Privacy Policy
Last updated: August 21, 2026
1. Who We Are
PagePal ("PagePal", "we", "us") operates the PagePal mobile application and this website. PagePal is an AI-powered reading app designed for children and families. Because our users include children, we hold ourselves to the strictest applicable privacy standards, including the Children’s Online Privacy Protection Act ("COPPA") in the United States, the GDPR in the European Economic Area and UK, and equivalent laws elsewhere.
[Questions? Contact us at any time: ]
2. Summary for Parents
- We do not sell personal information. Ever.
- We do not show third-party advertising or share data for ad targeting.
- A parent account is required before a child can use PagePal. Children access the app through child profiles created and managed from the Parent Zone.
- We collect only what is needed to run the service: account credentials, child profiles you create, reading progress, and technical/crash diagnostics.
- Parents may delete their account and all associated data at any time, and may contact us to review, correct, or delete any personal information we hold about their child.
3. Information We Collect
3.1 Information you provide
- Account information — when a parent creates an account we collect an email address and authentication credential via Firebase Authentication (including optional sign-in with Apple or Google).
- Child profile information — parents create child profiles containing a name or nickname, age or reading level, and optional interests used to personalize generated stories. This information is provided by the parent, not the child.
- Story prompts — themes, characters, and interests a parent selects when generating a custom book.
- Support communications — anything you send us by email.
3.2 Information collected automatically
- Usage analytics — anonymized product events (e.g., "paywall viewed", "quota reached", books completed). Analytics advertising features are disabled: ad storage, ad personalization, and ad user-data signals are all set to denied at startup, and no device identifiers are used for advertising.
- Crash diagnostics — Firebase Crashlytics collects crash reports and stack traces to fix bugs. Crash reports may include a random installation identifier, device model, OS version, and the state of the app at crash time.
- Subscription metadata — purchases are processed by Apple, Google, or Stripe. We receive from RevenueCat only non-financial entitlement data: product identifiers, tier (Plus/Family), trial status, and expiry dates. We never see or store full payment card numbers.
- Quota counters — per-profile counters of how many AI generations were consumed in a period, used solely to enforce free-tier limits.
3.3 Information we do NOT collect
- No precise location data.
- No photos, videos, or microphone recordings stored on our servers. Speech-to-text is processed on-device where supported.
- No contact lists, address books, or social graphs.
- No behavioral profiling for advertising.
4. How We Use Information
- To provide the service — authenticate users, store reading progress, generate personalized stories and illustrations, and read stories aloud.
- To enforce subscription entitlements and free-tier quotas.
- To improve the product — aggregate, de-identified analytics and crash reports.
- To communicate — transactional emails about your account or subscription when necessary.
We do not use personal information for targeted advertising, cross-app tracking, or resale to data brokers.
5. AI Processing
When a story is generated, the prompt and generation settings are sent to Google’s Gemini (Firebase AI) to produce text, and to image-generation models to produce illustrations. Story prompts should describe interests and themes, not identify a specific child. Where available, on-device generation processes everything locally and sends nothing to the cloud.
Voice narration is produced by Google Cloud Text-to-Speech from story text. Audio recognition features (pronunciation practice) are processed on-device.
6. Sharing & Service Providers
- Google / Firebase — authentication, database hosting, storage, analytics, crash reporting, remote configuration, and AI services.
- RevenueCat — subscription infrastructure and store receipt validation.
- Apple App Store / Google Play / Stripe — payment processing.
- Hugging Face — download of open-source on-device language models (model files only).
These providers process data on our behalf under contract. We disclose personal information only when required by law, or as part of a merger/acquisition subject to this policy’s continued protection.
7. Data Retention & Deletion
Account and profile data are retained while your account is active. When a parent deletes their account (from the Parent Zone or by emailing support@pagepal.us), we delete authentication records, child profiles, reading progress, usage counters, and entitlement records from our production systems within 30 days, except where retention is legally required. Aggregated, de-identified analytics events are not deletable once merged into aggregate statistics.
Backups roll off on a maximum 90-day cycle.
8. Children’s Privacy (COPPA)
PagePal is directed to families with children under 13. Consistent with COPPA, we do not knowingly collect personal information from a child without verifiable parental consent: a parent must create the account and each child profile before a child can use the app. Children cannot enter free-form chat with strangers, share content outside the app, or make purchases — all purchasing happens behind the Parent Zone.
Parents have the right to review the personal information collected from their child, request deletion, and refuse further collection. Email support@pagepal.us and we will respond within a reasonable time, and in any event within the period required by law.
9. Your Rights (GDPR / CCPA and similar)
Depending on your jurisdiction, you may have rights to access, correct, port, restrict, or erase your personal data, and to object to certain processing. To exercise any right, email support@pagepal.us. We never sell or "share" personal information as those terms are defined by the CCPA/CPRA.
10. Security
Data is encrypted in transit (TLS) and at rest in Google Cloud infrastructure. Database access is restricted by security rules so users can read only their own data, and administrative access requires authenticated service accounts. No method of transmission or storage is 100% secure, but we review our practices regularly.
11. International Transfers
Our service providers operate globally, which may involve transfers of data to the United States. Transfers are made under appropriate safeguards such as the EU Standard Contractual Clauses.
12. Changes to This Policy
If we materially change this policy, we will notify account holders by email or in-app notice before the change takes effect, and will obtain new parental consent if required for changes affecting children’s data. The "Last updated" date above always reflects the current version.