App: Tappy Tales ("the App") Provider / Database controller: Oriel Gilo ("we", "us", "our") Contact / Data requests: playtappytales@gmail.com Effective date: July 19, 2026
In a hurry? Jump to Children's privacy or read the kid-friendly version of this policy.
Tappy Tales is a learning app for young children, built to be set up and supervised by a parent or guardian. This policy is written with regard to Israel's Protection of Privacy Law, 5741-1981 (as amended by Amendment 13) and its regulations, as well as the GDPR and US state privacy laws where applicable. It explains what data the App handles, what stays on your device, what reaches our service providers, and your rights. It applies to the App itself; Google Play billing and other third-party services are governed by their own policies.
Everything you or your child create in the App — photos, audio recordings, and names — is stored only on your device, in the App's private storage. It is never uploaded to us or to anyone else. There is no cloud copy, no sync, and no backup service; if you delete the App or its data, that content is gone and we cannot recover it.
The App also contains no advertising, no analytics SDK, no crash-reporting SDK, and no push notifications, and it does not use your or your child's data with any AI system.
The only data that leaves the device is the minimum needed to run the parent account, purchases, and the family device limit — described in full below.
When you open a parent account we ask for an email address and password. In accordance with Section 11 of the Protection of Privacy Law, we hereby give notice:
| Data | Purpose | Basis (GDPR) | Whose data |
|---|---|---|---|
| Parent account: email address and an account identifier | Sign-in, password reset, tying purchases to your family | Contract performance | Parent |
| Purchase / entitlement data: which packs you own, active/refunded status, store, timestamps | Deliver Paid Content on your family's devices; honor refunds; restore purchases | Contract performance | Parent |
| Device registration: device model/name and an identifier per registered device | Enforce the family device limit | Contract performance / legitimate interest | Parent's devices |
| Technical logs: IP address and request metadata when the App contacts our backend (sign-in, entitlement checks, content downloads) | Security, abuse prevention, diagnostics | Legitimate interest | Not attributed to the child |
| Photos, recordings, and names created in the App | Operate the App's features on your device only | Not transmitted to us | Child / family (stays local) |
We do not collect advertising identifiers, location data, contacts, or usage analytics. We do not collect or process server-side any especially sensitive information as defined in Israeli law. We do not sell personal information and do not share it for advertising purposes.
Payment itself is handled entirely by Google Play; we never see your payment card or billing details.
The App has no feature that sends your or your child's data to any AI system. Some artwork and narration audio that we ship as content was produced with the assistance of AI tools during authoring and reviewed by us; this involves no user data.
The App does not use cookies, pixels, trackers, or similar technologies, and contains no tracking web components. The only storage is local in-app storage required for operation (your content, settings, and a local copy of the purchase list). Where these legal documents are shown on a web page, it is a static page with no tracking cookies and no analytics on our part.
We use a small number of service providers ("processors") to run accounts and purchases:
Each provider processes data only to provide its service to us, under its data-processing terms. We do not sell personal information to anyone and do not transfer it to any additional third parties, except:
Our backend services are hosted in the United States (Google Cloud, region us-central1; RevenueCat, US). Where data of EU/UK users is transferred, the transfer relies on the providers' standard contractual clauses and related safeguards under their data-processing terms. Data is transferred to these providers solely to operate the service, as set out in Section 7.
Our database contains only the account, purchase, and device data described above. Under the Protection of Privacy Law following Amendment 13, this database is not subject to registration and does not require notification to the Privacy Protection Authority (we are not data traders and hold no especially sensitive information server-side). Due to the limited, non-sensitive nature of the data we process, we are also not required to appoint a Privacy Protection Officer (DPO); privacy matters are handled directly by the controller at the contact address above. We implement security measures in accordance with the Protection of Privacy Regulations (Data Security), 5777-2017, appropriate to the database's scope and nature.
Under Israeli law (Protection of Privacy Law): - Right of access (Section 13): you are entitled to review the personal information we hold about you. We will respond to an access request within 30 days. - Right of correction and deletion (Section 14): if the information is incorrect, incomplete, or outdated, you may request its correction or deletion. We will respond within 30 days; if we refuse, we will explain, and you may apply to court. - Right to complain: you may complain to the Israeli Privacy Protection Authority.
Under foreign laws (where they apply to you): EU/UK GDPR — access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority; US state laws (such as CCPA/CPRA) — access, deletion, and opt-out of sale/sharing (we do not sell or share).
How to exercise: the parent exercises these rights on the child's behalf. Full account deletion is available directly in the App (Settings → Account → Delete account) and takes effect immediately. For any other request (access, correction, portability), email playtappytales@gmail.com from your account email address (this is how we verify your identity). We usually respond much sooner, and within 30 days at most.
Data in transit is encrypted (HTTPS/TLS). Server-side data lives in access-controlled Google Cloud services; paid-content downloads use short-lived signed URLs; entitlements are validated server-side. No system is perfectly secure, and we cannot guarantee absolute security, but we design the App so that the most sensitive data — your child's photos and recordings — never leaves your device at all.
If a security incident affects personal information, we will act in accordance with law: report to the Israeli Privacy Protection Authority as required by the Data Security Regulations, and, for an incident exposing you to significant risk, notify you directly as well. For EU/UK data, GDPR reporting duties apply (including 72-hour authority notification).
We may update this policy. Material changes will be announced in the App and take effect on the stated effective date. The current version is always available in the App and on our store listing.
Privacy questions and data requests: playtappytales@gmail.com.