Draft. Not yet in force.
This text was prepared by engineering so that a qualified lawyer reviews and corrects it rather than starting from a blank page. It has not had that review, and the marked fields below are still unfilled. It does not yet describe binding terms, and this page stays out of search engines until it does.
Privacy Policy
Effective [[EFFECTIVE_DATE]]
Vunali is a bedtime-story app for children aged two to eight. It is made by José Antonio Caballero Martos, a sole trader established in Spain, of Avenida Ciudad de Barcelona 103, 28007 Madrid, Spain, tax identification number (NIF) [[TAX_ID]] ("we", "us"). He is the data controller for everything this policy describes.
This policy explains what we collect, why, and what you can do about it. There is a shorter, plainer companion written for parents at Children's Privacy, and a practical guide to exercising your rights at Data Rights and Deletion.
1. The short version
- Nothing about an individual child reaches us. The app has no child profiles, asks for no child's name, age or date of birth, and sends us nothing about what a child reads. Reading progress and favourites stay on the device.
- We do not show advertising, and we do not use any advertising identifier. There is no IDFA and no Android Advertising ID in this app.
- We do not sell or share personal data, and we do not use it for behavioural advertising or profiling.
- We do not embed third-party analytics, crash-reporting or advertising software. No Google Analytics, no Firebase, no Meta SDK, no Sentry.
- We do not collect usage statistics. The app records nothing for us about which tales are opened, how far they are read, or for how long.
- An account is optional for free tales and reading progress. Paid access requires a signed-in account. An account belongs to a parent or carer, never to a child.
- If you set a password, we never store the password itself, only a one-way scrambled form of it that cannot be turned back into what you typed.
- If you sign in with Apple or Google, we never see your password for them, and Apple's Hide My Email is fully supported.
2. What we collect
2.1 A device identifier
When the app first runs, our server generates a random identifier for that installation and sends it back to the app. It is created by us, at random. It is not your device's hardware identifier, serial number, advertising ID or anything the operating system assigns. It cannot be used to recognise you in another company's app.
Alongside it we store the platform (iOS or Android), the app version, and the language your device is set to. We use these to serve the right content, to keep the service secure, and to diagnose faults. We do not use them to build a profile of anyone.
2.2 An account, if you choose to create one
You can read free tales and keep reading progress without an account. Paid access, including a lifetime purchase, requires a signed-in account. If you create one, we store an email address, used to sign you in and to reach you about your subscription or a support request. We do not use it for marketing unless you separately ask us to.
There are four ways to sign in, and you may use more than one on the same account:
| Way in | What we store |
|---|---|
| A code sent to your email | Nothing beyond the address. The code itself is stored only as a one-way hash and is deleted once used or expired. |
| An email address and a password | The address, and a one-way scrambled form of the password. See section 2.3. |
| Sign in with Apple | The address Apple gives us, and the anonymous identifier Apple assigns you for this app. See section 2.4. |
| Sign in with Google | The address Google gives us, and your Google account identifier. See section 2.4, which explains why this one is not app-specific and Apple's is. |
2.3 Your password, if you set one
We never store your password. We store the output of a deliberately slow one-way function (PBKDF2-HMAC-SHA-256, 600,000 iterations, with a random salt unique to you). That output cannot be turned back into your password, and the slowness is there to make guessing expensive for anyone who ever obtained the stored values.
We never write your password, or the stored form of it, into a log.
We do not impose composition rules (no forced symbols or mixed case), because they push people towards weaker, more memorable passwords. We ask only for length, and we do not prevent you from pasting, so a password manager works normally.
2.4 Signing in with Apple or Google
If you choose Sign in with Apple or Sign in with Google, that company shows you their own screen. We never see the password you use with them. They hand us a signed token, we check the signature against their published keys, and from it we keep:
- the identifier they use to name you, and
- your email address, if they gave us one and told us it was verified. If they did not confirm it, we do not record it.
The two identifiers are not the same kind of thing, and we would rather say so than let one description cover both. Apple's is specific to this app: the value Apple gives us cannot be used to recognise you in another company's app. Google's is your Google account identifier, which is the same value Google gives to other apps you sign in to with Google. We use it only to recognise you when you come back, and we send nothing to anyone that would let them join it up with what you or your children read.
Apple's Hide My Email works normally. If you use it, the address we hold is Apple's relay address, we never learn your real one, and turning the relay off in your Apple account stops our mail reaching you.
Choosing this does not give either company any information about what you or your children read. Nothing goes back to them beyond the sign-in itself.
2.5 Your children
We collect no personal information about any child. The app has no child profiles: there is nowhere to enter a child's name, nickname, age, date of birth, photograph or voice, and nothing a child does in the app is sent to us.
If we ever add child profiles, we will update this policy, and the Children's Privacy page, before that version of the app is released, and we will collect only what the feature cannot work without.
2.6 Reading activity stays on the device
The app remembers which tales have been opened, how far through each one a reader is, and which are marked as favourites, so a story can be resumed and a shelf can remember what a child likes. That record is kept on your device only. It is not sent to us, and deleting the app deletes it.
2.7 Usage statistics
We do not collect any. The app sends us no record of which tales are opened, how far they are read, how long the app is used, or which buttons are pressed. We decided that an app used by two-year-olds is the wrong place to build a picture of a reader, and that a tap in a settings screen is not honest consent for doing so.
What this costs us is real, and we would rather pay it: we cannot see which tales work, so we ask you directly instead (section 10).
2.8 Downloads
Tales you download for offline reading are stored on your device. To let you download a paid tale, the app asks our server for a short-lived download permission, and that request carries the device identifier and, if you are signed in, your account. We do not keep a history of what was downloaded.
2.9 Purchases
Subscriptions and one-time lifetime access are bought through Apple's App Store or Google Play. We never see or receive your card details.
We use RevenueCat to keep track of what the stores tell us. RevenueCat sits between the store and our server, receives the store's own purchase records, and tells us whether paid access is active. What reaches us is the status, the product purchased, and its expiry when it has one. RevenueCat receives an identifier for your account or device and the store's purchase data; it does not receive your email address, your reading activity, or your password.
RevenueCat's software library is built into the app so the store purchase screens can work. It starts when the app starts, without knowing who you are: it gives the installation an anonymous RevenueCat identifier and exchanges with RevenueCat technical details such as the app version, the platform and its version, the store country and currency, and any purchase receipts the store holds for that device. When a parent signs in, it is told the account identifier (never the email address). It collects no advertising identifier and runs no analytics.
We do not treat your device's word as proof of purchase. After a purchase completes on your phone, the app waits for our server to be told independently before unlocking anything.
2.10 Notifications
The app does not send push notifications, and it does not ask for permission to.
2.11 The website
The website at vunali.com stores two things in your browser, and neither is used to track you:
- Your light or dark choice, kept in your browser's storage, never sent to us. Choosing the setting your device already uses removes it, because at that point there is nothing left to remember.
- Your language, in a cookie called
vunali-lang, set when you choose a language or when the site picks one for you from your browser's language setting, so the pages do not change language as you move between them. It holds only a language code, lasts one year, is never used to recognise you, and is a technical cookie needed to show the site in your language, so it needs no consent. Clearing your browser's cookies removes it.
The site uses no analytics and carries no advertising or third-party trackers. It loads its typefaces from Google Fonts, which means Google receives the request for those files, including your IP address, as it would for any website that uses them.
The waiting list. If you ask to be told when Vunali launches, we store the email address you type with our email provider, Resend, and nothing else about you. To keep automated sign-ups out, the form uses Cloudflare Turnstile, which examines technical signals from your browser, such as your IP address and browser characteristics, only to check that a person is using the form. Cloudflare does not use that check for advertising.
2.12 What we deliberately do not collect
No information about an individual child. No date of birth. No photographs. No contacts, calendar, microphone or camera access. No location of any kind. No advertising identifier. No biometric data. No browsing history outside the app. No free-text diary or comment field.
3. Why we are allowed to do this
For readers in the EU, EEA and UK, our lawful bases under the GDPR and UK GDPR:
| Purpose | Lawful basis |
|---|---|
| Running the app, serving tales, recognising your device | Performance of a contract (Art. 6(1)(b)) |
| Keeping accounts and paid access working | Performance of a contract (Art. 6(1)(b)) |
| Keeping the service secure and preventing abuse, including the bot check on the waiting-list form | Legitimate interests (Art. 6(1)(f)): a service that cannot defend itself cannot protect anyone's data |
| The waiting list | Consent (Art. 6(1)(a)), which you give by joining and can withdraw at any time |
For readers in the United States, please see Children's Privacy, which covers our position under COPPA.
4. Who else is involved
We keep the list of companies that touch your data as short as we can.
| Who | What they do | Where |
|---|---|---|
| Cloudflare | Hosts our servers, database, media files and website, and runs the waiting-list bot check | Global network |
| Apple | Processes App Store purchases, delivers the app, and provides Sign in with Apple if you choose it | Global |
| Processes Google Play purchases, delivers the app, provides Sign in with Google if you choose it, and serves the website's typefaces | Global | |
| RevenueCat | Receives purchase records from the stores and tells our server whether paid access is active (section 2.9) | United States |
| Resend | Delivers the sign-in codes and account emails we send you, and holds the waiting list | United States |
We do not use any third-party analytics, advertising, attribution or crash-reporting provider. If that ever changes, we will update this policy before the change ships, not after.
Cloudflare, RevenueCat and Resend process personal data on our instructions as our processors, under data processing agreements that bind them to use it only to provide their service to us.
Apple and Google act as sellers of record for purchases and handle your payment details under their own privacy policies, which we do not control. Where you use Sign in with Apple or Sign in with Google, that sign-in also happens under their policies rather than ours.
5. Where data goes
Our infrastructure runs on Cloudflare's global network, which means data may be processed outside your country, including in the United States. RevenueCat and Resend operate from the United States.
Where personal data leaves the EEA or the UK, the transfer relies on the European Commission's Standard Contractual Clauses (with the UK Addendum for UK data), which are part of each processor's data processing agreement, and, for providers certified under it, the EU-US Data Privacy Framework and its UK Extension.
6. How long we keep things
| Data | Retention |
|---|---|
| Device record | While the app is in use. Deleting your account unlinks it from every device, and it then remains only as an anonymous installation record. Deleted once the app has not contacted us for 24 months, or sooner if you ask |
| Account and email | Until you delete the account. Deletion is immediate; copies in our database's point-in-time recovery expire within 30 days |
| Stored password form and salt | Deleted with the account, and immediately when you remove the password from the account |
| Apple or Google sign-in link | Deleted with the account, and immediately when you unlink that provider |
| Paid-access status, including a lifetime purchase | Deleted with the account. We also ask RevenueCat to delete its record of your purchases when you delete your account. Apple and Google keep their own records as sellers; the payout statements we receive from them, which we keep for Spanish tax purposes, do not identify you |
| Abuse-prevention records (a one-way hash of the IP address, and for sign-in the email address) | Deleted automatically within 48 hours |
| Waiting-list address | Until you unsubscribe or ask us to remove it, and in any case no longer than 12 months after the launch announcement is sent |
| Server request logs | Up to 7 days, then deleted automatically by our hosting provider |
7. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, take it elsewhere, object to certain processing, or withdraw consent. Exercising a right never costs you access to the app.
Data Rights and Deletion explains how to do each of these, and how quickly we will respond.
You may also complain to a data protection authority. Ours is the Spanish Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. If you live elsewhere in the EEA or in the UK, you may complain to your own national authority instead.
8. Security
Connections use TLS. Sign-in tokens, one-time codes and passwords are stored as one-way hashes rather than in readable form, and passwords additionally use a per-user random salt and a deliberately slow function (section 2.3). None of these values is ever written to a log. Access to production data is limited to the controller.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects you, we will tell you and the relevant regulator as the law requires.
9. Changes
If we change what we collect, we will update this policy before the change reaches the app, and we will say what changed at the top of this page. Material changes affecting children will be notified in the app.
10. Contact
| Data controller | José Antonio Caballero Martos, NIF [[TAX_ID]] |
| Privacy questions and requests | [email protected] |
| General support | [email protected] |
| Post | José Antonio Caballero Martos, Avenida Ciudad de Barcelona 103, 28007 Madrid, Spain |
| EU representative (Art. 27 GDPR) | Not required: we are established in the European Union |
| Data protection officer | Not appointed, because our processing does not meet the conditions in Article 37 GDPR or Article 34 of Spain's Organic Law 3/2018 that require one. Write to [email protected] and your message reaches the controller directly. |
Fields still to be filled in on this page: [[EFFECTIVE_DATE]], [[TAX_ID]]