🐥 Hushfluff AI Tales is built for families. We take your privacy and your children's safety seriously. Please read this document carefully. By using our service, you agree to these terms.
Who We Are
Hushfluff AI Tales ("Hushfluff", "we", "us", "our") is operated by Pyformix AI Labs. We provide an AI-powered personalised bedtime storytelling service designed for children aged 2–15 and their families.
Our registered contact address: hello@hushfluff.com
🛡️ Child Safety First. Hushfluff is built for families. We never collect a child's photo, voice recording, or biometric data. Child profiles use emoji avatars only. We do not knowingly allow children under 13 to create accounts — accounts are created by parents/guardians.
What Data We Collect
Account Data (Parent / Guardian)
- Email address (via Clerk authentication)
- Password (hashed by Clerk — we never see it)
- Google OAuth token if you sign in with Google
- Account creation date and membership status
Child Profile Data
- Child's first name or nickname
- Age range (used to calibrate story complexity and content)
- Emoji avatar (no photos, no biometric data ever)
- Story preferences: favourite themes, characters, moral lessons
- Reusable characters created for that child
Usage & Story Data
- Stories generated, their titles, and associated metadata
- Story generation parameters (genre, theme, moral, world)
- Subscription tier and story usage count
Technical Data
- Device type and operating system (mobile app only)
- App version
- Crash reports and error logs (anonymous, no PII in logs)
- Firebase session tokens
We do not collect: location data, photos, audio recordings of family members, behavioural tracking across other websites, or payment card numbers (payments handled by Apple/Google/Stripe).
How We Use Your Data
- Provide the service: Generate personalised AI bedtime stories tailored to each child profile.
- Authentication: Verify your identity and protect your account via Clerk.
- Subscription management: Track your plan (Explorer or Dreamer) and story usage quotas.
- Story personalisation: Use child name, age, and preferences to craft relevant, age-appropriate content.
- Quality & safety: Detect and prevent abuse, prompt injection attacks, and quota fraud.
- Service improvement: Aggregate, anonymised analysis to improve story quality and app performance.
- Legal compliance: Comply with applicable laws including COPPA, GDPR, and App Store requirements.
- Customer support: Respond to your emails at hello@hushfluff.com.
We do not use your data for advertising, sell it to third parties, or use it to profile children for commercial purposes.
AI Services & Third Parties
Hushfluff uses the following third-party services to deliver the platform. Each is governed by their own privacy policy:
Google Gemini (AI Story Generation)
- We send story parameters (theme, age range, character names) to Google's Gemini API to generate story text.
- We do not send personally identifiable information (email, last name) to Gemini.
- Google may use API inputs to improve their models — we have configured API calls with data minimisation in mind.
- Governed by Google Privacy Policy.
Clerk (Authentication)
- Handles all user authentication, password management, and session tokens.
- Stores your email address securely.
- Governed by Clerk Privacy Policy.
Firebase / Google Cloud (Database & Hosting)
- Firestore stores all child profiles, story metadata, and account data.
- Firebase Hosting and Cloud Run host the web application and API.
- Data is stored in the us-central1 region.
- Governed by Firebase Privacy Policy.
Apple / Google (App Stores & Payments)
- In-app purchases on iOS are processed by Apple and governed by Apple's Privacy Policy.
- In-app purchases on Android are processed by Google and governed by Google's Privacy Policy.
COPPA — Children's Privacy (US)
🇺🇸 US Families: Hushfluff complies with the Children's Online Privacy Protection Act (COPPA).
- Accounts are created by parents or legal guardians only — not by children.
- We do not collect personal information directly from children under 13.
- Child profiles contain only a nickname, age range, and emoji avatar — no email, phone, or location.
- Parents can view, edit, or delete all child profile data at any time from the app.
- We do not share children's information with third parties for commercial purposes.
- If you believe we have inadvertently collected information from a child under 13 without parental consent, please email hello@hushfluff.com and we will delete it within 72 hours.
GDPR — European & UK Users
🇪🇺 🇬🇧 EU/UK Families: If you are in the European Economic Area or United Kingdom, you have additional rights under the GDPR / UK GDPR.
Lawful Basis for Processing
- Contract performance: Processing your account data and child profiles to deliver the storytelling service.
- Legitimate interest: Security, fraud prevention, and service improvement using anonymised analytics.
- Legal obligation: Compliance with applicable laws.
Your Rights
- Access: Request a copy of all personal data we hold about you.
- Rectification: Correct inaccurate data.
- Erasure ("right to be forgotten"): Delete your account and all associated data. Use the in-app "Delete my account" button, or email us.
- Restriction: Ask us to restrict processing in certain circumstances.
- Data portability: Receive your data in a machine-readable format.
- Object: Object to processing based on legitimate interest.
- Complaint: Lodge a complaint with your national supervisory authority (e.g. ICO in the UK).
To exercise any right, email hello@hushfluff.com. We will respond within 30 days.
Data Retention & Deletion
- Account data is retained for as long as your account is active.
- If you delete your account, all account data, child profiles, and generated stories are permanently deleted within 30 days.
- Anonymised, aggregated usage statistics (no PII) may be retained indefinitely for service improvement.
- Clerk authentication records are deleted per Clerk's retention policy upon account deletion.
- You can delete individual child profiles from the app at any time without deleting your full account.
To delete your account and all data: open the app → Settings → "Delete my account". This is immediate and irreversible.
Security
- All data is transmitted over HTTPS / TLS.
- Passwords are hashed and stored by Clerk — we never see them in plaintext.
- Firestore security rules enforce that users can only access their own data.
- Story generation endpoints are rate-limited and authenticated — no anonymous access to AI generation.
- We perform regular dependency security audits and apply patches promptly.
- API keys and secrets are stored in Google Cloud Secret Manager, never in source code.
Despite our best efforts, no system is 100% secure. If you discover a security vulnerability, please report it responsibly to hello@hushfluff.com.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify you via the email address on your account or an in-app notification at least 14 days before the changes take effect.
Your continued use of Hushfluff after the effective date constitutes acceptance of the updated policy.
Contact Us
For any privacy-related questions, data requests, or concerns:
- Email: hello@hushfluff.com
- Subject line: "Privacy Request — [your issue]"
- Response time: Within 5 business days (GDPR requests within 30 days)
Operated by Pyformix AI Labs.
Questions?
Reach us anytime at hello@hushfluff.com
