Legal
Children’s Privacy Notice
Effective date: June 22, 2026 · Last updated: June 22, 2026
This notice is provided pursuant to the Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, and the FTC’s COPPA Rule, 16 C.F.R. Part 312.
1. Operator
EverLetter operates the everletter.family platform. Questions about this notice may be directed to:
EverLetter — Privacy Team
privacy@everletter.family
2. How EverLetter Works With Children’s Information
EverLetter is a platform used by adults — parents, grandparents, and other trusted family members — to create and store Memory Capsules intended for children. Children do not create EverLetter accounts, do not log in to the platform, and do not submit personal information directly to us.
When a parent or guardian creates a Child Vault, they provide basic information abouttheir child as a way to organize that child’s timeline of memories. This information is provided entirely by the parent or guardian, not by the child.
Children may later view Memory Capsules through a read-only portal accessible by a unique link (no account required, no data collected from the child during viewing).
3. Information We Collect About Children
When you create a Child Vault, you may provide:
- Child’s first and last name — used to label the vault and personalize capsule delivery
- Date of birth — optional; used to enable birthday-triggered capsule delivery and milestone suggestions
- Photo — optional; used as a visual identifier in the vault interface, visible only to your family circle
We do not collect from or about children: geolocation data, device identifiers, behavioral tracking data, or any persistent identifiers beyond the vault record you create.
4. How We Use This Information
Information about a child is used solely to:
- Organize and label the child’s Memory Capsule timeline
- Enable date-based capsule delivery (e.g., birthday messages, milestone unlocks based on age)
- Display a personalized greeting when the child views a capsule through the read-only portal
We do notuse children’s information for advertising, profiling, sale to third parties, or any purpose beyond the Memory Capsule service described above.
5. Disclosure to Third Parties
Information about children is shared only with the following service providers, solely to operate the platform:
- Supabase — database hosting and authentication infrastructure. Child vault records are stored in Supabase databases located in U.S. data centers.
We do not sell, rent, or share children’s information with advertisers, data brokers, analytics platforms, or any other third party. We do not use children’s information to train AI models.
6. Your Parental Rights
As the parent or guardian who created a Child Vault, you have the right at any time to:
- Reviewall personal information associated with your child’s vault, including name, date of birth, and photo
- Correct or update that information through your account settings or by contacting us
- Deleteyour child’s vault and all associated personal information, including all Memory Capsules and media files
- Refuse further collection— you may delete a Child Vault at any time to stop any further collection or use of that child’s information
- Withdraw consent— deletion of the Child Vault constitutes withdrawal of consent for us to hold or use that child’s information
Deleting a Child Vault will permanently delete all Memory Capsules, media files, and personal information associated with that vault. This action cannot be undone. We will complete deletion within 30 days of your request.
7. No Collection Directly From Children
EverLetter does not knowingly collect personal information directly from any child under the age of 13. Children do not submit information to us — all Child Vault information is provided by the parent or guardian account holder on behalf of their child.
If we discover that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will delete that information promptly. If you believe this has occurred, contact us immediately at privacy@everletter.family.
8. Security
We protect children’s information using the same security measures applied to all user data: encryption in transit (TLS/HTTPS), encryption at rest, and strict access controls. Child vault content is only accessible to the account holder and family members they explicitly invite.
9. How to Exercise Your Rights
To review, correct, or delete your child’s information, or to ask questions about our children’s privacy practices:
- Email: privacy@everletter.family
- In-app:Navigate to your child’s vault and use the vault settings to edit or delete it
We will respond to all parental rights requests within 10 business days and complete deletions within 30 days.
10. Changes to This Notice
We will notify you of any material changes to this Children’s Privacy Notice by email and by posting an updated notice on this page with a new effective date. Continued use of the platform after the effective date constitutes acceptance of the revised notice.
Related Policies
This notice is part of our broader commitment to privacy and accessibility. See also:
- Privacy Policy — full privacy practices
- Terms of Service — platform rules and rights
- Accessibility Statement — WCAG 2.1 AA commitment