Privacy Policy
Effective Date: January 1, 2025
1. Introduction
Welcome to our Privacy Policy. This Policy explains how we collect, use, disclose, and protect your information when using the Taily mobile app ("App") - an application for creating personalized children's stories using artificial intelligence.
Please read this Privacy Policy carefully. By using the App, you consent to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Personal Data
We collect personal data that you voluntarily provide when:
- You register an account in the App
- You create a child profile
- You personalize story settings
- You communicate with our support team
- You use Premium features
This information may include:
- Parent/guardian email address
- Child's first name (without surname)
- Child's age
- Child's interests and preferences
- Preferred language
- App settings
2.2 App Usage Data
We automatically collect information about how you use the App:
- Device identifier (IDFA on iOS, Android ID on Android)
- Mobile device type and model
- Operating system version
- App version
- Time spent using the App
- Features you use
- App errors and crashes
- Performance analytics data
2.3 AI-Generated Content
When you use story generation features:
- Prompts and parameters entered by the user
- Generated story content
- Saved favorite stories
- Reading history (without detailed content)
- Story ratings and preferences
2.4 Audio Data (Premium)
For audio narration features:
- Audio data generated through speech synthesis
- Voice preferences
- Story listening history
2.5 Legal Basis for Processing
We process your data based on:
- Your consent (Art. 6(1)(a) GDPR)
- Performance of contract - Terms of Use (Art. 6(1)(b) GDPR)
- Our legitimate interests (Art. 6(1)(f) GDPR) - improving the App, analytics
- Legal obligations (Art. 6(1)(c) GDPR)
3. How We Use Your Information
3.1 Service Provision
- Creating and managing user accounts
- Generating personalized stories using AI
- Saving and synchronizing favorite stories
- Providing audio narration services (Premium)
- Personalizing content based on child's age and interests
3.2 App Improvement
- Analyzing usage patterns to improve functionality
- Optimizing AI algorithms for story generation
- Testing new features
- Fixing bugs and crashes
3.3 Communication
- Sending notifications about new features
- Responding to technical support inquiries
- Informing about important App changes
- Marketing (with consent)
3.4 Safety and Compliance
- Preventing abuse and fraud
- Ensuring content safety for children
- Compliance with children's data protection regulations
4. Children's Data Protection
4.1 COPPA and GDPR-K Compliance
- We do not knowingly collect personal data from children under 13 without parental consent
- All children's data is processed with the highest care
- Parents have full control over their children's data
4.2 Children's Data Minimization
- We collect only necessary information (name, age, interests)
- We do not ask for surname, address, or other detailed personal data of the child
- Children's data is used exclusively for story personalization
4.3 Parental Rights
Parents have the right to:
- Review their child's data
- Correct or delete their child's data
- Withdraw consent for processing their child's data
- Limit how their child's data is used
5. Information Sharing
5.1 We Don't Sell Data
We never sell, rent, or commercially trade your personal data or your child's data.
5.2 Service Providers
We may share data with trusted service providers who help us operate the App:
- Supabase - database hosting and backend
- OpenAI/Anthropic - AI content generation (data is anonymized)
- ElevenLabs - speech synthesis (Premium audio only)
- App Store/Google Play - payment processing
- Sentry - error monitoring
- Analytics providers - usage analysis (in aggregated form)
5.3 Legal Requirements
We may disclose data if required by law or in response to valid requests from public authorities.
5.4 Child Protection
We may disclose information if we believe in good faith that it is necessary to protect a child's safety.
6. Data Security
6.1 Encryption
- All data is transmitted using SSL/TLS encryption
- Data is stored in encrypted databases
- Particularly sensitive children's data has additional protection layers
6.2 Access Control
- Limited access to data only for authorized personnel
- Regular security audits
- Two-factor authentication for administrators
6.3 Risk Minimization
- Regular data backups
- 24/7 security monitoring
- Staff training on children's data protection
7. International Data Transfers
7.1 Data Location
Your data is stored on servers in the European Union when possible.
7.2 Transfers Outside EU
When necessary to transfer data outside the EU, we ensure appropriate safeguards:
- EU Standard Contractual Clauses
- Adequacy decision certifications
- Other legally recognized protection mechanisms
8. Data Retention Period
8.1 Account Data
- Account data: throughout the activity period plus 1 year after account deletion
- Child data: deleted immediately upon parent request or account deletion
8.2 Story Content
- Generated stories: stored only as long as the user wants to keep them
- Reading history: maximum 2 years in anonymized form
8.3 Analytics Data
- Analytics data: maximum 2 years in completely anonymized form
- System logs: maximum 90 days
9. Your Rights
9.1 GDPR Rights
You have the right to:
- Access - receive a copy of your data
- Rectification - correct incorrect data
- Erasure - request deletion of data ("right to be forgotten")
- Restriction - limit data processing
- Portability - receive data in a format enabling transfer
- Object - object to data processing
- Withdraw consent - withdraw consent at any time
9.2 Exercising Rights
To exercise your rights, contact us at privacy@tailyapp.io. We will respond within 30 days.
9.3 Complaints
You have the right to lodge a complaint with a data protection supervisory authority.
10. Cookies and Tracking Technologies
10.1 Mobile App
In the mobile app we use:
- Local storage - to save settings and preferences
- Device identifiers - for analytics and personalization
- Analytics SDK - to understand app usage
10.2 Control
You can control some of these technologies in your device or App settings.
11. Social Features
11.1 Sharing
The App may contain story sharing features:
- Sharing is done through standard system APIs
- We do not share children's personal data
- Parents control what can be shared
12. App and AI Updates
12.1 AI Improvements
- We regularly improve our AI algorithms
- All improvements comply with our children's safety standards
- New AI features are tested for content appropriateness
12.2 Security Updates
- Automatic security updates
- Notifications about important privacy updates
13. AI-Generated Content
13.1 Content Safety
- All AI content is filtered for child appropriateness
- We implement multi-level moderation systems
- Parents can report inappropriate content
13.2 AI Learning
- We use data in anonymized form to improve AI
- We do not use specific child data to train AI models
- All data used for learning is stripped of personal identifiers
14. Changes to Privacy Policy
14.1 Change Notifications
We will notify you of material changes to the Privacy Policy through:
- In-app notification
- Email to the address associated with your account
- App store update (for major changes)
14.2 Consent to Changes
Continued use of the App after changes are introduced means acceptance of the new Privacy Policy.
15. Contact Us
15.1 Contact Information
For questions regarding this Privacy Policy:
Email: privacy@tailyapp.io
Support: support@tailyapp.io
Website: tailyapp.io
15.2 Data Protection Officer
For questions regarding children's data protection, you may also contact our Data Protection Officer at: dpo@tailyapp.io
15.3 Supervisory Authority
You have the right to lodge a complaint with the data protection supervisory authority in your country.
16. Regulatory Compliance
16.1 International Compliance
Our privacy practices comply with:
- GDPR (European Union)
- COPPA (United States)
- PIPEDA (Canada)
- LGPD (Brazil)
- Local children's data protection regulations
16.2 Certifications
- We regularly audit our security practices
- We follow industry best practices for children's apps
- We work with children's online safety experts
17. Final Provisions
17.1 Language
This Policy was prepared in Polish. In case of discrepancies between language versions, the Polish version takes precedence.
17.2 Severability
If any provision is deemed invalid, the remaining provisions remain in effect.
17.3 Governing Law
This Policy is governed by and construed in accordance with Polish law.
Last updated: January 1, 2025