanternlearning.io — we correct within seven (7) days |
| Deletion | Consent dashboard → Your data → Delete (our team completes deletion within 30 days, with email confirmation), OR email privacy@lanternlearning.io |
| Pause your child's profile | Consent dashboard → Your data → Pause (reversible) |
| Object to processing | Email privacy@lanternlearning.io |
| Withdraw consent for voice retention (research cohort) | Consent dashboard → Your consent → toggle off |
| Complain to a regulator | FTC (US), state AG, or relevant data protection authority |
For California-specific rights, see your-privacy-choices.md.
For European/UK rights under GDPR/UK GDPR, contact privacy@lanternlearning.io. (Note: Scout currently offers the Products and Services in the United States only.)
We respond to verifiable parental access, correction, and deletion requests within thirty (30) days (within seven (7) days for COPPA-related rights). We do not charge for the first request in any twelve-month period.
9. International Data Transfers
We currently process and store data in the United States only. If we expand to international operations, this section will be updated to describe transfer mechanisms (Standard Contractual Clauses, Adequacy Decisions, etc.) and the protections afforded to international users.
10. Children's Privacy (COPPA)
This section is required by the Children's Online Privacy Protection Act ("COPPA") and the FTC's COPPA Rule (16 CFR Part 312).
Lantern is directed to children. The categories of personal information we collect from children are listed in §3.2 above. The categories we use are limited to §4 above. The categories we disclose are limited to §5 above. The retention periods are §6 above.
A standalone, more readable Children's Privacy Notice is at childrens-privacy.md. The short-form COPPA Direct Notice required by §312.4(c) is at direct-notice-coppa.md.
10.1 Method of obtaining verifiable parental consent
We obtain verifiable parental consent using methods approved by the FTC (16 CFR §312.5(b)). As of the effective date above, the active method is a typed-name e-signature consent form completed in the consent dashboard under §312.5(b)(2)(i): we record a cryptographic hash of the exact notice text you signed against, the time, your IP address, and a record that you signed (we do not retain the typed name itself).
For wider availability we plan to use Kids Web Services (KWS) by Epic Games, which performs identity verification using face match to government-issued photo ID, a credit/debit card transaction with parent notification, or knowledge-based authentication. KWS is independently certified for COPPA compliance by the ESRB Privacy Certified Program, an FTC-approved Safe Harbor program. We will update this policy before KWS becomes the active method. The VPC method is independent of the optional research-cohort opt-in described in §11.
10.2 Parent rights under COPPA
In addition to the rights in §8 above, parents of children have specific COPPA rights:
- Review the personal information we collected from your child.
- Direct us to delete your child's personal information.
- Refuse to permit further collection or use of your child's personal information.
- Opt out of any new uses of your child's information without renewed consent.
To exercise any of these rights, email privacy@lanternlearning.io or use the Parent App's Dashboard.
10.3 Safe Harbor membership
As of the effective date above, Scout is not a member of an FTC-approved COPPA Safe Harbor program. Privacy complaints may be directed to privacy@lanternlearning.io, to the Federal Trade Commission at https://reportfraud.ftc.gov, or to your state attorney general (see §14 Dispute Resolution).
If Scout joins ESRB Privacy Certified, kidSAFE, iKeepSafe, PRIVO, Aristotle, or TRUSTe in the future, this section will be updated to name the program and include their independent dispute resolution contact.
11. Research Cohort
We invite a small group of families to participate in a research cohort that helps us improve Lantern's reading-coaching capabilities. Participation is optional and requires separate, explicit consent.
For research-cohort families:
- A copy of the child's reading-session audio is retained on the local device for research analysis.
- The audio is never sent to our cloud.
- We do not generate a voiceprint, biometric identifier, or AI training data set from the cohort recordings without separate, explicit consent.
- You may withdraw the cohort opt-in at any time from the consent dashboard at https://consent.lanternlearning.io.
- The data is kept while you are in the research cohort. Withdrawing files a deletion request; our team removes the retained recordings within thirty (30) days and confirms by email.
For full research-cohort terms, see research-cohort-addendum.md.
11.1 Internal forensic-diagnostics mode (cofounder accounts only — NEVER enabled for any consumer or cohort family)
Scout maintains an internal "forensic" diagnostic mode that, when enabled by Scout cofounders on their own accounts, uploads a complete session bundle (verbatim transcript, raw audio, camera frames, system prompt snapshot) to a separate, access-restricted Supabase storage bucket for thirty (30) days. Forensic mode is gated behind two independent feature flags (a daemon-wide setting and a per-student preference) and is intended exclusively for cofounder test sessions where intentional self-uploading of their own session data is appropriate.
Forensic mode is never enabled for any consumer family or any research-cohort family. The per-student feature flag is technically incapable of being enabled for any non-cofounder student through any user-facing surface. If you ever observe forensic mode behavior on your family's account (or have reason to suspect it), contact privacy@lanternlearning.io immediately. Scout treats unauthorized forensic-mode enablement on a consumer or cohort account as a reportable security incident.
12. AI Disclosure
Lantern uses OpenAI's real-time voice model (gpt-realtime-2) for the spoken conversation and Anthropic's Claude for session analysis, and uses Google's cloud service for text recognition (OCR) on page and handwriting images. For details on which models are used, when, what data they receive, and our policies on training and data retention with these providers, see ai-disclosure.md.
13. Third-Party Links and Content
Lantern may reference books, worksheets, online resources, or other third-party content for educational purposes. The privacy policies of those third parties govern any data you provide directly to them. We do not control and are not responsible for third-party privacy practices.
14. Dispute Resolution
For privacy-specific complaints, please first contact privacy@lanternlearning.io. If we cannot resolve your concern within thirty (30) days, you may escalate to:
- The Federal Trade Commission: https://reportfraud.ftc.gov
- Your state attorney general
If Scout joins an FTC-approved COPPA Safe Harbor program in the future (see §10.3), that program's independent dispute resolution will be added here as an additional channel.
General disputes are governed by the Terms of Service.
15. State-specific notices
In addition to COPPA, several US states have privacy laws (and increasingly, kids-specific laws) that apply to families resident in those states. The substantive Scout commitments above apply uniformly to all US families; these state notices describe additional rights and the legal bases on which Scout relies.
15.1 California (CCPA / CPRA / AADC)
California residents have additional access, deletion, correction, and opt-out rights described in your-privacy-choices.md. Scout does not "sell" or "share" (as defined in the CCPA/CPRA) any personal information, including children's information. The California Age-Appropriate Design Code Act (AADC) imposes additional design and assessment obligations for online services likely to be accessed by children; Scout treats Lantern as a service "likely to be accessed by children" and applies the AADC's high-privacy-by-default standard.
15.2 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA)
Residents of these states have rights similar to California's, including access, deletion, correction, portability, and opt-out from targeted advertising, profiling, and sale of personal data. Scout does not engage in any of those processing activities for any family. Exercise via privacy@lanternlearning.io.
15.3 Florida (Digital Bill of Rights / SB 262, and FL kids privacy law)
Florida residents have rights similar to the above. The Florida Digital Bill of Rights imposes additional restrictions on data collection from minors under 18; Scout does not collect data from teenagers in this product (Lantern is for children 4-12).
15.4 Other state kids privacy laws
Several additional states (Maryland AADC, Tennessee, Illinois, etc.) have enacted or proposed kids-specific privacy legislation. Scout monitors these regimes and will update this section as obligations crystallize. The substantive protections we provide today already exceed the floor set by most of these statutes.
15.5 How to exercise state rights
For any state right described above, email privacy@lanternlearning.io or use the Parent App's Settings → Privacy Request. Scout responds within forty-five (45) days (extendable once by 45 days where reasonably necessary), or within seven (7) days for COPPA-specific parent rights.
16. EU/UK Notice (Future)
Reserved for future expansion. Scout does not currently offer Products and Services to EU or UK residents.
17. Definitions
| Term | Meaning |
|---|---|
| "Child" | A natural person under 13 years of age. |
| "Supervised Minor" | The child whose consent you grant in the Parent App. |
| "Permitted Adult" | An additional adult you authorize to access the Parent App. |
| "Parent App" | The Scout-provided web or mobile application for parental management. |
| "Products and Services" | Lantern hardware, the Parent App, the Site, and customer support. |
| "Site" | lanternlearning.io and subdomains. |
| "Subprocessor" | A third-party service we use to provide the Products and Services. |
| "Verifiable Parental Consent" or "VPC" | Consent obtained using a method that satisfies 16 CFR §312.5(b). |
Questions? Email privacy@lanternlearning.io. To file a complaint, contact the FTC at reportfraud.ftc.gov or your state attorney general.