Lysro

Privacy

What Lysro collects, what it erases, and who else touches it — described from the code that does it.

Effective August 25, 2026

What we collect about your child

Nothing that identifies them. Lysro never asks for your child's name, birthday, age, school, address, photograph, or contact details, and there is no field anywhere in the product that would accept them. The profile their conversations hang off carries a placeholder name and nothing else.

This is a property of the database, not a promise about our intentions: the child record has room for a display name and an age band and no other personal column, and both are filled in by the product rather than by you.

What we collect about you

Your email address, which is how you sign in — there is no password — and where a safety notice or a billing notice would be sent.

If you reach the point of handing the device to your child, your card details are entered on Stripe's payment page and never reach us. What we store is the identifier Stripe gives us for your customer record and subscription.

Ordinary technical records that any website keeps: request logs, and an approximate country, used to decide which crisis resources are the right ones to show.

Your child's conversations

The messages your child sends and the replies Lysro gives are stored so that a conversation can continue and so that your weekly summary can be produced. After 14 days, the word-for-word text of your child's own messages is erased. Lysro's replies are kept — they are what the conversation is made of, and deleting one side of it would leave the other unreadable.

What outlives that window on your child's side is a non-identifying tag: a topic and a signal, drawn from a fixed vocabulary, of the kind "asked about science" or "kept trying after a wrong answer". Your weekly summary is built from those tags, which is why it can describe a week whose words have already been erased.

When something crosses the safety floor and you are told about it, what you are shown is written from a fixed set of phrases. A safety notice never quotes your child's own words back to you.

The try-it-first sandbox on our home page

The demonstration chat on the landing page stores no messages at all — not yours, not the model's. What it keeps is a count, so that one visitor cannot run up an unbounded bill, and a random session identifier that is attached to no person.

Your IP address is used to apply those limits and is stored only as a salted, irreversible hash. We do not keep it in a form that could be read back.

Cookies, measurement, and what we do not do

Three cookies run the product itself: one that keeps a parent signed in, one that marks a device as your child's, and one short-lived one for the landing-page sandbox. The measurement described next sets cookies of its own, and only on the two pages that carry it — nothing on your child's chat sets or reads one.

We buy advertising, and we measure whether it works. Two pages carry that measurement — the home page and the pricing page — and what it reports is that a visit reached a step we are counting, such as keeping a rule in the sandbox. It reports the step and never its contents: what you type into the sandbox stays in your browser, and nothing you type on either page is handed to the measurement. Anything else we ever measure about how those two pages are used will sit inside the same boundary.

Lysro shows you no advertising. There are no ad slots, no third-party ad content, and no ad network anywhere in this product — the measurement runs outward, about advertisements we placed elsewhere, and nothing runs inward. It is never loaded on your child's chat, and never on a page inside your account. We do not sell personal information, and there is no behavioural profile of you or your child anywhere in this product.

The usage counts we keep — a page was viewed, a sandbox session started, a rule was created — are recorded on our own servers, and no advertising identifier is stored beside them: the click identifier an advertisement puts in the address bar is deliberately never written to our database. Nor is what the measurement reports joined back to your account, for a plain reason — at the moment it fires there is no account.

Who else handles the data

Anthropic, whose model writes the answers. OpenAI, which screens messages for content that must not reach a child. Stripe, for payments. Resend, which delivers sign-in and billing email. Cloudflare, which sits in front of the site and runs the bot check. Google, in three separate roles: Google Cloud hosts the service and the database, Google Fonts serves the typeface every page is set in, and Google's advertising measurement receives the conversion reports described above. Meta, whose advertising measurement receives a report that one of those two pages — the home page or the pricing page — was viewed, and nothing further.

Each receives only what its job requires, and everyone here but two is bound to handle your family's data only for the work we ask of them. The two are the advertising measurements — Google's and Meta's — and they are worth naming rather than burying. What each receives is what any web request discloses — the address you are connecting from, the page you are on — together with the fact that an advertisement led to a step on that page, or, in Meta's case, simply that the page was reached. Nothing about your child, and nothing from an account, because at that point there is no account. What Google and Meta do with it afterwards is theirs, on their own terms.

The service and its database run on Google Cloud infrastructure located in Japan. If you are writing from elsewhere, your information is processed there.

Deleting everything

The account menu has a delete control that removes the household: your email, your settings, your child's profile, every stored message, and every derived summary. It is not a request queued for review — it runs when you confirm it.

Cancelling a subscription and deleting an account are separate actions, and deleting is the one that erases data.

Children's privacy and your rights as the parent

Lysro is bought, configured, and handed over by a parent or guardian. The account is yours, the email is yours, the settings are yours, and your child never creates an account or supplies information about themselves.

Before your child can send a single message, your card goes through our payment provider — that is the step that confirms an adult is setting this up, and it is why the hand-over asks for it. Nothing is charged at that moment, and your child cannot chat until it completes.

You can see what has been kept, change what Lysro is allowed to discuss, revoke your child's device, and delete everything, at any time, from your account.

If you believe a child has supplied personal information to us in spite of the above, write to us and we will remove it.

Changes, and how to reach us

Material changes to this notice will be posted here with a new date, and sent to the address on your account. This version is effective August 25, 2026.

Questions, requests, and anything you would rather say to a person: privacy@lysro.app.

Terms of service

Privacy · Lysro