Privacy Policy

Effective 2026-07-30 · Version 2026-07-30

1. Who we are

Bookybara is an app that creates personalised stories for children and lets them read those stories on a phone or tablet. This policy explains what we collect, why we collect it, how long we keep it, and what you can do about it.

This policy is written for the parent or guardian who set up the account. Children do not have their own accounts and never interact with us directly.

2. We do not ask for your name or email to get started

When you first open Bookybara, the app generates a random device identifier, stores it in your phone’s secure storage, and sends it to us. That identifier is your account. We do not ask for your name, your email address, or a password.

You may optionally add an email address later so that your library survives losing your phone. If you do, we store the address and send you a six-digit code to confirm it. We never send marketing email.

3. What we collect about a child

A child profile holds only what the story generator needs: a name or nickname you choose, an optional birth year, an avatar, a reading level, and a short list of interests. We do not ask for a surname, a birth date, a photograph, an address, a school, or contact details of any kind.

You can use a nickname instead of a real name. Nothing in the app requires the name to be accurate.

We also record which stories each child has read: the page they reached, when they last read, whether they finished, and how long each reading sitting lasted. This is what produces the reading statistics on the parent dashboard.

4. What we collect about the device

We store your device identifier, your app language, and your time zone. The time zone is used to work out what "today" means for a child’s reading streak, which would otherwise be wrong for everyone outside UTC.

If the app crashes, our crash reporting tool receives a technical report of what went wrong. These reports can contain device model, operating system version, and the sequence of screens that led to the crash.

5. How stories are generated

When you ask for a story, we send the story request — the topic, characters, length, language, and the age band derived from the child’s birth year — to a third-party AI provider that runs the language model. The child’s name is included when you have asked for the child to appear in the story.

We run automated safety checks on both the request and the generated story before it reaches the reader. Requests or stories that fail a check are recorded so we can review and improve those checks.

Stories are generated by a machine. They can be wrong, odd, or not what you expected. Read a new story yourself before handing the device to a young child.

6. Who else sees this data

We use a small number of service providers, and only for the purposes below. We do not sell personal data, and we do not share it for advertising.

AI model provider — receives story requests and returns story text. Our infrastructure and database hosting provider — stores everything described in this policy. Our subscription provider — processes purchases made through the App Store or Google Play. Our crash reporting provider — receives technical crash reports. Our email provider — delivers the six-digit code if you link an email address.

Payments are handled entirely by Apple or Google. We never receive or store your card number.

7. How long we keep it

Your account, your children’s profiles, your stories, and your reading history are kept until you delete your account. Deleting your account erases all of them immediately. A story that another family also has on a shelf is kept for that family.

Three kinds of record outlive account deletion. Generation cost records are kept without any link to you — the account reference is erased, leaving an anonymous entry we use to understand what the service costs to run. Safety-check records are kept for child-safety review. Subscription billing events are kept as evidence in the event of a payment dispute.

A full retention table, per database table, is published alongside this policy in our repository documentation.

8. Your rights

You can export everything we hold about your account at any time, from Settings inside the app. The export is a machine-readable file containing your account, every child profile, every story, and every reading session.

You can delete your account at any time, from Settings inside the app. Deletion is immediate and cannot be undone.

Depending on where you live you may also have the right to correct your data, to restrict or object to how we use it, or to complain to your local data protection authority. Contact us and we will help.

9. Security

Traffic between the app and our servers is encrypted. Your device identifier is held in your phone’s secure keystore, not in ordinary app storage. Access tokens are short-lived.

No system is perfectly secure. If we ever become aware of a breach affecting your data, we will tell you.

10. International transfers

Our providers may process data outside the country you live in, including outside the European Economic Area. Where that happens we rely on the transfer safeguards those providers offer.

11. Changes to this policy

If we change this policy we will update the effective date at the top and publish the new version at the same address. Material changes will be announced in the app.

12. Contact

Questions about this policy: privacy@bookybara.com

Read the Terms of Service →