Privacy Policy
Who we are
Kinmoria (working name StoryTime) helps adult caregivers turn a child's day into a calm bedtime story. The adult is the only account holder. Children do not create accounts, purchase, share, or receive notifications.
Data we process
- Adult account: email, password hash, optional display name, adult confirmation and consent records, App User ID (internal UUID used with RevenueCat — never a child name).
- Child profile (guardian-provided): nickname, age band, interests, optional notes — scoped to the family.
- Moments & stories: text or short audio you submit, transcripts, generated story text, optional illustrations and TTS audio, approved memories and world entities for personalization.
- Usage & billing: free-story ledger entries and StoryTime Plus entitlement snapshots from Apple via RevenueCat.
Processors
- Hosting and object storage on our infrastructure (Docker / MinIO S3 API; future R2/S3 compatible).
- PostgreSQL (incl. pgvector embeddings for memory retrieval) and Redis for jobs/cache.
- AI providers (OpenAI-compatible APIs when configured) for transcription, writing, moderation, images, and TTS.
- RevenueCat + Apple for in-app subscriptions on iOS.
We do not sell personal data. We do not use child content for ads.
Retention
Family content is retained while the adult account is active so the library and My World can personalize later stories. Short-lived upload URLs and export download tokens expire (typically within one hour). Job progress snapshots in Redis expire after several hours.
Your controls
- Export: Settings → parental gate → Export my data (authenticated, time-limited download).
- Delete: Settings → parental gate → Delete account cascades database rows (including embeddings), object storage under the family, and related caches.
- Parental gates protect purchases, sensitive settings, and external store links.
Contact
Privacy questions: use the waitlist email on the landing page or your App Store support channel. For support lookups, provide the App User ID shown in Settings (adult UUID), not a child's name.