Privacy Policy — Storydew

Effective date: 2026-06-04 Last updated: 2026-06-04

Storydew ("we", "our", "the app") is a bedtime-story app for parents. This policy explains what data we handle, where it lives, and what control you have over it.


1. Who we are

Storydew ("we") publishes the Android app Storydew — AI Bedtime Stories under package com.adakast.storydew. Contact us at adakast2026@gmail.com.

2. The privacy promise

Storydew is built around a strong default: by default, your child's name, age, mood, sibling profiles, and any "recurring character" details never leave your device. This default is enforced at three layers:

  1. The app writes these fields only to local Android storage (SharedPreferences).
  2. Android Auto Backup mirrors that local store to your personal Google Drive quota (under your control, not ours).
  3. The server's database rules refuse to accept those fields on your main account record, even if a malicious client tried to send them.

The one exception is opt-in Cloud Backup — a premium setting that is OFF unless you turn it on. When you enable it, the app stores a copy of that child-profile data under your own account (users/{your-id}/private/localBackup, readable only by you) so you can restore it after a reinstall or on a new device. You can turn it off at any time, and deleting your account erases it. It is never shared with third parties or used for advertising.

Where premium-tier custom AI stories are stored in the cloud, the saved text uses the literal placeholder [CHILD_NAME] — your child's actual name is substituted back in only on your device when the story is displayed.

3. Data we collect

Always (free + premium accounts)

Data Why we have it Where it lives
Google account email Authentication via Google Sign-In Firebase Auth
Firebase Auth user ID Links your purchases + entitlements to you Firebase Auth
Google Play purchase token Server-side receipt verification Firestore, encrypted in transit
In-app purchase history Required by law to retain for tax purposes (7 years) Firestore + Google Play records
FCM token (optional) Only sent when you opt into Story of the Day push Firestore (delete on opt-out)
Crash reports Diagnose app failures (no personal content included) Firebase Crashlytics
Anonymized usage analytics Improve the product (event counts, no child data) Firebase Analytics

Free tier only

Data Why we have it
lifetime_trials_used counter Enforce the 10-lifetime cap on free AI deliveries
seen_pool_ids list (story ids only) Make sure each free trial returns a story you haven't seen

Premium tier only

Data Why we have it
Custom story text (with [CHILD_NAME] placeholder) Cloud-sync your library across devices while subscribed
Custom story narration MP3 Replay your custom stories without re-spending AI cost
Child-profile backup (only if Cloud Backup is ON) Restore your child's name, age, mood, sibling profiles, and recurring characters after a reinstall / on a new device

Data that stays on your device

By default these are never sent to our servers:

Exception — opt-in Cloud Backup (premium, OFF by default): if you enable Cloud Backup, the child-profile items above (name, age, mood, sibling profiles, recurring characters) are copied to your private backup record so they can be restored on a new device. Your favorites, reading history, resume positions, and notification preferences always stay on your device and are never backed up to our servers.

4. Third-party processors

We rely on the following providers, each bound by their own privacy terms. We never ship your child's name to them.

Provider Purpose Data shared
Firebase / Google Cloud Auth, database, file storage, push, crash reports, analytics Email, uid, purchase tokens, custom-story text (with placeholder), and — only if you enable Cloud Backup — your child-profile backup
OpenAI Generate the text of custom premium stories Anonymized story prompt + the child's name during the API call only — discarded at OpenAI per their no-training policy for API customers, never stored by us
ElevenLabs Narrate the text into MP3 audio Same prompt + name, MP3 returned to us and stored under your uid
Google Play Billing Process subscription + theme-pack purchases Purchase token, product id
Google AdMob (free tier only) Show banner / interstitial / rewarded ads Per Google UMP consent — see §6

5. Children's privacy & COPPA

Storydew is designed for parents to use on behalf of their children. It is not designed for children to operate on their own. We do not knowingly collect personal information from children under 13 (or the equivalent age in your jurisdiction).

The privacy architecture (child data local-only by default, placeholder in cloud story text, TFCD-tagged ad requests) is set up so that even if a child ends up holding the device, no identifying information about them is transmitted to us or to our processors beyond the runtime needed to narrate one story — unless you, the parent, explicitly enable Cloud Backup, in which case your child's profile is stored under your own account solely so you can restore it, and is deleted when you delete your account.

For ad serving in particular we tag every ad request with tagForChildDirectedTreatment = TRUE and tagForUnderAgeOfConsent = TRUE and request a maximum content rating of "G". This applies regardless of whether the device's Google account belongs to a child or an adult.

6. EU / UK consent (GDPR)

If you are in the EEA, UK, or Switzerland, Google's UMP (User Messaging Platform) consent form appears the first time the app starts, and is re-openable from Settings → Privacy → Ad preferences. You can withdraw consent at any time.

Legal bases (Art. 6 GDPR): - Authentication, purchases, custom story sync — performance of a contract (Art. 6(1)(b)). - Crash reports + anonymized analytics — legitimate interest in diagnosing failures and improving the product (Art. 6(1)(f)). - Personalized ads (free tier, EEA only) — your consent (Art. 6(1)(a)), withdrawable as above.

7. Your rights

You can exercise the following at any time, from any device signed into the same Google account:

8. Data retention

Data Retention
Email + uid Until you delete your account
Purchase tokens + tax records 7 years (legal)
Premium custom stories (text + audio) While your subscription is active; then a 7-day monthly / 14-day yearly read-only grace window after premium ends; then hard-purged by a daily cron
FCM token Until you disable Story of the Day or change devices
Crash + analytics events Per Firebase defaults (Crashlytics ~90 days, Analytics 14 months)
Inactive accounts We will notify you 30 days before deleting any account that has been signed out for 14+ months

9. Security

10. International transfers

Firebase hosts data in us-central1. If you sign in from the EEA, your data is transferred under Google's Standard Contractual Clauses.

11. Changes to this policy

We'll post any material change at the same URL and bump the "Last updated" date. Significant changes get an in-app notice the next time you open the app.

12. Contact

Privacy questions, data requests, complaints: adakast2026@gmail.com

For Play Store concerns you can also use the Google Play "report" flow.