Privacy Policy

Last updated: April 26, 2026

1. Overview

BabySteps (the "Service") is an AI-powered learning platform for children aged 0-10. This policy explains how the Service collects, uses, stores and deletes your personal data, in line with applicable child data protection laws (e.g., COPPA in the US, GDPR-K in the EU, Korean Personal Information Protection Act (PIPA) Article 30 for Korean users).

2. Personal data we collect

2-1. Account sign-up and management (parent / legal guardian)

  • Required: email address and a unique social account ID (Google or Apple Sign-In)
  • Optional: nickname and profile picture

2-2. Service usage records

  • AI learning content history (stories, English, Korean, numbers, coloring)
  • Generated content text and assets (story body, learning materials, coloring pages)
  • Coloring stroke data created by the child (coloring_strokes)
  • Per-feature usage counts, timestamps and token usage (usage_logs) — used for billing and product improvement
  • Learning progress data (such as quiz results)

2-3. Payment information (paid subscriptions)

  • Purchase timestamp, amount, payment method type, and subscription period
  • * Card numbers, expiry dates and other actual payment credentials are never stored by the Service. Apple App Store, Google Play and our subscription processor (RevenueCat) handle them.

2-4. Voice profile (optional feature)

  • TTS API key (Fish Audio) entered by the user, stored encrypted
  • Voice recordings you make to create a voice model (sent to Fish Audio), generated voice profile ID and voice settings

2-5. Automatically collected information

  • IP address, browser, operating system, access time (Vercel server logs · Cloudflare proxy)
  • Cookies and session tokens (Supabase Auth)
  • Analytics cookies (Google Analytics — not collected in the EEA, UK or Switzerland)

2-6. What we do NOT collect

  • A child's real name, date of birth, address, phone number or other directly identifying information
  • Location data, device contacts, photo library, camera or microphone permissions
  • Advertising identifiers (GAID / IDFA)

3. How we use personal data

  • Authenticating accounts, managing accounts and providing the Service
  • Generating and delivering age-appropriate AI learning content
  • Processing subscription payments and managing subscription status
  • Service usage statistics, quality improvement and error analysis
  • Preventing abuse and maintaining the security of the Service
  • Meeting legal obligations such as retaining transaction records under applicable e-commerce laws

4. Retention and deletion

  • Account info and profile: deleted immediately when you close your account
  • Learning content: automatically deleted after 14 days (Free) or 30 days (Premium); items marked as Permanent Save are kept
  • Usage logs (usage_logs): retained for 90 days after account closure, then deleted
  • Payment and transaction records: retained for 5 years where required by applicable e-commerce laws (Korean Act on Consumer Protection in E-Commerce for Korean users)
  • Access logs: retained for 3 months where required by applicable communication-secrecy laws (Korean Communications Privacy Act for Korean users)
  • Abuse records: retained for 1 year, then deleted

5. Sharing and processing by third parties

We do not sell or share your personal data with third parties for their own purposes. To run the Service, we use the trusted processors listed below. Some are located outside your country, so we disclose this transfer at sign-up.

ProcessorPurposeLocation
Supabase Inc.Authentication, database, file storageUnited States (AWS)
Vercel Inc.Web hosting, access logs, visit analyticsUnited States
Google LLCSocial login · Gemini AI content generation from your entered learning topicUnited States
Fish AudioSpeech synthesis (TTS) and, if you opt in, voice model training (including voice characteristics)United States
Apple Inc.Apple Sign-In, App Store in-app purchasesUnited States
Google LLC (Play Billing)Google Play in-app purchasesUnited States
RevenueCat Inc.Subscription processing for App Store / Play Store IAPUnited States
Google LLC (Google Analytics)Service usage statistics and event analytics (uses cookies)United States
Cloudflare, Inc.CDN, DDoS protection, access logs (terminates TLS for all traffic)United States
Functional Software, Inc. (Sentry)Error diagnostics — error message, stack trace, page URL and browser/device info when the app failsUnited States

When generating AI content, only the information needed for generation (such as topic and age range) is sent to Google and Fish Audio. Identifying information like your email is never sent.

6. Children's privacy (parental consent)

The Service is built primarily for children, and protecting their privacy is our top priority.

  • Children under 14 need prior consent from a parent or legal guardian to use the Service, as required by applicable child data protection laws (e.g., COPPA in the US, GDPR-K in the EU, Korean Personal Information Protection Act (PIPA) Article 22-2 for Korean users).
  • Sign-up is performed by a parent or legal guardian using a Google or Apple account. The signup flow includes a parental consent checkbox.
  • We do not collect personal data directly from children. Sign-up, payment and account management are all done by the parent or legal guardian.
  • We do not perform behavioral tracking, profiling, or targeted advertising directed at children (COPPA / GDPR-K compliant).
  • We do not provide child-to-child communication features such as chat, comments or sharing.
  • A Parental Gate prevents accidental purchases by children at checkout.
  • A parent or legal guardian may at any time request access to, correction of, deletion of, or suspension of processing of their child's personal data.

See the Parental Consent Notice for full details.

7. Your rights and how to exercise them

  • You may request access to, correction of, deletion of, or suspension of processing of your personal data at any time.
  • You can delete all of your personal data immediately by closing your account from the Profile menu.
  • Send requests through the Profile menu or to kyd3534@gmail.com; we respond without undue delay.
  • For children under 14, a parent or legal guardian may exercise these rights on the child's behalf.

8. How we keep your data safe

  • All traffic uses HTTPS (TLS) encryption.
  • We do not store passwords (only Google and Apple Sign-In are supported).
  • Sensitive values such as TTS API keys (Fish Audio) are encrypted at rest.
  • Supabase Row Level Security (RLS) isolates each user's data.
  • Administrative access is limited to designated accounts and access activity is logged.
  • Internal staff receive regular privacy and data-protection training.

9. Cookies and similar technologies

  • We use essential cookies to keep you signed in (Supabase Auth).
  • Vercel Analytics may collect aggregate visit statistics to help us improve the Service (no personal identification).
  • We do not use advertising or tracking cookies.

10. Privacy contact

Information about our privacy officer and business contact is available on the Business Information page. For privacy questions, email kyd3534@gmail.com.

If you're in another jurisdiction, you may also contact your local data protection authority (for example, the FTC in the US, the ICO in the UK, your applicable EU DPA, or KISA's Privacy Infringement Report Center at privacy.kisa.or.kr for Korean users).

11. Changes to this policy

If we update this policy, we'll post a notice in the Service at least 7 days before the change takes effect. For changes that disadvantage users, we'll give 30 days' notice.