Children's Privacy Policy

The Why: Youth · Operator: Michael Rogers (sole developer) · Effective: May 30, 2026 · Last Updated: May 30, 2026

A plain-language summary is also published at /kids-privacy. This is the comprehensive policy.

Notice to Parents and Guardians

This Children's Privacy Policy describes how Michael Rogers, the sole developer and operator of The Why: Youth ("Operator," "we," "us," or "our"), collects, uses, and discloses personal information from children under 13 years of age. This policy is designed to comply with the Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. § 6501 et seq., and its implementing regulations at 16 CFR Part 312, including the amendments effective April 22, 2026.

If you are a parent or guardian and have questions, contact us at rogersmi87@gmail.com.

1. Overview

1.1 What This Policy Covers

This policy applies to personal information collected from children under 13 through The Why: Youth mobile application (iOS and Android). It does not apply to "The Why" (our companion adult application) or to any other service we operate.

1.2 Age Verification

1.3 Definitions

"Child" means an individual under 13 years of age. "Parent" includes a legal guardian. "Personal Information" has the meaning given in COPPA at 16 CFR § 312.2.

2. Information We Collect From Children

2.1 Information Collected Directly

A child never directly registers for the Service; only a parent or guardian creates an account and configures each child profile. Through that parent-managed process, we collect about a child:

Information TypeCollectedPurpose
First name or username (child's display name)YesApp functionality, personalization
Email addressNoWe do not collect a child's email; only the parent's email is on file
Profile pictureNoAvatar is a pre-defined emoji icon selected from a fixed set; no uploaded image
Date of birthPartial — birth year onlyCompute age band and prompt the parent to switch tracks when the child turns 14
User-generated contentNoThe only typed content a child can produce (a "gospel in your own words" practice exercise) stays on the device and is never transmitted
Audio or voice recordingsNoThe app has no microphone access
Photographs or videoNoThe app has no camera access
Precise geolocationNoThe app has no location access
Government identifiers (SSN, etc.)NoNever collected

2.2 Information Collected Automatically

Information TypeCollectedPurpose
Device type and operating systemYesSupport internal operations, troubleshooting
IP addressYes (transient, in server logs)Security, abuse prevention, internal operations
Pages visited / in-app activityYesApp functionality, personalization, progress tracking, internal analytics
Session timingYesInternal operations and product improvement
Persistent identifiers (account session token, subscription customer ID)YesSolely to support internal operations (account login, subscription identity). Not used for advertising or profiling.

Note on Persistent Identifiers. Under COPPA, persistent identifiers are not "personal information" when used solely to support internal operations. We use persistent identifiers solely for internal-operations purposes.

2.3 Information Collected from Third Parties

We do not collect children's personal information from third parties.

3. How We Use Children's Information

3.1 Permitted Uses

3.2 Prohibited Uses

We do not condition participation on disclosure of unnecessary information; target advertising to children; create behavioral-advertising profiles; sell or rent children's information; or share information with third parties for those parties' own marketing.

4. Disclosure of Children's Information

4.1 Service Providers

We disclose limited personal information only to service providers who need it to perform services on our behalf and are contractually prohibited from using it for any other purpose:

Service ProviderRole
Railway (railway.app)Hosting and database infrastructure
Clerk (clerk.com)Authentication for the parent account
RevenueCat (revenuecat.com)Subscription / in-app purchase management
Anthropic (anthropic.com)Generation of curated training content. A child's free-text input is never transmitted to Anthropic.
Bible API (bible-api.com)Public Bible-passage lookup. No personal information sent.

4.2 Other Disclosures

We may disclose information to comply with law, protect safety, protect Service security, or with verifiable parental consent.

4.3 No Sale or Sharing

We do not sell children's personal information, share it for cross-context behavioral advertising, or disclose it to third parties for their own marketing purposes.

5. Parental Consent

5.1 Consent Requirements

Under COPPA, we obtain verifiable parental consent before collecting personal information from a child beyond what is necessary to support internal operations, and before using personal information for purposes other than internal operations.

5.2 Verifiable Parental Consent Method

We rely on the "Email Plus" consent mechanism (16 CFR § 312.5(b)(2)), supplemented by parent-managed account architecture, because we use children's personal information solely for internal-operations purposes. Our process:

  1. The parent creates an account using their own email and a password they choose.
  2. The parent verifies ownership of the email address.
  3. The parent takes a deliberate, authenticated action inside the app to create a child profile.
  4. Sensitive-topic categories are gated by default and can be enabled only by the parent after entering a Parent PIN they set within the app.

5.3 Exceptions to the Consent Requirement

Consent is not required for activities within COPPA's exceptions in 16 CFR § 312.5(c), including obtaining a parent's contact information to obtain consent, protecting a child's safety, protecting Service security, complying with law, and supporting internal operations through persistent identifiers.

6. Parental Rights

6.1 Your Rights Under COPPA

As a parent or guardian, you have the right to review your child's information, delete it, refuse further collection or use, and revoke any consent previously provided.

6.2 How to Exercise Your Rights

6.3 Response Timeline

We respond to verified requests within 30 days. We may verify your identity and relationship to the child before completing a request.

7. Data Security

7.1 Security Measures

7.2 Data Breach Response

In the event of a security incident affecting children's personal information, we will promptly investigate, notify parents and applicable authorities as required by law, and take appropriate remedial action.

8. Data Retention

We retain a child's personal information only as long as is reasonably necessary to provide the Service to that child, comply with our legal obligations, resolve disputes, and enforce our agreements. A parent may delete a child's profile at any time from within the app or request full account deletion. Upon a verified deletion request, the child's personal information is deleted or de-identified within 30 days.

9. Third-Party Services and Links

The Service relies on the limited set of service providers identified in § 4.1. We do not include third-party advertising networks, third-party analytics SDKs, or social-media SDKs. The Service contains no social features. Children cannot post content publicly, chat with other users, exchange messages, or share content with other users of the Service.

10. Advertising

The Service contains no advertising of any kind. We do not display contextual ads, engage in behavioral or targeted advertising directed at children, track children across third-party websites for advertising, or create advertising profiles of children.

11. Connected Devices and Toys

Not applicable. The Service is a mobile application; it does not interact with connected devices or toys.

12. Schools and Educational Services

Not applicable. The Service is a consumer application sold to families. It is not designed, marketed, or distributed for use in school programs.

13. International Users

The Service is offered through the Google Play and Apple App Store ecosystems and may be downloaded internationally. We comply with applicable children's privacy laws in each jurisdiction where the Service is offered. Our infrastructure is operated in the United States; information about users outside the United States may be transferred to and processed in the United States, with appropriate safeguards.

14. State-Specific Provisions

California: We comply with the California Consumer Privacy Act and the California Privacy Rights Act. We do not sell or share children's personal information. Parents of a child under 16 may request deletion.

Other States: For residents of states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, and others), we comply with applicable requirements, including obtaining consent for the processing of sensitive data of minors and honoring opt-out requests for targeted advertising (which we do not conduct in any event).

15. Updates to This Policy

If we make material changes that affect how we collect, use, or disclose children's personal information, we will post a prominent notice within the Service, provide direct notice to the parent email on file, and obtain new verifiable parental consent where required. For non-material changes, we will update the "Last Updated" date at the top of this policy.

16. Contact Information

Email: rogersmi87@gmail.com
Mail: 3955 Green Valley Road, Lebanon, VA 24266, Attn: Children's Privacy

If you believe we have violated COPPA, you may file a complaint with the Federal Trade Commission, Consumer Response Center, 600 Pennsylvania Avenue NW, Washington, DC 20580 — www.ftc.gov/complaint — 1-877-382-4357.

17. Operator Information

Operator NameMichael Rogers (sole developer)
Address3955 Green Valley Road, Lebanon, VA 24266
Emailrogersmi87@gmail.com
WebsiteNot applicable — mobile application only

We are the sole operator of the Service. No third-party operator collects personal information directly through the Service.


This policy was drafted to reflect the actual data practices of The Why: Youth and the April 22, 2026 COPPA amendments. Privacy policies are legally binding; consult qualified legal counsel before relying on any policy text in production.