Bunny Path LLC ("we," "us," or "our") owns and operates Bunny Path, a parent-facing tool that surfaces a catalog of play ideas. The app is designed to be operated by parents and guardians, not by children directly. This Privacy Policy explains what information we collect, how we use it, how long we keep it, and how we protect it.
For our separate, staff-only Pinterest publishing tool, see Pinterest Publisher Privacy. That notice covers the internal publishing connection and its local credentials; the customer app and website data practices below remain separate.
1. Information We Collect
Information You Provide
- Account Information. When you create an account, we collect your name, email address, and authentication credentials (or an authentication token, if you sign in through a third-party sign-in provider). We do not store credit card numbers.
- Payment and Billing Details. If you subscribe on the web, you enter your card details directly on our payment processor's own hosted checkout page. We never receive or store your full card number; we keep only a payment token, the card brand and last four digits, and the billing country we need for tax. If you subscribe inside the app, the app store takes the payment and we receive only the resulting purchase record.
- Household Profile Fields. An age band is required when you set up a child profile so we can surface age-appropriate activities. We store an estimated birth date based on that band; you may optionally refine the birth date in Settings. A first name or nickname is optional. These fields are supplied by the parent, not by the child.
- Activity Preferences. You may tell us about the kinds of activities and focus areas your household is interested in.
- User-Submitted Content. You may optionally provide written feedback and ratings on activities. The app does not collect or upload photos.
- Search Text. We send the words you enter in search to our servers to find relevant activities. For semantic matching, our servers may send that text to OpenRouter, which uses an OpenAI embedding model to turn it into a numerical representation. We cache search text and these representations to make repeated searches faster. Operational logs may also contain an abbreviated copy of the search text. Please avoid including names, contact details or other personal information in your searches.
Information Collected Automatically
- Usage Data. Features used, activities viewed or saved, session duration, and device type. Usage events include pseudonymous app or device identifiers and, when signed in, your account identifier.
- Campaign Attribution. When included in a link used to open Bunny Path, we collect campaign metadata (such as source and campaign name) and ad-click identifiers and associate them with usage events to measure campaign performance.
- Approximate Location. Our product analytics provider infers your approximate city or region from your IP address. The app does not request GPS or precise-location permission.
- Device Information. Device model, OS version, app version, and app or device identifiers used for product analytics, crash diagnostics, subscription and entitlement management, and push notification delivery.
- Crash and Performance Data. Crash logs and performance metrics associated with a pseudonymous app installation identifier to improve stability.
Information We Do NOT Collect
- We do not collect last names, physical addresses, schools, photos, voice recordings, or precise geolocation about any child.
- We do not allow children to use the app directly.
- We do not share child-related data with third parties for profiling, advertising, or any purpose beyond what is strictly required to operate the app.
2. How We Use Your Information
- Personalize Activity Suggestions. Your child's age and preferences surface age-appropriate ideas from our catalog.
- Improve the App. Pseudonymous usage events and aggregated usage reports help us develop new functionality.
- Measure Campaign Performance. We use campaign metadata and ad-click identifiers associated with usage events to understand which campaigns bring people to Bunny Path.
- Communicate With You. We use your email for transactional messages and, if you opt in, promotional content.
- Process Payments and Subscriptions. We use billing details and purchase records to take payment, keep your subscription and entitlements current, handle renewals and refunds, and keep the tax records we are legally required to hold.
- Provide Customer Support. If you contact us, we use your information to respond.
3. Children
Bunny Path is designed for parents and guardians. The app is not directed at children under 13, and we do not knowingly collect personal information directly from children. The user of Bunny Path is an adult; child-related data is provided by that adult and used only to recommend age-appropriate activities.
- Adult-only gate. Only adults (18+) may create accounts. The app contains no child-facing surface, in-app purchase prompts directed at children, or chat features.
- Parent-supplied data only. Parents provide a required age band when setting up a child profile and may optionally enter a first name or nickname. We do not collect last names, schools, photos, voice recordings, or precise geolocation about any child.
- Minimum necessary. We store only what is required to surface age-appropriate activities inside that parent's own account.
- Deletion at any time. Parents can delete child-related data at any time via Settings → Delete account, or by emailing privacy@bunnypath.com.
- No advertising. Bunny Path contains no advertising of any kind, for children or adults. We do not use child-related data for profiling, behavioral targeting, or cross-context advertising, and we do not integrate any advertising SDK.
- No sharing for marketing. We never sell, rent, or share child-related information with third parties for marketing.
- COPPA contact. If you believe we have collected information from a child without parental consent, contact privacy@bunnypath.com; we will delete the information within 5 business days of verification.
4. Activity Catalog
Bunny Path's activity catalog is assembled and published in periodic batches. Activities are filtered and ranked against this catalog using your preferences inside our own backend.
- AI-Assisted Content. Activities may be created or edited with AI assistance before being added to the catalog. See Use of Artificial Intelligence in our Terms. They are not generated in real time from your child's data.
- No Cross-Site Profiling. We do not share child-related preferences with advertising or profiling networks.
- Activity Safety. Read the full instructions and safety notes, check suitability for your child and setting, and provide adult supervision throughout.
5. Sub-processors
We rely on a small set of vetted service providers to operate Bunny Path. We describe them here by the function they perform for us rather than by brand name, which is the "categories of recipients" disclosure that GDPR Article 13(1)(e) and the CCPA both provide for. Each provider is bound by a data-processing agreement that limits it to the purpose shown below.
| Category of recipient | Purpose | Region | What we share |
|---|---|---|---|
| App store distribution and in-app purchases | Distributing the mobile apps, and selling, billing, and validating subscriptions bought inside the app | USA / global | The purchase and subscription record tied to your store account. The store takes the payment, so we never receive your card details. |
| Payment processing (web subscriptions) | Taking card payments for subscriptions bought on the web, processing renewals and refunds, and issuing receipts | USA / global | Your name, email address, billing country, and the card details you enter on the processor's own hosted checkout page. We never see or store your full card number; we keep only a payment token plus the card brand and last four digits. The processor handles your payment details under its own privacy terms as well as under its agreement with us, including for fraud prevention and its own regulatory obligations. |
| Third-party sign-in providers | Letting you create and access your account with an existing platform identity instead of a password | USA / global | Only what passes at the moment you sign in: the authentication token and the email address you choose to share. |
| Push notification delivery | Delivering push notifications to your device | USA / global | A device push identifier and the content of the notification. |
| Cloud database, authentication, and file storage | Hosting our primary database, account authentication, and stored files under row-level security | USA | Your account record and the household profile, preference, and activity data described in §1. |
| Content delivery, edge compute, and DDoS protection | Serving the marketing site, running our edge worker and deep-link handler, absorbing attacks, and holding off-platform database backups | Global | Request metadata such as IP address, user agent, and the URL requested, plus backup copies of the database. |
| Crash and error monitoring | Diagnosing crashes and errors so we can fix them | USA | Crash logs and diagnostics, a pseudonymous app installation identifier, device model, OS version, and app version. |
| Product analytics | Product analytics, campaign attribution, and campaign performance measurement. Bunny Path displays no in-app advertising. | USA / EU | Pseudonymous app or device identifiers, your account identifier when signed in, campaign metadata and ad-click identifiers when present, approximate city or region inferred from your IP address, and usage events: features used, activities viewed or saved, and session duration. |
| Subscription and entitlement management | Validating purchase receipts and keeping your Premium entitlement in sync across your devices | USA | Your account and device identifiers and purchase or receipt metadata. No card details. |
| AI model routing and semantic search | Internal catalog processing and converting search text into numerical representations used to find relevant activities | See provider processing terms | Search text submitted in the app, sent through OpenRouter using an OpenAI embedding model; internal catalog data. |
These categories cover providers that receive customer app and website personal data from Bunny Path. The separate internal Pinterest publishing connection is described in Pinterest Publisher Privacy. Because the table describes functions rather than brands, changing which specific provider sits inside a category does not change the table, and any such change is still made under a data-processing agreement on the same terms. We will update the table if we add a new category of recipient, or if what an existing category receives changes; material changes will be communicated through the app or by email before they take effect.
If you want to know the specific providers we currently use inside any of these categories, email privacy@bunnypath.com and we will tell you.
6. Data Storage and Security
The following describes customer app and website data, not the internal publisher’s local credential files.
- Data is stored on a secure managed cloud database platform (see Sub-processors).
- All data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Access is restricted to authorized personnel on a need-to-know basis with row-level security.
- Passwords are hashed and never stored in plain text.
- In the event of a breach, we will notify affected users and relevant authorities per applicable law. Researchers can report vulnerabilities under our disclosure policy.
7. How long we keep your data
We keep data only as long as needed for the purpose it was collected. Some retention periods are legally required (for example, tax records on receipts and subscriptions), some are vendor defaults baked into the platforms we use, and others are our own policy. The table below summarizes the categories we hold and when each is deleted.
| Category | Retained | When deleted |
|---|---|---|
| Account record in our cloud database (email, child name, age band) | While active + 30 days after delete-account | Marked for deletion on Settings → Delete account. Contact privacy@bunnypath.com during the 30-day recovery period to request recovery. Permanent deletion begins after that period; backup copies and the limited retained categories below follow their own schedules |
| Activity completion / saved / streak / referral data | While active | Cascade-deleted with the account row at the end of the 30-day grace window |
| Welcome-trial eligibility record | Indefinitely, including after account deletion | Not deleted on a schedule, and deliberately not removed when you delete your account, because that would make deletion a way to reset the free welcome week. We store a one-way hash of your email address rather than the address itself; the hash is pseudonymous rather than anonymous, so we still treat it as personal data and will erase it on request to privacy@bunnypath.com |
| Crash and error reports | 30 days (provider default on our current plan) | Auto-rolling deletion by the crash-monitoring provider |
| Product analytics events | 12 months (provider default) | Auto-rolling deletion by the analytics provider |
| Edge and CDN access logs | Up to 7 days, retained by our content-delivery provider as part of its service | Auto-rolling at that provider; we do not separately store or export them |
| Database backups (off-platform object-storage dumps) | 90 days | Daily prune of dumps older than 90 days |
| Receipts / subscription records (legal hold for tax) | 7 years | The transaction record itself sits with whoever took the payment and is retained under that provider's own policy for tax compliance: the app store for a purchase made inside the app, or our payment processor for a web subscription. In both cases we retain summary subscription state alongside the active account, plus an internal audit log of subscription events for up to 7 years to satisfy tax-record obligations |
| Support email correspondence | Typically up to 2 years | Retained as long as needed for support continuity and account recovery, and purged on request |
If a category is missing from this table or you have a specific deletion request, email privacy@bunnypath.com.
8. Your Rights
- Access, correct, delete, or export your personal data.
- Opt out of marketing communications at any time.
- Withdraw consent for processing at any time.
Region-specific rights are described in California residents and EEA / UK.
9. California residents: your privacy rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the rights described below. To exercise any of them, email privacy@bunnypath.com or use in-app Settings → Privacy. We respond within 45 days, extendable to 90 days where the request is complex (we will tell you if we need the extension).
Your rights
- Right to know. The right to know what personal information we collect, use, disclose, and share, and how we use it.
- Right to delete. The right to request deletion of personal information we have collected. This is also exposed in-app at Settings → Delete account; see also how long we keep your data.
- Right to correct. The right to request correction of inaccurate personal information.
- Right to limit use of sensitive personal information. Bunny Path does not use sensitive personal information for any purpose beyond what is necessary to operate the service, but you may still ask us to confirm this.
- Right to opt out of sale or sharing. See below.
Do Not Sell or Share My Personal Information
Bunny Path does not sell personal information for money, and does not share personal information for cross-context behavioral advertising. Bunny Path contains no advertising and integrates no advertising SDK, so there is no ad partner to opt out of. We have no "sale" or "sharing" to disclose under the CCPA/CPRA.
If you would like this confirmed in writing for your records, email privacy@bunnypath.com with the subject line "Do Not Sell or Share" and we will respond.
Notice at Collection
At or before the point of collection, the categories of personal information we collect and the purposes are:
- Identifiers (name, email, account ID, and app or device identifiers), to operate your account, authenticate you, support product analytics and campaign attribution, diagnose crashes, manage subscriptions, and send transactional and (with consent) promotional messages.
- Customer records (parent-supplied child first name and age band, activity preferences), to surface age-appropriate activities inside your account.
- Internet/network activity (features used, activity views, session duration, crash diagnostics), to operate, debug, and improve the app.
- Commercial information (subscription status, receipt metadata, and for web subscriptions your billing country plus a payment token with the card brand and last four digits), to fulfill purchases, process renewals and refunds, and keep tax records.
- Geolocation, approximate city or region inferred from your IP address for product analytics; the app does not request GPS or precise-location permission.
We retain each category for the period described in How long we keep your data.
Authorized agents
You may designate an authorized agent to exercise these rights on your behalf. We will ask the agent to provide written authorization signed by you and may ask you to verify your identity directly with us before completing the request.
No discrimination
We will not deny service, charge different prices, or provide a different level of service because you exercised any of these rights.
Website privacy choices
Optional browser analytics is off until you choose Allow analytics. You can decline or change your choice using Privacy choices on our public website. We remember this preference in a functional cookie for up to 180 days. On bunnypath.com, the choice can also be read by the web app on app.bunnypath.com. A Global Privacy Control or Do Not Track signal keeps optional website analytics off.
If allowed, PostHog uses browser storage and cookies to measure website visits and account-link clicks. Declining leaves sign-in, activity links and invitation codes working. Changing to decline stops future optional collection and removes the marketing analytics identifiers accessible to this browser; it does not erase events already received.
Our server also counts page requests using a shared daily identifier, without a visitor cookie or retained visitor IP address in those events. It records page categories, valid activity IDs, response status, country and sanitized campaign tags, not raw URL queries, invitation codes or full referrer URLs. We suppress these counts when a request carries Do Not Track, Global Privacy Control, or a declined analytics preference. Hosting providers may separately process request data to deliver and secure the service.
Business mailing address: Bunny Path LLC, 3333 Preston Rd, 100N, Frisco, TX 75034, United States. Privacy requests: privacy@bunnypath.com.
10. Users in the European Economic Area / UK
If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent UK law give you the rights described below.
Legal basis for processing
- Legitimate interest, operating and improving the app, securing accounts, and preventing abuse.
- Performance of a contract, providing the service you signed up for, fulfilling subscriptions, and customer support.
- Consent, analytics where required, and marketing email; you may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation. Tax records on receipts and subscriptions, and responses to lawful requests from authorities.
Your rights
- Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
- Right to lodge a complaint with your local Data Protection Authority. You can find your DPA via the European Data Protection Board's directory.
How to exercise your rights
Email privacy@bunnypath.com; we respond within 30 days. We may ask you to verify your identity before completing the request.
EU / UK contact and representation
For EU and UK privacy matters, contact privacy@bunnypath.com.
Where applicable law requires a designated representative, their contact details must be provided separately. A minimum user count is not the test for that requirement.
International transfers
Most of the recipient categories listed in Sub-processors operate in or transfer data to the United States. That includes cloud database, authentication, and file storage; payment processing; app store distribution and in-app purchases; third-party sign-in; push notification delivery; crash and error monitoring; product analytics; subscription and entitlement management; and our back-office model routing. Content delivery and edge compute is global. Where personal data is transferred out of the EEA / UK / Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, plus supplementary measures such as encryption in transit and at rest. The full list of recipient categories is in Sub-processors.
11. Push Notifications and Email
- Push notifications are opt-in and can be disabled in device settings.
- Transactional email (verification, password resets, receipts) cannot be opted out of while your account is active.
- Marketing email requires consent; unsubscribe any time via the link in each message or in Settings.
12. International Data Transfers
If you are outside the United States, your data may be transferred to and processed in the U.S. We ensure appropriate safeguards for international transfers. EEA / UK / Swiss residents: see Users in the European Economic Area / UK for details on transfer mechanisms.
13. Security & vulnerability disclosures
We take security seriously. If you believe you have found a vulnerability in Bunny Path, we want to hear from you.
How to report
Email security@bunnypath.com. Please include enough detail for us to reproduce the issue (URL or endpoint, steps, expected vs. observed behavior, and any proof-of-concept). PGP key available on request.
What we promise
- We will acknowledge receipt within 72 hours.
- We will not pursue legal action against good-faith researchers who follow this policy.
- We will credit researchers in our disclosure notes (with permission) once a fix has shipped.
In scope
- Authentication, session management, and account-takeover paths.
- Data storage, anything that could expose, modify, or delete other users' data.
- Payment integrity (subscription state, receipt validation).
- Ad-network integrity (mis-attribution, click fraud against our account).
- Server-side configuration of
bunnypath.com, the marketing site, and our edge worker.
Out of scope
- Social engineering of our staff, users, or vendors.
- Physical attacks on our offices or hardware.
- Denial-of-service or volumetric attacks.
- Anything that requires the attacker to root or jailbreak the user's own device, or to have already compromised it.
- Reports generated solely by automated scanners with no demonstrated impact.
Bounty
We do not currently run a paid bounty program. We offer credit and a sincere thank-you. We will revisit this as Bunny Path scales.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app or by email before they take effect.
15. Contact Us
- Privacy and data-rights requests: privacy@bunnypath.com
- Security and vulnerability reports: security@bunnypath.com
- Terms-of-Service and other legal matters: legal@bunnypath.com
- General product support: support@bunnypath.com