Privacy Policy

Last updated September 12, 2026

MomDadTales is a bedtime-stories app made for parents to share with their children. We designed it to collect as little information as possible. This policy explains, in plain language, what the app sends to us and what never leaves your device.

The short version: Your child's name stays on your device and is never sent to us. MomDadTales has no analytics and no tracking of any kind — no analytics software, no advertising software, no third-party trackers, and nothing that follows you across other apps or websites. To suggest stories and operate the service, the app sends limited information such as a single age taken from the age range you picked, the interests you picked, a language code, and a randomly generated identifier. Our service records which stories that identifier has read, so the same story is not offered twice. If you subscribe, we also use App Store transaction information to verify your subscription. We do not sell personal information or use it for advertising.

Information stored only on your device

When you set up a child profile, the details you enter — your child's name, age range, gender, and interests — are stored locally on your device. The name and the gender never leave the device: they are never transmitted to our servers or to any third party. If you delete the app or remove a profile, that information is gone.

Information used to choose stories

Stories are written and illustrated ahead of time and kept in our story library. Nothing is written about your child or made to order. To pick which of those existing stories to offer, the app sends a minimal request to our story service. That request contains only:

  • a single age for your child, taken from the age range you picked — the 4–5 range is sent as 5, for example, never an exact birthday,
  • the interests you selected (for example: animals, space, magic),
  • a language code — always English in the App Store release,
  • three technical values the screen needs: a default story theme, the artwork size to return, and how many stories to return, and
  • a random identifier created on your device, so we can tell which stories have already been sent to you. If you subscribe, the App Store transaction identifier is included too, so we can confirm the subscription is active.

These requests carry no name, no email address, and no account with us — there are no accounts to create. The identifier is generated at random on your device and exists so we can avoid sending the same story twice. Your child's name is never part of it, because the name never leaves your device at all.

We cannot identify you from this information on its own. It is, however, tied to a persistent random identifier, so under the GDPR it counts as pseudonymous personal data rather than anonymous data, and we treat it accordingly: we keep it to the minimum listed above, we do not combine it with data from other sources, and we do not sell it or use it for advertising.

What we keep on our servers

Tied to that random identifier — and to nothing else about you — our service keeps:

  • a record of each story actually read or listened to, with the time — the app reports one only after real reading (near the last page, or a minute of narration), never on a glance. That list is kept on our side, rather than sent up from your device each time, so the same story is not offered again,
  • your thumbs up or thumbs down, when you choose to rate a story, which nudges that story up or down in the suggestions everyone sees, and
  • a device-check key. Before the app may call our service, iOS creates a key — with Apple's help — that proves the request comes from the real MomDadTales app on a real Apple device. Apple calls this App Attest. We store the public half of that key and a daily count of the requests made with it, to keep fair-use limits and to keep fake clients out. The key says nothing about you, your device, or your child.

As with any request over the internet, your IP address reaches our server. We use it only to rate-limit abuse: it is not written into our request logs, which record the path and the status code only, and it is never joined to any of the data above. Our hosting provider and CDN may keep it briefly in their own security logs.

If you contact support

The support form on our website asks for your name, your email address, and your message. We use them for one thing: to answer you. The message is delivered to our inbox through an email delivery provider, and it is not added to any mailing list or shared with anyone else. Please don't include your child's name or other details about them — we don't need them to help. To stop automated submissions, the form is protected by Cloudflare Turnstile, which checks that a person sent it without profiling you and without advertising cookies. That check sends your IP address to Cloudflare, which is the only thing it needs to judge the submission.

Children's privacy (COPPA & GDPR-K)

MomDadTales is operated by the parent or guardian, who manages setup, story selection, and any subscription. The app is directed to parents, not to children, and it is intended to be used by an adult on behalf of a child. Because we never receive your child's name or any contact details, we do not knowingly collect personal data from children under 13 (or the equivalent age in your region). The limited information described above is the full extent of what leaves the device.

How stories are made and kept appropriate

Every story in MomDadTales is written and illustrated in advance, with the help of AI, and reviewed against automated safety checks designed to keep content gentle and age-appropriate — all before it ever reaches the app. The app then chooses from that finished library. No story is written on demand, and none is written about your child. If you ever come across a story that doesn't feel right, tell us and we'll review it: tap Send Feedback in the app's More tab, or email us at [email protected]. A thumbs down at the end of a story also counts as a signal, though it doesn't tell us what was wrong — so an email helps far more.

Subscriptions and payments

Subscriptions are handled entirely by Apple through the App Store. We never receive or store your payment details. Apple's processing of your purchase is governed by Apple's own privacy policy.

Analytics, tracking, and advertising

MomDadTales contains no analytics of any kind — neither a third party's nor our own. The app bundles no analytics software, no advertising software, and no third-party trackers. It does not use the Advertising Identifier (IDFA), so it never asks for permission to track you, and it is declared as non-tracking in the privacy manifest Apple ships with the app. Nothing we receive is joined with data from other companies' apps or websites, no data broker receives any of it, no third party is told how you or your child use the app, and we never build a profile of your child. We do not sell personal information.

There are no screen-view counters, no analytics events, no session recording, and no crash-reporting service. Nothing records what you tap, which screens you visit, or how long you stay. The only information that reaches us is what the app needs to work, described above — which stories were opened and rated, and nothing more: it is tied to the same randomly generated device identifier, so it is pseudonymous rather than anonymous. You can ask us to delete the data associated with your device identifier by emailing us.

Our website runs no analytics either — no Google Analytics, no tracking pixels, and no advertising cookies. We set no cookies of our own. Cloudflare, which hosts the site and runs the Turnstile check described above, may set short-lived security cookies of its own; they exist to tell people from bots, not to profile you. Turnstile is the only third-party code on the site.

Your choices and rights

Because your child's profile lives on your device, you are always in control: you can edit or delete any profile, or remove the app entirely, to erase that information. One thing to know: the random identifier is held in the device keychain, so it survives deleting and reinstalling the app — it is what lets a subscription and a reading history come back on the same device. For the limited pseudonymous information we do hold, you can ask us to access or delete it — depending on where you live, you may also have rights to correct it, restrict or object to its processing, or receive a copy. If you have questions or requests regarding this policy or your data, contact us at [email protected].

Changes to this policy

If we make material changes to this policy, we'll update the date above and, where appropriate, note the change in the app. Continued use after an update means you accept the revised policy.

Contact

Questions about privacy? Email [email protected].