Lumi Tales ๐ŸŒ™

Privacy Policy

Effective date: 25 July 2026

Lumi Tales ("we," "us") makes a bedtime-story app for families. This policy explains, in plain language, what happens to your and your child's information when you use the app. Our design goal is simple: keep your child's data on your device, and never store it on our servers.

If you have any question about this policy, email [email protected].

The short version

1. Who we are

Lumi Tales is the developer and operator of the Lumi Tales app. Contact: [email protected].

2. What stays on your device

Your child's profile โ€” first name, age, and optional gender โ€” and any stories you tap "Save" on are stored locally on your device only (in the app's on-device storage). They are never uploaded to us, never synced to a cloud account, and never shared. If you delete the app or use "Delete my data," they are gone.

3. What is sent when you create a story

When you ask the app to write a story, the app sends the following to our backend, which passes it to our AI providers to generate that specific story and its optional narration: - your child's first name, age, and (if set) gender; - the theme you picked or the short description you typed; - the language.

This information is used only to generate that story at that moment. Our own server is stateless โ€” it processes the request and forgets it. We do not save your child's name, the theme, or the story text on our servers.

4. AI service providers (sub-processors)

Story text and narration are produced by third-party AI services. Your child's first name is included in the text sent to them so the story can be personalized:

Provider Purpose Data sent
Anthropic (Claude) Generates the story text Child's first name, age, optional gender, theme/topic, language
OpenAI Text-to-speech narration The generated story text (contains the first name)
Google Cloud Text-to-Speech Text-to-speech narration (alternate) The generated story text (contains the first name)

These providers process the request to return the story or audio. Under their standard API terms, API inputs are not used to train their models by default. We do not authorize them to use your child's information for any purpose other than generating your story.

5. What our server logs

For reliability and abuse-prevention only, our server keeps anonymized technical logs โ€” the type of action (e.g. "story"), the language, timing, and success/failure. These logs never contain your child's name, the theme, or the story text.

6. Anonymous device token

The app generates a random, anonymous identifier stored on your device and sends it with requests only as a rate-limit key (to prevent abuse of our service). It is not linked to your identity, your child, your name, or any story.

7. Purchases

Subscriptions and the one-time Lifetime purchase are handled by Apple (and processed through RevenueCat for subscription management). Payment details are handled by Apple โ€” we never see your card information. We receive only whether an entitlement is active.

8. Analytics โ€” and what we do not do

The app contains no advertising, no ad-tracking or cross-app tracking SDKs, and no social media trackers. We do not use the device's advertising identifier, we do not build advertising profiles of you or your child, and we do not sell or share personal information.

We do use one product-analytics tool, PostHog, to understand how the app itself is used, so we can fix what is broken or confusing.

What PostHog receives A random ID created by the app (not your Apple ID, not an advertising identifier); which screens were opened; which actions happened (story created, story finished, paywall shown, purchase completed); the chosen story theme; an age range such as "4-5"; app language, app version, device model and OS version. IP addresses are discarded on arrival, leaving only an approximate country.
What PostHog never receives Your child's name, your child's exact age, the text of any story, the narration audio, your email, or any account identifier.

PostHog, Inc. processes this data on our behalf and stores it on its US cloud, under its own privacy policy and data-processing terms. This is the only analytics tool in the app.

9. Children's privacy

Lumi Tales is meant to be operated by a parent or guardian โ€” you enter the child's details, choose the theme, and manage the subscription behind a parental gate. We practice data minimization: only the first name and age needed to personalize a story are used, only on-device storage is used for the profile, and nothing about the child is retained on our servers. We do not knowingly collect or store personal information from children beyond this parent-directed, on-device flow. If you believe a child has provided information in a way you did not intend, contact us at [email protected] and we will help.

10. Your choices and rights

11. Data retention

On-device data stays until you delete it (or delete the app). Our server retains no personal content; anonymized technical logs are kept only briefly for operations and then discarded.

12. International processing

Our AI providers may process the story request on servers in the United States or other countries. The information sent is limited to what's described in Section 3 and is used only to generate your story.

13. Security

Requests between the app and our server are sent over encrypted HTTPS connections.

14. Changes to this policy

If we make material changes, we will update this page and the effective date above.

15. Contact

Email: [email protected]