Deleting your data
Masaldan Erdeme
Masaldan Erdeme works without accounts: it never asks for a name, email or password, and there is no user account on our servers. Your data lives on your device first. The only things our server can hold are: your family's end-to-end encrypted records if you turned on family sync (we cannot read them), the files of stories and character portraits you created, and one subscription/story-credit record — an allowance record derived from the purchase, keyed to an anonymous store identifier, holding no name or email. Most of the deletion is in your hands, and it is immediate.
1. Delete from inside the app (recommended)
In the app, go to:
Parent Area → Privacy & data → Delete account & data
The Parent Area is PIN-protected so a child can't reach it by accident. Once you confirm, deletion happens immediately and cannot be undone. All of the following is permanently removed from your device:
- Your household record and consent records
- Child profiles (name or nickname, age, and settings such as the daily time limit)
- Activity: favourites, watch-later, watched history and your resume position
- The library of stories you created, and downloaded stories
- The parent PIN held in the device's secure storage (Keychain)
- The sync copy in your personal iCloud (the cleared state is written to iCloud too)
- If the device is in a family: it leaves the family first and its family credential is deleted. The family's encrypted records stay on the server for the other family devices; to delete them too, use "Delete the family for everyone" below.
Deleting the app from your device also removes its on-device data; we still recommend running the in-app deletion first — it is the only way the iCloud sync copy and the PIN entry in secure storage get cleared as well. Deleting the app does not take the device out of a family: it stays in the family's device list until another family device removes it (Parent Area → Family → Remove from family).
2. What is and isn't on our servers
Full-size character photos are never stored on our servers — they stay on your device and are only processed transiently during story generation, then deleted. If you use family sync, a reduced copy of the photo is end-to-end encrypted and goes to the family's other devices inside the character's record, unless the family turns photo sharing off (see family sync records below). What our server can hold, and how it is deleted:
- Family sync records (only if you turned on family sync): end-to-end encrypted; we cannot read them or tell whose they are, so we cannot find and delete them from an email. Unless the family turns photo sharing off, character records also include a reduced copy of the photo (at most 512 pixels); turning off the “Share character photos” switch in Parent Area → Family deletes the copies from our server and the other devices. On any family device, Parent Area → Family → Delete the family for everyone immediately deletes all of the family's records, its device list and pending pairings from our server; each device keeps its own local copy. Leave the family unlinks only that device; when the last device leaves, the family is deleted. A removed or departed device keeps the data and story delete keys it had received, but can no longer reach our server as a family device, and the recovery code changes. If no family device checks in for 24 months, the family is deleted automatically.
- Files of created stories: images, narration audio, text and word timings, kept in our content storage under an unguessable link so the app can download them. Deleting a story in the app deletes its files from our server too (stories made before version 1.2 are removed by their ID). Delete any stories you want removed before you reset the device.
- Drawn character portraits: kept in our content storage under an unguessable link, not linked to your name or identity. Write to us if you would like them removed.
If you can no longer reach the app, or would like a file removed, write to us:
We complete requests within 30 days at the latest, and usually reply within 2 business days. An emailed request cannot locate end-to-end encrypted family records; those are deleted from inside the app or at the end of the 24-month period.
What is not deleted
- Purchase records. Subscription payments are processed by Apple or Google; billing records stay in the store's systems, which it is legally required to retain. You must cancel the subscription in your store account settings — deleting your data does not cancel a subscription.
- Subscription and story-credit record. The record that tracks your monthly story allowance and credits, keyed to a digest of the purchase identity or an anonymous Adapty profile ID; it holds no name or email and is kept for as long as needed to track your allowance.
- Any limited records we are legally required to keep (e.g. accounting records) are retained only for as long as required.
Remember to cancel your subscription
Deleting your data or the app does not automatically cancel an App Store or Google Play subscription. To cancel:
- iPhone / iPad: Settings → [your name] → Subscriptions
- Android: Google Play → your profile icon → Payments & subscriptions → Subscriptions
Any questions? See our Support page or the Privacy Policy.