Privacy Policy
Last Updated: September 24, 2026
Pillowtale ("we", "our", or "us") is an app built by Parallax Technologies LLC. This Privacy Policy explains what information the Pillowtale iOS app handles, why, who processes it on our behalf, where it goes, how long it is kept, and how you can delete it.
Pillowtale is made for parents and guardians. The parent is the user of the app; the stories are for children. A parent can record their own voice so that bedtime stories are narrated in that voice, read ready-made stories, and create personalized AI stories with illustrations. Pillowtale has no email sign-up and no login, and it does not show ads.
1. Summary
- Your voice stays with us. Your voice recording is turned into a cloned voice on a server operated by Parallax Technologies in Turkey. It is not sent to any third-party voice cloning company, and it is used only to narrate stories for you.
- Your child's name is not sent to the AI that writes the story or draws the pictures. Those models are given a placeholder, and the app puts the name in on your device afterwards. There is exactly one place the name does leave your device: reading a story aloud in the narrator voice. Section 3 describes it in detail.
- Nothing goes to an AI service until you say so. Before the first AI story, the app shows you what would be sent and to whom, and asks for your permission. You can withdraw it later in Settings, and withdrawing it stops the sending.
- No tracking. We do not use the advertising identifier (IDFA), we do not show an App Tracking Transparency prompt, and there are no advertising or social media SDKs in the app.
- No analytics SDK and no crash reporting service. Usage events travel through a server of ours that removes everything about your device before passing them on. The app collects no crash reports at all.
- No account, but an anonymous cloud backup so your AI stories survive a reinstall. It is not tied to your name, email or Apple Account.
- You can delete everything from inside the app (Section 9).
2. Information We Handle
2.1 Information You Enter About Your Child
During setup the app asks for a first name or nickname, an age group, interests, a daily listening goal and an avatar. You choose what to enter. The app also keeps simple progress counters on your device (stories read, listening minutes, current streak). This profile is stored on your device and is not uploaded anywhere as a profile.
2.2 Voice Recordings and Cloned Voices
If you use the voice feature, the app records a sample of your voice with your device microphone. The recording is saved on your device and uploaded to our own voice server to create a cloned voice. See Section 3.1.
2.3 Stories and Illustrations
- The choices you make when creating a story: character, topic, age group and language.
- Generated story text and titles. Because the app inserts your child's name into the story on your device, saved stories can contain that name.
- Generated illustrations.
- Narration audio, cached on your device so a story does not have to be narrated again each time it is opened.
2.4 Anonymous Cloud Backup
When the app first connects, it signs in anonymously to our cloud database. This creates a random user identifier; the sign-in token is stored in your device Keychain so the same anonymous identity is kept if you reinstall the app. Your AI-generated stories and their illustrations are stored in the cloud under that identifier, and database access rules allow each anonymous user to read and delete only their own stories.
2.5 Purchases
Subscriptions are purchased through Apple. We never receive your payment card details. We use RevenueCat to check whether you have an active subscription or free trial. RevenueCat receives purchase and subscription status information and an anonymous app user identifier that is separate from the cloud backup identifier.
2.6 Usage Analytics
We record a small set of product events to understand how the app is used: screens viewed and left with how long they were open, meaningful button taps, onboarding steps and completion, story played, story created, voice clone saved, AI consent granted, declined or withdrawn, paywall shown and closed, purchase completed, AI story limit reached, update prompts, a content report being filed, and a request for the rating prompt. Events carry only values the app chose from a fixed list, such as a screen name, a button name, a plan name, a language code or a number of seconds. They never carry your child's name, a story title, story text, your voice, an email address, or anything you typed.
There is no analytics SDK in the app. Events are sent to a server of ours, which forwards them to Mixpanel. This matters for three reasons, and all three are enforced by that server rather than promised by us:
- Mixpanel sees the network address of our server, never your device's, so your location cannot be inferred from it.
- Nothing about your device is included. An analytics SDK would normally add the device model, the operating system version and similar details by itself. Our server accepts only the fixed list of values described above and rejects anything else, so those details cannot be added by us either.
- The identifier attached to your events is a random value the app generates on your device at install. It is not the advertising identifier, not the device identifier, and not derived from your device in any way. Deleting your data replaces it with a new, unrelated one.
Mixpanel stores these events in the European Union.
2.7 Crash Reports
The app contains no crash reporting or performance monitoring service, and collects no crash data, stack traces or performance measurements. If you have chosen in iOS to share diagnostics with app developers, Apple may make crash reports available to us through its own developer tools; that is a feature of iOS, not something this app collects, and it is governed by Apple's privacy policy and your iOS settings.
2.8 Content Reports
If you use Report and Hide Story on a story, the report is stored in our cloud database so we can review it. A report contains the reason you chose, the story's language, and the story text in its placeholder form, which is the version before your child's name was inserted. It does not contain your child's name and carries no identifier for you.
2.9 Advertising Measurement
If you installed Pillowtale after seeing an ad, two measurement systems built by Apple may be used, and neither identifies you:
- SKAdNetwork. The app tells Apple a small number representing how far a new install has progressed (for example, finished setup, started a trial, subscribed). Apple passes that number to the advertising network without telling it who you are. No identifier for you or your device is involved.
- Apple Search Ads attribution. RevenueCat collects Apple's own attribution token so a subscription can be matched to an Apple Search Ads campaign.
We do not use the advertising identifier (IDFA), we never ask for App Tracking Transparency permission, and there is no Meta, Google Ads or other advertising SDK in the app.
2.10 Information We Do Not Collect
We do not collect your email address, phone number, contacts, photos, precise location, or the advertising identifier. We do not use your data for advertising and we do not sell it.
3. Voice, AI and Narration
3.1 Voice Cloning
- Before any voice is recorded, whether during setup or later from the Voices screen, the app asks you to confirm that you are the parent or guardian and that you consent to the voice being recorded and processed to create story narrations. Recording stays disabled until you do.
- The recording is uploaded over an encrypted connection to a voice server operated by Parallax Technologies (tts.parallaxtechnologies.net), which runs an open-source speech model from Kyutai. The connection reaches that server through a Cloudflare tunnel, so Cloudflare carries the encrypted traffic. The server is physically located in Turkey.
- The recording you upload, and the cloned voice created from it, are stored on that server until you delete the voice or delete your data. They are used only to narrate stories for you. They are not shared with, sold to, or used to train models for anyone else, and no third-party voice cloning provider is involved at any point.
- Only record your own voice, or the voice of an adult who has given you explicit permission.
- You can delete a voice at any time on the Voices screen. Deleting it removes the recording from your device and instructs our voice server to delete the stored voice.
3.2 Your Permission Before Anything Reaches an AI Service
The first time you create an AI story, the app stops and shows you what each AI service would receive and what it would not, including the one case where your child's name is involved. Nothing is sent until you agree. If you decline, no AI story is created.
You can withdraw this permission at any time in Settings. While it is withdrawn, the app does not create AI stories and does not send the text of an AI story to a speech service. The ready-made stories that come with the app still work, including in the narrator voice, because their text is written by us and contains nothing about your child. Narration in a voice you recorded also still works, because that stays on our own server. An AI story you already have is read aloud by the voice built into your iPhone instead.
If we materially change what is sent or who it is sent to, the app asks for your permission again rather than treating the old one as covering the new arrangement.
3.3 AI Story Text
To write an AI story, the app sends the chosen character, the topic, the age group and the language to OpenAI. If that request fails, the same request is sent to Google Gemini. Your child's name is not included, and neither are their interests, daily goal or avatar. The model is instructed to write a fixed placeholder token wherever the hero's name belongs, and the app replaces that placeholder with the name on your device after the story arrives.
3.4 Illustrations
Each page's illustration is created from a short visual scene description written by the model, plus a fixed art style. These descriptions never contain your child's name: the model is instructed not to put the placeholder in them, the app writes the hero as "the child" when it fills the story in, and the text is checked once more for the placeholder immediately before each request leaves your device. Inside pages are drawn by Google Gemini. The cover is drawn by fal, using an OpenAI image model that fal hosts; if fal is unavailable the cover is drawn by Gemini like every other page.
3.5 Narration
To narrate a story, the text of each page is sent to a speech service and the resulting audio is played and cached on your device:
- When a story is narrated in a voice you recorded, the page text is sent to our own voice server (Section 3.1) and to nobody else.
- Otherwise the standard narrator voice is created by Google Gemini text-to-speech.
- If neither is available, the app uses the voice built into iOS, which works entirely on your device.
Because the name is inserted on your device before narration, the page text sent for narration of a personalized AI story does contain your child's first name or nickname. This is the only path on which the name leaves your device to a company other than us, it happens only after you have given the permission described in Section 3.2, and it stops when you withdraw that permission. Ready-made library stories contain no name, in any voice. When read-aloud is switched on, the app prepares the whole story rather than one page at a time, so the text of every page of that story is sent.
3.6 How the AI Providers May Use What We Send
Our OpenAI and Google Gemini usage is on paid API plans. Under the API terms of both companies, content sent through those paid plans is not used to train or improve their models. They keep request data for a limited period for abuse monitoring and support, under their own published terms.
4. How We Use Information
- To provide the app: voice cloning and narration, AI stories, illustrations, and cloud backup of your stories (performance of our agreement with you)
- To process your voice recording, based on your explicit consent, which you can withdraw by deleting the voice
- To send story content to AI services, based on your explicit consent, which you can withdraw in Settings
- To manage subscriptions, free trials and usage limits
- To review content you report to us, so we can keep the app suitable for children
- To understand how the app is used, with the anonymous events described in Section 2.6 (our legitimate interest in keeping the app working and improving it)
- To comply with legal obligations
5. Where Information Is Stored
- On your device: the child profile and progress counters, voice profiles and recordings, saved stories and illustrations, cached narration audio, your AI permission, and the random analytics identifier. Voice recordings, stories and illustrations are kept in the app's documents folder, which can be included in your device backups; cached narration audio is excluded from backups. Usage counters for free and trial AI stories and the anonymous sign-in token are kept in the iOS Keychain.
- On our voice server in Turkey: your uploaded recording and the cloned voice made from it.
- In our cloud database (Supabase), hosted in Frankfurt, Germany: your AI stories and illustrations under your anonymous identifier, app configuration, and any content reports you file.
- With the processors in Section 6, for the purposes listed there.
All network requests use encrypted (HTTPS) connections.
6. Third-Party Processors
We share data only with the service providers below, only for the purpose listed, and we do not sell personal information. Each provider processes data under its own terms and privacy policy.
| Provider | Purpose | Data involved |
|---|---|---|
| OpenAI | Writing AI story text | Character, topic, age group, language. No child name. |
| Google (Gemini API) | Fallback story text, inside-page illustrations, fallback cover, standard narrator voice | Story choices and scene descriptions, neither containing the child name; and, for narration, page text which does contain the child's first name |
| fal | Cover illustration | Scene description. No child name. |
| Supabase | Anonymous sign-in, cloud backup of stories and illustrations, app configuration, content reports, and the server that forwards analytics events | Anonymous user identifier, story text which can include the child's first name, illustrations, content reports, analytics events |
| Cloudflare | Secure network connection to our voice server | Encrypted traffic to and from the voice server |
| RevenueCat | Subscription and trial status, Apple Search Ads attribution | Anonymous app user identifier, purchase history, device and app information, Apple's attribution token |
| Mixpanel (European Union) | Anonymous usage analytics | The events in Section 2.6 and the random install identifier. No device information and no network address from your device. |
| Apple | Payments, subscriptions and advertising measurement | Handled by Apple under Apple's privacy policy |
We may also disclose information where required by law or to protect the rights and safety of our users or others.
7. Children's Privacy
Pillowtale is designed to be set up and used by a parent or guardian. Children do not create accounts, and the app does not ask a child to enter any information. Purchases and links that leave the app sit behind a parental check. We do not knowingly collect personal information directly from children.
The only information about a child is what the parent chooses to enter: a first name or nickname, an age group, interests and an avatar. We keep this to the minimum needed to personalize stories:
- The child profile stays on your device.
- The child's name is never sent to the AI that writes stories or to any illustration provider, and never appears in analytics events or content reports.
- The name does appear inside your own personalized AI stories. Those stories are stored on your device and in your anonymous cloud backup in Frankfurt, and their page text is sent to a narration service to create audio, as described in Section 3.5, only with your permission.
- Nothing about your device is sent to any analytics provider, and no advertising identifier is used, so a child cannot be recognized across apps or services.
- We do not use a child's information for advertising, profiling or tracking, and we do not sell it.
By entering information about a child, you confirm that you are the child's parent or guardian, or that you otherwise have authority to provide it and to consent to its processing as described in this policy, including under the U.S. Children's Online Privacy Protection Act (COPPA) and the GDPR rules on children's data. You can review, change or delete this information at any time (Section 9). If you believe a child has given us information without a parent's involvement, contact us and we will delete it.
8. Legal Bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract with you, for providing the app and your cloud backup; your consent, for processing your voice recording and for sending content to AI services, either of which you can withdraw at any time without affecting processing that already took place; our legitimate interests, for anonymous usage analytics, for reviewing reported content, and for security; and compliance with legal obligations where they apply.
9. Data Retention and Deletion
9.1 How Long We Keep Data
- Data on your device is kept until you delete it in the app or delete the app. Items in the iOS Keychain (the anonymous sign-in token and AI story usage counters) can remain on the device after the app is deleted.
- Your voice recording and cloned voice are kept on our voice server until you delete the voice, delete your data, or delete your account.
- Cloud stories and illustrations are kept until you delete the story, delete your data, or delete your account. Deleting the app alone does not delete your cloud backup; reinstalling the app on the same device restores it.
- Content reports are kept until we have reviewed them and for a reasonable period afterwards, so a pattern of reports can be acted on. They contain nothing that identifies you or your child.
- Requests to AI providers are retained by each provider according to its own API data retention terms.
- Analytics events are retained according to Mixpanel's retention settings for our project.
- Subscription records are retained by Apple and RevenueCat as needed to manage your subscription and meet legal and accounting requirements.
9.2 How to Delete Data
- Delete a voice: on the Voices screen, delete the voice. The recording is removed from your device and the stored voice is deleted from our voice server.
- Remove a story: delete it, or use Report and Hide Story in the reader. The story is removed from your device and from your cloud backup.
- Delete All Data or Delete Account (Settings, then Data): removes your voice profiles and recordings, the child profile and progress, saved stories and illustrations from your device; deletes your stored voices from our voice server; deletes your cloud stories, illustrations and narration audio; withdraws your AI permission; discards any analytics events still waiting to be sent and replaces your random analytics identifier with a new, unrelated one; and, for Delete Account, deletes the anonymous cloud identity itself. If part of this cannot be completed because a server is unreachable, the app remembers what is left and finishes it the next time it can.
Because Pillowtale has no login, we usually cannot match an email request to your data. In-app deletion is the most reliable way to delete it, so please use it before deleting the app. You can still contact us at any time and we will help as far as we can identify your data.
10. Your Rights
Depending on where you live, including under the GDPR and UK GDPR, you may have the right to access, correct, export or delete your personal data, to restrict or object to processing, to withdraw consent at any time (without affecting processing before withdrawal), and to lodge a complaint with your local data protection authority. Most of these rights can be exercised directly in the app as described in Section 9. For anything else, contact us at contact@parallaxtechnologies.net.
10.1 KVKK (Turkey)
For users in Turkey, under the Personal Data Protection Law No. 6698 (KVKK) you have the right to learn whether your personal data is processed, to request information about the processing and its purpose, to know the third parties to whom it is transferred in Turkey or abroad, to request correction or deletion, and to object to processing. To exercise these rights, contact contact@parallaxtechnologies.net.
11. International Transfers
Parallax Technologies LLC is based in the United States. Where your information goes depends on what you use:
- Turkey: our voice server, which holds your voice recording and cloned voice.
- European Union: our cloud database and the server that forwards analytics events, both hosted in Frankfurt, Germany; and Mixpanel, which stores analytics events in the EU.
- United States and other countries: OpenAI, Google, fal, RevenueCat, Cloudflare and Apple operate globally and may process data in the United States and elsewhere.
Where personal data is transferred across borders, we rely on the safeguards each provider offers under its own data processing terms, and on your consent where consent is the basis for that processing. If you would like to know more about the arrangements that apply to a particular provider, contact us.
12. Security
We use encrypted connections for all data in transit, database rules that limit each anonymous user to their own stories, an API key on our voice server, and secrets held on our servers rather than inside the app where that is possible. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Privacy Policy, for example when we add a new provider or feature. We will change the "Last Updated" date above and, for material changes, tell you in the app. If a change affects what is sent to an AI service or who receives it, the app asks for your permission again (Section 3.2).
14. Contact Us
Parallax Technologies LLC
1111B S Governors Ave Ste 37573, Dover, DE 19904, United States
Email: contact@parallaxtechnologies.net
By using Pillowtale, you acknowledge that you have read and understood this Privacy Policy.