Privacy Policy
Last updated: April 26, 2026
1. Overview
BabySteps (the "Service") is an AI-powered learning platform for children aged 0-10. This policy explains how the Service collects, uses, stores and deletes your personal data, in line with applicable child data protection laws (e.g., COPPA in the US, GDPR-K in the EU, Korean Personal Information Protection Act (PIPA) Article 30 for Korean users).
2. Personal data we collect
2-1. Account sign-up and management (parent / legal guardian)
- Required: email address and a unique social account ID (Google or Apple Sign-In)
- Optional: nickname and profile picture
2-2. Service usage records
- AI learning content history (stories, English, Korean, numbers, coloring)
- Generated content text and assets (story body, learning materials, coloring pages)
- Coloring stroke data created by the child (
coloring_strokes) - Per-feature usage counts, timestamps and token usage (
usage_logs) — used for billing and product improvement - Learning progress data (such as quiz results)
2-3. Payment information (paid subscriptions)
- Purchase timestamp, amount, payment method type, and subscription period
- * Card numbers, expiry dates and other actual payment credentials are never stored by the Service. Apple App Store, Google Play and our subscription processor (RevenueCat) handle them.
2-4. Voice profile (optional feature)
- TTS API key (Fish Audio) entered by the user, stored encrypted
- Voice recordings you make to create a voice model (sent to Fish Audio), generated voice profile ID and voice settings
2-5. Automatically collected information
- IP address, browser, operating system, access time (Vercel server logs · Cloudflare proxy)
- Cookies and session tokens (Supabase Auth)
- Analytics cookies (Google Analytics — not collected in the EEA, UK or Switzerland)
2-6. What we do NOT collect
- A child's real name, date of birth, address, phone number or other directly identifying information
- Location data, device contacts, photo library, camera or microphone permissions
- Advertising identifiers (GAID / IDFA)
3. How we use personal data
- Authenticating accounts, managing accounts and providing the Service
- Generating and delivering age-appropriate AI learning content
- Processing subscription payments and managing subscription status
- Service usage statistics, quality improvement and error analysis
- Preventing abuse and maintaining the security of the Service
- Meeting legal obligations such as retaining transaction records under applicable e-commerce laws
4. Retention and deletion
- Account info and profile: deleted immediately when you close your account
- Learning content: automatically deleted after 14 days (Free) or 30 days (Premium); items marked as Permanent Save are kept
- Usage logs (
usage_logs): retained for 90 days after account closure, then deleted - Payment and transaction records: retained for 5 years where required by applicable e-commerce laws (Korean Act on Consumer Protection in E-Commerce for Korean users)
- Access logs: retained for 3 months where required by applicable communication-secrecy laws (Korean Communications Privacy Act for Korean users)
- Abuse records: retained for 1 year, then deleted
5. Sharing and processing by third parties
We do not sell or share your personal data with third parties for their own purposes. To run the Service, we use the trusted processors listed below. Some are located outside your country, so we disclose this transfer at sign-up.
| Processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Authentication, database, file storage | United States (AWS) |
| Vercel Inc. | Web hosting, access logs, visit analytics | United States |
| Google LLC | Social login · Gemini AI content generation from your entered learning topic | United States |
| Fish Audio | Speech synthesis (TTS) and, if you opt in, voice model training (including voice characteristics) | United States |
| Apple Inc. | Apple Sign-In, App Store in-app purchases | United States |
| Google LLC (Play Billing) | Google Play in-app purchases | United States |
| RevenueCat Inc. | Subscription processing for App Store / Play Store IAP | United States |
| Google LLC (Google Analytics) | Service usage statistics and event analytics (uses cookies) | United States |
| Cloudflare, Inc. | CDN, DDoS protection, access logs (terminates TLS for all traffic) | United States |
| Functional Software, Inc. (Sentry) | Error diagnostics — error message, stack trace, page URL and browser/device info when the app fails | United States |
When generating AI content, only the information needed for generation (such as topic and age range) is sent to Google and Fish Audio. Identifying information like your email is never sent.
6. Children's privacy (parental consent)
The Service is built primarily for children, and protecting their privacy is our top priority.
- Children under 14 need prior consent from a parent or legal guardian to use the Service, as required by applicable child data protection laws (e.g., COPPA in the US, GDPR-K in the EU, Korean Personal Information Protection Act (PIPA) Article 22-2 for Korean users).
- Sign-up is performed by a parent or legal guardian using a Google or Apple account. The signup flow includes a parental consent checkbox.
- We do not collect personal data directly from children. Sign-up, payment and account management are all done by the parent or legal guardian.
- We do not perform behavioral tracking, profiling, or targeted advertising directed at children (COPPA / GDPR-K compliant).
- We do not provide child-to-child communication features such as chat, comments or sharing.
- A Parental Gate prevents accidental purchases by children at checkout.
- A parent or legal guardian may at any time request access to, correction of, deletion of, or suspension of processing of their child's personal data.
See the Parental Consent Notice for full details.
7. Your rights and how to exercise them
- You may request access to, correction of, deletion of, or suspension of processing of your personal data at any time.
- You can delete all of your personal data immediately by closing your account from the Profile menu.
- Send requests through the Profile menu or to kyd3534@gmail.com; we respond without undue delay.
- For children under 14, a parent or legal guardian may exercise these rights on the child's behalf.
8. How we keep your data safe
- All traffic uses HTTPS (TLS) encryption.
- We do not store passwords (only Google and Apple Sign-In are supported).
- Sensitive values such as TTS API keys (Fish Audio) are encrypted at rest.
- Supabase Row Level Security (RLS) isolates each user's data.
- Administrative access is limited to designated accounts and access activity is logged.
- Internal staff receive regular privacy and data-protection training.
9. Cookies and similar technologies
- We use essential cookies to keep you signed in (Supabase Auth).
- Vercel Analytics may collect aggregate visit statistics to help us improve the Service (no personal identification).
- We do not use advertising or tracking cookies.
10. Privacy contact
Information about our privacy officer and business contact is available on the Business Information page. For privacy questions, email kyd3534@gmail.com.
If you're in another jurisdiction, you may also contact your local data protection authority (for example, the FTC in the US, the ICO in the UK, your applicable EU DPA, or KISA's Privacy Infringement Report Center at privacy.kisa.or.kr for Korean users).
11. Changes to this policy
If we update this policy, we'll post a notice in the Service at least 7 days before the change takes effect. For changes that disadvantage users, we'll give 30 days' notice.
