Updated 26 July 2026
Privacy Policy
A plain-language account of what Let’s Build It! handles when a parent and child create together, who processes it, and the choices a parent controls.
Who runs Let’s Build It!
Let’s Build It! by Cann Studios
Operated by Michael James Cann, an Australian sole trader.
ABN 25 719 492 087
This policy applies to letsbuildit.app and the Let’s Build It! app.
A parent-managed family app
Only a parent creates an account. A parent creates kid profiles, chooses settings and guardrails, and is responsible for a child using the creation tools.
There are no public kid accounts, public profiles, social feeds, advertising profiles, or public project sharing in the launch product.
Information we handle
We collect information needed to run the family account, generate projects, keep them available, provide support, and protect the service.
- Parent account details such as name, email, profile image, sign-in provider identifiers, and authentication records.
- Kid profile details chosen by the parent, including name, avatar, birth month or age, reading level, interests, boundaries, and optional guidance.
- Spoken and typed transcripts, project prompts, generated code and images, project state, titles, and editing history.
- Credit usage, model and provider usage, device and push-notification details, and technical diagnostics.
- Information a parent chooses to send when asking for support or submitting diagnostic feedback.
Voice, AI and generated projects
Microphone audio is streamed to speech and AI services so the app can understand an idea and respond. We do not store raw microphone audio in our application database, but the speech and AI providers process it while providing the service.
We store text transcripts and project content so families can continue conversations, revisit projects, edit them, and investigate failed builds.
Generated-project requests use zero-data-retention routing where supported. Google Gemini Live processes live voice directly. Google may temporarily retain content for abuse monitoring unless and until our production project receives written zero-data-retention approval.
How we use information
We use information to authenticate the parent, personalise kid profiles, create and edit projects, save the family shelf, operate launch credits, send requested notifications and reset emails, provide support, prevent misuse, and improve reliability.
We do not sell personal information. We do not use it for third-party advertising or cross-app tracking.
Services that process information
We use specialist providers only where needed to operate Let’s Build It!. Their own terms and privacy practices also apply to the information they process.
- Convex for accounts, application data, generated projects, and file storage.
- Apple and Google for parent sign-in, and Apple or browser speech services where used.
- Google Gemini Live, OpenRouter, and routed AI model providers for voice interaction and project builds.
- Sentry for privacy-scrubbed crash, performance, and optional support diagnostics.
- Expo, Apple Push Notification service, and Firebase Cloud Messaging for parent-enabled notifications.
- Cloudflare Email Service for parent PIN reset email and Cloudflare Workers for the public web service.
How long we keep data
Account, profile, project, and generated content stays available while the account is active. Full voice and text transcripts are kept for up to 30 days. Soft-deleted kids, projects, versions, generated files, project state, diagnostic reports, and disabled push tokens are purged within 30 days.
Expired or used parent PIN reset records are purged within seven days. Backup copies may remain until provider backup cycles expire. We target a maximum of 90 days and do not use those copies for normal product operation.
We may retain de-identified aggregate usage and cost information that no longer identifies a family. We may also retain information where the law requires it.
Account deletion and parent choices
A parent can delete the account from Parent Settings. Access and sessions are revoked immediately, and primary application data is deleted through a bounded process within 30 days.
If Sign in with Apple was used and the app cannot revoke the Apple credential automatically, the deletion screen explains how to remove Let’s Build It! from Sign in with Apple settings. Account deletion still proceeds.
Parents can choose whether to allow microphone, speech, and notification permissions. A parent can ask to access, correct, or delete information by contacting privacy@letsbuildit.app. Additional rights may apply depending on where the family lives.
Security and international processing
We use access controls, encrypted transport, provider privacy settings, short retention periods, and content-scrubbed diagnostics to protect family information. No online service can promise absolute security.
Our service providers may process information outside Australia, including in the United States and other regions where their infrastructure operates.
Contact and policy changes
Privacy questions and data requests: privacy@letsbuildit.app
General support: support@letsbuildit.app
Legal correspondence: legal@letsbuildit.app
We may update this policy when the product, providers, or legal requirements change. The latest version will always be published at letsbuildit.app/privacy with its effective date.