Privacy Policy
Effective 15 July 2026 · Updated 2 September 2026 · Applies to StarryTime version 1.x for Android
The short version: in this version of StarryTime, your story library — every story's words and audio — lives on your device, not in a cloud library (our servers hold only short-lived delivery records for each story, including its text, for up to 30 days — see “How long we keep things”). We process the details you type in (like a first name and interests) only to write and narrate your stories. There are no ads, no advertising identifiers, and no behavioural tracking or ad profiling. The only things we collect beyond what a story needs are crash diagnostics and, only if you switch it on, anonymous usage statistics (see “Crash reports and optional usage statistics”). You can delete your account and the data we hold at any time, from inside the app or from this website.
This policy is deliberately version-scoped: it describes what the current version of the app actually does. If a future version changes how data is handled (for example, an optional cloud backup), we will update this policy and the in-app summary before that version ships.
Who we are
StarryTime is made by Geniosity. For anything in this policy, contact us at support@starrytime.app — see the contact page.
What the app is
StarryTime generates original short children's stories on demand and narrates them with expressive, AI-generated audio. Story text and narration are produced by artificial-intelligence models based on the choices and text you provide. A parent or guardian creates and manages the account; the app is then used by the whole family — including older children, under their grown-up's supervision — and is designed for listening by children roughly aged 3–12.
What we process, and why
1. Account information
- Email address and sign-in identity (Google Sign-In or email & password), used to create and secure your account. Story generation is a paid service for us to run, so an account is required even on the free plan to prevent abuse.
- During sign-up we ask for a birth year to confirm an adult is creating the account. It is checked on your device during sign-up and is not stored.
2. Story inputs
When you create a story, you can provide:
- a listener's first name, age range (3–5, 6–8, or 9–12), and interests;
- an optional free-text story idea (up to 300 characters);
- your chosen story style, narration style, narrator voice, and length.
These are sent to our servers and used to write and narrate your story. To do that, they are shared with our AI providers — Anthropic (story text) and ElevenLabs (narration audio) — solely to fulfil your request. The app asks you to use first names only and to avoid putting personal details in the story idea; please follow that guidance.
3. Service records
- Story job records (your story inputs, job status, and error details — and, once a story is finished, its title and text until the record expires) so the app can deliver your story and never charge a story credit twice for a failed generation.
- Usage counters (stories generated this month, story size metrics) to enforce the monthly story allowance on your plan and to monitor our costs.
- Subscription state from Google Play (whether your subscription is active), so premium features unlock. We never see your payment details — Google Play handles all billing.
- A one-time rating card: in this version, after your first story has played to its end, the next time you open the app it can show Google Play’s own rating card, once. Anything you type there goes to Google Play under Google’s terms; the app never sees it. You can also open our Play listing any time from Grown-ups to leave a rating.
- Story reports: if you report a story, we receive the story content, your reason, and your optional note so we can review it.
4. Crash reports and optional usage statistics
We use Firebase Crashlytics to learn about crashes so we can fix them. It is configured child-safe: advertising-ID collection is disabled and no personalised signals are gathered.
If you switch on Share anonymous usage statistics, the app also sends Google Analytics for Firebase anonymous usage events such as which screens are used, whether a story was made, played and finished, and whether the subscription screen was seen or a subscription was started, together with a random per-install identifier, app version, device model, OS version, language and country. The switch is off unless you turn it on, and you will find it during sign-up, in onboarding and in the Grown-ups tab. These events never include names, story ideas, interests or story text, and they are never used for advertising. We do not collect the Android Advertising ID, we have switched off Google signals and ads personalisation, and we do not link Analytics to any advertising product. Google keeps event-level data for 2 months. You can switch it off at any time from the same toggle, which also erases the analytics identifier on your device. Google explains how it handles this data at https://policies.google.com/technologies/partner-sites.
What stays on your device
- Your story library — all story text and narration audio.
- Listener profiles (a premium feature) — stored in the app's local database only.
- Your app settings and last-used story choices.
- Downloaded sleep-music tracks — the optional calming music that can play after a story is our own catalog content, streamed from our cloud storage and cached on your device. Choosing or playing it involves no personal data, and the music folder is excluded from backup.
Generated narration audio is placed in our cloud storage just long enough for your device to download it (see retention below). After that, playback is entirely local. Android's automatic backup may back up the app's database and settings to your own Google account when you have device backup enabled; the audio folder is excluded from backup.
How long we keep things
| Data | Kept for |
|---|---|
| Generated audio in cloud storage | Deleted automatically about 7 days after generation (your device downloads it within moments in normal use) |
| Story job records | Deleted automatically about 30 days after creation |
| Account record & usage counters | For the life of your account |
| Subscription/purchase verification records | Retained as required for billing integrity and fraud prevention |
| Story reports | Until reviewed and resolved — then the story text, your note and the link to your account are erased, and the record is deleted 30 days later. Any report is deleted after 180 days, reviewed or not |
| Crash reports | Per Firebase Crashlytics' standard retention (90 days) |
| Usage statistics (only if switched on) | Google Analytics event data: 2 months. Aggregated, non-identifying reports are kept longer |
| Abuse-prevention rate counters (including a scrambled code derived from your sign-in email — see below) | Deleted automatically about 30 days after their last activity; the email-derived one survives account deletion until that same expiry |
| Deleted-account marker (internal account ID + deletion date only) | Kept indefinitely after account deletion — see below |
When you delete a story in the app, it is removed from your device. Usage records connected to past generations are retained server-side for billing integrity and fraud prevention, as disclosed above.
About the deleted-account marker. When your account is deleted we write one small record that we keep afterwards. It contains only your account's internal identifier — the random ID Firebase assigned at sign-up — and the date the deletion happened. No email address, no name, no story content, nothing else is attached to it, and it is not readable by anyone using the app. Its single job is to stop the deleted account coming back: a subscription notification from Google Play that arrives moments after deletion, or a sign-in token still cached on an old device, would otherwise re-create your account record. Our servers check this marker before writing anything for a user, so a deleted account stays deleted. We keep it for as long as that protection is useful.
About the abuse-prevention counters. Because each free story
costs us real money to generate, our servers keep small rolling counters of how
often stories are requested. They never contain story content. Most are keyed to
your account or to a scrambled form of your network address. One is keyed to a
scrambled code derived from your sign-in email: the address is
first reduced to the inbox it actually delivers to (for example,
name+tag@gmail.com counts as name@gmail.com) and then
passed through a keyed one-way scramble, so the stored code cannot be turned back
into your email address. Its single job is to stop the free tier being farmed by
creating many accounts from one inbox, which is why it is not
erased at the moment you delete your account — it simply expires on its own about
30 days after its last activity, like the rest of the counters.
Children
StarryTime is used by families with children, and we treat that with care:
- Accounts are created and managed by a parent or guardian. Sign-up is parent-facing and gated by a birth-year check, there are no child accounts, and everything that costs money or changes the account — subscriptions, deletion, settings — sits behind the grown-ups area.
- Once an account exists, StarryTime is meant to be used together: a grown-up can hand the phone over, and older children (roughly 9–12) may pick a story or type a story idea themselves, under their grown-up's supervision. So the details that reach us — a listener's first name, age range, interests and the optional story idea — may be typed by a parent or by a supervised child. We treat all of it the same way: it is used only to write and narrate the requested story, the app asks on-screen for first names only and no personal details in the story idea, and we ask no more than that.
- There is no advertising of any kind, no advertising identifiers, and no selling of personal information — full stop.
- Usage statistics are off unless a parent turns them on, and never identify a child.
- Story content is filtered against children's-content guardrails scaled to the chosen age range, and every story can be reported from the player for our review.
We aim to honour the spirit and letter of children's-privacy laws, including COPPA (United States) and the GDPR's rules for children (EU/UK). Whatever your local law, the practical promises above are the same for everyone.
Who we share data with
We share data only to run the service, with providers acting on our instructions:
| Provider | What | Why |
|---|---|---|
| Google Firebase | Account identity, service records, crash reports and, only if you switch it on, anonymous usage events | Authentication, our database and storage, notifications, crash reporting, usage statistics |
| Anthropic | Story inputs (name, age range, interests, story idea) | Writing your story's text |
| ElevenLabs | The finished story text | Producing the narration audio |
| Google Play | Purchase tokens; a rating or review you choose to leave in Play’s own rating card | Verifying subscriptions; Google Play handles all payment details, ratings and reviews |
We do not sell personal information, and we do not share it for advertising.
Security
All traffic between the app and our servers is encrypted in transit (TLS). Server access is locked down so that only our backend code — not other users, not the public — can read your records, and requests must come from a verified, unmodified copy of the app (Google Play Integrity attestation). On your device, the library is protected by Android's built-in device encryption.
Your rights & choices
- Delete your account and server data at any time — from the app (Grown-ups → Delete account) or via the account-deletion page. You choose whether the on-device library is kept or removed.
- Access or correct what we hold about you — email us and we'll help.
- Notifications are optional and requested in context; you can turn them off in system settings at any time.
- Usage statistics are off unless you switch them on. The switch is in the app under Grown-ups → Privacy → Share anonymous usage statistics, and you also meet it during sign-up and in onboarding. Switching it off stops the collection and resets the analytics identifier on your device.
Depending on where you live, you may have additional statutory rights (for example under the GDPR, UK GDPR, or your state or national privacy law), such as the right to access, rectify, delete, or port personal data, and the right to complain to a supervisory authority. We honour requests to the extent your local law provides; nothing in this policy limits those rights.
Changes to this policy
When we change this policy, we'll update the effective date above; for meaningful changes we'll also flag it in the app. Because the policy is version-scoped, new capabilities ship together with the policy text that covers them.
Contact
Questions, requests, or concerns: support@starrytime.app.