Skip to content
Timistories
How it works Features Pricing FAQ Our story
FR EN
Get the app

Privacy Policy

Privacy Policy — Timistories

Effective date: Version 1.0 — effective 10 June 2026 Document version: 1.0

This policy explains, in plain language, what personal data Timistories collects when you use the service, why we collect it, who we share it with, and how you can exercise your rights. It is written for parents — no law degree required.

1. Who is responsible for your data

The Timistories service (the mobile app, the website at timistories.com, the API) is operated by:

ILAD DIGITAL AGENCY - FZCO IFZA Business Park, Premises 56908-001, Building A1 Dubai Digital Park, Dubai Silicon Oasis Dubai, United Arab Emirates IFZA licence number: 56908 Privacy contact: privacy@timistories.com General contact: support@timistories.com

ILAD DIGITAL AGENCY - FZCO is the data controller under the EU General Data Protection Regulation (GDPR) — meaning we are the entity that decides why and how your data is processed.

In this policy, “we”, “our”, “Timistories” mean ILAD DIGITAL AGENCY - FZCO. “You” means the parent or legal guardian who creates the account.

2. EU Representative

Timistories is operated from the United Arab Emirates. GDPR Article 27 requires non-EU companies that regularly process EU residents’ data to designate a representative inside the EU whom users and supervisory authorities can contact.

At the time this policy is first published, no EU representative has yet been designated. We commit to designating an EU Representative (through a specialised provider such as EDPO or Prighter) within sixty (60) days of Timistories’ public launch and to updating this policy with their contact details as soon as the appointment is in place. Until then, you can exercise your rights directly with privacy@timistories.com.

3. What data we collect

Below is the complete list of personal-data categories Timistories collects in this version.

#CategoryConcrete examplesSource
1Email addressThe address used to create your parent accountYou enter it
2Child’s first nameFirst name used to personalise storiesYou enter it
3Other user contentChild’s date of birth, family values, topics to address or avoid, story prompts, characters and places you createYou enter them
4Payment informationStripe / RevenueCat / Apple / Google transaction identifiers. We never store your card number — it stays with Stripe or the App Store.Sent by the payment provider
5Crash dataTechnical error reports (Sentry)Generated automatically
6Performance dataTechnical performance metrics (Sentry)Generated automatically
7Product interactionsPseudonymous in-app funnel statistics (PostHog) — never linked to your identityGenerated automatically

No voice recording in this version. Recording a parent’s own voice so that stories can be read back in that voice is a planned future feature (Pro) that is not available yet. In this version we collect no voice samples and build no voice model. Story narration uses standard synthetic voices (see section 7). If and when we launch the voice feature, we will update this policy first, add an “Audio data” row to the list above, and ask for your explicit consent before any recording — see section 6.

We do not collect: your card number, your phone number (unless you write it yourself in a support message), your GPS location, your contacts, your web browsing history, any advertising identifier (IDFA / GAID).

4. Why we collect this data, and on what legal basis

GDPR requires every processing operation to rest on a legal basis (Article 6). Here is our mapping:

Data categoryPurposeLegal basis (GDPR Art. 6)
Email, child’s first name, user contentRun the service: create your account, generate personalised stories, send you essential emails (verification, reset, billing receipts)Performance of contract (Art. 6(1)(b))
Voice recording (planned future Pro feature — not active in this version)Would let your child hear stories read in your own voice, if we launch itExplicit consent (Art. 6(1)(a) + Art. 9(2)(a)) will be required before any recording — see section 6
Payment informationCharge a subscription or credit pack, prevent fraudPerformance of contract + legal obligation
Crash and performance dataDiagnose bugs, measure app stabilityLegitimate interest (Art. 6(1)(f)) — narrow technical diagnostics, pseudonymised
Product interactions (PostHog)Understand which flows work and improve the experienceLegitimate interest (Art. 6(1)(f)) — pseudonymous data, no advertising profiling

You can object to any legitimate-interest processing (see section 9: Your rights).

5. Children’s data

Timistories is a parent-operated application for generating stories for a child to listen to. The child does not create an account, does not type, does not pay. You — the parent or legal guardian — are the one who:

  • Creates the account with your email address.
  • Enters the first name and date of birth of your child to personalise stories.
  • Optionally adds an avatar and narrative preferences.

The application is not directed at children in the sense of the U.S. Children’s Online Privacy Protection Act (COPPA), and is not enrolled in the App Store Kids Category. It is designed to be used by an adult who then shares the resulting story with their child. We do not knowingly collect data from U.S. children under the age of 13.

We nonetheless apply child-protective principles:

  • Verifiable parental consent: account creation requires you to confirm you are at least 18 years old and the parent or legal guardian of the child whose details you enter.
  • Data minimisation: we collect only what is strictly useful to personalise the story (first name, approximate date of birth, the preferences you choose to enter).
  • No public profile, no social sharing on the child’s behalf, no advertising targeted at the child.
  • Deletion on request: you can delete the child profile at any time — see section 10.

If you believe a minor’s data has been entered without the parent’s consent, write to privacy@timistories.com; we delete within 7 days of verification.

6. Cloned voices — biometric data (GDPR Art. 9) — planned future feature, not active in this version

This feature is not available in this version of Timistories. Today, story narration uses standard synthetic voices provided through OpenAI (see section 7). We do not record your voice, do not build a voice model, and collect no audio samples.

We describe the feature here so you know the safeguards we intend to put in place before we ship it. If we launch parent-voice narration (as a Pro feature), your recorded voice samples would be used to build a digital voice model capable of reading new text in your voice. A voice model is special-category personal data under GDPR Article 9 (biometric data). Before that feature becomes usable, we commit to:

  • Updating this policy first and adding “Audio data” to the collection list in section 3.
  • Asking for explicit consent: before the first recording, the app would show a dedicated screen explaining what happens and ask you to actively check “I consent to my voice being used to create a voice model”, withdrawable at any time from Settings → Voices.
  • Defining retention and deletion: raw samples and the voice model would be kept only while your account exists and you have not deleted the voice yourself, in a private bucket encrypted at rest, and deleted within a maximum of 30 days of account closure.
  • Limiting reuse: the model would narrate stories on your account only — never shared with anyone, never used to train a general-purpose AI model.

Until we publish that update, none of the above is active and no voice data is collected. Every Timistories feature works today with the default synthetic voices.

7. Sub-processors and recipients

To run Timistories we rely on the service providers (“sub-processors” within the meaning of GDPR Art. 28) listed below. Each is bound by a Data Processing Agreement (DPA) incorporating the EU Standard Contractual Clauses (SCCs, Module 2 Controller-to-Processor) where data leaves the EEA.

Sub-processorRoleData transferredHosting regionDPA
Stripe Payments Europe Ltd.Payment processing (web, grandfathered subscriptions)Customer ID, amounts, transaction metadataIreland (EU) + United Stateshttps://stripe.com/legal/dpa
RevenueCat, Inc.iOS/Android in-app purchase receipts, subscription stateTimistories user ID (UUID), product identifiers, transaction eventsUnited Stateshttps://www.revenuecat.com/legal/dpa
Google LLC (Gemini API)Primary story-text generation and illustration generation (all plans)Story prompt (child first name, family values, narrative preferences), illustration promptUnited States + EUhttps://cloud.google.com/terms/data-processing-addendum
OpenAI, L.L.C.Default audio narration for all plans (text-to-speech, model gpt-4o-mini-tts). Turns the story text into the spoken narration your child hears.Story text to be narrated — which contains the child’s first name — and the chosen voice/styleUnited Stateshttps://openai.com/policies/data-processing-addendum
Anthropic, PBCFallback text-generation provider (Claude model) — configured for failover only, not active at v1; receives no user data in normal operationStory prompt — only if Gemini is unavailable and failover is triggeredUnited Stateshttps://www.anthropic.com/legal/commercial-terms (DPA in annex)
ElevenLabs Inc.Parent-voice narration (planned future Pro feature — not active in this version; receives no data today)None in this version. If launched: voice samples, voice model, text to narrateUnited Stateshttps://elevenlabs.io/legal/dpa
Resend, Inc.Transactional email delivery (verification, reset, receipts)Email address, message contentUnited States + EUhttps://resend.com/legal/dpa
Functional Software, Inc. (Sentry)Crash and error reportingPseudonymised user ID, error tracesUnited States + EUhttps://sentry.io/legal/dpa/
PostHog, Inc.Product analytics — pseudonymous in-app funnel statisticsPseudonymous distinct ID, in-app events (screens viewed, funnel steps); no story content, no child dataEuropean Union (EU Cloud, eu.i.posthog.com)https://posthog.com/dpa
MongoDB, Inc. (Atlas)Primary database hostingAll non-media account dataEU (eu-west-1, Ireland)https://www.mongodb.com/legal/dpa
Cloudflare, Inc. (R2)Media storage — generated audio narration and cover images (S3-compatible object storage)Generated audio files, cover-image files, object keysEuropean Union (R2 EU location)https://www.cloudflare.com/cloudflare-customer-dpa/
Cloudflare, Inc.CDN, DDoS protection, email routingRequest metadata, headersGlobal network (EU PoPs preferred)https://www.cloudflare.com/cloudflare-customer-dpa/
Amazon Web Services, Inc.EU compute host — runs the Timistories API (ECS Fargate, eu-west-1). Processes requests in transit; no media or database is stored on AWS (media is on Cloudflare R2, the database on MongoDB Atlas).Request data processed transiently in memoryEU (eu-west-1, Ireland)https://aws.amazon.com/agreement/ (DPA in annex)
Apple Inc.App distribution, iOS in-app purchase processingApp Store transaction identifierUnited StatesUnder Paid Apps Agreement
Google LLC (Play)Android distribution, Android in-app purchase processingPlay transaction identifierUnited StatesUnder Developer Distribution Agreement

We update this list whenever we change provider. The last update date appears at the top of this page.

8. International transfers

Timistories is operated from the United Arab Emirates (which is not, at the time of writing, the subject of an EU Commission adequacy decision). Several sub-processors are based in the United States or replicate data there.

To frame these transfers:

  • To the UAE: we rely on the EU Standard Contractual Clauses (SCCs) integrated into the contract between you (EU user) and Timistories.
  • To the United States: U.S. sub-processors (Stripe US, RevenueCat, Google, OpenAI, Resend, Sentry, Apple, Google Play — plus Anthropic and ElevenLabs as configured-but-inactive providers) are bound through SCCs, and several are certified under the EU-U.S. Data Privacy Framework where applicable. Our media storage (Cloudflare R2), our product analytics (PostHog EU Cloud) and our compute host (AWS, eu-west-1) keep that data inside the European Union.
  • To the United Kingdom / Switzerland: equivalent DPAs (UK Addendum / Swiss DPA).

You can request a copy of the contractual safeguards in place by writing to privacy@timistories.com.

9. Your rights

As a user you have the following rights under GDPR (Articles 15–22):

  • Right of access (Art. 15): obtain confirmation that we process your data and receive a copy.
  • Right of rectification (Art. 16): have inaccurate data corrected.
  • Right to erasure (Art. 17, “right to be forgotten”): have your data deleted — see section 10.
  • Right to restriction of processing (Art. 18).
  • Right to data portability (Art. 20): receive your data in a structured format (JSON).
  • Right to object (Art. 21): object to legitimate-interest processing.
  • Right to withdraw consent at any time (for any processing based on your consent).
  • Right to lodge a complaint with a supervisory authority (e.g., the CNIL in France: cnil.fr).

To exercise any of these rights, write to privacy@timistories.com from the email address registered on your account. We respond within one month at most, as GDPR requires.

If you reside in the United States: we do not knowingly collect data from children under 13 (the app is parent-operated and not directed at children for COPPA purposes). If you are a parent and believe your child has provided data without your consent, contact privacy@timistories.com.

10. Retention and account deletion

Here is how long we keep each category of data:

CategoryRetention period
Parent account (email, hashed password)As long as the account is active. Deletion: see below.
Child profile (first name, DOB, preferences)Same as parent account
Generated storiesSame as parent account
Generated audio narration + cover images (Cloudflare R2)Same as parent account; deleted within 30 days of account deletion
Payment data (Stripe / RevenueCat transactions)10 years (accounting requirement) — transaction identifiers only, no card data
Sentry crash logs90 days, then automatic deletion
PostHog logs (pseudonymous interactions)12 months
Internal audit log5 years, anonymised after account deletion (actorUserId: null)

Account deletion:

  1. From the app: Settings → Account → Delete my account.
  2. A 30-day cooling-off window opens — during this period, you can reactivate the account by emailing privacy@timistories.com or by signing back in.
  3. After 30 days, a nightly scheduled job (the gdpr_hard_purge cron) permanently deletes: stories, series, episodes, characters, places, family context, generated audio and illustration files in Cloudflare R2, sessions, email OTPs, shared links. The credit-ledger row is preserved but anonymised (userId: null) to meet our accounting obligation.
  4. The internal audit log retains records of actions in anonymised form for security and legal traceability reasons.
  5. MongoDB Atlas backups may still contain your data for the backup retention window (30 days) — this is an inherent property of any backup system.

11. Security

We implement the following measures:

  • Encryption in transit: all client ↔ server traffic uses TLS 1.2+.
  • Encryption at rest: the database and stored media files (Cloudflare R2) are encrypted (AES-256).
  • Password hashing with Argon2id (no plaintext storage, no reversible encryption).
  • Authentication tokens: short-lived JWTs + rotating refresh tokens; every session can be revoked.
  • Audit log: every sensitive action (deletion, admin access, payment) is traced.
  • Log redaction: Sentry and our server logs filter sensitive data before storage (Pino redaction layer).
  • Private bucket for generated narration audio; cover images are served read-only through the CDN.
  • Rate limiting on sensitive routes (/auth, story generation, /admin).

No system is invulnerable; we commit to notifying affected users and the relevant supervisory authority within 72 hours of any data breach with significant impact (GDPR Art. 33–34).

12. Cookies and trackers

The Timistories mobile app does not use cookies in the European-law sense (cookies are a browser concept). Authentication uses a token stored in expo-secure-store, the phone’s secure enclave.

The marketing site timistories.com is served by Cloudflare Pages and at v1 launch carries no advertising tracking pixel, no Google Analytics tag, no third-party attribution tool. If we add an audience-measurement tool in the future, we will update this policy and request your prior consent where legally required.

13. Changes to this policy

We may update this policy to reflect new sub-processors, new features, or legal developments. When the changes are substantial, we notify you by email and/or via an in-app notification at least 30 days before they take effect. The current version is always available at https://timistories.com/privacy.

14. Contact

For any question relating to your personal data:

ILAD DIGITAL AGENCY - FZCO IFZA Business Park, Premises 56908-001, Building A1 Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE Privacy: privacy@timistories.com General support: support@timistories.com Legal: legal@timistories.com

Timistories

The bedtime story, without having to invent it.

Built by a dad. Published by ILAD DIGITAL AGENCY - FZCO, Dubai.

Product

How it works Features Pricing FAQ Our story

Legal

Privacy Terms Copyright Contact
© 2026 Timistories. All rights reserved. · ILAD DIGITAL AGENCY - FZCO, Dubai · hello@timistories.com