Skip to main content
Moonlit Tales
Features Bedtime guides Questions Support
English EN
English 日本語 简体中文 繁體中文
Download

Privacy policy

Last updated: August 13, 2026

Applies to the Moonlit Tales website and iOS app in mainland China.

This English version is provided for convenience. If it differs from the Simplified Chinese version, the Simplified Chinese version controls.

Moonlit Tales (the “app,” “we,” or “us”) values the privacy of parents and children. This policy explains how we collect, use, store, share, and protect information when we provide bedtime story generation, narration, memberships, support, and website access.

The app is intended for parents or guardians to use with children. A parent or guardian should read and accept this policy before entering or selecting any information for a child. We recommend using only a nickname and not entering a child's real name or other directly identifying information.

1. Information we process

1.1 Child-related information a parent provides or selects

To create and narrate personalized bedtime stories, the app may process the following child-related information:

  • Nickname or form of address;
  • Age or age range;
  • Gender;
  • Story preferences, such as theme, companion, narrator voice, and speaking rate;
  • Story-generation selections or input;
  • The resulting story title, text, cover theme, playback duration, and recent-story records.

This information should not include a child's real name, national identification number, phone number, precise location, home address, school, photo, or other information that can identify the child in the real world. Although a nickname, age, or gender may not identify a child by itself, we treat it conservatively as child-related personal information when linked to a device, local record, order, or generated content.

1.2 Membership, subscription, and story-credit information

The app may store membership status, plan, remaining story credits, and subscription start and expiration dates on the device. Apple App Store / StoreKit handles actual purchases, refunds, renewals, and billing; we do not receive full payment card numbers or payment credentials.

To verify subscription entitlements, sync story credits, and avoid duplicate use of generation resources, our backend may process Sign in with Apple results, app-generated account identifiers, StoreKit transaction-verification information, quota events, and generation-job status.

1.3 Information created by the device and system features

The app may store recent stories, preferences, audio caches, debug-setting state, and generation-progress markers locally. If iCloud Documents or backup is available, Apple may sync or back up files according to the user's system settings; we do not directly sign in to, read, or control the user's iCloud account.

To recover from a network interruption, the app entering the background, or a lost response after a story is created, our backend may temporarily keep synthesized narration audio or recovery records for no more than 12 hours. This cache is used only to deliver or recover the newly generated audio, not for advertising profiles, public distribution, or resynthesizing historical stories.

1.4 Website access and security logs

Cloudflare provides website hosting and CDN delivery, security, and basic traffic and performance processing. Cloudflare dashboard data and server logs are the website's basic traffic and performance source; this website source does not send a second Cloudflare analytics beacon. We do not use those records for cross-site tracking. Cloudflare's necessary security and delivery logs are not controlled by optional analytics consent.

2. How we use information

We use the information above only for the following purposes:

  • Create bedtime stories suited to the selected age, theme, and preferences;
  • Narrate stories, cache audio, and show playback progress;
  • Save recent stories and preferences for future use;
  • Manage membership status, subscription entitlements, and story credits;
  • Send system notifications when story generation finishes;
  • Handle support, deletion, correction, and withdrawal-of-consent requests;
  • Keep the website and app safe, stable, and reliable.

We do not use children's data for advertising tracking, sell personal information, publicly disclose children's data, or build marketing profiles unrelated to bedtime story generation and narration.

3. Service providers and delegated processing

We may use the following third-party and system services to provide app features:

  • Volcengine / Doubao Ark model services: When story generation is enabled, a request may be sent to Volcengine interfaces and may include a nickname, age, gender, theme, companion, and story preferences.
  • Volcengine speech services: When cloud TTS is enabled, generated story text, voice, and speaking-rate settings may be sent to synthesize narration audio.
  • Apple StoreKit / App Store: Handles subscription purchases, purchase restoration, renewals, refunds, and transaction verification.
  • Cloudflare Pages / Workers / D1 / R2: Hosts the website and backend and stores records needed for sessions, subscription verification, credit synchronization, generation recovery, temporary audio recovery, and troubleshooting.
  • Google Analytics: May be enabled only when configured and a parent or visitor grants analytics consent. Code that is ready for configuration does not mean it is active in production. Moonlit Tales active business fields (8): landing_page, locale, market, content_group, app_storefront, utm_source, utm_medium, utm_campaign. Google Analytics also processes standard technical, user, and session fields by default, including a first-party _ga client ID, approximate region, browser, and device information. It may create the automatic events first_visit, session_start, and user_engagement. Web events also carry standard fields such as language, page_location, page_referrer, page_title, and screen_resolution. This implementation overrides page_location with the canonical page URL without query parameters or a hash; Google still processes the other standard technical and session fields.
  • Apple system services: Includes local notifications, Live Activity, Now Playing, iCloud Documents, and backup. Story titles, children's nicknames, or cover details may appear in system notifications, on the Lock Screen or Dynamic Island, or in playback controls.

If enabled, Google Analytics helps us understand useful pages, channels, and App Store calls to action so we can improve the website. Moonlit Tales custom events (5): page_view, app_store_cta_clicked, video_started, share_rules_viewed, share_submission_started. This list does not describe all Google Analytics automatic events. Before production enablement, Moonlit Tales must disable Enhanced Measurement in the GA4 web data stream and record a settings readback, and verify that Google Signals, User-ID, and ad personalization remain disabled. The retention setting must also be configured and read back. Source code and a local build cannot prove those account settings. We do not send a child's name, story text, audio, support email address or message body, account identifiers, or payment identifiers. We do not sell analytics information, use it for behavioral advertising, or build cross-site advertising profiles.

4. Information we do not collect

Unless a future feature clearly explains otherwise and obtains any required consent, the current service neither requires nor intentionally collects the following:

  • A child's real name, national identification number, phone number, home address, school, photo, or contacts;
  • Precise geolocation;
  • IDFA or another cross-app identifier used for ad tracking;
  • Payment card numbers or full payment credentials;
  • Community content, public profiles, or social relationships between users.

5. Storage and retention

Stories, preferences, membership status, and audio caches are stored primarily on the user's device and in any user-account storage Apple may provide. We keep only information needed to provide the features. You can delete the app, use system settings, or contact us to request deletion or correction.

The backend keeps sessions, credits, transaction verification, generation jobs, and troubleshooting records only as long as needed. To recover a newly created generation job, story text may be retained briefly until the request is completed, acknowledged, or expires, and is then cleaned up under system policy.

Narration audio for a newly generated story may enter a private temporary recovery cache. We delete it promptly after the app confirms successful local storage; without confirmation, it is retained for no more than 12 hours and then cleared by the system. Historical playback, local replay, and bookshelf selection do not trigger narration synthesis again or consume generation resources again.

Moonlit Tales is responsible for setting, configuring, reading back, documenting, and periodically reviewing the Google Analytics account retention policy before production use. Analytics data is retained according to that configured account retention, while security records are retained only for the necessary operational period. We do not state an exact analytics retention period until the product owner has configured and recorded it as a release gate. If laws or regulations require otherwise, we handle them as required by law.

6. Your rights

A parent or guardian may exercise the following rights regarding their own or a child's information. A parent or visitor can use the footer's “Analytics settings” to decline or withdraw optional analytics consent. Withdrawal stops future GA events, and we make a reasonable effort to clear GA cookies. It does not remove Cloudflare's necessary security and delivery logs, which are not part of optional analytics consent.

  • Learn what information we process and why;
  • Request correction of inaccurate information;
  • Request deletion of children's data, story records, or support-request information;
  • Withdraw consent to process children's data;
  • Close an account or stop using the relevant services;
  • Ask questions or submit complaints and suggestions about our handling of information.

Contact us at support@moonlittales.app. To protect children, we may need to verify that the requester is the child's parent or guardian or otherwise verify the request.

7. Children's personal information

When we process personal information about children under 14, we follow principles of necessity, informed consent, clear purpose, security safeguards, and lawful use. We do not publicly disclose or sell children's data or use it for ad tracking.

For more detail, read the Children's Privacy Notice.

8. Policy updates

Cloudflare and Google may process website information outside the visitor's country or region. The Moonlit Tales product owner must, before production enablement, confirm and record the applicable processor terms or DPA, any required transfer mechanism, and safeguards. Until that readback is recorded, we do not claim those measures are in place. We may update this policy if product features, service providers, or legal requirements change. We will provide an appropriate notice for material changes to the purpose, method, or types of processing and obtain consent again when required.

9. Contact us

For questions about this policy or requests involving children's data, deletion, or correction, email support@moonlittales.app. We usually respond within 15 business days.

Guides

Which language should tonight's bedtime story use?A calm bedtime routine checklist that fits real family lifeHow to choose an age-appropriate bedtime storyA screen-light wind-down that still works on busy evenings

Support

About Moonlit TalesFrequently asked questionsSupport and data requestsShare rewardContact us

Legal

Privacy policyTerms of serviceChildren's privacyAge suitability

Social

X YouTube Instagram

© 2026 Moonlit Tales. All rights reserved.

浙ICP备2026030253号-2A