
Updated 10 September 2026
Privacy Policy
A plain-language account of what Let’s Build It! handles when a parent and child create together, who processes it, and the choices a parent controls.
Who runs Let’s Build It!
Let’s Build It! by Cann Studios
Operated by Michael James Cann, an Australian sole trader.
ABN 25 719 492 087
This policy applies to letsbuildit.app and the Let’s Build It! app.
A parent-managed family app
Only a parent creates an account. A parent creates kid profiles, chooses settings and guardrails, and is responsible for a child using the creation tools.
There are no public kid accounts, public profiles, social feeds, advertising profiles, or public project sharing in the launch product.
Information we handle
We collect information needed to run the family account, generate projects, keep them available, provide support, and protect the service.
- Parent account details such as name, email, profile image, sign-in provider identifiers, and authentication records. Before launch, we also collect an email address when someone chooses to join the launch waitlist.
- The AI sharing notice version and time recorded when a parent or legal guardian explicitly agrees to the described AI processing. Withdrawing permission removes that active permission record.
- Kid profile details chosen by the parent, including name, avatar, birth month or age, reading level, interests, boundaries, and optional guidance.
- Temporary spoken and typed conversation transcripts, short project briefs, generated code and images, project state, titles, and editing history.
- Credit usage, model and provider usage, device and push-notification details, and technical diagnostics.
- Apple purchase records such as product and transaction identifiers, purchase date, price and currency where Apple provides them, subscription status, refunds or revocations, and credits granted or reversed. We do not receive payment card or bank account details.
- Information a parent chooses to send when asking for support or submitting diagnostic feedback.
Voice, AI and generated projects
With your explicit permission, Google Gemini receives microphone audio and conversation text so the app can understand an idea and respond. We do not store raw microphone audio in our application database, but the speech and AI providers process it while providing the service.
We temporarily keep conversation text while a project is built or can still be retried. Conversation text for a successful build is removed within 24 hours in normal operation, and in all cases within seven days. A failed or abandoned conversation is also removed within seven days. We keep a short project brief with the generated project so the family can revisit and edit it without keeping the full conversation.
Conversation text, the profile name, approximate age, reading level, interests, parent guidance, project prompts, existing code and generated images may be sent to Google Gemini and OpenRouter to create and edit projects. OpenRouter routes those requests to the companies named below. Project-icon requests send the project title.
Chat-based project-generation requests sent through OpenRouter require zero-data-retention endpoints and fail closed when none is eligible. Google Gemini processes live voice and some project-edit requests directly under a production prompt-logging exception approved by Google. Project icons use a separate OpenAI image route through OpenRouter; we do not claim zero data retention for that route.
How we use information
We use information to authenticate the parent, record the parent acknowledgement before child features open, personalise kid profiles, create and edit projects, save the family shelf, operate free and paid credits, verify and restore Apple purchases, apply subscription, refund, and revocation changes, send requested notifications and reset emails, manage the launch waitlist, measure anonymous App Store and Google Play interest, provide support, prevent misuse, and improve reliability.
We do not sell personal information. We do not use it for third-party advertising or cross-app tracking.
Services that process information
We use specialist providers only where needed to operate Let’s Build It!. We require providers receiving family information to protect it to the same or an equivalent standard described in this policy, including purpose-limited processing, appropriate security and the stated retention controls. Their own terms and privacy practices also apply.
- Convex for accounts, application data, generated projects, and file storage.
- Apple and Google for parent sign-in, and Apple or browser speech services where used.
- Apple App Store and StoreKit for subscriptions, one-time top-ups, transaction verification, purchase restoration, refund requests, and server notifications.
- Google Gemini for voice and direct AI processing. OpenRouter routes project-generation requests to Google, xAI, Microsoft Azure, Together AI and Fireworks AI. Project icons are generated by OpenAI GPT Image 2.5 Sunburst through OpenRouter using the project title, without the conversation transcript or profile details.
- Sentry for privacy-scrubbed crash, performance, and optional support diagnostics.
- Expo, Apple Push Notification service, and Firebase Cloud Messaging for parent-enabled notifications.
- Cloudflare Email Service for parent PIN reset and waitlist verification email, Cloudflare Workers for the public marketing site and web app, and Cloudflare Workers Analytics Engine for anonymous aggregate counts of App Store and Google Play button clicks. Those click events contain only the store selected and where the button appeared, not an email address, account ID, cookie, or fingerprint.
How long we keep data
Account, profile, project, and generated content stays available while the account is active. Full conversation text is removed within 24 hours after a successful build in normal operation, and in all cases within seven days. Failed or abandoned conversation text is also removed within seven days. A short project brief and editing history stay with the project. Soft-deleted kids, projects, versions, generated files, project state, diagnostic reports, and disabled push tokens are purged within 30 days.
Expired or used parent PIN reset records are purged within seven days. An unverified waitlist signup is deleted after its 24-hour verification link expires. We keep a verified waitlist email until launch notifications are complete or the person asks us to remove it. Backup copies may remain until provider backup cycles expire. We target a maximum of 90 days and do not use those copies for normal product operation.
App Store server-notification records are used for billing security, duplicate-event prevention, and reconciliation. This includes records that cannot be linked to an account or arrive while account deletion is in progress. They contain limited event metadata and an optional payload hash, not the signed notification payload, and are purged no later than 90 days after receipt.
We may retain de-identified aggregate usage and cost information that no longer identifies a family. We may also retain information where the law requires it.
Account deletion and parent choices
A parent can delete the account from Parent Settings. Access and sessions are revoked immediately, and primary application data is deleted through a bounded process within 30 days.
Account deletion does not cancel an Apple subscription. The app warns active subscribers and provides Apple’s subscription-management screen so they can cancel before deleting the account. Billing records linked to the account are included in the staged deletion process. Because Apple can send server notifications independently during or after deletion, limited billing and reconciliation metadata may arrive or be recreated after a deletion stage has run. We do not use that metadata to restore the deleted account, and provider-event records are purged no later than 90 days after receipt. Apple keeps its own App Store records under its terms.
Parents can choose whether to allow microphone, speech, and notification permissions. A parent can ask to access, correct, or delete information by contacting privacy@letsbuildit.app. Additional rights may apply depending on where the family lives.
Security and international processing
We use access controls, encrypted transport, provider privacy settings, short retention periods, and content-scrubbed diagnostics to protect family information. No online service can promise absolute security.
Our service providers may process information outside Australia, including in the United States and other regions where their infrastructure operates.
Contact and policy changes
Privacy questions and data requests: privacy@letsbuildit.app
General support: support@letsbuildit.app
Legal correspondence: legal@letsbuildit.app
We may update this policy when the product, providers, or legal requirements change. The latest version will always be published at letsbuildit.app/privacy with its effective date.