Privacy policy

Last updated: May 26, 2026

The Tiny Steps Company, doing business as Clear Day (“we,” “our,” or “us”), provides software for daycare centers, preschools, and private pre-K and K-5 programs (the “Service”). This Privacy Policy explains what information we collect, how we use it, who else touches it, how long we keep it, and what rights you have.

1. Who Uses Clear Day

Clear Day is a business-to-business service. Our customers are the licensed childcare programs that subscribe to the Service. Within each program, the Service is used by:

  • Staff: directors, teachers, and administrators at the program.
  • Parents and guardians: the families enrolled at, or evaluating, the program.

Children themselves are not users of the Service. Information about children is entered by authorized staff and is processed by Clear Day on behalf of the program.

2. Information We Collect

  • Account information for staff and parents: name, email address, phone number, relationship to the child, and credentials needed to sign in.
  • Information about children entered by staff: name, date of birth, photos shared by teachers, attendance, daily activity logs (food, naps, toileting, mood, incidents), milestones, and notes the program chooses to record.
  • Billing and payment information: invoice records and payment status. Card and bank details are processed by Stripe and never stored on Clear Day’s infrastructure.
  • Messages and family communications: the content of messages exchanged through the Service between staff and families, including any files (such as images and PDFs) that staff or parents attach to those messages.
  • Technical and usage data: device type, browser, IP address, and first-party interaction events used to operate the Service and diagnose issues.

3. How We Use Information

We use the information above to operate the Service for the program that collected it: maintain attendance and daily records, send messages and updates between staff and families, draft routine communications for staff approval, process tuition payments through Stripe, surface tasks for staff (such as a quiet family or an upcoming tour follow-up), and prevent unauthorized access. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use customer data to train AI models.

4. AI and Drafting

Some Service features draft routine communications, surface families needing attention, and assemble brief summaries from existing records. The same models also extract structured fields from the text of a document a staff member pastes or uploads (for example, an application form), and clean up the dictated or typed text of a quick call recap into a log entry; in both cases the input is text the staff member provides; the Service does not upload or transcribe audio recordings. These features are performed by Anthropic’s API, which under its commercial terms does not use customer data to train its models; every call is routed through a single wrapper that cannot pass a training parameter, and a build check blocks any code path around it. Drafts of outreach to a family are presented for staff review, and no such message is sent without a staff member sending it. Two AI-written communications to families are delivered on a schedule rather than by staff action: the end-of-day report, sent at the time a school sets and subject to each parent’s own notification preferences, and the weekly family digest, which is sent to every family with an enrolled child and has no per-parent or per-school opt-out. The Service does not analyze or process child photos.

5. Children’s Privacy

The Service is designed for childcare programs and the staff and families they serve. It is not directed to children, and Clear Day does not knowingly collect personal information directly from children. The program (our customer) is responsible for obtaining any consents required to enroll a child and to use the Service on the child’s behalf.

When a parent or guardian believes information about their child has been collected or used improperly, they can contact us at [email protected] or reach their program directly. We will work with the program to correct, restrict, or delete the information as appropriate.

6. Subprocessors

Clear Day uses the following service providers to operate the Service. Each one performs a specific function, and none receive roster or child records for advertising.

  • Railway: application hosting, managed Postgres database hosting, and encrypted S3-compatible object storage, United States.
  • Stripe: payment processing for tuition and parent payments, United States.
  • Anthropic: AI inference for drafting features, under commercial terms that prohibit training on customer data, United States.
  • Resend: transactional email delivery and inbound email processing (so replies to Clear Day notifications post back to the right message thread), United States.
  • Expo: push notification delivery to mobile devices, United States.
  • Cloudflare: CDN and DDoS protection, global edge.
  • Sentry: application error reporting. Stack traces only; personal information is stripped before send, United States.
  • PostHog: first-party product analytics, configured without cross-site tracking and without ingesting child personal information, United States.
  • DocuSign: e-signature provider for signed enrollment and consent documents. Schools connect their own account via OAuth, United States.
  • Dropbox Sign: e-signature provider for signed enrollment and consent documents; same per-school OAuth model as DocuSign, United States.
  • Giphy: client-side GIF search when a staff member adds a GIF to a message; only the typed search term is sent, and no roster or child records, global.
  • Apple WeatherKit: weather forecast for the staff morning view; receives the school’s coordinates only, and no roster or child records, United States.
  • OpenStreetMap / Nominatim: geocodes a school’s address to coordinates so the forecast can be looked up; only the school’s city, state, and ZIP are sent, and no roster or child records, global.

The full list, with regions and purposes, also lives on our security page. Email [email protected] to be notified when the list changes.

7. Data Retention

We retain customer data for as long as the program uses the Service, plus a short window after a program cancels. Deleting an individual account works differently: it is immediate. The details are below.

  • Active accounts: information is retained while the program’s subscription is active so that records remain available for staff and families.
  • After a program cancels: the program’s data remains available for export for 30 days, and the cancellation can be reversed in full at any point in that window. After it, everything the program held is permanently deleted from our systems, including the photos, milestones, and messages its families read in their own accounts. Backups are purged on a rolling 90-day cycle. A family’s own login is not deleted with the program; the records that program shared are, so export before the window closes.
  • When someone deletes their own account: deletion takes effect the moment it is confirmed. We sign the account out everywhere, then replace the name and email address with a placeholder and disable the password in a single step. There is no grace period, no export window afterwards, and no way to restore the account, so export anything you want to keep before you confirm. There is no separate “family account” to delete: each parent and each staff member deletes their own login.
  • What a program still holds: a child’s record belongs to the program that enrolled the child, not to a parent’s login, so deleting a parent account does not delete it. It is retained under the program rules above. To have it removed sooner, ask your program or email us below.
  • On request: a program or a family may request earlier deletion at any time by emailing [email protected]. We confirm and complete deletion within 30 days.
  • Logs and security events: access logs and security telemetry are retained for up to 12 months and used only to operate and protect the Service.
  • Legal holds: where required by law, we may retain limited information for the period required to meet the obligation; this is rare and limited to what the law requires.

8. Sharing of Information

We do not sell personal information, do not share it for cross-context behavioral advertising, and do not disclose customer data to third parties other than (a) the subprocessors listed above, who handle data only as needed to provide the Service, and (b) where required by law or to respond to lawful process. We do not run advertising trackers on the marketing site.

9. Security

Customer data is encrypted in transit and at rest on US-based cloud infrastructure with role-based access controls. Parents see only their own child; staff see their own school, and no school’s data is visible to another. Changes to a child’s record, to billing, and to billing policy are each recorded with who changed what and when. Payment details are processed by Stripe and never traverse Clear Day’s own infrastructure. The full posture is on the security page.

10. Your Rights

Where applicable law gives you privacy rights, those rights apply. Under the California Consumer Privacy Act, as amended by the CPRA, you may exercise the following:

  • Right to know: request the personal information we hold about you or your child.
  • Right to delete: request deletion of that information.
  • Right to correct: request correction of inaccurate information.
  • Right to opt out of sale or sharing: we do not sell personal information or share it for cross-context behavioral advertising, but you may record the request regardless.
  • Right to limit use of sensitive information: request that we limit our use of sensitive personal information.

To submit a request, email [email protected]. You do not need a Clear Day account to do this , so a parent of a former student who no longer has a login can still exercise these rights. We confirm receipt within 10 business days and provide a full response within 45 days, in line with CCPA §1798.130. We verify your identity before fulfilling a request.

If you are a parent at a Clear Day program, you may also contact your program directly.

11. Updates

We may update this policy from time to time. Changes will be posted with a revised “Last updated” date at the top of this page. If a change materially affects how we use information, we will email account administrators in advance.

12. Contact

General privacy questions: [email protected]. Security and vulnerability reports: [email protected]. For everything else, [email protected]. Real humans read each address.

Last updated: May 26, 2026