Privacy Policy
Last updated: 1 October 2026
Masaldan Erdeme ("the App", "we", "us") is a storytelling app made for children and operated by WITE Bilişim Teknolojileri A.Ş., Huzur Mah. Azerbaycan Cad. No:4B/262, Sarıyer/İstanbul, Türkiye. This policy explains what we collect, why, and the choices you and your child have. The App is designed to be used by a child under the supervision of a parent or guardian ("you"); it works without an account or sign-in and never asks for an email address, password or phone number.
1. Our approach to children's privacy
- No accounts, and your data lives on your device first. The App works without an account or sign-in: there is no email, no password, and no Sign in with Apple or Google. Used on a single device, the household, child profiles, activity and library are stored on your device and backed up only through your personal iCloud account on iPhone/iPad, or Google's device backup on Android. If you link your family's devices with optional family sync, this data syncs through our server end-to-end encrypted; we cannot read its contents (see Section 2, "Family sync"). For subscription verification and story credits, anonymous Adapty profile IDs, a digest of the purchase identity, subscription dates, usage and credit adjustment records are stored privately on Cloudflare; these records hold no name or email address.
- We show no advertising and use no tools for behavioural advertising. The service we use for subscription management (Adapty, see Section 6) runs without collecting the advertising identifier (IDFA) or IP addresses. Only if you grant the optional "Diagnostics" permission are crash and performance data processed with Google Firebase — without advertising identifiers and solely to keep the App stable (see Section 2).
- We do not sell or rent personal data, and we do not use it for behavioral advertising.
- Setup, settings and any purchases sit behind a parental gate.
- We collect the minimum information needed to run the App.
2. Information we collect
| Data | Why |
|---|---|
| Child profiles: a first name or nickname, an age, an avatar, a daily story limit and the downloads setting, entered by the parent. | To personalize greetings, choose age-appropriate content and apply parental limits. Stored on your device; if you turn on family sync, synced to your family's devices through our server only end-to-end encrypted — our server cannot read it. |
| App activity: stories opened and watched, favorites, watch-later, resume positions and daily viewing counts. | To provide "continue", favorites, and parental daily-time limits. Stored on your device; if you turn on family sync, synced to your family's devices only end-to-end encrypted. |
| Created stories: the story idea text, chosen characters and art style sent to our story-generation service, and the resulting story text, images and narration. | To generate a story and save it to your library. Your library entry lives on your device (synced encrypted with family sync). The story's images, narration audio, text and word timings are kept in our content storage under an unguessable link so the app can download them; these files are not end-to-end encrypted and anyone holding the link can open them, but they are not linked to your name or email address. |
| Characters: the name, description and drawn-portrait link of characters you create. | To reuse characters in later stories. Stored on your device; the drawn portrait sits in our content storage under an unguessable link. With family sync, the name, description and portrait link sync encrypted, and so does a reduced copy of the photo unless the family turns photo sharing off (see Photos). |
| Voice input (only if you use the microphone button): when a story idea is spoken, the recording is sent to our story-generation service purely to be turned into text, and from there to our AI provider (OpenAI, Whisper); as soon as the text comes back, both the temporary file on the device and the server-side copy are deleted. Voice search is converted to text by the device's own speech recognition (Apple / Google), on-device where supported; that audio never reaches our servers. | To let a child speak a story idea, however long. We do not keep the audio, do not link it to your identity, and do not use it for anything else. |
| Photos (only if you add a character photo): kept on your device. Only when you create a story is the photo sent transiently to our story-generation service for that one job: it is safety-checked first (the check is performed by OpenAI), then passed to our image-generation provider (OpenAI) as a reference so the character keeps the same look; the transient server-side copy is deleted when the job finishes. If you use family sync, by default a reduced copy of the photo (at most 512 pixels) is end-to-end encrypted on your device, stored inside the character's record on our server and sent to the family's other devices; we cannot see that copy. Turning off the “Share character photos” switch in Parent Area → Family deletes the copies from our server and the other devices, which then show the character without its photo; the photo stays on the device that picked it. | Shown as that character's picture and used so generated illustrations resemble the character. A story is never generated from a photo that fails the safety check. |
| Subscription status: purchases go through Apple's App Store or Google Play; our subscription-management service Adapty verifies the subscription state. | To unlock features, and with family sync, to unlock Premium on the family's other devices too (see "Family sync"). Payments are processed by Apple or Google; we do not receive card details. Adapty processes purchase/receipt information under an anonymous profile ID only; it does not collect the advertising identifier (IDFA) or IP addresses. |
| Consent records: which permission you granted or withdrew and when, the policy version and a device ID. | To keep a record of your consent (GDPR/KVKK accountability). Stored on your device; synced encrypted with family sync. |
| Connection data: like any web request, each request to our server carries an IP address, a time and a size. | To deliver the service, limit abuse (e.g. daily request caps) and keep it secure. Never used for profiling or advertising. |
| Diagnostic data (only if you grant the optional "Diagnostics" permission): crash reports and performance measurements, processed with Google Firebase (Crashlytics and Performance); on Android additionally limited usage statistics without advertising identifiers (Firebase Analytics, under the app-instance ID only — no advertising ID / AD_ID). No analytics tool is used on iOS. | To find and fix defects and keep the App stable. If you do not grant it, no diagnostic data is processed; you can withdraw the permission at any time in the Parent Area. It is never used for advertising. |
Family sync (optional)
Family sync runs only if you turn it on; if you don't, none of the data above is synced through our server. The Family screen sits behind the parental gate and requires a parent PIN (a device without one asks the parent to set a PIN first). To add a device, a parent gets a one-time 8-digit code valid for 10 minutes on the Family screen of a family device, enters it on the new device, and confirms that both screens show the same 6-digit number.
- What syncs: child profiles (name, age, avatar, daily limit, downloads setting), the library of created stories, characters (name, description, drawn-portrait link and, unless the family turns photo sharing off, a reduced copy of the photo), favourites, watch history, resume points, daily counts, consent records and device names (e.g. "Mum's phone"). Downloaded stories, the parent PIN, the app language and the full-size original photos stay separate on each device.
- End-to-end encryption: these records are encrypted on the device with AES-256-GCM and stored on our server (Cloudflare Durable Objects) only as ciphertext under meaningless IDs. The family key stays on the family's devices: on iPhone/iPad only in iCloud Keychain (end-to-end encrypted by Apple); on Android in the Google backup only when that backup is end-to-end encrypted (the device has a screen lock) — without a screen lock the key never leaves the device and the family is rejoined with the recovery code. Our server holds only a copy of the key locked with the recovery code, which we cannot open. That is why we cannot read, search or export family data for you.
- What encryption does not hide: encryption hides record contents (names, ages, favourites, limits, consent choices, device names), but not: which devices belong to a family, their platform (iOS/Android), when they joined and were last seen, and the IP addresses of their requests; how many records a family has, their approximate kind and size, when they change (including, coarsely, when a tale is being watched, since resume points are sent along with other syncs) and when items are deleted; an irreversible hash of the recovery code; and, during pairing, the code and one-time public keys.
- Created stories: we produce them; their text, pictures, narration audio and word timings are kept unencrypted in our content storage and may contain the names and ideas a family typed. Requests to create, open or delete a story come from the family's devices, so we can see which created stories a family's devices use. Story files sit under unguessable links; anyone who has a link can open it.
- Sharing Premium with the family: if one device in the family has Premium, it works on all of the family's devices, and the monthly story allowance is shared within the family. For this, our server knows the anonymous Adapty profile ID each family device uses for its subscription record, so it can see which of a family's devices has an active subscription and which subscriptions the family's stories are charged to. A family can have at most 10 devices.
- Removed or departed devices: a device keeps the family data and story delete keys it had at that moment, but can no longer reach our server as a family device; it could decrypt family records only if it obtained them some other way. When a device is removed or leaves, the recovery code changes: the old code stops working and the Family screen shows the new one.
- Retention: family records are kept until the family deletes them, or until no family device has checked in with our server for 24 months, after which they are deleted automatically. So that a deleted item cannot come back from another device, a content-free, encrypted deleted marker is kept until the family is deleted. See Section 7.
3. How we use information
- Provide and personalize the App and its parental controls.
- Generate stories, images and narration you request.
- Keep your library and settings stored on your device and, if you turn on family sync, sync them end-to-end encrypted between your family's devices.
- Provide customer support and keep the App secure and reliable.
4. Legal bases (GDPR/UK GDPR)
We process data based on your consent (given by the parent during setup), to perform our contract with you (running the App you set up and the family sync you turn on), and our legitimate interests in keeping the App secure and functional. You may withdraw consent at any time (see Section 9).
5. Children and parental consent (COPPA, GDPR-K, KVKK)
The App is intended for children with a parent's involvement. The parent performs the setup, provides the child's profile details, and consents to this policy on the household's behalf during onboarding — including on every device that later joins the family. We do not knowingly collect more personal information from a child than is reasonably necessary, we do not condition participation on disclosing more than necessary, and we do not enable children to make personal information publicly available. If you believe we have collected information from a child without proper consent, contact us and we will delete what we hold. Because we cannot read end-to-end encrypted family data or tell whose it is, that data is deleted with the in-app "Delete the family for everyone" option.
6. Service providers
We share data only with providers that process it on our behalf to run the App:
- Apple — App Store payments and subscriptions, on-device speech recognition for voice search, and the backup/sync in your personal iCloud (including, with family sync, the family key's copy in iCloud Keychain).
- Cloudflare — media delivery and storage (CDN), the infrastructure our story-generation service runs on, subscription and story-credit records, and the encrypted records of optional family sync (Durable Objects).
- AI model providers — OpenAI to generate story text and images, to turn a spoken story idea into text, and to run content-safety checks, and ElevenLabs to generate narration audio, solely from the idea, character details and recording you submit.
- Adapty — subscription verification and management; runs under an anonymous profile ID without collecting the advertising identifier (IDFA) or IP addresses.
- Google — Google Play payments and subscriptions, and Android's device backup (including, with family sync on a device with a screen lock, the end-to-end encrypted backup of the family key). Google Firebase — only with the optional Diagnostics permission: crash reports and performance measurements (on Android additionally usage statistics without advertising identifiers). Data is processed without advertising IDs and never used for advertising.
Unless you create a story or a character, no data is sent to the AI providers at all (when you create a character, the character's name/description goes to OpenAI for the portrait, and — if you added one — the character photo goes to OpenAI for the safety check). Each provider is bound to use the data only to provide its service. We do not sell data or share it for advertising.
7. Data retention
On a single device, your household, profiles, activity and library live on your device (and in your personal iCloud sync on iPhone/iPad, or your device backup on Android) and stay there until you delete them. You can delete everything instantly at any time from Parent Area → Privacy & data → Delete account & data; the deletion propagates to your iCloud copy as well, and a device in a family leaves the family first. The encrypted records of family sync are kept until they are deleted with Parent Area → Family → Delete the family for everyone, or until no family device has checked in for 24 months; Leave the family only unlinks that one device, and each device keeps its own local copy. The images, narration audio, text and word timings of stories you created are kept in our content storage until you delete the story in the App; deleting a story also removes its files from our server (stories made before version 1.2 are removed by their ID). Full-size character photos are never stored on our servers; with family sync, only an end-to-end encrypted reduced copy syncs, and turning photo sharing off deletes those copies too (see Section 2). Drawn character portraits are kept in our content storage; just email us if you would like them removed. Subscription and story-credit records are kept for as long as needed to track your allowance. Details: Delete data.
8. International transfers
Our providers (Cloudflare, OpenAI, ElevenLabs, Adapty and Google) may process the data sent during story generation, subscription verification, family sync and diagnostics in countries outside your own, including the United States and the EU. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
9. Your rights and choices
- Access, correct, export, or delete your data — in-app ("Export our data", "Delete account & data"; in a family also "Leave the family", "Remove from family" and "Delete the family for everyone") or by email. Because we cannot read end-to-end encrypted family data, we cannot export or correct it on request; it is managed from your family's devices.
- Withdraw consent and stop using the App at any time.
- Depending on your region (EEA/UK/Türkiye/California), you may have additional rights; contact us to exercise them.
10. Security
We use industry-standard measures: encrypted transport (HTTPS), the parent PIN kept in the device's secure storage (Keychain) only as an irreversible hash, and provider access controls. With family sync, records are encrypted on the device with AES-256-GCM, record IDs are made meaningless with keyed hashes (HMAC), and the keys never reach our servers in readable form; each device has its own credential (our server keeps only its hash), which stops working when the device is removed from the family, and the recovery code is renewed. The Family screen requires a parent PIN. A new device is added only after both screens show the same 6-digit number, which stops anyone in between from joining it to the family. No system is perfectly secure, but we work to protect your information.
11. Changes
We may update this policy. We will post the new version here and update the date above; material changes affecting children's data will be brought to the parent's attention in the App.
12. Contact
Questions or requests (privacy and support): [email protected].
WITE Bilişim Teknolojileri A.Ş., Huzur Mah. Azerbaycan Cad. No:4B/262, Sarıyer/İstanbul, Türkiye.