Last Updated: January 4, 2026
Children's Online Privacy Protection Act Compliance
Vitasphere, Inc. (DBA HeroMe) is fully committed to complying with the Children's Online Privacy Protection Act (COPPA). This policy explains how we protect children's privacy and what rights parents have regarding their children's information.
1. Overview
COPPA is a U.S. federal law that protects the privacy of children under 13 years old. HeroMe is designed for children ages 3-12, so COPPA compliance is central to how we operate.
Key Principle: We collect information about children only from their parents or legal guardians, never directly from children.
2. Information We Collect About Children
We collect only the minimum information necessary to provide our service:
| Information | Purpose | Required? |
|---|---|---|
| First name only | Personalize stories with child's name | Yes |
| Age or date of birth | Age-appropriate content and pacing | Yes |
| Behavioral challenges | Therapeutic story customization | Yes |
| Comfort objects/interests | Story personalization | No |
3. Information We Do NOT Collect
We explicitly do NOT collect:
- Last names or full names of children
- Home addresses or school information
- Phone numbers of children
- Email addresses of children
- Photos, videos, or audio recordings of children
- Social Security numbers or government IDs
- Precise geolocation data
- Persistent identifiers for behavioral advertising
- Any information directly from children
4. Parental Consent
How We Obtain Consent
Before collecting any information about a child, we require verifiable parental consent:
- Parent creates an account using their own email address
- Parent explicitly agrees to our Terms of Service and Privacy Policy
- Parent provides a digital signature acknowledging they are the child's parent/guardian
- Parent enters the child's information themselves
Consent Verification
We use the "email plus" method for consent verification, which is approved by the FTC for services that collect limited information for internal use only. For higher-risk activities, we may require additional verification such as:
- Credit card verification (small charge, immediately refunded)
- Government ID verification
- Video call verification
5. Parental Rights Under COPPA
As a parent or guardian, you have the right to:
Review Information
Request a description of the types of information collected about your child and review the actual information. Access your child's profile anytime through your account dashboard.
Delete Information
Request deletion of your child's information at any time. Use the "Delete Profile" option in Settings or contact us at privacy@herome.ai.
Refuse Further Collection
Refuse to allow any further collection or use of your child's information. Note that this may require us to delete the child's profile and associated stories.
Withdraw Consent
Withdraw your consent at any time by closing your account or contacting us.
6. How We Use Children's Information
Children's information is used ONLY to:
- Generate personalized therapeutic stories
- Provide age-appropriate content and pacing
- Track reading progress within the family's account
- Improve our story generation algorithms (using anonymized, aggregated data only)
We NEVER use children's information for:
- Advertising or marketing to children
- Behavioral targeting or profiling
- Sale to third parties
- Any purpose unrelated to providing our service
7. Third-Party Sharing
We share children's information only with service providers who are:
- Necessary to provide our service (e.g., cloud hosting, AI processing)
- Bound by contractual obligations to protect children's privacy
- Prohibited from using the information for any other purpose
- Required to maintain appropriate security measures
Our service providers include:
- Supabase: Database hosting (data encrypted at rest)
- Vercel: Application hosting
- OpenAI: AI story generation (no data retention)
8. Data Security
We maintain strict security measures to protect children's information:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Access controls limiting who can view children's data
- Regular security audits and vulnerability assessments
- Employee training on COPPA compliance
- Incident response procedures for potential breaches
9. Data Retention
We retain children's information only as long as necessary:
- Active accounts: Data retained while subscription is active
- Inactive accounts: Data deleted after 12 months of inactivity
- Deleted profiles: Data permanently deleted within 30 days
- Closed accounts: All data deleted within 30 days
10. Contact Us
For questions about our COPPA compliance or to exercise your parental rights:
Vitasphere COPPA Compliance OfficerEmail: coppa@herome.ai
Phone: [Phone Number]
Address: [Company Address]
We will respond to all COPPA-related requests within 48 hours.
11. FTC Information
For more information about COPPA, visit the Federal Trade Commission's website at ftc.gov/coppa.
To file a complaint about a potential COPPA violation, contact the FTC at ftc.gov/complaint.