TaleTiles is built for families and is directed to children. We take your child's privacy seriously and design the TaleTiles app and related services to collect, use, and share as little personal information as reasonably necessary to provide the requested experience, operate and improve the service, maintain security, comply with law, and support current and future features as described in this Privacy Policy.
This Privacy Policy explains, in plain language, what information we collect, how we use it, when we disclose it to our service providers, how long we retain it, what choices and rights parents have, how we protect it, how our website and app differ, and how to reach us with questions or requests.
About TaleTiles
TaleTiles is a screen-light storytelling app for children ages 3 to 10. Children arrange physical wooden tiles featuring illustrated characters, settings, and objects. A parent or guardian then scans the arrangement with the device camera, and the app generates a personalized audio story in which the child may be the hero.
The current TaleTiles experience is intentionally bounded. In the current version, there is no child-created account, no child login, no open chat interface, no child voice-input feature, and no open-ended social gameplay. The parent or guardian may enter a small amount of information, the child arranges tiles, and the app produces a story. If we later add features, including features that involve remote storage or additional family participation, we will update this Privacy Policy and, where required, provide additional notice and obtain any required consent before using those features.
TaleTiles is operated by Fable Dynamics LLC, a Colorado limited liability company. For purposes of the Children's Online Privacy Protection Act (“COPPA”), Fable Dynamics LLC is the operator of TaleTiles. You can reach us at any time at privacy@taletiles.com, or by mail or phone using the details at the end of this Privacy Policy.
Information from Children
At setup, a parent or guardian may optionally provide a few pieces of information to personalize stories for a child. Every field is optional, and a story can be made without any of it.
- The child's first name. Optional and skippable. If skipped, the story uses “the hero” instead.
- A pronunciation hint. An optional “sounds like” spelling, used only to help the narration voice say the name correctly.
- A pronoun or gender preference. Optional and skippable. If skipped, the story uses they and them.
We do not ask for the child's last name, birthday, photo, voice recording, or precise location in the current version of the app. In the current 1.0 design, the child's first name, pronunciation hint, pronoun preference, saved stories, and saved audio are stored on the device rather than in a child profile on our backend. However, the child's first name, pronunciation hint, pronoun preference, and story text may leave the device when needed to generate and narrate a story through our service providers, as described in Sections 5 and 6. If we later add features that store child-related story content on our backend, we will update this Privacy Policy and, where required, provide additional notice and obtain any required consent before doing so.
Information from Parents
When you join the beta or otherwise contact us, we may ask for your email address and, optionally, your name and other contact or shipping details you choose to provide. We use this information to confirm participation, administer the beta, arrange shipping, provide support, send program and product updates, respond to questions, communicate about privacy or legal matters, and understand which testers are active during the beta.
Your beta email and name may be stored on your device and may also be sent to our backend service provider, currently Supabase, and to other service providers that support beta administration, support, communications, and parent-facing operational analytics, including PostHog where used. We design our product telemetry to avoid sending a child's name or story content to analytics and crash-reporting tools, and we do not intend to use parent contact details for targeted advertising. Parent contact records we maintain in backend or parent-facing operational systems are deleted through our manual deletion workflow after a verified request, subject to any legal retention requirements, as described in Sections 9 and 14.
Technical Information
To run the app reliably, understand whether stories are being generated successfully, monitor costs, improve performance, and maintain security, we record a limited amount of technical information. This information is designed not to include a child's name or story content, but some identifiers may still be treated as personal information under applicable law.
Pseudonymous identifiers
The app generates random identifiers that are stored on the device:
- install_id. A random ID created on first launch, stored locally on the device.
- session_id. A random ID created each time the app is opened fresh.
- story_run_id. A random ID created each time a story is generated.
These identifiers are random values. They are not tied to your name or your child's name, and they are not derived from a device hardware serial number or an advertising identifier. Even so, persistent identifiers can be personal information under COPPA and certain state privacy laws when used to recognize a user or device over time.
Product events and crash reports
- Product interaction events such as tile scans, story generations, playback completions, settings changes, and similar app events. Sent to Supabase, PostHog where used, and other internal service providers we use to support analytics, operations, and product reliability.
- Crash and performance data, sanitized to remove personal content where reasonably practicable. Sent to Sentry or a similar crash-monitoring service provider.
- Cost telemetry recording how much each story generation costs us to produce. Sent to Supabase.
Before this information leaves the device, we design the relevant event and crash-reporting flows to exclude a child's name, pronunciation hint, pronoun preference, story text, parent email address, and tile image from analytics and crash-reporting payloads. Our analytics and crash tools are intended to receive metrics and random identifiers, not story content and not a child's name.
What we do not collect technically
Apart from the parent beta contact information described in Section 3, we do not currently collect:
- Phone numbers or mailing addresses from users.
- The child's photo, voice recording, or video.
- Location data of any kind.
- Device advertising identifiers (such as the iOS IDFA or the Android advertising ID).
- Contacts, browsing history, or search history.
- Financial or payment card information in the app. If we add subscriptions or purchases in the future, billing is expected to be handled through the applicable app store or payment processor, and we will update this Privacy Policy if our practices change.
Camera Permission
TaleTiles needs access to your device camera to photograph the tile arrangement. The camera is active only when you tap to scan. The app does not capture images in the background or at any other time.
The photograph of the tiles is sent to OpenAI's vision service so the app can identify which tiles your child arranged. In the current design, this is intended to be a picture of the wooden tiles, not of your child. The scan request is designed not to include the child's name. We do not store these photographs on our own servers. Vendor processing may be transient or subject to the vendor's applicable service terms, and we continue to review vendor retention and model-training commitments as part of our compliance program.
You can revoke camera permission at any time in your phone settings. Doing so will disable story generation, since the app cannot read the tiles without it.
Third Party Processors
To deliver the core experience and operate our services, the app sends data to a limited number of third-party service providers. We engage these companies to perform functions on our behalf, such as AI processing, cloud hosting, analytics, support, and crash monitoring. We do not use them as data brokers, and we do not permit them to use children's personal information for targeted advertising.
OpenAI: Tile recognition and alternate story generation
Receives: The photograph of the physical tile arrangement for tile recognition, together with candidate tile information. The tile scan request is designed not to include the child's name, pronoun, or an image of the child. OpenAI also receives the story prompt text, which may contain the child's first name, pronunciation hint, and optional pronoun or gender preference, but only if we enable an internal PIN gated testing configuration that is not part of the default family experience.
Purpose: Identifying which tiles the child arranged and, only when an internal PIN gated testing configuration is enabled, writing the story narrative for limited testing.
Retention: Subject to OpenAI's applicable service terms and any additional contractual commitments we obtain. We do not retain the tile image on our own servers. We are pursuing and reviewing vendor commitments regarding retention, confidentiality, deletion, and restrictions on model training.
Anthropic: Current default story generation
Receives: The story prompt text used to write the story, which may contain the child's first name, pronunciation hint, and optional pronoun or gender preference if those were provided.
Purpose: Writing the story narrative in the current default configuration.
Retention: Subject to Anthropic's applicable service terms and any additional contractual commitments we obtain. We are pursuing and reviewing vendor commitments regarding retention, confidentiality, deletion, and restrictions on model training.
Inworld: Narration
Receives: The generated story text, which may contain the child's first name and related personalization details if those were provided.
Purpose: Producing the spoken narration audio.
Retention: Subject to Inworld's applicable service terms and any additional contractual commitments we obtain. The audio is delivered to the device, and we do not retain the story text on our own servers in the current 1.0 design unless you voluntarily submit story feedback to us.
Supabase: Backend, analytics, and feedback
Receives: Pseudonymous identifiers; scrubbed product, reliability, and cost-telemetry events; parent contact and beta administration information; support and feedback information you choose to submit; and, if you choose to send us feedback on a saved story, the submitted story text and related information needed to review that feedback. In future features, Supabase may also receive additional story-related content if those features are launched with appropriate notice and consent.
Purpose: Cloud backend functions, analytics and cost telemetry, beta administration, support, feedback review, product improvement, and any future backend-supported features we launch with appropriate notice and consent.
Retention: We retain information in Supabase only as long as reasonably necessary for the purposes described in this Privacy Policy, subject to our internal retention practices, deletion workflows, and legal obligations. Access to tables that hold parent contact information, support materials, or feedback submissions is restricted, and those records are intended to be written only through secured functions and authorized administrative access.
Tally: Beta intake forms
Receives: Parent or household contact information and beta application responses submitted through our website forms.
Purpose: Collecting and administering beta applications and related communications.
Retention: Subject to our internal retention practices and the applicable service terms for the form provider. We review and delete beta intake information when no longer reasonably needed for beta administration, support, or related legal and operational purposes.
Sentry: Crash monitoring
Receives: Pseudonymous identifiers and sanitized crash logs and performance traces. No child name, no story content, and no tile images are intended to be included.
Purpose: Crash and performance monitoring so we can identify and fix problems more quickly.
Retention: Subject to Sentry's applicable service configuration and our retention settings.
What We Never Do
To make this concrete, here is a list of things TaleTiles does not do.
- We do not sell personal information.
- We do not share data with advertisers or data brokers.
- We do not use data for targeted advertising, and we do not show behavioral advertising to children.
- We do not authorize our AI service providers to use children's personal information for their own model training or targeted advertising purposes, and we are working to confirm these restrictions contractually with each provider.
- We do not track users across other apps or websites for advertising purposes.
- We do not build advertising profiles.
- We do not send a child's name to our analytics or crash-reporting tools.
- The commitments in this section apply to the TaleTiles app and to children's personal information. Our marketing website is directed to adults and may use cookies, pixels, hashed identifiers, and advertising or measurement technologies as described in Section 12.
COPPA Compliance
TaleTiles is directed to children under 13. Fable Dynamics LLC is the operator under COPPA. We also seek to align our practices with applicable state privacy requirements to the extent they apply to our services and data practices. Our operator contact details are at the end of this Privacy Policy.
- We collect the minimum data reasonably necessary to provide the service, maintain and improve it, support security and operations, and comply with law.
- Every child-personalization field we currently collect from a parent or guardian, including the first name, pronunciation hint, and pronoun or gender preference, is optional.
- Before collecting personal information from children in a way that requires consent, we provide parents or guardians with notice of our child-data practices and obtain verifiable parental consent through a single in app consent step that is recorded before any child information is collected, including acceptance of the applicable Beta Test Agreement and related disclosures for the then-current experience.
- We retain personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
- Parents have the right to review, delete, or refuse further collection or use of their child's information by contacting us as described in this Privacy Policy.
- We do not condition a child's participation in the app on the collection of more data than is reasonably necessary for the relevant activity.
- We do not authorize children's personal information to be used for our service providers' independent model-training purposes, and we are working to confirm these restrictions contractually with each provider.
For parents and guardians. If you believe your child has provided information without your knowledge or consent, if you want a description of what we have on file, if you want us to delete information, or if you want us to stop further collection or use of your child's information, email privacy@taletiles.com and we will take reasonable steps to verify your request and respond as required by applicable law.
Parents' Rights
As a parent or guardian, and in some cases as a consumer under applicable state privacy law, you may have the right to:
- Review the personal information we have collected about your child or household, subject to applicable verification requirements and legal exceptions.
- Request deletion of personal information associated with your child's use of the app or your interactions with us, subject to applicable legal exceptions.
- Refuse further collection or use of your child's information, which may limit or disable some app functionality.
- Receive notice of material changes to this Privacy Policy and, where required, any additional notices regarding new data practices.
Most information about your child stays on your device and can be removed by deleting a character, deleting a story, or uninstalling the app. To request deletion of information we hold, email privacy@taletiles.com with the subject line “Privacy Request TaleTiles” and describe your request. After taking reasonable steps to verify the request, we will manually review and delete applicable backend contact records, support or feedback records you identify, and other information we are not required or permitted to retain by law. Because certain parent contact and operational records are maintained in backend and service-provider systems for beta administration and support, deletion requests for those records are completed through a manual workflow rather than self-service in the app. We will respond within the time required by applicable law.
Data Retention
We maintain internal data-retention practices designed to keep personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Scrubbed analytics and reliability data, including install_id, session_id, story_run_id, and product event logs, are retained for a limited period based on operational need, troubleshooting, security, and product-improvement purposes, and are then deleted or de-identified in accordance with our retention practices.
- Parent beta and support contact information is retained for as long as reasonably necessary to administer the beta, provide support, maintain records of consent and communications, and satisfy legal and operational obligations, unless you request deletion earlier and no exception applies.
- Story feedback submissions you voluntarily send us may be retained for a limited period reasonably necessary to review the feedback, improve the product, resolve support issues, document beta findings, and satisfy legal and operational obligations.
- Crash and performance data is retained in accordance with our service-provider settings and operational needs.
- Tile photographs sent to OpenAI are not retained on our own servers and are subject to OpenAI's applicable service terms and any additional contractual commitments we obtain.
- Story prompts sent to OpenAI, Anthropic, or another story-generation provider when enabled are not retained on our own servers in the current 1.0 design and are subject to the applicable provider's service terms and any additional contractual commitments we obtain.
- Story text sent to Inworld for narration is subject to Inworld's applicable service terms and any additional contractual commitments we obtain. We do not retain that story text on our own servers in the current 1.0 design unless you voluntarily submit story feedback to us.
- On-device information, including the child's name, saved stories, and saved audio, remains on your device until you delete it or uninstall the app, subject to device-level backup behavior that may apply to the current version of the app, including iCloud or other device backup settings.
Parents and guardians may request deletion at any time by emailing privacy@taletiles.com.
Security
We use reasonable administrative, technical, and physical safeguards designed to protect the limited amount of personal information we process. These measures include encrypted transmission over TLS, restricted access to backend systems, role-based limitations on who may access support and feedback records, vendor review as part of our compliance process, and efforts to minimize personal information in telemetry and crash reporting. Backend tables that hold contact information, support materials, or feedback submissions are intended to be access restricted and written only through secured functions or authorized administrative tools. On-device information is also protected in part by your device's sandboxing and device-level security features, such as passcode-based encryption where enabled. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
Our Website
Our marketing website, which hosts this Privacy Policy, is separate from the TaleTiles app. The website may use tools such as Tally to collect adult beta applications and may use advertising or measurement technologies, including Pinterest-related measurement tools, PostHog, and similar website analytics tools, to understand website traffic and ad performance. Those website tools are intended for adults and are not part of the in-app child storytelling experience. We do not intentionally collect a child's personal information through those website tools. Website-related data practices may involve cookies, pixels, hashed identifiers, or similar technologies associated with adult visitors or applicants.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, including changes related to new features, new categories of personal information, new uses, or new disclosures, we will update the effective date above and provide additional notice as required by law, which may include notice in the app, on our website, or by email to known parents or beta participants. If a change requires new consent, we will obtain that consent before applying the new practice where required by law.
Contact Us
If something on this page is unclear, if you want to know what we have on file about your family, if you want to exercise a privacy right or make a COPPA-related request, or if you want us to delete information, please contact us using the information below.
Privacy Questions
Fable Dynamics LLC
9451 S Hackberry Ln, Highlands Ranch, CO 80129
Email: privacy@taletiles.com
Phone: 303-618-5206
Subject line for privacy inquiries: “Privacy Request TaleTiles”