This Children's Privacy Policy describes how Michael Rogers, the sole developer and operator of The Why: Youth ("Operator," "we," "us," or "our"), collects, uses, and discloses personal information from children under 13 years of age. This policy is designed to comply with the Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. § 6501 et seq., and its implementing regulations at 16 CFR Part 312, including the amendments effective April 22, 2026.
If you are a parent or guardian and have questions, contact us at rogersmi87@gmail.com.
This policy applies to personal information collected from children under 13 through The Why: Youth mobile application (iOS and Android). It does not apply to "The Why" (our companion adult application) or to any other service we operate.
"Child" means an individual under 13 years of age. "Parent" includes a legal guardian. "Personal Information" has the meaning given in COPPA at 16 CFR § 312.2.
A child never directly registers for the Service; only a parent or guardian creates an account and configures each child profile. Through that parent-managed process, we collect about a child:
| Information Type | Collected | Purpose |
|---|---|---|
| First name or username (child's display name) | Yes | App functionality, personalization |
| Email address | No | We do not collect a child's email; only the parent's email is on file |
| Profile picture | No | Avatar is a pre-defined emoji icon selected from a fixed set; no uploaded image |
| Date of birth | Partial — birth year only | Compute age band and prompt the parent to switch tracks when the child turns 14 |
| User-generated content | No | The only typed content a child can produce (a "gospel in your own words" practice exercise) stays on the device and is never transmitted |
| Audio or voice recordings | No | The app has no microphone access |
| Photographs or video | No | The app has no camera access |
| Precise geolocation | No | The app has no location access |
| Government identifiers (SSN, etc.) | No | Never collected |
| Information Type | Collected | Purpose |
|---|---|---|
| Device type and operating system | Yes | Support internal operations, troubleshooting |
| IP address | Yes (transient, in server logs) | Security, abuse prevention, internal operations |
| Pages visited / in-app activity | Yes | App functionality, personalization, progress tracking, internal analytics |
| Session timing | Yes | Internal operations and product improvement |
| Persistent identifiers (account session token, subscription customer ID) | Yes | Solely to support internal operations (account login, subscription identity). Not used for advertising or profiling. |
Note on Persistent Identifiers. Under COPPA, persistent identifiers are not "personal information" when used solely to support internal operations. We use persistent identifiers solely for internal-operations purposes.
We do not collect children's personal information from third parties.
We do not condition participation on disclosure of unnecessary information; target advertising to children; create behavioral-advertising profiles; sell or rent children's information; or share information with third parties for those parties' own marketing.
We disclose limited personal information only to service providers who need it to perform services on our behalf and are contractually prohibited from using it for any other purpose:
| Service Provider | Role |
|---|---|
| Railway (railway.app) | Hosting and database infrastructure |
| Clerk (clerk.com) | Authentication for the parent account |
| RevenueCat (revenuecat.com) | Subscription / in-app purchase management |
| Anthropic (anthropic.com) | Generation of curated training content. A child's free-text input is never transmitted to Anthropic. |
| Bible API (bible-api.com) | Public Bible-passage lookup. No personal information sent. |
We may disclose information to comply with law, protect safety, protect Service security, or with verifiable parental consent.
We do not sell children's personal information, share it for cross-context behavioral advertising, or disclose it to third parties for their own marketing purposes.
Under COPPA, we obtain verifiable parental consent before collecting personal information from a child beyond what is necessary to support internal operations, and before using personal information for purposes other than internal operations.
We rely on the "Email Plus" consent mechanism (16 CFR § 312.5(b)(2)), supplemented by parent-managed account architecture, because we use children's personal information solely for internal-operations purposes. Our process:
Consent is not required for activities within COPPA's exceptions in 16 CFR § 312.5(c), including obtaining a parent's contact information to obtain consent, protecting a child's safety, protecting Service security, complying with law, and supporting internal operations through persistent identifiers.
As a parent or guardian, you have the right to review your child's information, delete it, refuse further collection or use, and revoke any consent previously provided.
We respond to verified requests within 30 days. We may verify your identity and relationship to the child before completing a request.
In the event of a security incident affecting children's personal information, we will promptly investigate, notify parents and applicable authorities as required by law, and take appropriate remedial action.
We retain a child's personal information only as long as is reasonably necessary to provide the Service to that child, comply with our legal obligations, resolve disputes, and enforce our agreements. A parent may delete a child's profile at any time from within the app or request full account deletion. Upon a verified deletion request, the child's personal information is deleted or de-identified within 30 days.
The Service relies on the limited set of service providers identified in § 4.1. We do not include third-party advertising networks, third-party analytics SDKs, or social-media SDKs. The Service contains no social features. Children cannot post content publicly, chat with other users, exchange messages, or share content with other users of the Service.
The Service contains no advertising of any kind. We do not display contextual ads, engage in behavioral or targeted advertising directed at children, track children across third-party websites for advertising, or create advertising profiles of children.
Not applicable. The Service is a mobile application; it does not interact with connected devices or toys.
Not applicable. The Service is a consumer application sold to families. It is not designed, marketed, or distributed for use in school programs.
The Service is offered through the Google Play and Apple App Store ecosystems and may be downloaded internationally. We comply with applicable children's privacy laws in each jurisdiction where the Service is offered. Our infrastructure is operated in the United States; information about users outside the United States may be transferred to and processed in the United States, with appropriate safeguards.
California: We comply with the California Consumer Privacy Act and the California Privacy Rights Act. We do not sell or share children's personal information. Parents of a child under 16 may request deletion.
Other States: For residents of states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, and others), we comply with applicable requirements, including obtaining consent for the processing of sensitive data of minors and honoring opt-out requests for targeted advertising (which we do not conduct in any event).
If we make material changes that affect how we collect, use, or disclose children's personal information, we will post a prominent notice within the Service, provide direct notice to the parent email on file, and obtain new verifiable parental consent where required. For non-material changes, we will update the "Last Updated" date at the top of this policy.
Email: rogersmi87@gmail.com
Mail: 3955 Green Valley Road, Lebanon, VA 24266, Attn: Children's Privacy
If you believe we have violated COPPA, you may file a complaint with the Federal Trade Commission, Consumer Response Center, 600 Pennsylvania Avenue NW, Washington, DC 20580 — www.ftc.gov/complaint — 1-877-382-4357.
| Operator Name | Michael Rogers (sole developer) |
|---|---|
| Address | 3955 Green Valley Road, Lebanon, VA 24266 |
| rogersmi87@gmail.com | |
| Website | Not applicable — mobile application only |
We are the sole operator of the Service. No third-party operator collects personal information directly through the Service.
This policy was drafted to reflect the actual data practices of The Why: Youth and the April 22, 2026 COPPA amendments. Privacy policies are legally binding; consult qualified legal counsel before relying on any policy text in production.