KathaSagaram · Privacy

Privacy policy

Last updated 3 May 2026

KathaSagaram is built for children ages 4–8 and the grown-ups reading along. We treat your child's data as if it were our own child's. This page explains, in plain English, exactly what we collect and why.

What we collect

At first launch, we ask for two things:

  • Your child's first name — used only to greet them inside the app. The name never leaves your device.
  • Your child's age — an integer. We use it for engagement analytics: understanding what age groups enjoy which stories. Age is sent to our servers alongside a random profile id, not a name or any direct identifier.

We also automatically collect anonymous engagement events while the app is in use: which story was opened, how far through the audio you got, which quiz answers were chosen, app version, device platform (iOS / Android), and language. Each event carries the random profile id and the age, but no name, email, phone number, IP, or precise location.

What we don't collect

  • No email, phone, or login. The app has no account system.
  • No third-party advertising trackers. There are no ads in the app.
  • No precise location.
  • No camera, microphone, or contacts access.
  • No content from the WhatsApp feedback button — those messages stay on WhatsApp's servers, not ours.

Where data is stored

The name and age are stored in your device's local app storage (AsyncStorage on iOS / Android). Anonymous events are sent to our servers (operated by us, hosted on Cloudflare in a region close to your child) and retained for up to 18 months for analysis, after which they are automatically purged.

Deleting everything

Open the app, go to Settings → Reset progress. This clears the local profile and tells our servers to delete every event tied to your child's profile id within 30 days. You can do this at any time, for any reason, without contacting us.

COPPA & DPDP compliance

We designed KathaSagaram to comply with the U.S. Children's Online Privacy Protection Act (COPPA), India's Digital Personal Data Protection Act 2023 (DPDP), and the U.K./EU GDPR-K standard. The combination of "first name local-only" + "anonymous-id + age in events" + "one-tap deletion" was chosen specifically to keep us under the threshold of collecting "personal information" as those laws define it.

A parental gate (press-and-hold for three seconds) at first launch confirms an adult is setting up the app.

Sharing with third parties

We do not sell or share data with third parties for advertising, marketing, or any other purpose. We use:

  • Cloudflare for content hosting, edge caching, and DDoS protection. Cloudflare may briefly process IP addresses for those purposes; logs are not retained beyond what's needed for security.
  • Apple App Store / Google Play for distribution. Their privacy policies apply to install/update flows.

We do not use Google Analytics, Facebook SDK, Mixpanel, Amplitude, Sentry, or any third-party SDK that would receive your child's data.

Stories, quotes, and AI

The stories themselves are written and voiced with help from large language and text-to-speech models, then read end-to-end by a human reviewer before publication. We do not send any of your child's data to those models. See our AI disclosure for details.

Changes to this policy

If this policy changes materially, we'll publish an in-app notice and update the date at the top of this page. The full version history lives in our public source repository.

Contact

Questions, deletion requests, or data-protection concerns: