Privacy Policy

Last updated: June 5, 2026

Moonlit Stories ("we", "us", "the app") is operated by Information Labs. We take your privacy — and your child's privacy — seriously. This policy explains what we collect, how we use it, and the choices you have.

1. Who this app is for

Moonlit Stories is designed to be used by parents and guardians on behalf of children. Accounts are created by an adult. Children listen via "kid profiles" inside the parent's account; kid profiles cannot sign in independently. The app does not contain ads, in-app purchases visible to children, or third-party tracking for advertising.

2. Information we collect

3. What we do NOT collect

4. How we use information

We use the data above strictly to operate the service: authenticate you, personalize stories to your kid's age, save offline downloads, track listening quota, deliver family-shared usage, and prevent abuse. We do not sell personal data.

5. Children's privacy (COPPA / GDPR-K)

We follow the principles of the U.S. Children's Online Privacy Protection Act (COPPA) and the EU General Data Protection Regulation as applied to children. Children's information is only ever provided to us by a parent or guardian who has set up the account. We collect the minimum necessary information, do not target advertising to children, and never sell or share kid profile data. Parents can review, edit, or delete a kid profile at any time from the Account screen.

6. Third-party services

We use the following sub-processors strictly to operate the service: hosting and database (Supabase / Cloudflare), authentication (Google OAuth at your option), text-to-speech providers (OpenAI, ElevenLabs) to generate narration. These vendors process audio and text on our behalf and are contractually prohibited from using it for their own purposes.

7. Data retention & deletion

You can delete a kid profile or your entire account at any time from Account → Sign out / Delete. On account deletion, profile data and stored listening history are removed within 30 days. Backups are purged on the next rotation cycle.

8. Security

All traffic is encrypted in transit (HTTPS). Row-level security is enforced on our database so users can only read their own and their family's data. Service-level keys are kept on the server and never shipped to your device.

9. Your rights

You can request access, correction, export, or deletion of your data by emailing hello@informationlabs.io. Users in the EU, UK, and California have additional rights under GDPR / CCPA which we honor.

10. Changes

If we make material changes to this policy we will notify signed-in users by email and update the "Last updated" date above.

11. Contact

Information Labs — www.informationlabs.io
hello@informationlabs.io