Privacy policy
Effective 2 October 2026
Lantern connects to your family’s Yoto players so you can see what’s playing, look back at listening history, and change things from your phone. This page says what Lantern keeps, why, who else sees it, and how to get it back or delete it. Questions or requests: info@whiteboardworks.com.
What Lantern keeps
- Your account. Email address, a salted hash of your password (never the password itself), your family name, and the limits and rules you set.
- Your Yoto connection. The access and refresh tokens Yoto issues when you connect. They are encrypted before they are stored, and are never shown, logged, or included in exports.
- Your players. Each player’s name, id, model, battery, volume, sleep timer, and the card, chapter and track it reports.
- Raw player messages. Everything a player reports, stored as received so history can be rebuilt. Deleted automatically after 90 days.
- Listening history. Listening sessions built from those messages: which card played on which player, when, for how long, and how it stopped. Card titles are looked up from Yoto.
- Activity. A log of every change made to a player or a rule and who made it (you, a rule, the assistant, or a connected app), plus requests waiting for your approval and the alerts Lantern shows you.
- Connected apps. A hash of each access token you create for an MCP client, with the name you gave it.
- Assistant usage. How many AI tokens your family used each month, to enforce its allowance. Your conversations with the assistant are not stored on the server.
- Backups. A copy of the whole database is made nightly so Lantern can recover from a failure. Each backup is kept for 14 days and then deleted.
- Waitlist. If you join the waitlist, your email address, so we can invite you.
Lantern sets one cookie: a session cookie that keeps you signed in. There are no analytics, advertising, or tracking scripts.
Who else sees it
- Yoto, because Lantern signs in to your Yoto account (with your permission) to list your players, read what they report, and send the commands you, your rules, or an approved request ask for.
- Anthropic, only when you use Ask. Your question, the conversation so far, and the player and listening details needed to answer are sent to Anthropic’s API, which processes them to produce the reply.
- Apps you connect over MCP, which can read your players and history and request changes, within the limits and approvals you set.
Lantern doesn’t sell your data or share it with anyone else, and doesn’t use it for advertising.
Children
Lantern accounts are for parents and guardians. Listening history describes what played on your household’s players, not who was listening, and Lantern doesn’t knowingly collect personal information from children.
Your choices
- Download my data in Settings gives you a copy of your family’s data listed above, except passwords and tokens.
- Disconnect Yoto in Settings deletes the stored Yoto tokens and stops all connections to your players.
- Delete everything in Settings permanently deletes your account, family, players, history, rules, activity and tokens. Card titles that only your family played are deleted too. Copies in backups disappear as those backups age out, within 14 days.
- To be removed from the waitlist, or for anything else, contact info@whiteboardworks.com.
Security
Lantern is served over HTTPS, stores passwords and connected-app tokens only as hashes, encrypts Yoto tokens, and keeps every family’s data separate.
Changes
If this policy changes, the effective date above changes. This page always shows the current version.
Lantern is an independent beta and isn’t made by or affiliated with Yoto.