yearloom

Last updated: June 2, 2026

Privacy Policy

Yearloom is built by a single founder with the goal of preserving children's art beautifully. This page explains what we collect, what we don't, and how we protect your family's data.

We've kept this short and in plain English. If anything is unclear, email hello@yearloom.co.

What we collect

When you sign in with Google, we receive:

  • Your name and email address
  • A unique identifier from Google so we know it's you

When you use Yearloom, we collect:

  • The artwork images you upload
  • The first names you provide for your children (e.g., "Arlo")
  • The medium and short description you provide for each piece (e.g., "watercolor")
  • The captions our AI generates from your uploads
  • Basic usage information (when you signed in, which pieces you viewed)

If you subscribe, we collect billing information via Stripe (we never see your card number directly).

What we don't collect

We will never collect or store:

  • Your child's face or photograph of them
  • Your child's last name, birth date, or other identifying information
  • Your child's school, neighborhood, address, or location
  • Your child's voice or audio
  • Browsing data from outside Yearloom
  • Anything from your phone other than the artwork you choose to upload

Who we share data with

We share the minimum necessary data with these trusted providers to make Yearloom work:

  • Google: handles your sign-in
  • Supabase: stores your account and gallery data
  • Amazon Web Services (S3): stores your artwork images
  • Anthropic (Claude): generates the captions for your artwork (sees the image and your child's first name only)
  • Replicate: enhances artwork images (sees the image only)
  • Stripe: processes payments (sees billing info, never your gallery)

We will never sell your data to anyone. We will never use your child's name or artwork for advertising. We will never share data with marketers, data brokers, or third-party analytics services beyond basic usage tracking.

Email from Yearloom

By creating a Yearloom account, you agree to receive emails from us, including:

  • Welcome and onboarding messages
  • Important account and billing notifications (you cannot opt out of these — they're required to use the service)
  • Updates about new features and product improvements
  • Occasional notes from the founder about Yearloom's progress
  • Tips and inspiration for getting the most from your gallery

You can opt out of marketing and founder emails at any time via the unsubscribe link in any email, or by emailing hello@yearloom.co. You will continue to receive essential account notifications (billing receipts, security alerts, terms changes) for as long as you have an active account.

We will never share your email address with third parties for their marketing purposes.

How we protect your data

  • All data is encrypted in transit (HTTPS everywhere)
  • All data is encrypted at rest in our database and storage
  • Database access is restricted at the row level — you can only see your own data
  • Authentication is handled by Google, which has industry-leading security
  • We never store passwords (Google handles that)
  • Server access requires two-factor authentication

Your rights

You can, at any time:

If you're in the European Union, you also have rights under GDPR including the right to access, correct, port, or erase your personal data. Email us to exercise any of these rights.

If you're in California, you have similar rights under CCPA.

Children's privacy

Yearloom is designed for parents to use on behalf of their children. We do not knowingly collect any data directly from children under 13. The artwork you upload represents your child's creative work, but we never collect identifying information about them — only a first name of your choosing.

If you believe a child has somehow created an account on Yearloom without parental consent, please email hello@yearloom.co immediately and we will delete the account and all associated data.

Cookies

Yearloom uses minimal cookies — only what's required to keep you signed in and remember your preferences. We don't use tracking cookies, advertising cookies, or third-party analytics cookies.

Changes to this policy

If we change this policy, we'll email all active users at least 30 days before the change takes effect. We'll never change our data practices in ways that reduce your privacy without notice.

Contact

Privacy questions: hello@yearloom.co
General support: hello@yearloom.co

This policy was written by a real human (the founder) — not a legal team. We aim for clarity over completeness. If you spot something unclear or missing, please email us.