What the Services collect, why we use it, which providers
process it, how long we keep it, and the rights available to parents.
Last updated: September 24, 2026 | Effective upon publication
Be The Monster Inc. (“BTM,” “we,” “us,” or “our”) operates the Dr. Seuss: Learn & Play mobile application (the “App”) and the website at drseusslearn.com (the “Website,” and together, the “Services”). Dr. Seuss Enterprises, L.P. is the licensor and owner of the Dr. Seuss intellectual property; it does not operate the Services or receive user information merely because its intellectual property appears in the App.
The App is directed to children ages 2–8 and their parents or guardians. This policy explains what information the Services collect, why we use it, which service providers process it, how long we keep it, and the choices and rights available to parents.
We do not:
We limit collection, use persistent technical identifiers only to support internal operations, protect private profile and learning records, provide parents with review and deletion controls, and obtain parental notice or consent where COPPA requires it.
Depending on the account and subscription path, we may collect:
We do not receive or store a payment-card number from Apple, Google Play, or Amazon. If website billing through Stripe is offered, Stripe processes payment-card details and sends us the account, customer, subscription, product, payment status, and transaction information needed to provide and support the subscription.
A parent creates a private child profile using:
Please use a nickname and do not enter a surname. The profile is visible only inside the authenticated family account and is never a public screen name.
The Services store child-linked progress needed to continue the experience and show parent reports, such as:
These records use an internal child record ID and do not contain a child email, phone number, physical address, precise location, photo, voice, or public content.
Firebase Analytics processes a randomly generated app-instance identifier and limited technical and usage information, such as app version, device/operating-system category, general country-level region derived from network information, session/activity timing, and low-cardinality feature or result events.
We configure Analytics for internal operations:
Google may process an IP address transiently to provide and secure the service and derive general region information. Google states that Google Analytics does not log or store individual IP addresses.
Our hosting, authentication, database, rate-limiting, email, job-processing, and monitoring providers may process limited information needed to operate and secure the Services, including:
We do not use this information for behavioral advertising.
We use PostHog to understand public-page visits, clicks, and performance and improve the Website. Analytics can include public page text, page URLs, referrers, and browser, device, and viewport information. We also use heatmaps and feature flags. Input values, element attributes, and sensitive email displays are masked, and authentication secrets are redacted from URLs. Public interaction tracking does not run in the parent portal or staff admin area. We do not enable PostHog person profiles.
Cookieless public-page analytics starts before you choose in the privacy banner. Accepting enables analytics cookies, browser storage, session recordings, and surveys. Rejecting continues analytics in cookieless mode, without session recordings or surveys; events still go to PostHog. You can change your choice through Privacy Settings in the page footer. Declining analytics cookies does not affect site access.
We also collect error and performance diagnostics on all pages, including the parent portal, staff admin area, and error screens. These diagnostics follow the same analytics cookie choice: cookieless before a choice or after rejection, and cookie-based after acceptance. Error reports remove original messages, stack traces, custom error types, and arbitrary properties; they retain a standard error type, handled status, technical SDK and browser information, and a page identifier. Performance diagnostics on private pages retain numeric web-vital measurements without interaction tracking.
We use c15t to store your privacy preference in a necessary cookie and browser local storage. This configuration keeps preferences in your browser and does not send them to a hosted c15t service.
Coloring artwork remains on the device. The App may ask for permission to save artwork to the device’s photo library or local storage. It does not upload the artwork, inspect the existing photo library, import photos into the child experience, or use the camera for this feature.
The App does not request precise-location permission. The App does not send push or local notifications.
We use information to:
We do not use children’s personal information for behavioral advertising, sale, independent third-party marketing, or non-integral disclosure.
The Services use a neutral grown-ups gate before parent-directed settings and account functions. The gate entry is not retained or sent to Analytics.
For subscription purchases, we obtain verifiable parental consent through a qualifying parent-associated subscription payment. On the purchase screen before the parent completes the purchase, the parent sees clear notice of the parent information we collect, how we use it, our non-disclosure position, and clearly clickable links to the Children’s Privacy Policy and Terms. The parent must affirmatively complete the purchase; without consent, the parent cannot subscribe.
This subscription consent covers the collection and uses disclosed at purchase, including the parent email used for account access, support, and optional parent communications and any later optional Apple or Google account linkage in the grown-ups area. Ordinary Terms of Service or privacy-policy links alone are not treated as verifiable parental consent.
Any legally required direct notice to a newly collected parent contact address is provided separately from marketing.
A parent may:
Self-service access, correction, and deletion require the parent to be signed in to the family account. Support is provided by ordinary email, including when the age-gated App opens the device email client. A request sent from the stored account email may be treated as authenticated to that account. A request from another address must complete a verification challenge sent to the stored account email or, if that channel is unavailable, provide minimally necessary transaction evidence. A child nickname, age range, book history, plan, or approximate subscription date is not sufficient authentication by itself.
To make a request, contact help@drseusslearn.com. We will respond within 30 days, or sooner if applicable law requires.
We do not sell or rent personal information. We disclose limited information only to operate the Services, comply with law, protect safety and rights, complete a business transaction with appropriate safeguards, or act with a parent’s authorization.
Our operational providers may include:
| Provider | Function | Information processed |
|---|---|---|
| Google/Firebase and Google Cloud | Authentication, Analytics, hosting, database, security, and infrastructure | Analytics app-instance and technical data; parent email and Auth UID for authentication; device IANA time-zone setting; private account/profile/progress records in hosted systems |
| RevenueCat | Subscription and entitlement management | Parent/family Auth UID as the App User ID; store, product, receipt or purchase token, entitlement, purchase history, and transaction status |
| Apple, Google Play, and Amazon | Store authentication, payment, subscription, and redemption | Store account and transaction information under the platform’s own policy; limited status/receipt information supplied to us or RevenueCat |
| Stripe, if website billing is offered | Website payment and subscription processing | Parent/customer contact, billing, subscription, product, payment status, and transaction information; BTM does not receive the full card number |
| Resend and the parent’s email provider | Transactional, security, support, and optional parent email | Parent email, message content, delivery and engagement status, and account/event tags needed for the communication |
| Axiom | Operational monitoring and incident investigation | Technical logs, errors, request metadata, and limited account identifiers only when needed for operations |
| Inngest | Reliable background jobs | Job/event data and limited account identifiers needed to complete the requested operation |
| Upstash/Redis | Rate limiting, caching, and short-lived operational state | IP-derived keys, request/account keys, and short-lived operational values |
| Unity Cloud Content Delivery, when remote content is enabled | Storage and delivery of downloadable game content | Connection IP irreversibly hashed by Unity on ingestion and provider-described approximate location; no precise location or player-entered content |
We require providers to process information only for the contracted service, apply appropriate security, and comply with applicable data-protection obligations. We review provider terms, data-processing and security materials, subprocessors, and relevant product settings before use and at least annually or after a material change or incident.
We maintain a written information security program proportionate to our company size, systems, and the limited data collected. Safeguards include managed cloud infrastructure, encrypted transport and provider-supported encryption at rest, authenticated account sessions, ownership checks, named administrator accounts with MFA or passkeys, least-privilege access, managed secrets, dependency and vulnerability review, monitoring and alerts, provider diligence, incident response, backups, restore controls, and recurring risk and program review.
No system is perfectly secure. We cannot guarantee absolute security, but we investigate and address suspected incidents and provide notices required by law.
We retain information only for the business or legal need stated below and delete or de-identify it when it is no longer reasonably necessary.
An account is active while it has a current paid or gift entitlement or the parent has authenticated activity in the App or Parent Portal. An account becomes dormant when it has neither a current entitlement nor authenticated activity. The dormancy period begins after the later of the entitlement ending or the last authenticated activity. We retain a dormant account for 24 months, then delete or de-identify the account and associated child-profile data, subject to the legal, transaction, security, and bounded-backup retention described below.
| Data class | Purpose and business need | Retention |
|---|---|---|
| Parent email, Auth UID, OAuth identity, time-zone setting, and preferences | Account access, communication, security, parent controls, and local-time reporting | While active and for 24 months after becoming dormant; then deleted or de-identified. If deletion is requested sooner, active-system purge follows a 30-day deletion period, subject to legal records and bounded backup expiry |
| Private child profile, settings, and progress | Personalization, continuity, and parent reports | While active and for 24 months after the account becomes dormant; then deleted or de-identified. Individual-child and whole-account deletions requested sooner remain recoverable for 30 days and are then purged from active systems, subject to legal records and bounded backup expiry |
| Firebase Analytics app-instance and event data | Internal operations, reliability, and product improvement | Event-level and user-level data each use a two-month setting; the user-level retention clock does not reset on new activity. Standard aggregated reports are not governed by these detailed-data retention controls. |
| Subscription, entitlement, receipt/token, and transaction status | Provide access, prevent fraud, support purchases, and meet tax/accounting obligations | While needed for the account and applicable legal/financial period; provider records follow the documented deletion or retention process |
| Support communications | Resolve requests, preserve decisions, and identify recurring issues | Two years after resolution, unless a legal dispute or other legal requirement requires longer |
| Security, service, and job logs | Prevent abuse, investigate incidents, and operate reliable services | Standard operational logs are generally retained for up to 30 days; required Google Cloud audit logs may be retained for up to 400 days; longer retention is limited to a documented incident or legal need |
| Backups and point-in-time recovery | Recover from outage, corruption, or accidental loss | Cloud SQL keeps a rolling set of seven automated backups and seven days of point-in-time recovery transaction logs. If the entire database instance is deleted, its final backup may remain for up to 30 days. Restored environments do not serve users until prior deletions and scheduled purges are reapplied |
Whole-family deletion currently uses a 30-day soft-delete period before active-system purge. Store billing is managed separately: deleting the account does not itself cancel, refund, or alter an Apple, Google Play, Amazon, or Stripe subscription unless the applicable product flow expressly says so.
Some providers retain limited legal, anti-fraud, security, transaction, or backup records under their terms. We do not restore deleted information to active use merely because a backup exists.
BTM is based in Canada. The Services and providers may process information in Canada, the United States, and other locations where the providers operate. Where required, we use contractual or other lawful transfer safeguards. Regional privacy rights may supplement the parent rights described above.
We may update this policy when the Services, providers, law, or data practices change. We update the “Last updated” date and provide additional parent notice or obtain new consent before a material change when required. Material changes to registration, parental notice/consent, child data, sharing, providers/SDKs, retention/deletion, or this policy are submitted to KidSAFE for review before release where the certification terms require.
Be The Monster Inc., Attn: Privacy Officer, 1005 Langley St, 3rd Floor, Victoria, BC V8W 1C6, Canada