Privacy Policy
Giggle Tales · Last Updated: July 5, 2026
Introduction
Simply Practical, LLC ("we," "us," or "our") operates the Giggle Tales mobile application ("Giggle Tales" or the "App"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use the App.
Giggle Tales is designed for families and children. We collect only the information needed to provide age-appropriate stories, playback, profile management, parental controls, and related app functionality. We do not sell personal information, show ads, or use children's personal information for behavioral advertising.
Information We Collect
Parent or Account Data
- Anonymous authentication identifier: When cloud features are available, the App may create an anonymous Firebase Authentication identifier to secure app access. This identifier does not require a name or email address, and is not used to upload a child's profile (see "Cloud Services" below — child data stays on the device).
- Email address and password: If you choose to create or sign in to an email-based parent account, Firebase Authentication processes the email and password credentials. We store the email address with the account so the account can be identified and managed.
- Parental consent timestamp: When a parent or legal guardian completes the grown-up consent flow, we store a timestamp on the device showing that consent was provided.
Child Profile Data
Parents or guardians may create child profiles. Profile data may include:
- Display name chosen by the parent or guardian.
- Age or age range used to filter and recommend age-appropriate stories.
- Avatar or profile settings used to personalize the in-app experience.
- Favorites and listening history, such as stories saved or played.
App Preferences and Playback Data
The App may store preferences needed for playback and personalization, including:
- Voice preset selections.
- Pitch, speed, and silly-level settings.
- Sleep timer preferences.
- Active profile and playback state.
Story and Content Data
The App may download story catalog data, story text, cover images, and related content from our backend services. Story narration currently runs on the device using the operating system's text-to-speech capabilities.
Diagnostics and Analytics
At this time, Giggle Tales does not send child profile content, story listening details, or user-entered profile data to an advertising or third-party analytics network. The App includes internal diagnostic logging and local counters used to understand app behavior during development and operation.
If we enable third-party crash reporting, analytics, or similar telemetry in a future release, we will update this Privacy Policy and provide any required notices or controls before using those services for personal information.
Information Giggle Tales Does Not Request or Receive Directly
- Precise GPS location.
- Contact lists or address books.
- Photos or videos from the device.
- Microphone recordings.
- Device advertising identifiers.
- Browsing history outside the App.
- Payment card numbers.
Apple and Google process payment and store-account information under their own privacy policies when you make a purchase; Simply Practical does not receive your full payment-card number. App stores and infrastructure providers may also process device and network information (such as an IP address) as part of delivering their services.
How We Use Information
We use information only to operate, improve, and protect Giggle Tales, including to:
- Provide and personalize child profiles.
- Filter stories by age or age range.
- Save favorites, listening history, playback settings, and preferences.
- Support parental consent, parental controls, and data deletion requests.
- Authenticate an optional email-based parent account and secure app access.
- Load the public story catalog and related media.
- Troubleshoot bugs and maintain app reliability.
- Process or verify subscriptions if premium features are offered.
We do not use children's personal information for targeted advertising, behavioral profiling, or unrelated marketing.
Children's Privacy and COPPA
Giggle Tales is designed for use by families, including children under 13 with parent or guardian involvement. We follow the Children's Online Privacy Protection Act (COPPA) and similar children's privacy principles.
Our children's privacy practices include:
- Child profile information — display name, age or age range, avatar, favorites, and listening history — is entered by a parent or guardian and stored only on the device. It is not transmitted to our servers, so it is not collected online by us.
- Before a child profile is created, we present a direct notice to the parent or guardian in a parental gate describing what information the profile holds, that it stays on the device, and how to delete it, and we require the grown-up to complete that gate.
- Because child personal information stays on the device and is not transmitted to us, we rely on this parental gate and on-device attestation rather than a server-side verifiable-parental-consent mechanism. If we ever collect a child's personal information online (for example, optional cloud sync), we will first implement verifiable parental consent as COPPA requires and update this policy.
- We collect only the child profile information reasonably needed to provide the App, and we do not condition a child's use of the App on providing more than is reasonably necessary.
- Settings, profile management, data deletion, and other grown-up controls are protected by a parental gate.
- Parents and guardians may review, correct, delete, or stop further collection of their child's personal information.
- We do not show ads to children and do not integrate advertising SDKs or ad networks.
Persistent identifiers. Where cloud features are enabled, the App may create an anonymous authentication identifier to secure app access. A persistent identifier is treated as personal information under COPPA; we use this identifier solely to support the internal operation and security of the App and, where you create one, an optional parent account. We do not use it to build profiles of children or for behavioral advertising. The categories of third parties that may receive information (cloud infrastructure and authentication providers, and app stores and payment processors) are identified in "Third-Party Services" below.
If you believe a child provided personal information without proper parent or guardian consent, contact us at [email protected] and we will take appropriate steps to review and delete the information.
Data Storage and Security
Local Storage
Giggle Tales is designed to work locally where possible. Child profile information and parental-consent state are stored using the operating system's secure-storage mechanisms (the iOS Keychain and Android Keystore-backed storage). Non-sensitive preferences — such as caption and voice settings — are kept in the App's private application storage. This information stays on your device.
Deleting the App from your device generally removes local app data from that device. You can also use the in-app deletion controls described below.
Cloud Services
A child's personal information — child profiles (name, age), favorites, and listening history — is stored only on the device (in the operating system's secure storage) and is never uploaded to Firebase or any other server. Server-side collection of a child's personal information would require a higher standard of verifiable parental consent than the App implements, so the App does not do it.
When Firebase-backed features are configured and available, Giggle Tales may use Google Firebase only for purposes that do not involve a child's personal information: anonymous authentication identifiers, an optional email-based parent account (email address and password), and the shared public-domain story library.
Data sent to Firebase is protected in transit using HTTPS/TLS. Google Firebase and Google Cloud provide infrastructure-level security controls, including encryption at rest for supported services.
Narration
Story narration currently runs on-device through the operating system's built-in text-to-speech engine. Story text is not sent to a third-party narration service by the active playback experience.
Access Controls
We limit access to user data to authorized personnel and service providers who need access to operate, support, or secure the App. No method of storage or transmission is perfectly secure, but we use reasonable administrative, technical, and organizational safeguards appropriate to the information we process.
Third-Party Services
We use service providers to operate the App. These providers process information only as needed to provide their services to us. The services below are currently active in the released app:
| Service | Provider | Purpose / data involved | Privacy Policy |
|---|---|---|---|
| Firebase Authentication | Anonymous app-access identifier and, if you create one, optional email/password parent-account authentication | Google Privacy Policy | |
| Cloud Firestore | Public story catalog and, for an optional parent account, a parent user record (email, subscription status). No child profile data. | Google Privacy Policy | |
| Apple App Store | Apple | App distribution and purchase processing | Apple Privacy Policy |
| Google Play Store | App distribution and purchase processing | Google Privacy Policy |
Services not currently enabled. The following are not active in the current release and receive no user information today. We will update this policy, and provide any notices or controls required, before enabling any of them: Firebase Storage and Google Cloud Functions (reserved for possible future server-generated narration audio); RevenueCat (subscription and purchase validation, if premium billing is later turned on); and any third-party crash-reporting or analytics service.
We do not integrate advertising SDKs or ad networks.
Data Sharing
We do not sell personal information.
We may share limited information in the following circumstances:
- Service providers: With trusted providers listed above so they can provide hosting, authentication, storage, distribution, purchase processing, or other app infrastructure.
- Legal compliance: If required by law, legal process, or to protect our rights, users, or the security of the App.
- Business transfers: If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy or a policy with materially similar protections.
- With parent or guardian direction: When a parent or guardian uses app features to manage, export, delete, or otherwise control the information associated with their family.
Data Retention
We keep information only as long as needed for the purposes described in this policy, and we do not retain a child's personal information indefinitely. For each category below we identify why we collect it, the business need for keeping it, and when it is deleted.
| Data | Purpose & business need | Deletion timeframe |
|---|---|---|
| Local child profiles (name, age, favorites, listening history) | Provide age-appropriate stories and a personalized on-device experience | Kept on the device until you delete it in the App, clear app data, or uninstall the App |
| Parental-consent state | Record that a grown-up consented before profile creation | Kept on the device until you revoke consent or delete app data |
| Anonymous authentication identifier | Secure app access | [RETENTION — confirm against Firebase: e.g., cleared on sign-out or after N months of inactivity] |
| Optional parent email account | Identify and manage an email-based account | Kept while the account is active; deleted within [RETENTION: N days] of a verified deletion request |
| Diagnostic logs and local counters | Understand app behavior and maintain reliability | [RETENTION: e.g., 30–90 days] |
| Purchase records (only if premium billing is enabled) | Verify purchases, prevent fraud, provide premium access, and meet legal/accounting duties | Held by Apple, Google, and RevenueCat under their policies; any records we keep are retained for [RETENTION: legal/accounting period] |
| Support requests | Respond to and resolve your request | [RETENTION: N months after the request is resolved] |
| Aggregated or de-identified data | Understand usage in a non-identifying way | May be kept longer because it cannot reasonably identify a child or other individual |
Parental Rights and Controls
Parents and legal guardians may:
- Review the personal information collected from their child.
- Correct or update child profile information.
- Delete child profile information.
- Refuse further collection or use of their child's personal information.
- Revoke previously provided consent.
You can delete child profile data and revoke parental consent in the App by opening Settings > Privacy > Delete All Data. This removes child profiles, favorites, and listening history from the device and resets parental consent. Because this information is stored only on the device, deleting it in the App removes it; there is no server copy of a child's profile for us to delete.
For help with review, correction, deletion, or consent requests, contact us at [email protected] with the subject line "Parental Data Request." We may take reasonable steps to verify that the requester is the child's parent or legal guardian before fulfilling the request.
Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to certain processing of personal information, and to withdraw consent. To exercise any of these rights, contact us at [email protected]. We will respond as required by applicable law and may take reasonable steps to verify your identity or your authority as a parent or guardian.
United States (including California)
California and certain other state residents may have rights to know, access, delete, and correct personal information, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information, and we do not use children's information for targeted advertising.
European Economic Area and United Kingdom (GDPR / UK GDPR)
Simply Practical, LLC is the controller of the limited personal information we process to operate the App. The legal bases on which we rely are:
| Processing | Legal basis |
|---|---|
| Anonymous identifier used to secure app access | Legitimate interests — operating and securing the App (Art. 6(1)(f)) |
| Optional email-based parent account | Performance of a contract with you, or your consent (Art. 6(1)(b) / 6(1)(a)) |
| Processing a premium subscription (if enabled) | Performance of a contract (Art. 6(1)(b)) and legal/accounting obligations (Art. 6(1)(c)) |
| Diagnostic logs to maintain reliability and security | Legitimate interests (Art. 6(1)(f)) |
| Child profile information entered by a parent/guardian and stored on the device | Consent of the holder of parental responsibility (Art. 6(1)(a) and Art. 8); processed on-device under the parent's control and not transmitted to us |
You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). If you do not provide information needed for a feature you request — for example, an email account or a purchase — we may be unable to provide that feature; the core on-device reading experience does not require it.
Recipients. The categories of recipients are our cloud infrastructure and authentication providers, and app stores and payment processors, as listed in "Third-Party Services." EEA/UK representative: [ARTICLE 27 REPRESENTATIVE — appoint and list an EU and UK representative before EEA/UK launch, where required].
Children in the UK. For services likely to be accessed by children in the UK, we aim to follow the principles of the UK Age Appropriate Design Code (Children's Code), including privacy by default, data minimization, high-privacy settings, parental controls, and no advertising or tracking.
International Data Transfers
We are based in the United States, and our service providers may process information in the United States or other countries whose data-protection laws differ from yours. Where we transfer personal information from the EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful transfer mechanism. Contact us for more information about these safeguards.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by one or more of the following methods:
- Posting the updated policy in the App or on our website.
- Updating the "Last Updated" date above.
- Providing an in-app notice or app store release note when appropriate.
Continued use of the App after the updated policy becomes effective means the updated policy applies to your use of the App.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Simply Practical, LLC
Website: www.simplypractical.life
Email: [email protected]
Phone: [BUSINESS PHONE — TO ADD BEFORE PUBLISHING]
Address: 971 US HIGHWAY 202N STE N, BRANCHBURG, NJ 08876
Privacy by Design
Giggle Tales was built with privacy and child safety as core product principles:
- Minimal collection: We collect only what is needed to provide the App.
- Parent control: Parents manage child profiles, consent, and deletion.
- No ads: We do not show ads or use advertising trackers.
- On-device narration: The active narration experience uses the device's text-to-speech engine.
- Transparency: This policy explains the categories of data involved and the services we use.
© Simply Practical, LLC. All rights reserved.