Lanternprivacy

Privacy policy

Effective September 2, 2026. Lantern is run by Blue Camel Consulting LLC, a New York limited liability company, at 265 Sunrise Hwy. Ste. 1-452, Rockville Centre, NY 11570. Questions to privacy@lantern.family.

The short version

Lantern shows children videos their parents have set rules for. We sell nothing about you. There are no ads, no trackers, and no analytics scripts anywhere on this site. Your child never makes an account, never types a password, and never gives us their name. When you delete your family, it really deletes, and we hand you a receipt.

Who Lantern is for

Lantern is for children, roughly ages two to fifteen, watching under rules a parent sets. The account always belongs to the parent, who must be an adult. A child never has an account, and children under thirteen use only the viewing surface their parent made for them.

What we collect from you, the parent

Your email address, to sign you in and send you invites you asked for. If you join the waitlist, the note you write about how you found us. When you sign in, the short line your browser sends describing itself, kept with the session so you can see which devices are signed in. A display name for each child that you choose. We tell you on the setup page to pick a nickname, and we never use it as an identifier. Each child's age band, the dial settings you pick, and any reason you type when you change a dial. If you use the "work out their settings" helper, the sentences you type about your child. If you report a bug, the sentence you write, the page you were on, which child's page it was, the line your browser sends describing itself, and a screenshot if you attach one.

We do not ask for your name, address, or phone number. We do not store passwords; you sign in from an emailed link. Our application code never reads or records your IP address.

What we collect from your child

As little as we can while still doing the job. The child's page needs no account and no login. It works from a private link only your family holds. It sets no cookies. It stores two kinds of thing in the browser itself: a random id, made up on the spot, that marks the browser and not the child, and a running count of minutes watched today, which is how the daily limit works. The random id is the same if two of your children share one tablet, which is how we can tell one device with two kids from two devices with one. We do not build it from your child's link or anything about them. It is saved next to their play records in your family's own storage, so within your family it does connect a device to a child. It goes nowhere else.

When your child watches a video, likes it, asks for it, or taps "tell a grown-up," we record which video and when, in your family's own storage. That record exists so your weekly report and their shelf work.

Your child's page has a search box. What they type stays on the device: it filters the shelf that is already loaded, and it is never sent to us in any request, never saved to any database, and never sent to YouTube. It does show up in the page's own web address, the way search boxes usually do, so if the page is reloaded mid-search that word arrives at our server inside the address and sits in our host's request log for a few days. We do not read those logs for search words and we keep nothing from them.

Where the videos come from, and what Google sees

Videos play inside YouTube's own player, using YouTube's reduced-tracking player domain. When a video plays, your child's device talks to Google to fetch the video and its thumbnails, the same as any site that embeds YouTube. Google sees the device's address and which video was requested, and it learns the request came from a Lantern page, because the embed says so. It does not receive your child's link, name, nickname, or the random id described above. Video titles are fetched from YouTube when a page is drawn rather than kept by us long term.

If discovery is on, we search YouTube for new videos using the interest words you typed for your child, on your key if you have added one and otherwise on ours. Those words travel to YouTube as search terms with no name attached. Videos we consider get screened by an AI reading service before your child can see them; what we send it is the video's public details or its public link, plus the same fixed list of questions we ask about every video, never anything about your family.

If you add your own screening key and it is a free one, Google's terms for unpaid use let Google use what we send on it to improve Google's products, and let a person there read it. What we send does not change: a public video link or a video's public details, and our own fixed questions, never your child's name, link, age band or viewing. Your key also screens some videos for the shared library, which is what saves every family from paying to screen the same video twice, so what it sees is not only your children's candidates. When you have added no key, the screening we do for your family runs on our own key, which is billed and so sits under Google's paid terms. Videos that reach the shared library are screened on whichever key that night's run used, which may be another family's free one; that call names no family and carries nothing about any child. You can move your own key to the paid side at any time by turning on billing for it. The screening key page explains this at length.

The companies that help us run Lantern

Each of these processes data to do one job for us. None of them may use it for anything else, and none of them gets more than the job needs.

Google, for the YouTube player, thumbnails, video details, and video search, as described above. Google Gemini, for reading and screening public video details. Anthropic, whose Claude reads the sentences you type in the "work out their settings" helper, and writes your weekly report card paragraph from your child's display name, age band, limits, and that week's viewing totals; we say this on the pages where it happens. Cloudflare, which hosts the site and stores our data. Modal, which runs the nightly jobs that build each child's shelf. Invites are sent through Gmail. Stripe takes payment for paid plans: it sees your name, email, billing address and card, and we see none of the card. Nothing about your child goes to Stripe.

What we never do

We never sell data, to anyone, about anyone. We never show ads. No third party runs any code on our pages, and nothing here reports your child to an advertiser; the child's page technically cannot load third-party scripts even if we made a mistake, because the page's own rules forbid it. The one outside connection is YouTube's own player, on its reduced-tracking domain, and the section above says exactly what it sees. We never build a profile of your child for any commercial purpose. We never share one family's rules, verdicts, or viewing with another family. What families do share is knowledge about videos: when our readers score a video, that score is about the video, carries nothing about any child, and saves the next family from paying to screen it again.

How long things last

Sign-in sessions last thirty days. Play-count summaries that help rank videos keep no child identifier and are pruned after thirty-five days. Our cache of video details from YouTube refreshes or deletes itself on a thirty-day clock. Our host keeps ordinary request logs for a few days. A record of any payment you made is kept for as long as tax law requires, even after you delete your family. Everything else about your family lasts until you delete it, and you can delete it at any time.

Your controls

Both live in settings. "Download your family's record" hands you your family's whole database as one file, whenever you like. "Delete this family" asks you to type DELETE, then deletes everything: every child, every setting, every stored sentence, every screenshot, your family's whole storage area, and every link your kids' devices hold. We keep three things: a dated marker that a family existed and was deleted, the deletion receipt we show you, and our own monthly record of what running your family cost us, which is a family id, a month, and a dollar figure and nothing else. There is no undo. You can also rotate or retire a child's link at any time, and the old link stops working immediately. If anything here does not work, write to privacy@lantern.family and a person will do it by hand.

Children's privacy

Everything about a child is created by the parent, inside the parent's account. The child's surface accepts taps on videos and a search of their own shelf, and nothing a child types leaves the device. We collect no name, contact detail, precise location, or photo from a child. There is one lasting id: the random per-browser id described above. It exists so the daily limit works and so a parent can tell devices apart in their own report. It is not used to advertise, not used to build a profile, and never recognises your child anywhere else, and it never leaves your family's own storage. If you believe we hold something about a child that we should not, write to privacy@lantern.family and we will delete it.

Security

Sign-in tokens are stored only as hashes. If you add your own screening key, it is encrypted with a per-family wrap and the plain text never appears in our database, our logs, or our job payloads. The child's page runs under strict browser rules that block every destination except us and YouTube's player.

Changes

If this policy changes in a way that matters, we email the parents. The date at the top is the date the words below it took effect. This is an invite-only alpha run by a small family company; if a promise here ever has to weaken, we will say so plainly rather than quietly rewording.