Privacy Policy
Last updated: August 21, 2026 · Effective: April 1, 2026
Sherwood Entertainment LLC ("Sherwood," "we," "us," or "our") operates the Sherwood Kids application and related services (the "Service"). This Privacy Policy explains how we collect, use, and protect information when you use our Service.
Sherwood Kids is a family reading and audiobook platform. A parent or legal guardian ("Parent") creates and manages the account, and children access the Service through profiles created by their Parent. We are committed to protecting children's privacy and complying with the Children's Online Privacy Protection Act ("COPPA"), the General Data Protection Regulation ("GDPR"), and the UK Age Appropriate Design Code.
Contact Us:
- Sherwood Entertainment LLC
- Email: help@sherwoodkids.com
- Address: 270 E Hunt HWY 16-243, San Tan Valley, Arizona 85143, United States
- Phone: (602) 456-7749
1. Information We Collect
1.1 Parent Account Information (Provided by You)
When a Parent creates an account, we collect:
- Name and email address — to create and manage your account and communicate with you about the Service
- Password — managed by our authentication provider, Google Firebase Authentication, and stored only as a cryptographic hash, never in plain text
- Payment information — processed by Stripe, Inc. We do not store credit card numbers, bank account numbers, or other payment credentials on our servers. See Stripe's privacy policy at https://stripe.com/privacy for details on their data practices
- Device identifier — a non-reversible hash of browser characteristics, collected at signup only, used solely to prevent abuse of free trial periods. This identifier cannot be used to identify you personally and is not shared with any third party
- Marketing attribution — if you reach us from one of our ads or marketing links, we record (once, at signup) the campaign parameters in that link — UTM tags and the advertising click identifiers attached to it (Meta's
fbclid/_fbc/_fbpand Google'sgclid) — together with the date first captured. We use this only to measure which marketing campaigns bring families to Sherwood and what each signup costs us (per-campaign customer-acquisition cost). We share it with Meta and Google for that measurement (see Section 3). If a ChatGPT ad link contains OpenAI's opaqueopprefvalue, our marketing site, signup page, or Parent subscription page may retain that value in a Sherwood first-party cookie so it can be used later if the Parent proceeds to subscription checkout. Landing on Sherwood or signing up is not reported to OpenAI as a conversion. The opaque reference is used only for the Parent subscription funnel, never a child profile - Shipping and contact information (for the free speaker) — if you qualify for our free speaker promotion (described in our Terms of Service) and we ship a speaker to you, we collect the shipping name, postal address, and phone number you provide at checkout (collected on our behalf by Stripe) so we can deliver it. This is associated with the Parent account only
1.2 Child Profile Information (Provided by the Parent)
Parents create and manage child profiles within their account. For each child profile, the Parent provides:
- Display name — this can be a first name, nickname, or any label the Parent chooses
- Age — used to filter content to age-appropriate material
- Avatar selection — a chosen character image, not a photo
- Content preferences — access mode (age-based or parent-curated), excluded content categories, and daily time limits
Children do not create their own accounts or provide any personal information directly. All child profile information is entered by the Parent.
1.3 Usage Information (Collected Automatically)
When child profiles use the Service, we collect:
- Reading and listening activity — which titles are accessed and for how long, tied to the child's internal profile identifier. This powers the family activity report available to Parents and helps us understand which content is engaging
- Reading position and preferences — current page or audio position, font size, and theme settings, so children can resume where they left off
- Library search queries — when you search our catalog, your search terms are sent to our servers to return results, and may be retained in our logs to improve search and recommendations. Search terms are associated only with the account or internal profile identifier, are never shown to other users, and are never used for advertising
We do not collect:
- Device advertising identifiers (IDFA, AAID)
- Precise geolocation
- Photos, videos, or audio recordings
- Contact lists
- Browsing history outside the Service
- Biometric data
1.4 Error Reports
We use Sentry for error monitoring to identify and fix technical problems. Before any error report leaves your device or our server, we strip all personally identifiable information including email addresses, IP addresses, usernames, cookies, and authentication headers. Only an anonymous account identifier is retained for debugging purposes. Sentry does not receive any information about children's identities or usage.
1.5 Personal Library (Optional)
Subscribers may upload their own ebook files to a personal library. Uploaded files are stored in a separate, encrypted storage bucket accessible only to the account holder. Files are permanently deleted when the account is deleted or when the subscriber removes them. Uploaded files are not shared with any third party and are not used for any purpose other than making them available to the account holder's profiles.
1.6 Device Permissions
The Service explicitly disables access to your device's camera, microphone, and geolocation through browser security headers. We do not request or use these permissions.
2. How We Use Information
We use the information we collect for the following purposes:
- Providing the Service — authenticating your account, delivering content, saving reading/listening progress, and applying content filters based on age and parental preferences
- Family Activity Reports — showing Parents a summary of their children's reading and listening activity
- Account Management — processing subscription payments, responding to support requests, and communicating about your account (billing, security, or service changes)
- Marketing and Onboarding Emails — when you create an account, we add your email address and first name (if provided) to our email list and send these messages through Amazon Web Services (Amazon Simple Email Service). We use this to send you a welcome series, occasional product updates, and information about your subscription. You can unsubscribe from marketing emails at any time by clicking the link at the bottom of any email. Unsubscribing from marketing emails does not stop transactional emails such as receipts, password resets, and account notices, which are required to operate your account. We do not add child profile information to our email list — only the Parent account email is used.
- Fulfilling the speaker promotion — if you qualify for a free speaker, we use the shipping name, address, and phone you provide to ship it and to resolve any delivery issues.
- Measuring marketing — understanding which campaigns bring families to Sherwood and what each signup costs and, for eligible ChatGPT ads, whether a Parent starts a free trial or makes the first successful subscription payment (see Sections 1.1 and 3).
- Building Meta advertising audiences — sharing your email address with Meta, in hashed form only, so we can reach families similar to our subscribers (see Section 3). We do not use Parent email addresses for OpenAI advertising audience matching. You may object to this processing by emailing help@sherwoodkids.com.
- Service Improvement — understanding aggregate content engagement to improve our library and recommendations
- Security and Fraud Prevention — protecting accounts and detecting unauthorized access
- Referral Program — if you participate, tracking referral codes and awarding subscription credits (see Section 7)
We do not use children's information for:
- Advertising or marketing of any kind
- Behavioral profiling or targeted content recommendations based on tracked behavior
- Sale or rental to any third party
- Training artificial intelligence or machine learning models
3. Information We Share
We share personal information only in the following limited circumstances:
| Recipient | What Is Shared | Purpose |
|---|---|---|
| Stripe, Inc. | Parent payment information (processed directly by Stripe, not stored by us) | Subscription billing |
| RevenueCat, Inc. | Anonymous account identifier | Subscription entitlement verification across platforms |
| Sentry (Functional Software, Inc.) | Anonymized error reports with all PII stripped | Error monitoring and service reliability |
| Amazon Web Services (incl. Amazon SES) | Encrypted content files and application hosting; and your email address and first name for sending account and marketing emails (Amazon Simple Email Service) | Infrastructure, content delivery, and email delivery |
| Firebase (Google LLC) | Parent email and hashed password | Account authentication only — we do not use Firebase Analytics, Crashlytics, or any other Firebase service |
| Meta Platforms, Inc. | One-way hashed Parent email, account identifier, Meta advertising cookies (_fbp, _fbc), IP address, browser user-agent, and campaign (UTM) parameters — collected at Parent signup/checkout, never from a child profile | Conversion measurement — attributing signups and subscriptions to the marketing campaign that drove them; and audience matching (see below) |
| Google LLC (Google Analytics / Tag Manager) | Pseudonymous site-usage and device/browser data and the Google Analytics cookie (_ga) for visitors to our marketing site and signup flow, never a child profile | Understanding site traffic and which campaigns drive signups |
| OpenAI, LLC (ChatGPT advertising) | Server-to-server Parent-subscription conversion events only: trial_started when a Parent starts a free trial, and subscription_created for the first successful paid subscription invoice. We send the event type, event time, source URL, Stripe price identifier, and a purpose-specific random event identifier used for retry idempotency and deduplication. A trial sends no amount; a paid event includes amount and currency. OpenAI's opaque oppref click reference is included when available. We do not report account registration, checkout initiation, or renewals | Measuring the performance of ads shown in ChatGPT by attributing Parent free-trial starts and first paid subscription conversions; events are marked to opt out of future user-level personalization |
| Shipping carrier / fulfillment partner (e.g., USPS) | Recipient name, shipping address, and phone | Delivering your promotional speaker (United States only) |
| Anthropic, PBC | If you contact support (email or the site chat): the text of your message, so our AI assistant can suggest or provide an answer. Support AI is clearly labeled as automated, never handles children's-data or privacy requests (those always go to a person), and Anthropic does not train on this data | AI-assisted customer support |
| OpenAI, LLC (support search) | Short text embeddings of support questions and our own help articles (used to find the relevant help article); no account identifiers | Support knowledge-base search |
Audience matching. We may share Parent email addresses with Meta in one-way hashed (SHA-256) form so Meta can match them against its own accounts, letting us show our ads to audiences similar to our subscribers. The address itself is never shared in readable form, and no child profile information is ever used this way. You may object to audience matching by emailing help@sherwoodkids.com. We do not send Parent email addresses or email hashes to OpenAI for ChatGPT advertising. Our server-only integration does not use OpenAI's Measurement Pixel or automatic advanced matching.
OpenAI advertising data boundary. Both events leave Sherwood's servers only after server-side confirmation of a Parent free trial or first successful subscription payment. Sherwood does not load an OpenAI advertising SDK or Measurement Pixel in any browser. Our OpenAI conversion code does not send Parent or child names, email addresses or email hashes, Sherwood account identifiers, Firebase identifiers, profile identifiers, Stripe customer, subscription, or invoice identifiers, child ages, reading or listening activity, payment-card details, end-user IP addresses, browser user-agent strings, OpenAI's browser-level obref, or a user object. It does not report child-profile activity, native-app activity, or non-production activity.
No child profile information — including names, ages, or usage data — is shared with any third party for advertising, marketing, analytics, or any purpose other than providing the core Service as described above.
We may also disclose information if required by law, court order, or governmental regulation, or if necessary to protect the safety of our users or the public.
4. Children's Privacy (COPPA Compliance)
Sherwood Kids is designed for families. We take children's privacy seriously and comply with the Children's Online Privacy Protection Act.
What We Collect from Children's Use
The only information associated with child profiles is:
- Profile settings entered by the Parent (display name, age, avatar, content preferences)
- Reading and listening activity (title accessed, duration, and progress position), tied to an internal profile identifier
- Reader display preferences (font size, theme)
We do not collect personal information directly from children. Children do not create accounts, communicate with others, or generate any content. Search terms entered to find titles are used only to return results and improve our library, as described in Section 1.3.
We Do Not Require Unnecessary Information
We do not condition a child's use of the Service on the disclosure of more personal information than is reasonably necessary to provide the reading and listening experience.
Parental Rights
As a Parent, you have the right to:
- Review the information associated with your child's profile, including their reading and listening activity (available through the Family Activity Report in the app)
- Delete your child's profile and all associated data at any time through the profile management settings
- Refuse further collection by deleting the child's profile or deleting your account entirely
- Request information about what data we have collected by contacting us at help@sherwoodkids.com
To exercise these rights, you may use the in-app profile management tools or contact us at help@sherwoodkids.com. We will verify your identity as the account holder before processing any request.
Data Retention
- Child profile data is retained as long as the profile exists. When a Parent deletes a child profile, all associated data (reading activity, progress, preferences) is permanently deleted.
- Parent account data is retained as long as the account is active. When a Parent deletes their account, all account data and all child profiles are permanently deleted.
- Error reports (anonymized) are retained by Sentry according to their data retention policy.
- Payment records may be retained as required by law for tax and accounting purposes, even after account deletion.
- Marketing attribution data (UTM tags and Meta/Google click identifiers, collected at Parent signup) is retained for the life of the account and permanently deleted when the Parent deletes their account.
- OpenAI advertising attribution and conversion data sent to OpenAI uses an opaque
opprefvalue for ad attribution and purpose-specific random event identifiers rather than a Sherwood account or profile identifier. Sherwood's internal delivery queue remains linked to the Parent account solely for deduplication, delivery, and deletion. Thesh_openai_opprefbrowser cookie expires after no more than 90 days unless you clear it sooner. If a Parent begins checkout, theopprefvalue may be copied to Stripe checkout/subscription metadata. Trial and first-paid conversion records, includingopprefwhen present, are copied to Sherwood's server-side conversion-delivery queue. The queue keepsopprefonly within OpenAI's seven-day event window and clears it sooner when delivery succeeds, delivery is permanently abandoned, or the account enters deletion. Any remaining Sherwood conversion-delivery record is deleted when account deletion completes. Copies in Stripe metadata are retained with Stripe's billing records under Stripe's retention practices. - Speaker shipping information is retained as needed to fulfill and document the promotion and to meet tax and accounting obligations, and is deleted when you delete your account except where retention is legally required.
5. Data Security
We implement technical and organizational safeguards to protect the information we collect, including:
- Encryption of data in transit (TLS) and at rest
- Hashed and salted storage of PINs using bcrypt; account passwords are managed by our authentication provider (Firebase Authentication) and are never stored by us in plain text
- Session-based authentication with server-verified cookies
- Role-based access controls for administrative functions
- Regular security review of our application and infrastructure
No method of electronic transmission or storage is perfectly secure. If you have reason to believe your account has been compromised, contact us immediately at help@sherwoodkids.com.
6. Cookies and Local Storage
We use a minimal set of cookies and local storage for functional purposes, plus a limited set of measurement cookies to understand which ads bring families to Sherwood:
| Type | Name/Purpose | Duration | Third-Party? |
|---|---|---|---|
| Session cookie | Authenticates your login session | 14 days | No |
| Session storage | Stores active profile selection and recent search queries | Current browser tab only | No |
| IndexedDB | Queues reading/listening activity data for batch sync | Until synced (pruned after 30 days) | No |
Meta advertising cookies (_fbp, _fbc) | Attribute a signup to the Meta ad that referred it; read at signup for conversion measurement (see Sections 1.1 and 3) | Up to 90 days (set by Meta) | Yes (Meta) |
Google Analytics cookie (_ga) | Distinguish visitors to measure marketing-site traffic and which campaigns drive signups | Up to 2 years (set by Google) | Yes (Google) |
Sherwood OpenAI attribution cookie (sh_openai_oppref) | Stores only an opaque OpenAI-provided oppref value when it appears in a ChatGPT ad link; used later only for Parent subscription attribution. Landing on Sherwood or signing up alone does not send a conversion | Up to 90 days | No |
| Support chat token (localStorage) | Created only if you start a chat on our site; lets the conversation continue if you reopen the page | Until you clear browser data | No |
Other than the Meta and Google measurement cookies and Sherwood's first-party OpenAI attribution cookie described above, we do not use advertising or tracking cookies. Sherwood does not load an OpenAI advertising SDK or Measurement Pixel in any browser, and it does not send child-profile activity or data as an OpenAI conversion. We do not use cookies or local storage to track children across websites or applications.
7. Referral Program
When you create an account, you are automatically provided a unique referral code and link that you can share to earn credit toward your subscription.
- What we collect: We track which referral code was used when a new account signs up, and whether the referred account activates a subscription. This data is associated with the referring Parent's account.
- What we share: We do not share your name, email, or any personal information with the person you refer, or vice versa. Referral tracking is handled through anonymous codes.
- Communications: We may send you information about the referral program by email. You can opt out of referral-related communications at any time through your account settings or by contacting us at help@sherwoodkids.com.
- Children's profiles: The referral program is available only to Parent account holders. Child profiles do not have access to referral features, and no child data is used in connection with the referral program.
8. Your Rights
All Users
You may:
- Access and update your account information at any time through the app
- Delete your account and all associated data by contacting us
- Contact us with questions or concerns about your data
United States Residents
Depending on your state of residence, you may have additional rights under state privacy laws, including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information.
European Economic Area, UK, and Swiss Residents
Under the GDPR and UK GDPR, you have the right to access, rectify, erase, restrict processing, data portability, and objection. Our legal basis for processing Parent account data is contractual necessity (providing the Service you subscribed to). Our legal basis for processing child profile usage data is legitimate interest in providing the Service, subject to parental rights described in Section 4.
Our legal basis for first-touch marketing attribution (Section 1.1) is our legitimate interest in measuring the effectiveness and cost of our marketing. To object to this processing or make another applicable privacy-right request, email help@sherwoodkids.com. You can also remove browser-stored attribution values by clearing cookies or site data.
To exercise any of these rights, contact us at help@sherwoodkids.com.
9. International Data Transfers
The Service is operated from the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (at the address associated with your account) or by a prominent notice within the app before the changes take effect. Your continued use of the Service after the effective date of a revised policy constitutes acceptance of the changes.
We will not reduce your rights or make material changes to how we handle children's data without providing renewed notice and, where required by law, obtaining fresh consent.
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your parental rights, or have concerns about how we handle your data:
- Sherwood Entertainment LLC
- Email: help@sherwoodkids.com
- Address: 270 E Hunt HWY 16-243, San Tan Valley, Arizona 85143, United States
- Phone: (602) 456-7749