TaleToaster

Privacy Policy

Last updated: September 17, 2026

TaleToaster ("we", "us", "our") is operated by Amit Bhawnani, a sole proprietor. This Privacy Policy explains how we collect, use, share, and protect information about you and your children when you use the TaleToaster mobile app and the public share-link pages on this website.

TaleToaster is designed for parents and guardians to use on behalf of children ages 2 through 12. Children do not create their own accounts and we do not knowingly collect any personal information directly from children under 13. If you are a parent or guardian and you do not agree with this Privacy Policy, please do not use TaleToaster.

TaleToaster displays no third-party advertising— no behavioral or contextual ads of any kind appear in the app. To measure our own app-install advertising, the app includes the Meta (Facebook) SDK for install attribution in a privacy-limited configuration: we never show Apple's tracking prompt, never access your device's advertising identifier (IDFA), and rely on Apple's aggregate SKAdNetwork reporting (see Section 3).

1. Information we collect

Account and guest-library information

Every library has a randomly assigned TaleToaster user ID. Where guest access is available, you can start without providing an email address or linking Apple or Google. A guest library is still stored on our servers and associated with this ID; it is not anonymous to TaleToaster. Linking an account is optional and lets you recover your library on another device.

  • Your assigned user ID and account-linking records, including connections between a guest library and a linked account
  • Email address, if you register or link an account (used for sign-in and account recovery)
  • If you sign in with Apple or Google, an opaque identifier and verified email from those providers

The app stores login credentials securely on your device to reconnect to your library. Restore Purchases can restore eligible App Store subscription access, but does not by itself recover an unlinked guest library. Uninstalling the app does not delete server-side data or cancel a subscription.

Child profile information (provided by you, the parent or guardian)

  • Each child's first name (used inside the story so the child is the hero)
  • Age tier (one of 2–3, 4–6, 7–9, or 10+ years — used to pick story complexity and language. We do not collect an exact date of birth.)
  • Gender (used so the story refers to your child with the right pronouns)
  • Optional: list of interests, names of friends
  • Optional: a one-line "Anything else?" instruction you may add for a specific story
  • Preferred narrator voice (male or female)

Stories and audio

  • Story text generated for your child
  • Audio narration of those stories. The narration speaks the child's first name verbatim, so the audio file itself contains personal data. We treat audio files with the same care as profile data and delete them when you delete the underlying story or your account (see Section 7).
  • The order in which saved stories appear in your playlist (manually reorderable from the app)

Limited service-quality logs

  • Story-generation events: theme used, story title, story length, time generated
  • Audio-generation events: voice used, success/failure, processing time
  • Feedback you submit through the in-app Send Feedback form
  • App launch and foreground activity: user ID, random session ID, first and most recent activity times, app version, and build number
  • Diagnostic events for troubleshooting: request IDs, errors, timing, device platform, and authentication, purchase, and generation outcomes. These diagnostic payloads exclude child names, story text, emails, passwords, and access tokens.

Subscriptions and story allowance

We store subscription status, product and transaction identifiers, purchase and expiry times, and renewal or cancellation information received through RevenueCat and Apple. We also record story and narration usage identifiers and timestamps, and associate them with an allowance group to preserve used allowance across account linking and subscription restoration. We do not receive your payment-card details from Apple. Limited allowance records remain after account deletion, as explained in Section 7.

What we do NOT collect

  • We do not access your device's advertising identifier (IDFA), location, or browsing history. The Meta SDK used for install attribution operates without the IDFA and without Apple's tracking prompt (see Section 3).
  • We do not collect biometric data or microphone audio of your child
  • We do not knowingly collect any information directly from children under 13
  • We do not display third-party advertising of any kind in the app

2. How we use the information

We use the information described above only to:

  • Generate personalized stories for your child by passing relevant child-profile information to our story-generation provider so the story stars your child by name
  • Generate audio narration through our audio providers
  • Save generated stories to your account so they appear in your playlist
  • Operate, secure, debug, and improve the service
  • Measure app activity and reliability, including onboarding and subscription outcomes
  • Restore subscriptions, combine libraries when you request account linking, enforce story allowances, and prevent repeated free-use abuse
  • Respond to your feedback and support requests

We do not use information about your children for advertising, profiling, or any purpose unrelated to running TaleToaster.

3. Sharing of information

We share the minimum information necessary with the following third-party service providers, each of whom processes the data on our behalf under their own confidentiality and data-processing terms. With the single exception of Meta (which measures installs from our own advertising, described below), none of these providers are advertising or marketing partners.

In particular, story text and audio narration are generated by third-party AI service providers acting on our behalf: Anthropic generates the story text, and our text-to-speech providers, ElevenLabs and MiniMax, generate the audio narration. We use these providers as service providers: we send them only what is needed to generate your story and narration, and we do not share your child's information with them for advertising, marketing, or any purpose of our own beyond creating your stories.

  • Supabase, Inc. (United States) — hosts our database, authentication, and audio file storage. Receives all data we store about you.
  • Anthropic, PBC(United States) — receives the child's first name, age range, gender, interests, friends' first names, theme title, and your "Anything else?" instruction (if provided), embedded in the story prompt, to generate the story text.
  • ElevenLabs, Inc.(United States) — text-to-speech provider; receives the finished story text (which already contains the child's first name as a story character) for audio narration. Receives no separate child identifier or profile information.
  • MiniMax(People's Republic of China) — text-to-speech provider; receives the finished story text (which already contains the child's first name as a story character) for audio narration. Receives no separate child identifier or profile information. Because MiniMax is based in China, this processing involves a transfer of the story text to the People's Republic of China (see Section 9).
  • Meta Platforms, Inc. (United States) — install-attribution partner for our own app-install advertising. The Meta SDK in our app auto-logs app-launch events and an SDK-generated anonymous identifier so Meta can measure ad campaign installs. It does notreceive your name, email, or any child or story information, does not access the device advertising identifier (IDFA), and we never present Apple's tracking prompt.
  • Google LLC / Google AI Studio (United States) — receives only theme metadata (title, description, category) for cover-image generation; never receives child profile information.
  • Apple Inc. and Google LLC — only if you choose to sign in with those providers; they verify your identity and pass us your email and an opaque user identifier.
  • Vercel Inc. (United States) — hosts the public share pages on this website.
  • RevenueCat, Inc.(United States) — manages our subscription state and processes purchase events from Apple's in-app billing. Receives your TaleToaster account identifier and subscription metadata (product and transaction identifiers, period, renewal status), including for guest users. Does not receive child profile information or story content.
  • Resend (Resend Inc.) (United States) — sends transactional account emails on our behalf (signup confirmation, password reset). Receives your email address and the body of those emails (which contain a one-time confirmation or reset link). Does not receive any child profile information or story content.

We do not sell your data. We do not share your account, child, or story data with advertisers, marketing networks, or data brokers. We do not share data with anyone for cross-context behavioral advertising. The only advertising-related data flow is the install-attribution signal to Meta described in Section 3, which contains no account, child, or story information. We may disclose information if required by law (e.g., a valid subpoena), in which case we will notify you unless legally prohibited from doing so.

4. Public sharing (the "Share" button)

Stories are private by default. When you tap "Share" inside the app, you authorize the creation of a public link of the form taletoaster.ai/s/<random-id>. Share links are public, unauthenticated URLs: anyone who has the link can open it, without signing in, and view that single story's cover image and title and play its audio narration. Be aware that the story title may include your child's first name, and the audio narration speaks your child's first name as a character in the story. (The full story text is not displayed on the share page.) The link does notexpose your child's age tier, profile information, your email, or any other account information.

You can stop a share link from working ("un-share") at any time by deleting the underlying story in the app, or by deleting your account. Once the story or account is deleted, the link returns "not found." If you are unable to do this from the app, email privacy@taletoaster.ai and we will disable the link for you.

5. Children's privacy (COPPA)

TaleToaster operates in compliance with the U.S. Children's Online Privacy Protection Act (COPPA). Children do not create their own accounts and we do not knowingly collect any personal information directly from children under 13. The parent or guardian starts the guest library or creates the account, creates the child profile, and provides any information about the child.

By creating a child profile, you (the parent or guardian) verify that you have the authority to provide the information about that child and you consent to our collection, use, and sharing of that information as described in this Privacy Policy.

As a parent or guardian, you may at any time:

  • Review the personal information we have collected about your child (visible in the app)
  • Edit any child profile (Settings tab → tap profile)
  • Delete a child profile (Settings tab → tap profile → "Delete this profile"), which removes the profile immediately. Saved stories remain in your library but are no longer linked to that specific child.
  • Refuse the further collection or use of your child's information by deleting the profile or your entire account

If you believe we have inadvertently collected information directly from a child without parental consent, please contact us at privacy@taletoaster.ai and we will delete it within 7 days.

6. Your rights — and how to delete your account

You can at any time, through the app:

  • View your child profiles and saved stories inside the app; request other account data using the export option below
  • Edit any child profile (Settings tab → tap profile → edit fields → Save)
  • Delete a child profile(Settings tab → tap profile → "Delete this profile" link at the bottom of the form). Two confirmation prompts protect against accidental deletion.
  • Delete your account or guest library in-app:
    1. Open Settings.
    2. Scroll to the "Danger Zone" at the bottom.
    3. Tap "Delete Account."
    4. Read the warning, tap Continue.
    5. You will be asked to solve a simple math problem (e.g., "27 × 8 = ?"). This step prevents accidental deletion by a child or by mistaken taps. Solve and tap Delete.
    When deletion succeeds, your authentication account, child profiles, saved stories, generated audio, public share links, feedback, and account-linked activity and diagnostic records are removed from the live service. Limited allowance and subscription-recovery records are retained as described in Section 7. You will be signed out. Deleting your account does not cancel an Apple subscription; manage cancellation in your App Store subscription settings.

If for any reason the in-app deletion does not work, you can also email privacy@taletoaster.ai. If you have a linked account, use its registered email address. For a guest library, include the Support ID shown in Settings. We may need to verify ownership before processing a request; a Support ID alone is not proof of ownership. We aim to complete verified deletion requests within 7 days.

Data export — email privacy@taletoaster.ai and we will provide a JSON archive of your data within 30 days.

European Economic Area, United Kingdom, Switzerland (GDPR / UK-GDPR)

If you are in the EEA, the UK, or Switzerland, you also have the right to:

  • Access, rectify, or erase your personal data
  • Restrict or object to certain processing
  • Data portability
  • Lodge a complaint with your local supervisory authority

Our lawful bases for processing are (a) your consent, in respect of child profile information, and (b) the performance of our contract with you, in respect of account information and content generated for you, and (c) our legitimate interests in service security, reliability, and preventing allowance abuse, subject to your applicable rights. Retaining limited records does not remove your right to request erasure or object to processing.

California (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect about you
  • Delete that information
  • Opt out of the "sale" or "sharing" of personal information — TaleToaster does not sell or share personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA
  • Limit the use and disclosure of sensitive personal information
  • Not be discriminated against for exercising these rights

7. Data retention and deletion specifics

We retain your account information and saved library to provide the service while you keep your account. Saved stories and narration do not expire after one year, and cancelling Pro does not delete your library. You can delete individual stories or your account at any time. We do not currently automatically delete libraries based on inactivity. When you:

  • Delete a story from the app, the story row, the cached audio file on your device, and the audio file on our storage are removed. Any public share link for that story stops working.
  • Delete a child profile, the child profile row is removed immediately. Any saved stories that were tied to that child remain in your library but are no longer linked to a specific child.
  • Delete your account or guest library, the app requests removal of your authentication record, profiles, stories, generated audio, share links, feedback, and account-linked activity and diagnostic records. Deletion is confirmed only after the server finishes the operation. If it fails, the app shows an error so you can retry or contact us. Copies already downloaded or shared outside TaleToaster cannot be recalled.

Technical records

  • Remote diagnostic events: scheduled for deletion after 30 days from the event timestamp.
  • Detailed story-generation, narration, login-funnel, and allowance-usage records: scheduled for deletion after 90 days from the event timestamp.
  • App-session records: scheduled for deletion after 90 days without activity in that session.
  • Temporary generation retry records: removed once their expiry is more than one hour old. These are separate from stories saved in your library.
  • Aggregate guest-generation cost counters: scheduled for deletion after 8 days.

Cleanup runs hourly. Account-linked diagnostics and activity records are removed earlier when you delete your account. Pre-sign-in activity that cannot be linked to your account expires under the 90-day schedule. These schedules apply to our live application database, not to Apple's or our service providers' independently maintained records.

Limited records retained after deletion: the former user ID and its allowance-group association; story and narration usage record IDs, types, and timestamps; and App Store transaction identifiers associated with that allowance group. These records prevent used allowances from being reset by restoring a subscription or linking accounts. They contain no child names, email addresses, profile details, story text, or audio, but remain pseudonymous identifiers rather than fully anonymized data. Detailed usage records expire after 90 days from their event timestamps. Unneeded identity mappings are scheduled for deletion 90 days after we identify that their allowance group has neither a surviving account nor a subscription binding. They do not restore a deleted library.

Subscription ownership and account-linking records are handled separately from disposable logs. They connect verified purchases to the correct allowance and account, including after a reinstall or a change of device. Subscription transaction bindings and the identity mappings still needed by an account or subscription currently have no automatic deletion deadline; the technical-log schedule does not erase a valid subscription. Access is restricted to our backend services and authorized operators. To ask us to review retention or exercise your deletion or objection rights, contact privacy@taletoaster.ai. We will assess the request and any permitted retention under applicable law. Apple and RevenueCat may separately retain purchase records under their own policies.

8. Security

We use industry-standard practices to protect your information:

  • All connections to TaleToaster servers use HTTPS / TLS 1.2 or higher
  • Stored data is encrypted at rest by our database provider
  • Access to our database is restricted to authenticated administrators
  • Row-Level Security policies in our database ensure each user can only access their own data
  • Per-user storage paths for generated audio prevent one user's deletion request from affecting another user's files

No system is 100% secure. If we discover a security incident affecting your data, we will notify affected users within 72 hours of discovery, as required by applicable law.

9. Cross-border data transfer

Information you provide will be transferred to and processed in the United States, where most of our service providers are located. In addition, when audio narration is generated by our text-to-speech provider MiniMax, the finished story text — which contains your child's first name as a story character, but no other profile or account information — is transferred to and processed in the People's Republic of China, where MiniMax is based (see Section 3). By using TaleToaster you consent to these transfers. Where required for users in the EEA, the UK, or Switzerland, we rely on Standard Contractual Clauses or other appropriate safeguards for these transfers.

10. Changes to this policy

We may update this Privacy Policy from time to time. The "last updated" date at the top of this page indicates the version. If we make material changes — for example, adding a new third-party processor, or changing what data we collect — we will post a notice in the app and, where we have a linked email address, notify users by email at least 30 days before the changes take effect.

11. Contact

Questions about this Privacy Policy or your data?