Loading…
Loading…
Last updated 2026-09-20. See the Terms of Service for the rules of using the app.
Marker Sessions is built for adults to use. A child never creates an account, logs in, or interacts with the app directly, everything inside it is set up and used by a parent or guardian. Where this policy talks about a child’s name, birthday, or photo, that’s information a parent chooses to enter about their own child, not information collected from the child themselves.
Account information: your email address, and a password if you sign up that way. If you sign up with just your name and email, or through Google, we collect what those methods provide, your name, your email, and, for Google, whatever your Google account shares with us during sign-in.
Child profile information, entered by you: a name (which doesn’t need to be a real name) and, optionally, a birthday. Neither is verified. This exists so you can track favorites, session history, and notes across the children you run sessions with.
Photos you choose to upload: a photo of a session or a child’s work, only if you actively take or upload one. If you send a photo to someone else by email, we handle it only for that purpose.
Usage and session data: which sessions you’ve viewed, favorited, or logged, and basic activity needed to run the app, like login sessions and, on the native app, a push notification token if you have notifications enabled.
Payment information: not collected by us directly. Once subscription billing is live, payment is handled by Stripe, and we receive confirmation of your subscription status, not your card details.
To create and run your account, to remember your favorites, kids, and playlists across devices, to send you account-related email (verification, password reset, login codes), to send a photo where you’ve asked us to, and to keep the service secure and working correctly. We don’t use your data to train AI models, and we don’t sell it.
We share data with the vendors that run parts of the service, and only for that purpose:
Stripe processes payment and subscription information, once billing is live.
Resend sends account and transactional email on our behalf.
Vercel Blob stores uploaded photos.
Firebase (Google) delivers push notifications on the native app.
Google handles Google Sign-In, if you choose that option.
Our database runs on Prisma Postgres, hosted in Paris.
We don’t sell your information to anyone, and we don’t share it for advertising purposes. If that ever changes for any targeted advertising, we’ll update this policy and provide a way to opt out first.
As of the date at the top of this page, Marker Sessions doesn’t use advertising or tracking cookies. If that changes, we’ll update this section and, where required, ask for your consent before setting any non-essential cookie.
We keep account and session data for as long as your account is active. Information tied to a specific purpose, like a payment record, may be kept longer where we’re required to for accounting or legal reasons. If you delete your account, we delete or anonymize the data associated with it, other than what we’re required to retain.
You can access, correct, export, or delete your data, or ask us to stop processing it, by contacting us at the email below. We’ll respond within 30 days. If you’re in the European Union or UK, you also have the right to lodge a complaint with your local data protection authority.
For EU and UK users specifically: our processing has no minimum threshold under the GDPR, so these rights apply to you regardless of how large or small Marker Sessions is. At our current size, we don’t have a Data Protection Officer (not required unless processing is large-scale or systematic), haven’t conducted a formal Data Protection Impact Assessment (not required outside high-risk processing like large-scale profiling or special-category data, which we don’t do), and don’t currently have a designated EU representative (an exemption available while our EU processing stays occasional and low-risk).
Our database is hosted in Paris. Some of our vendors (Stripe, Vercel, Firebase) may process data in the United States. Where that happens, we rely on those vendors’ own Standard Contractual Clauses and data processing agreements as the transfer safeguard.
Marker Sessions is not directed at children, and no child ever creates an account or uses the app directly, a parent or guardian does. Because of that, the U.S. Children’s Online Privacy Protection Act (COPPA), which applies to services that collect data directly from children using them, doesn’t apply here. The same is true of the GDPR’s special rules for children’s consent, which are aimed at services offered directly to a child, not a service like this one that a parent uses on their child’s behalf. A child’s name, birthday, or photo that you enter is still real personal data, and we treat it with the same minimization principle as everything else here: it’s used only for the purpose you entered it for.
We may update this policy as the service changes. The date at the top of this page always reflects the current version. Continuing to use Marker Sessions after a change means you accept the update, so check back here if you want to know what changed.
Questions about this policy, or requests about your data, can be sent to support@markersessions.com.
What follows is the complete privacy policy governing how Marker Sessions processes your data. This is the document you actually agree to when you create an account, not the summary above.
This Privacy Policy describes how Jeffrey Ayache, the founder and current sole operator of Marker Sessions (“Company,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information in connection with the Marker Sessions website and mobile application (collectively, the “Service”). Company is, at this time, the data controller for purposes of the General Data Protection Regulation (“GDPR”) and the equivalent decision-maker for purposes of applicable U.S. state privacy laws. Company is in the process of forming a corporate entity to operate the Service; once formed, this section will be updated to identify that entity as the data controller.
“Personal Information” means any information relating to an identified or identifiable natural person. “Process” or “Processing” means any operation performed on Personal Information, including collection, storage, use, disclosure, and deletion.
3.1 Account Information. Your email address; a password, if you register using that method; and, if you register using Google Sign-In, your name and any additional information your Google account provides during authentication.
3.2 Child Profile Information. A name, which need not be the child’s legal name, and an optional birthdate, entered by you at your discretion.
3.3 User Content. Photographs and notes you choose to upload or create within the Service.
3.4 Usage Data. Sessions you have viewed, favorited, or logged; login sessions; and, on the native mobile application, a push notification token if you enable notifications.
3.5 Payment-Related Information. Company does not directly collect payment card information. Once website billing is active, Stripe, Inc. (“Stripe”) will process payment information on Company’s behalf, and Company will receive only confirmation of your subscription status.
We collect Personal Information directly from you when you register for an account, create a child profile, upload User Content, or otherwise interact with the Service, and from Google when you elect to authenticate using Google Sign-In.
We Process Personal Information for the following purposes: to create and administer your account; to provide, maintain, and personalize the Service, including favorites, child profiles, and playlists; to send you account-related communications (verification, password reset, and login codes); to transmit a photograph to a recipient you designate; and to maintain the security and integrity of the Service. Where the GDPR applies, our legal bases for these Processing activities are: performance of a contract with you (Article 6(1)(b)); our legitimate interests in operating and securing the Service (Article 6(1)(f)); and, where applicable, your consent (Article 6(1)(a)). We do not use your Personal Information to train artificial intelligence or machine learning models, and we do not sell your Personal Information.
We disclose Personal Information only to the following categories of third-party service providers, and only as necessary for them to perform services on our behalf:
Stripe processes payment and subscription information, once website billing is active.
Resend sends transactional and account-related email on our behalf.
Vercel Blob stores uploaded photographs.
Firebase (a Google service) delivers push notifications to the native mobile application.
Google provides Google Sign-In authentication, where you elect to use it.
Prisma Postgres hosts our database, in Paris, France.
We do not sell Personal Information, and we do not disclose it for cross-context behavioral advertising. If this practice changes, we will update this Policy and, where required, provide a mechanism to opt out before doing so.
As of the Last Updated date above, the Service does not use advertising or tracking cookies. If this changes, we will update this Section and, where required by applicable law, obtain your consent before setting any non-essential cookie.
We retain account and Usage Data for as long as your account remains active. Information tied to a specific legal or accounting purpose, such as payment records, may be retained longer where required by law. Upon deletion of your account, we delete or anonymize the associated data, except to the extent we are required to retain it by law.
9.1 General. Subject to applicable law, you may request to access, correct, export, or delete your Personal Information, or object to or restrict our Processing of it, by contacting us at the email address in Section 14. We will respond to verified requests within thirty (30) days.
9.2 European Union and United Kingdom. If you are located in the EU or UK, the GDPR and UK GDPR grant you the rights described in Section 9.1, as well as the right to withdraw consent at any time where Processing is based on consent, and the right to lodge a complaint with your local supervisory authority. These rights apply regardless of the size of Company’s operations, as the GDPR imposes no minimum processing threshold. At its current size, Company has not appointed a Data Protection Officer, as this is not required for organizations whose processing is not large-scale or systematic; has not conducted a formal Data Protection Impact Assessment, as this is not required outside of high-risk processing such as large-scale profiling or processing of special category data, neither of which Company undertakes; and has not designated a representative in the European Union, in reliance on the exemption available where such processing remains occasional and low-risk.
9.3 Other Jurisdictions. If you are located in a U.S. state or other jurisdiction that grants you statutory privacy rights, we will honor requests made pursuant to those rights to the extent required by applicable law.
Our database is hosted in Paris, France. Certain of our service providers, including Stripe, Vercel, and Firebase, may Process Personal Information in the United States. Where Personal Information is transferred outside of the European Economic Area or United Kingdom, we rely on those providers’ Standard Contractual Clauses and data processing agreements as the applicable transfer safeguard.
The Service is not directed at children, and no child creates an account or otherwise interacts with the Service directly; the Service is used exclusively by a parent or legal guardian. Because the Service does not collect Personal Information directly from children, the U.S. Children’s Online Privacy Protection Act (“COPPA”) does not apply to Company’s operations. For the same reason, the GDPR’s special provisions governing a child’s consent to information society services, which apply to services offered directly to a child, do not apply here. Where a User enters a child’s name, birthdate, or photograph, that information is nonetheless treated as Personal Information subject to this Policy and is Processed solely for the purpose for which the User provided it.
We use commercially reasonable administrative, technical, and organizational measures designed to protect Personal Information against unauthorized access, disclosure, alteration, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We may update this Policy from time to time. The “Last updated” date at the top of this page reflects the date of the current version. Your continued use of the Service after a change to this Policy constitutes your acceptance of the updated Policy.
Questions about this Policy, or requests regarding your Personal Information, can be sent to support@markersessions.com.