beansprout

Privacy Policy

Effective: September 17, 2026

This Privacy Policy (the "Policy") describes how Little Boat LLC ("Little Boat", "we", "us", or "our") collects, uses, discloses, and retains information when you use the Beansprout Journal application, website, and related services (together, the "Service"). Capitalized terms that this Policy does not define have the meaning given in the Terms of Service.

1. Scope and Operator

Little Boat LLC operates the Service and is responsible for the information described in this Policy. The Service is offered in the United States. This Policy applies to the Service and not to any third-party service that the Service links to or relies on.

2. Children

The Service is for account holders who are at least 18 years old. Little Boat does not knowingly collect personal information directly from children, and children do not create accounts or submit information. A journal may be about a child: parents, legal guardians, and other adult members of a Household decide what information about a child to enter and whom to invite. If you believe that a child has created an account, contact us at support@beansproutjournal.com and we will delete it.

3. Information We Collect

3.1 Account and profile information

Your email address, account identifier, display name, optional profile photo, sign-in method (email link, Google, or Apple), sign-in records, your acceptance of the Terms of Service and the version you accepted, and your app preferences.

3.2 Household and child information

The Household name and time zone, its members, their roles and family relationships, invites and the email addresses they name, and the child information that adult members enter, including child names, birth dates, sex, profile photos, firsts, and age milestone notes. Feed and sleep records created before those features were retired remain stored until the related account, child, or Household is deleted.

3.3 Journal content

The photos, videos, and their audio, capture dates, captions, comments, reactions, and other content that members add. During processing we remove source metadata such as GPS from stored photos and video outputs and keep the capture date so that each item can be placed in the journal. We also keep the dimensions, duration, content type, and crop and framing choices of each item.

3.4 Subscription information

If you purchase Beansprout Plus ("Plus"), we give RevenueCat your account identifier, and RevenueCat reports the subscription state the Store observes for it: the Store, the product, the subscription period, and its expiry and renewal state. We record which Household the subscription applies to. We never receive your payment method.

3.5 Notifications

If you enable notifications, a device push token, platform, registration dates, and delivery records. Push messages name the member who acted and what they added, but never include comment text or your Household name. Delivery records include internal notification, Household, and media identifiers.

3.6 Activity within your Household

A per-Household tally of which photos and videos each member opens, which powers Recap features, and a record of when a member opens a Recap. This information never leaves Beansprout and is never shown to other members.

3.7 Safety reports

The reporter and target identifiers, a reason, an optional note, a snapshot of the reported content or member details, moderator actions, and preservation status.

3.8 Operational and security information

IP address, request and device metadata, internal identifiers, upload grants and storage paths, authentication and invite artifacts, server errors and stack traces, and security and job logs. Our application logger removes query strings and known secret fields, and keeps only the route name of a request after replacing any identifier or token in it. Cloud hosting infrastructure can separately record full request URLs, including hosted invite-link paths, sign-in callback parameters, and export download links. Limiting that platform-level logging and its retention is an open production control.

3.9 Diagnostics

Beansprout collects a diagnostic error report when the app fails, so that problems can be fixed. Those reports carry the error and the app version, never your content, your email address, or an identifier for your device. During setup, Beansprout records which setup steps are completed using a random identifier created by your device. That identifier is not tied to your account and is not saved to it. The installed app also sends aggregate counts about its on-device cache and its video processing that identify no person, Household, or item.

3.10 Support

Messages you send to support contain whatever information and attachments you choose to include.

3.11 Legal requests

Removal requests, copyright notices, and counter-notices sent to us by email, whether or not the sender has an account, contain the sender's name and contact details, the statements the law requires, and a description of the content. We keep them in a restricted case system for the periods in Section 6.

4. How We Use Information

We use information to authenticate accounts, provide the private Household journal, process and deliver photos and videos, provide and administer Plus, send the notifications you request, apply the settings you choose, provide support, prevent abuse, investigate safety reports, enforce the Terms of Service and the Community Rules, secure and operate the Service, and comply with legal obligations. We do not use journal content to train artificial-intelligence models.

5. How We Share Information

5.1 With your Household

Household content and member profile information are visible to the other members of each Household you join or create, subject to role, blocking, and moderation controls.

5.2 With platform administrators

Our platform administrators can access safety reports and preserved content when needed for safety review and enforcement.

5.3 With service providers

We use the following providers, which process information to provide services to us under their agreements. Google Cloud and Firebase provide authentication, application hosting, media storage, push delivery, monitoring, and operational logs. Supabase hosts the application database. Apple provides Sign in with Apple and iOS push delivery, and Google provides Google Sign-In. The Apple App Store and Google Play bill Plus subscriptions, and RevenueCat manages subscriptions and validates store receipts. RevenueCat receives your account identifier and the subscription state the Store reports.

5.4 For legal reasons and business transfers

We may disclose information when required by law or legal process, to protect the rights, safety, or property of any person or of the Service, or in connection with a merger, acquisition, or sale of assets, in which case this Policy continues to apply to the transferred information.

5.5 What we do not do

We do not sell personal information, and we do not share it for cross-context behavioral advertising. There are no third-party advertisements, advertising SDKs, data brokers, cross-app trackers, or third-party analytics in the Service.

6. Retention

6.1 Active information

Account, Household, child, and visible journal information is kept while the related account or Household remains active.

6.2 Short-lived records

Sign-in handoffs expire after 10 minutes, upload grants after 15 minutes, and invite links after 48 hours. Raw upload staging files become eligible for deletion after one day. Device push tokens are removed on sign-out or account deletion, when the push service reports them invalid, or after 60 days without a registration refresh.

6.3 Original files

Media you upload keeps its viewable copies while the Household remains active. The stored original file behind a photo or video, which we use for full-resolution downloads, follows a separate schedule. In a Household without Plus, an original uploaded on or after August 21, 2026 is kept for at least 180 days, and we may remove it after that. Originals uploaded before that date are kept without a time limit. A Household on Plus keeps its originals while it stays on Plus, and the 180-day minimum starts again only if Plus ends.

6.4 Subscription records

Your subscription record and your RevenueCat customer are deleted with your account unless a paid period is still running. In that case the Household your subscription pays for keeps Plus until the period ends, and the record and the customer are deleted then.

6.5 Logs and safety records

Operational and security logs are kept for a limited period set in our cloud configuration. Safety reports, report snapshots, enforcement history, and hidden media may be kept longer when needed to investigate abuse, handle an appeal, prevent repeat harm, comply with law, or preserve evidence.

6.6 Legal request records

Records of intimate-image removal requests, suspension appeals, and other legal requests are kept for two years after the case closes. Copyright notices, counter-notices, and the record of which accounts they concerned are kept for three years after the case closes. A legal hold extends any of these. A photo or video hidden after a removal request is deleted 90 days after the case closes unless a legal hold or a child-safety obligation requires us to preserve it.

6.7 Backups

We do not restore deleted information from a backup except for disaster recovery or a legal preservation need. Information in database backups, if enabled, remains until the configured backup expires.

7. Security

We use encrypted connections, private media storage, access controls, and temporary signed media links. Information is stored in the cloud regions selected for the Service's systems, and a provider's delivery network may process it elsewhere. No method of transmission or storage is completely secure, so keep your own copies of anything irreplaceable.

8. Deletion and Your Choices

8.1 Deleting your account

You can delete your account from Settings, in the app or on the web. Deleting your account deletes your photos, videos, comments, and reactions in every Household you belong to, ends your memberships, and scrubs your profile. Deleting your account does not cancel a Plus subscription; your subscription record and your RevenueCat customer are deleted as described in Section 6.4.

8.2 Leaving a Household

If you leave a Household, or a Parent removes you from it, your photos, videos, comments, and reactions in it are deleted with you. If a Parent deletes a Household, all of its content is deleted for every member.

8.3 What deletion means

Deleted content becomes inaccessible immediately. Photo and video files are permanently removed through a 30-day recovery window followed by expiration of storage versions, generally within a further 30 days. Processing by storage lifecycle systems is asynchronous. To preserve database integrity, we retain scrubbed account, Household, and media tombstones after deletion. Account email, display name, and profile details are scrubbed, but tombstones can retain internal identifiers and non-file media metadata. A safety report or preservation record can retain a snapshot that identifies an account or content after deletion, for the purposes described in Section 6.5.

8.4 Correction and other choices

You can correct profile and child information in Settings, leave a Household to end its access to you, and disable notifications in your device settings.

8.5 Requests

If you cannot access Settings, or to ask about your information, email support@beansproutjournal.com and we will process the request. We may need to verify your identity before acting on a request.

8.6 Rights under state law

Depending on where you live, you may have the right to access, correct, or delete your personal information, and the right not to be discriminated against for exercising those rights. Submit a request to support@beansproutjournal.com.

9. International Users

The Service is offered in the United States, and information is processed and stored in the United States. If you use the Service from outside the United States, you understand that your information is transferred to and processed in the United States.

10. Changes to This Policy

We may update this Policy as the Service or its providers change. Material changes are posted on this page with a new effective date. When a change materially affects how we handle your information, we also revise the Terms of Service, and the Service asks you to review and agree before you continue.

11. Contact

Questions and privacy requests may be sent to Little Boat LLC at support@beansproutjournal.com.