Security

Effective Date: 2026-05-29 Last Updated: 2026-07-17 2026-07-17: aligned this page's data-flow descriptions with the corrected 2026-07-16 privacy disclosures (voice processed by OpenAI/Deepgram with OpenAI's up-to-30-day abuse-monitoring window; camera/handwriting images read by Google OCR; transcript retention described as it operates today) and corrected the subprocessor-certification summary to defer to the per-vendor Subprocessor List; no change to security practices.


Trust comes first

Scout is built for children and their families. We take our responsibility to protect privacy and security seriously. This page describes — in plain English — how we think about security, what data we collect, how we protect it, and the controls available to you.

For full legal details, see our Privacy Policy and Terms of Service.


Our Privacy and Security Principles

Principle What it means
Privacy-by-design We build privacy into the product from the start. Your child's voice is processed in the moment by our speech providers (OpenAI for the conversation, Deepgram for reading transcription) and is never stored in our own cloud — OpenAI keeps it up to thirty (30) days for abuse monitoring, then deletes it. Verbatim transcripts stay on the family device (shared transiently with Anthropic for post-session analysis); our cloud stores summaries and metrics, not verbatim speech.
Data minimization We only collect data necessary to operate Lantern. We do not collect last names, addresses, phone numbers, or social media accounts of children.
Parent control Parents control everything. You can view, export, correct, delete, pause, or withdraw consent at any time through the Parent App.
Security-first engineering Industry-standard encryption, restricted access, audit logging, and SOC 2 Type II certified subprocessors.
Transparency We document what we do, what we use, and how we protect it — including this page and our subprocessor list.

What We Collect (Short Version)

The complete list is in our Privacy Policy. The summary:

From you (the parent): account email, billing info, your sworn affirmation that you're the parent.

About your child: first name, age, grade, optional context notes you choose to provide.

During sessions: voice audio (processed in the moment by OpenAI and Deepgram, never stored in our own cloud; OpenAI keeps it up to 30 days for abuse monitoring; a short reading recording stays on the device up to a day or two), camera and handwriting images (sent to Google for text recognition (OCR); camera copies stay on the device ≤7 days, handwriting copies until you request deletion), text transcripts (on the device; deleted on your request).

In the cloud: aggregated session summaries, reading scores, books read, AI-generated narratives.

We never collect: voiceprints, biometric identifiers, last names, home addresses (other than billing), phone numbers, school names, or social media accounts of children.


How We Protect Data

In transit

At rest

Access controls

Vendor security

Application security


Children's Privacy Specifics

In addition to the above:


Incident Response

If we identify a security incident affecting personal information:

  1. Triage: within 24 hours of detection
  2. Containment: as fast as is safely achievable
  3. Notification to affected families: within 72 hours of confirmed impact, by email
  4. Notification to regulators: as required by applicable law (state breach notification laws, FTC if COPPA-related)
  5. Postmortem: publicly available redacted version, within 30 days

Parent Controls

In the Parent App, you can:


Independent Verification

We do not currently hold third-party certifications. Programs we may pursue:

Subprocessor certifications are listed per vendor on the Subprocessor List.


How to Reach Us

For a vulnerability disclosure, we commit to:


Updates to this page

This page is updated as our security posture evolves. Material changes are announced via the Parent App and email.


Questions? Email privacy@lanternlearning.io. To file a complaint, contact the FTC at reportfraud.ftc.gov or your state attorney general.