Privacy Policy
Last updated: July 22, 2026 ยท Policy version: 2026-07-22
The short version
MorphyLearn is used by parents to help their kids practice reading vocabulary skills. We collect deliberately little about the child using the product: a nickname and an emoji you choose, plus their in-app learning activity. We never collect a child's birthdate, photo, email address, or any free text a child writes. We never use a child's data for behavioral advertising.
Who this policy covers
MorphyLearn is a service for parents. An account is always created and controlled by a parent or guardian ("you," "the account holder"), never directly by a child. Everything below distinguishes between the account holder's own information and a child's information.
What we collect
About the parent (account holder):
- Email address and password (stored as a salted, one-way hash โ we never store your actual password)
- An optional display name
- Billing information, handled entirely by our payment processor (Stripe) โ we never see or store your card number ourselves
- Basic session and device information needed to keep your account secure (e.g. when a device is paired for kid gameplay, and when it's revoked)
About a child (kid profile):
- A nickname and an emoji the parent chooses โ never a full legal name, birthdate, photo, or the child's own email address
- In-app learning activity: which missions were played, which word parts were practiced, how accurately, and when โ the data that powers the Parent Progress Dashboard
- We never ask a child to type or submit free-form text, and we never surface anything resembling a child's own written words in any report
Automatically collected, for both:
- Timestamps of activity, device/browser information, and IP address, used for security (e.g. detecting abuse of a pairing code) and basic product analytics โ never for advertising
Why we collect it
Solely to operate the product: authenticate your account, remember your kids' profiles and progress, let a paired device play missions for the right kid, process your subscription, and show you an accurate Progress Dashboard. We do not sell personal information, and we do not use a child's data to build an advertising profile of any kind.
Third-party services
We use a small number of trusted service providers to operate MorphyLearn, each of which processes personal information only as necessary to provide their service to us:
- Stripe โ payment processing and subscription billing. Stripe never shares your full card number with us; we only receive confirmation that a payment succeeded or failed.
- Resend โ delivery of transactional email (e.g. password reset and email verification messages). Resend processes the recipient address and message content solely to deliver that email.
- Cloudflare โ domain name system (DNS), email routing, and hosting infrastructure.
As MorphyLearn grows, we may add other infrastructure providers (for example, additional cloud hosting or security-monitoring tools) that process data only as necessary to keep the product running securely โ never for their own independent advertising purposes.
Cookies
MorphyLearn uses a small number of strictly necessary cookies โ never for advertising or cross-site tracking:
- A session cookie that keeps you logged in.
- A separate, longer-lived cookie for a device you've paired for kid gameplay.
- A security cookie used to help protect your account from certain types of forged requests.
These cookies are required for the product to function. There's nothing to opt out of, because none of them are used for tracking or advertising.
Children's privacy (COPPA)
MorphyLearn is directed at use by children under parental supervision, but every account is created and controlled by a parent โ a child never signs up, enters payment information, or provides their own contact information. At signup, a parent must explicitly check a box confirming they agree to this Privacy Policy and our Terms of Service before an account can be created โ this is a real, required step, not implied by simply using the product. Creating a kid profile is itself the mechanism by which a parent then provides verifiable consent for their child's limited data (nickname, emoji, and learning activity) to be collected, for the sole purpose of operating the product for that child. A parent can review, export, or delete a child's data at any time (see below) โ we treat this as an ongoing right, not a one-time signup checkbox. We record which version of this policy a parent agreed to, and when, so we can identify affected accounts if this policy materially changes.
Your rights and controls
- Review: your Parent Dashboard shows the real, complete learning data recorded for each kid profile.
- Export: from your account settings, you can download a complete copy of your account information and every kid profile's learning data, at any time, as a plain data file.
- Delete a kid profile: you can delete a single kid profile and all of its learning records from your account at any time โ this removes that child's data immediately, not just the profile name.
- Delete your entire account: from your account settings, you can permanently delete your account, every kid profile, and all associated data at any time โ this requires re-entering your password to confirm, and takes effect immediately. You don't need to contact Support to do this.
- Data retention: when you delete a kid profile or your account, the underlying records are removed from our active database immediately. A copy may persist for up to 30 days in encrypted backups used solely for disaster recovery, after which it is fully purged. We do not restore an individually deleted record from backup for any other purpose.
Analytics and advertising
We use tightly-scoped, aggregate product analytics to understand how the app is used as a whole (e.g. which features are used) โ never analytics that build a profile of an individual child for advertising, and we do not run behavioral advertising of any kind.
Security
We use industry-standard measures to help protect your information, including:
- All traffic between your device and MorphyLearn is encrypted in transit (HTTPS/TLS).
- Our infrastructure providers encrypt data at rest by default.
- Passwords are hashed with a salted, one-way algorithm โ never stored in plain text.
- Sensitive tokens (password resets, email verification, device pairing codes) are stored only as one-way hashes.
- Access to your account data is limited to your own authenticated session; internal access is restricted to what's needed to operate and support the product.
- We apply security updates to our systems on an ongoing basis.
- Payment information is handled entirely by Stripe and never touches our own servers directly.
No method of transmission or storage is 100% secure, and we can't guarantee absolute security โ but we work to protect your information using the measures above.
Data breach notification
If we become aware of a security incident that compromises personal information, we will notify affected account holders, and any regulators required by law, without unreasonable delay.
Business transfers
If MorphyLearn is involved in a merger, acquisition, or sale of some or all of its assets, personal information may be transferred as part of that transaction. We'll provide notice before your information becomes subject to a different privacy policy.
Law enforcement disclosures
We may disclose information if required to do so by law, or if we believe in good faith that disclosure is necessary to comply with a legal obligation, protect the safety of a user or the public, or protect our rights.
State privacy rights
Depending on where you live, you may have additional rights under state privacy laws โ for example, the right to know what personal information we hold about you and to request its deletion. The rights described in "Your rights and controls" above are already available to every account holder, regardless of location. To ask about any additional rights available under your state's law, contact us using the information below.
International users
MorphyLearn is currently operated from, and intended for use within, the United States. If you access the product from outside the United States, your information will be processed in the United States.
Changes to this policy
If we make a material change to this policy, we'll notify account holders and, where required, ask for renewed consent. Each version of this policy is tracked, so we can always identify which version a given parent agreed to.
Who operates MorphyLearn
MorphyLearn is operated by Saul Steward, based in Tennessee, United States.
Contact
Privacy questions, a data request, or general support: email support@morphylearn.com, or see our Support page.