Effective: September 9, 2026 (replaces the policy effective September 1, 2026)

Lullavo is operated by MFV LLC, a Tennessee company (“Lullavo,” “we”). This policy explains what we collect, why, and the choices you have. The short version, which the rest of this document keeps: your recordings are private by default, we don’t sell data, we don’t run ads, and we don’t do anything with your voice except store it and play it back for the people you share it with.

What changed on September 9, 2026: one sentence was added to Section 1. When a recording, an upload, or a sign-in fails, the anonymous event our own analytics records now also notes the browser family, its major version, and the operating system family, so we can tell when a browser update has broken recording. These are categories, never identifiers: nothing new can identify a person, nothing is shared with anyone new, and no right was reduced.

What changed on September 1, 2026: two descriptions were made more precise. Section 1 now describes exactly which anonymous, identifier-free events our own analytics records on playback pages, instead of saying playback pages carry no analytics. Sections 5 and 6 now describe our backups as automated archive copies on a rolling cycle that always retains the three most recent archives, matching how the backup system actually works. Nothing new is collected, nothing is shared with anyone new, and no right was reduced.

What changed on August 26, 2026: this update adds one sentence to Section 5 describing something the app already does to protect you while you record: your own device briefly keeps a local copy of an in-progress recording so an interrupted session does not lose your reading. Nothing new is collected, nothing leaves your device because of it, and nothing is used in a new way. Our contact address also changed to hello@collegiateabcs.com.

What changed on August 17, 2026: this update describes information we already handled but had not written down, to match Section 8A of the Terms published the same day. It adds trusted contacts and account-transfer requests to what we collect (Section 1), gives all three a retention period (Section 5), and confirms that someone named as a trusted contact, or who asks for a transfer, has rights over their own information even without an account (Section 7). Nothing new is collected and nothing is used in a new way.

1. What we collect, and from whom

If you buy from our websites: name, email, shipping address, and order details. Payments are handled by the payment providers shown at checkout; your card details go directly to those providers and are never stored on Lullavo’s systems.

If you record: your email address (used for the sign-in link), your name, the details you choose to add (the listener’s first name, the book, the occasion), and your audio recordings.

If you listen: nothing personal. Playback requires no account, login, name, or any information from the listener. Our servers keep basic technical logs (IP address, device/browser type, timestamp) for security, abuse prevention, and debugging only; these are retained 30 to 90 days and are never used to identify, profile, advertise to, or contact anyone.

If you name a trusted contact: their name, email address, your relationship to them, and an optional short note. We email them to say you have named them, and we email them again if you later remove or replace them, so no one is left believing they hold a role they no longer have. This is information about someone else, so we keep it to the minimum: naming a person does not create an account for them, gives them no access to your recordings while you can manage your own account, and we never use their address for marketing or add them to any list.

If you ask us to transfer someone’s account: your name, email address, your relationship to the account holder, any message you include, and the supporting document you upload, such as a death certificate or documentation of legal authority. We ask for a document because we will not hand a person’s recordings to someone we cannot verify. We use it only to check the request, and we delete it on the schedule in Section 5.

On our sites: we use first-party analytics only. We run no third-party analytics, advertising, or tracking scripts anywhere, including on playback pages. A small number of anonymous events are recorded on playback pages so we can tell when something is broken, for example that an occasion card was opened or that kid-held mode was started. Each event stores only the event name, a short non-identifying property such as which occasion theme was used, and the page path. When something fails (a recording, an upload, a sign-in), the event also records the browser family, its major version, and the operating system family, so we can tell when a browser update has broken recording; these are categories, never identifiers. We do not store IP addresses, cookies, device or browser identifiers, or any user or session identifier alongside these events, and we cannot connect them to a person.

2. What we do, and don’t do, with recordings

We use your information to operate the Service: storing and streaming recordings, sending sign-in links and service emails, fulfilling orders, providing support, and keeping the Service secure.

We do not: sell or rent personal information; share recordings with anyone except the people who scan your sticker; use recordings for advertising; or listen to recordings except when you ask for support, when reviewing a specific report of abuse or a legal notice, or as required by law.

No voice recognition, no biometrics, no AI training. We do not perform voice recognition, speaker identification, or voiceprint analysis; we do not extract any biometric identifier or template from recordings; and we do not use recordings or voices to train or improve any artificial-intelligence, voice-synthesis, or voice-cloning system. Recordings are stored and played back as ordinary audio files. Any future feature that would change this would require your explicit opt-in and an update to this policy.

3. Children

The recording side of Lullavo is for adults; we do not knowingly collect personal information from children under 13. Information about a child (a first name, or a child’s voice within a recording) enters the Service only when an adult chooses to include it, and we require that adult to be the child’s parent/guardian or to have the parent/guardian’s consent. Playback collects no personal information from listeners. Audio containing a child’s voice is treated as personal information: a parent or legal guardian may review it, or have it deleted, by contacting hello@collegiateabcs.com, and we will verify and honor the request. We retain it only per the schedule in Section 5 and never use it for any purpose beyond storing and playing the recording.

4. Who processes data for us

We share personal information only with service providers that host and operate the Service under contract: Supabase (database and audio storage, hosted in the United States), Vercel (application hosting), Resend (transactional email), Klaviyo (marketing email for customers who opt in; order data from our store), Cloudflare (bot and abuse protection), Sentry (error logging, configured to scrub emails, tokens, and identifying details), the payment providers shown at checkout, and our e-commerce platform (WooCommerce/WordPress) for orders. We may disclose information if required by law, and in a business transfer your information transfers with the Service subject to the Continuity Pledge in our Terms of Service.

5. How long we keep things (retention schedule)

Data Kept Why / trigger for deletion
Recordings & sticker details While your account/recording is active So your recording can play for the life of the product. Deleted within 14 days of your deletion request; on any Service wind-down, per the Wind-Down Policy (90 days’ notice + export, recovery window, then final deletion)
Account info (email, name) While your account is active Deleted with your account (within 14 days)
Trusted contact details (their name, email, relationship, note) While the designation stands Deleted when you remove or change the designation, and with your account. The person named can also ask us directly to remove them (Section 7)
Transfer request supporting documents (death certificate, proof of legal authority) 30 days after the request is resolved Deleted automatically 30 days after we approve or decline a request. A document on a request that is still open is never deleted while it is pending, so a family is never asked to send it twice
Transfer request records (requester name, email, relationship, message, and our decision) Kept after the documents are deleted Retained as the record of who asked, what we decided, and why, so a transfer can be explained or revisited later. Ask us at any time and we will tell you what a request holds
Order records As required for tax/accounting Legal retention obligations
Security/technical logs 30 to 90 days Abuse prevention, security, debugging only
Sign-in tokens Single use, expire after 1 hour Authentication
Backups Rolling 30-day cycle, except that we always retain the three most recent archives so a run of failures cannot leave us with none Disaster recovery; backup archives age out on the rolling cycle, so deleted content also ages out of backups as the cycle turns

While you are recording, your device may briefly keep a copy of your in-progress reading in your browser’s own storage so nothing is lost if the page closes unexpectedly; this local copy clears automatically once your recording is saved, and any copy left behind clears itself within about a week.

We do not retain children’s personal information indefinitely; the triggers above are the retention policy for all recording data, including any child’s voice or name an adult has included.

6. Security

Recordings are stored in access-controlled cloud storage with automated archive copies; new recordings are streamed through short-lived signed links rather than permanent public URLs. No storage system is infallible, so your account lets you download any recording at any time, and we encourage you to keep your own copy of the recordings that matter most to you. Documents sent with a transfer request are held in the same access-controlled storage, are never public, and are reachable only by us. Sign-in uses single-use, expiring email links instead of passwords. We restrict internal access, scrub identifying data from error logs, and maintain a written information security program that we review at least annually. No system is perfectly secure; if a breach affects your personal information we will notify you as required by law.

7. Your choices and rights

You can: download your recordings at any time; delete recordings or your entire account from account settings (completed within 14 days); correct your details; unsubscribe from marketing email with one click (service emails, like sign-in links, aren’t marketing); and request a copy of your data at hello@collegiateabcs.com.

If you were named as a trusted contact, or you asked us for a transfer. You do not need a Lullavo account to have rights over your own information. Write to hello@collegiateabcs.com and you can ask what we hold about you, correct it, or ask to be removed as someone’s trusted contact. We will honor a removal request without asking the account holder to approve it. Being named as a trusted contact places no obligation on you at all.

State privacy rights (US). Depending on your state, you may have rights to access, correct, delete, and port personal information and to opt out of sales/targeted advertising; we honor access, correction, deletion, and portability for everyone regardless of state, and we do not sell personal information or engage in targeted advertising at all. Residents of Illinois, Texas, and Washington: we do not collect, capture, or possess biometric identifiers or biometric information (including voiceprints) as defined by the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, or the Washington My Health My Data Act; recordings are stored solely as audio files and no identifier template is generated or extracted from them.

Visitors from the EU/UK. Lullavo is a US service and we market to US customers; if you use the Service from the EU/UK, our legal bases for processing are performance of a contract (operating the Service you’ve requested) and legitimate interests (security, and verifying an account transfer), your data is processed in the United States, and you may exercise access, rectification, erasure, portability, restriction, and objection rights at hello@collegiateabcs.com, and lodge a complaint with your local supervisory authority.

8. Changes and contact

Material changes to this policy will be announced by email and/or prominent notice at least 30 days before taking effect. Contact: MFV LLC (Lullavo) · hello@collegiateabcs.com