Lillory Sign in

Published with the product, word for word

Privacy at a glance

We collect only a child's first name (or initials) and their learning progress. Nothing more.

We never sell data, show no ads, use no third-party trackers, and never access the microphone or camera.

You can review, correct, export, or delete your child's data, and withdraw consent, at any time.

Read the full policy below, or our retention schedule and accessibility statement.

Privacy Policy

What we collect: a child's first name or initials, a coarse age band (set by your center, e.g. Early/Upper/Teen, used only to choose age-appropriate words, not a date of birth), and learning telemetry (which activities were practiced, how they went). No date of birth, email, address, photo, voice, or location is stored on a child profile.

Why: solely to deliver the reading-intervention service and show progress to the authorized adult (tutor or parent). No other use.

No sale, no advertising, no third-party tracking, no microphone/camera/biometric capture. The only services that process data are our integral sub-processors (see the Trust page).

No AI/ML training on identifiable student data without separate written authorization.

Your rights (COPPA §312.6): review what we hold, correct it, export it, delete it, and withdraw consent, all from the Family page.

No conditioning (COPPA §312.7): a child can take part without disclosing more personal information than is reasonably necessary. We require only a first name (or initials). Nothing more is a condition of participation.

Retention: we keep data only as long as needed, then delete or de-identify it (see the Retention schedule). We do not retain any category indefinitely.

Children's privacy: this service is for children under 13 used through a school/tutoring center under a signed Data Privacy Agreement, or through a parent who provides verifiable consent.

How we obtain verifiable parental consent: on the parent-consent channel, before any cloud collection we obtain verifiable parental consent by a method reasonably designed to confirm the person consenting is the child's parent or guardian (COPPA §312.5(b)), for example a consent form the parent signs and returns, or a consent action taken from a verified parent account. The child may practice locally, collecting nothing, until consent is recorded. On the school or center channel we rely on school consent under §312.5(c)(1) together with a signed Data Privacy Agreement.

United States audience: the Service is operated from and intended for use in the United States, and we do not target it to users in other countries.

State privacy rights: a parent's own contact information may be covered by a US state privacy law, such as the California Consumer Privacy Act as amended. Where such a law applies, you may have the right to access, correct, delete, or obtain a copy of that information, and to opt out of sale, sharing, or targeted advertising. We do not sell personal information, share it for cross-context behavioral advertising, or run targeted advertising, so there is nothing to opt out of; you may exercise the other rights by contacting us. A child's personal information is governed by COPPA and the stricter protections stated above.

Data Retention & Deletion

Learner profile (first name, id): active relationship + 30 days, then deleted.

Learning telemetry (sessions, skill events, achievements): last-active + 12 months, then deleted or de-identified to non-re-linkable aggregates.

External assessment scores (when used): per the school/family DPA; default active + 24 months (BKT validation + two academic years of normed growth).

Consent records, deletion records, and the audit log: 5 years (compliance evidence).

Backups: <=30 days (point-in-time recovery configured to <=30 days), then expire.

Deletion requests are honored within 30 days and confirmed in writing; deletion cascades to all dependent records.

Accessibility

We target WCAG 2.2 AA. Touch targets are at least 40px; color is never the only cue for correctness; we honor reduced-motion preferences.

There are no timers and no time pressure anywhere in the activities.

A full self-audit and an independent third-party accessibility review are planned before district-wide procurement; a VPAT/ACR will be published here.

If you hit an accessibility barrier, contact us (below) and we will prioritize a fix.

Trust & Security (for schools & districts)

Principles: the school owns its student data; we are a custodian/processor; purpose-limited to the contracted reading-intervention service; no commercial use, no sale, no advertising.

Sub-processors: Supabase (database and auth, storing profiles + telemetry) and Vercel (hosting/CDN). Both bound to equivalent terms; listed and updated here.

Security posture: row-level security per center, encryption in transit (TLS) and at rest, a locked Content-Security-Policy (the only network destination for child data is Supabase), camera/microphone/geolocation denied at the browser level, and an append-only audit log.

Data Privacy Agreement: we sign the SDPC National DPA (NDPA) and applicable state addenda; request our DPA, WISP summary, and security documentation from the contact below.

Data rights & SLAs: export or delete on request, honored within 30 days (or the DPA timeline); deletion-on-termination per the DPA.

Retention: see the Retention schedule (identity +30d, telemetry +12mo, assessments +24mo, audit 5yr, backups <=30d).

Breach notification: we notify the district within 72 hours of determining a breach and meet the strictest applicable state timeline.

Contact: gabe@lillory.com.

Policy version: privacy-2026-06-19. Questions: gabe@lillory.com.