Effective date: October 9, 2026
Last updated: October 9, 2026
This Privacy Policy explains how IDEELY LLC, a Florida limited liability company doing business as ideely (“ideely,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you use the ideely Story Time mobile application, websites that link to this Policy, support services, and related features (collectively, the “Service”).
The Service turns photographs and user instructions into private, synthetic spoken-audio experiences. It can photograph pages, recognize and clean text, translate text, generate stories and cover art, synthesize speech, add sound or music, organize books and playlists, and transfer selected content to a user’s Yoto account.
IDEELY LLC is the controller or business responsible for the personal information described in this Policy, except where a named third party acts as an independent controller.
Contact details:
Privacy and general support: ideely.cc@outlook.com
Accounts are for adults who are at least 18 years old and able to enter a binding agreement. The Service is designed for a parent, guardian, teacher, caregiver, or other authorized adult to set up and control. A child may listen to content or use an adult-controlled device only with that adult’s active involvement and supervision. Children may not create accounts or submit personal information directly to us.
The adult account holder is responsible for what is photographed, entered, generated, or transferred, including a child’s name, voice instructions, image, school details, interests, or other personal information. The adult must have legal authority to provide that information and must avoid submitting more information about a child than is necessary.
If you believe a child provided personal information without appropriate adult authorization, contact us immediately. We will investigate and delete the information when required. See Section 13 for more information.
Depending on how you sign in, we collect or receive:
a Firebase user identifier;
email address, display name, and authentication provider;
account creation and last sign-in information;
sign-in tokens and authentication records;
Internet Protocol address, device and browser information, and security signals processed by our authentication provider; and
for temporary demonstrations, an anonymous account identifier, timestamps, preferred language, and usage allowance information.
If you sign in with Apple or Google, those providers send us information according to your settings and their policies. Apple may provide a relay email address instead of your ordinary address.
When you use creation features, we collect and process the content you choose to provide, including:
camera photographs or selected images of covers and pages, which may incidentally contain faces, names, handwriting, locations, barcodes, surroundings, or embedded file metadata;
book titles, authors, page order, age settings, language and voice choices, and playback settings;
optical-character-recognition text, cleaned text, pronunciation text, user edits, and translated text;
story prompts, character details, themes, selected stylistic settings, safety or moderation results, generated stories, titles, author labels, and generated cover images;
synthesized narration, combined audio, music and page-turn selections, duration, and processing status;
library, playlist, and queue information; and
technical identifiers for books, pages, upload sessions, and files.
For clarity, we treat these content types differently:
Captured Content includes existing books, pages, images, text, illustrations, or covers you photograph, select, or upload, and OCR text, translations, narration, or other output derived from them.
User Inputs include prompts, choices, instructions, names, character details, photographs, and other material you provide for an AI-creation feature, excluding Captured Content.
Generated Content includes new stories, titles, cover art, narration, and other material created by an AI-creation feature from User Inputs. It does not include Captured Content or output derived from Captured Content.
Shared Content is Generated Content that you affirmatively choose to publish or send through an ideely sharing feature. Storing content privately in your account does not make it Shared Content.
The Service currently uses cloud processing for these features. Do not photograph or upload private documents, payment cards, medical records, government identifiers, addresses, or any content that is not needed for a story.
If you choose to connect Yoto, we process:
Yoto authorization and refresh tokens, stored in protected storage on your device;
the name or email returned by Yoto, where available;
connection status and the Yoto account email stored with your ideely profile;
Yoto playlist, card, track, and icon selections; and
the title, audio, and optional cover image you direct us to transfer to Yoto.
Yoto separately processes content and account information after a transfer. Its retention, deletion, and other processing are governed by Yoto’s own privacy notice and terms.
Apple or Google processes payment details. We do not receive your full payment-card number. We and our subscription provider, RevenueCat, receive information needed to provide paid access, such as:
ideely account identifier;
subscription product, entitlement, purchase, renewal, expiration, cancellation, and refund status;
App Store or Google Play transaction or receipt information;
email address, display name, authentication-provider identifiers, application environment, and Firebase app-instance identifier; and
device, application, store, and diagnostic information used to validate and manage purchases.
Optional RevenueCat attributes such as phone number, preferred language, and account-creation date are disabled in the reviewed production configuration. If we enable them, we will update this Policy where required.
We use Firebase Analytics and operational logs to understand whether features work and to protect the Service. This can include:
a Firebase app-instance identifier and, for registered users, an ideely account identifier;
application version, platform, device type, operating system, locale, and approximate location derived from network information;
feature events, processing outcomes, screen activity, counts, limits, durations, language and voice categories, subscription state, and error categories;
network and request metadata, including Internet Protocol address; and
server events, authentication checks, file paths, internal book/page identifiers, and debugging information.
Our intended analytics event design excludes book images, recognized or generated story text, prompts, book titles, character names, email addresses, and other direct content. Operational logs in the version reviewed may nevertheless contain book titles, author names, internal user or content identifiers, storage links, and short excerpts of recognized, cleaned, or translated text. We are working to remove that content from logs. Until that work is completed, it is processed under the security, access, and retention controls described here.
We disabled Android advertising-ID collection in the reviewed application and do not use advertising networks. Firebase Analytics may still process an app-instance identifier and device or usage data.
If you contact us, we collect your message, contact details, account identifier, attachments, and information needed to respond. Do not include book pages or a child’s information unless needed to resolve the issue.
The Service requests camera or photo-library access when you choose to capture or select images. It stores temporary images, audio, cached files, preferences, analytics flags, and Yoto credentials locally as needed to operate.
The current Service does not intentionally record or upload microphone audio. If we introduce a voice-recording feature, we will request permission and update this Policy before collecting recordings.
We receive information:
directly from you and from the content you submit;
automatically from your device and use of the Service;
from Apple, Google, Firebase, RevenueCat, Yoto, and other providers you connect; and
from security, fraud-prevention, analytics, and support systems.
We do not purchase data-broker profiles about you.
Where law requires a legal basis, we rely on the following:
Create and secure accounts; authenticate users
Types of information: Account, device, security, sign-in data
Legal basis under the GDPR/UK GDPR: Performance of our contract; legitimate interests in security
Photograph, recognize, clean, translate, generate, synthesize, store, and play content at your direction
Types of information: Images, text, prompts, settings, generated output, audio
Legal basis under the GDPR/UK GDPR: Performance of our contract; consent where local law requires it
Connect to and transfer content to Yoto
Types of information: Yoto tokens, account details, selected content
Legal basis under the GDPR/UK GDPR: Performance of our contract; your direction and consent to connect
Provide subscriptions and restore purchases
Types of information: Account, entitlement, transaction, device data
Legal basis under the GDPR/UK GDPR: Performance of our contract; legal obligations; legitimate interests in fraud prevention
Maintain, debug, secure, and improve the Service
Types of information: Usage, device, diagnostics, limited content where incidentally logged
Legal basis under the GDPR/UK GDPR: Legitimate interests in operating and protecting the Service; consent where required
Measure product performance and analytics
Types of information: App-instance, account, device, event and approximate-location data
Legal basis under the GDPR/UK GDPR: Consent where required; otherwise legitimate interests, balanced against your rights
Respond to support, rights, and legal requests
Types of information: Account, communications, content relevant to the request
Legal basis under the GDPR/UK GDPR: Performance of our contract; legal obligations; legitimate interests
Enforce terms and prevent misuse, infringement, fraud, or harm
Types of information: Account, content, security, and usage information
Legal basis under the GDPR/UK GDPR: Legal obligations; legitimate interests in protecting users, rightsholders, and the Service
When we rely on legitimate interests, we consider whether our interests are necessary and proportionate and whether your rights override them. You may object as described in Section 12.
The Service uses automated systems, including optical character recognition, language models, image generation, and text-to-speech, to process content at your direction. Depending on the selected feature and current configuration, processing may involve Google Cloud services, Google Gemini models, or third-party models such as xAI models made available through Google Cloud Vertex AI.
AI systems can make mistakes, omit context, produce offensive or unsafe material, mistranslate text, mispronounce words, or generate output similar to existing material. An adult must review content before a child uses it or before it is sent to another service.
We may use automated tools to detect unsafe requests, abuse, security threats, or violations. We do not use the reviewed system to make decisions that produce legal or similarly significant effects about you without meaningful human involvement.
We do not use Captured Content to train or fine-tune a general-purpose model operated by ideely or a third party, and we do not authorize our providers to do so. We also do not use Captured Content as input, retrieval material, grounding data, or other context to generate AI-created books for you or another user.
This no-training and no-cross-use commitment does not prevent the processing needed to provide the feature you request for the same Captured Content. For example, we may send the content to automated systems or providers to perform OCR, clean recognized text, detect language, translate, conduct a safety review, generate narration, store files, or complete a transfer you request. That is service processing, not model training or reuse as context for AI-book creation.
Training, service processing, and retention are different. Some providers may temporarily process or retain prompts, content, and outputs for safety, abuse detection, caching, security, or service operation under their terms and our configuration. We will not claim zero retention unless the applicable service, model, project settings, and exceptions are technically configured and verified for it. If we ever propose a materially different use of Captured Content, such as an optional training program, we will provide clear advance notice and obtain separate affirmative permission where required; ordinary acceptance of this Policy or the Terms is not permission for that use.
We disclose information only as described below, at your direction, or with your consent:
Google and Firebase: Authentication, Firestore database, Cloud Storage, Cloud Functions/Run, Analytics, App Check, Vision/OCR, Vertex AI, Gemini, text-to-speech, logging, security, and related cloud operations. These services process account, content, device, usage, and diagnostic data as needed for each feature.
Model providers available through Google Cloud, including xAI where selected: Process prompts or content for a requested model feature, subject to the applicable Google Cloud and model terms and configuration.
RevenueCat: Verify and manage subscriptions and entitlements, connect store transactions to an ideely account, and diagnose purchase issues.
Apple and Google Play: Distribute the app, authenticate users where selected, process purchases, manage subscriptions and refunds, prevent fraud, and provide store services.
Yoto: At your direction, authorize account access, list your Yoto content, and create or update a playlist or track containing selected ideely audio, title, icon, and cover information.
Professional advisers and vendors: Hosting, security, customer support, auditing, legal, insurance, and other operational services, under duties appropriate to their role.
Authorities, rightsholders, and affected parties: Comply with law, valid legal process, intellectual-property notices, and safety obligations; protect rights and security; investigate fraud or abuse; or establish and defend legal claims.
Business transaction participants: Evaluate or complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and notice where required.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, use third-party ad networks, or knowingly sell or share personal information of children.
Except when you affirmatively use a sharing feature, we do not publicly distribute your content through the ordinary operation of the Service. A sharing feature may make the Generated Content you select, associated attribution, and information you include in that content visible to the audience you choose or to the public, as explained at the time of sharing. Do not include a child’s identifying or sensitive information in Shared Content. We do not make Captured Content publicly shareable merely because it has been processed with AI.
A transfer you request to Yoto creates a copy in Yoto’s systems, and a cover or media link may be transmitted so Yoto can perform that request. Your own sharing, device access, or use of third-party services may disclose content beyond ideely. Copies downloaded, reposted, transferred, cached, or retained by other users or services may remain after you remove or unshare the original from ideely.
The Service is operated from Florida, United States. Core data reviewed for this draft is hosted in the United States, including a Firestore multi-region in the United States and Cloud Storage in US-EAST1; processing also occurs in us-east1. Providers and personnel may process information in other countries where they operate.
Those countries may have privacy laws different from those where you live. Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, we use an approved transfer mechanism such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the United Kingdom addendum or international data-transfer agreement, or another lawful safeguard. Contact us to request information about applicable safeguards.
We keep personal information only as long as reasonably necessary for the purposes described above, including providing the Service, resolving disputes, enforcing agreements, preventing fraud, and meeting legal, tax, accounting, and security obligations. Current retention practices include:
Account and profile: while your account is active and until it is deleted, subject to legal and backup retention.
Book images, text, generated output, and ideely audio: until you delete the applicable book, delete the account, or ask us to delete it, unless retention is required by law, a dispute, or security needs.
Cloud Storage recovery copies: deleted objects may remain recoverable for approximately 7 days under the currently configured soft-delete policy.
Authentication backups: Firebase states that some authentication backups may persist for up to 180 days after deletion.
Operational logs: ordinary Cloud Logging records are currently retained for approximately 30 days; certain mandatory audit logs may be retained for up to 400 days. We may preserve specific records longer for an active security incident or legal claim.
Firebase Analytics: user-level and event-level data is retained for up to 14 months under available property settings; aggregate reports may remain longer.
Subscription and transaction records: for the life of the account and as required for entitlement, tax, accounting, chargeback, fraud-prevention, and legal purposes. Apple, Google, and RevenueCat apply their own retention periods.
Yoto connection data: local tokens remain until you disconnect, sign out, remove the app, or they expire; limited account connection status may remain in your profile until deletion. Content already transferred to Yoto remains subject to Yoto’s controls and is not necessarily deleted when ideely data is deleted.
Support records: while a request is active and ordinarily for up to 24 months after it is closed or last active, unless a shorter period is required or a longer period is reasonably necessary for security, fraud prevention, or an ongoing dispute.
Legal and compliance records: for as long as reasonably necessary to establish, exercise, or defend legal claims and satisfy legal, tax, accounting, regulatory, or enforcement obligations.
Deletion from active systems is not always instantaneous. We delete or de-identify data according to technical schedules and applicable law. Information that has been irreversibly aggregated or de-identified may be retained because it no longer identifies a person.
We use administrative, technical, and organizational safeguards designed to protect information, including authenticated access, user-scoped database and storage rules, encrypted network transport, protected device storage for Yoto credentials, application-integrity checks, access controls, and provider security controls.
No system is completely secure. You are responsible for protecting your device, account credentials, email account, Apple or Google account, and connected Yoto account. Contact us promptly if you suspect unauthorized access.
Depending on the feature, you can:
edit or delete individual ideely books and page content;
choose whether to connect Yoto and disconnect it;
manage app camera and photo permissions in device settings;
manage or cancel subscriptions through Apple or Google;
change certain language, voice, audio, and content settings; and
contact us to request access, correction, export, or deletion.
Deleting ideely content or an ideely account does not automatically cancel an App Store or Google Play subscription and may not delete content already transferred to Yoto. Manage the subscription with the applicable store and delete transferred content using Yoto’s controls.
Depending on where you live, you may have the right to:
know or access the personal information we hold about you;
correct inaccurate information;
delete information;
receive a portable copy of information you provided;
restrict or object to certain processing, including direct marketing or processing based on legitimate interests;
withdraw consent at any time, without affecting earlier lawful processing;
opt out of sale, sharing for cross-context behavioral advertising, or qualifying profiling;
appeal a refusal of a privacy request; and
complain to a privacy or data-protection authority.
We do not currently sell personal information or use it for cross-context behavioral advertising. If that changes, we will provide legally required notices and choices before the change.
Email ideely.cc@outlook.com with “Privacy Request” in the subject to exercise a privacy right other than account deletion. We may verify your identity and authority to protect the account. An authorized agent may submit a request where permitted, but we may require proof of authorization and direct identity verification. We will not discriminate against you for exercising a privacy right.
Account deletion must be initiated through the account-deletion control inside the app. Deletion can be irreversible. Deleting your ideely account does not automatically cancel an App Store or Google Play subscription or delete content already transferred to Yoto; those actions must be completed separately through the applicable service.
Residents of the EEA, UK, or Switzerland may complain to their local supervisory authority. Contact details for EEA authorities are available through the European Data Protection Board; the UK authority is the Information Commissioner’s Office.
The Service concerns children’s stories and may appeal to families, but ideely accounts and content-submission features are intended for adults. We do not knowingly allow a child under 13, or the higher digital-consent age that applies locally, to create an account or independently provide personal information.
An adult must:
control the account and device;
decide what information about a child is submitted;
obtain consent from another parent, guardian, or person where required;
avoid including a child’s surname, address, school, contact details, precise location, health information, or identifying photograph unless strictly necessary and lawful; and
review AI output before allowing a child to hear or view it.
If we learn that we collected personal information directly from a child without required authorization, we will take reasonable steps to delete it. Parents and guardians may contact us to review or delete information about a child. We may verify identity and parental authority.
Because an adult-only statement is not enough by itself for a child-appealing product, we are evaluating and implementing age-assurance, parental-gate, privacy-by-default, and child-specific risk controls. The Service should not be launched in a country until those controls have been assessed against local law.
Apple, Google, Firebase, RevenueCat, Yoto, identity providers, and any external sites have their own terms and privacy practices. We are not responsible for a third party’s independent processing. Review their notices before connecting an account or sending content. Yoto’s account and service may have separate age requirements.
We may update this Policy to reflect product, provider, legal, or operational changes. We will post the updated date and provide additional notice or request consent when required. If a change materially affects how we use information already collected, we will apply it only as permitted by law.
Questions, complaints, and privacy requests may be sent to:
IDEELY LLC
Attn: Privacy
ideely.cc@outlook.com
If you contact us in a supported language, we will make reasonable efforts to respond in that language. The legally controlling version of this Policy and any required local-language version are described at publication; machine translation alone should not be relied on for material legal terms.