Privacy Policy
Effective August 22, 2026 · Policy version 2.6
This policy describes how Embertales ("we", "us") collects, uses, and shares information when you use the Embertales iOS app and this website. Embertales is an independently operated service; the operator can be reached any time at embertaleshelp@outlook.com. The short version: we collect what the app needs to run, your stories are yours, no person reads them unless safety systems or you flag them, and you can delete everything in one tap.
1. Information we collect
Account. Your email address and a Firebase-generated user ID. If you sign in with Apple, we store the Apple-provided identifier and the email Apple shares (which may be a private relay address), plus whether your email is verified.
Age check. Before the interactive app opens, we ask you to confirm that you meet its 16+ requirement. Where an approved date-of-birth fallback is used, the date is evaluated on the device and discarded; the browser or app keeps only the passed/blocked result and an adult/non-adult age band. Supported Apple devices may instead provide a privacy-preserving declared age range. The exact fallback date is not sent with a guest catalog request. Some existing accounts may have a birth date already stored on their private profile for server-side Mature-mode enforcement.
Profile. A username, an optional public display name, a separate private nickname the Storyteller uses for you, an optional uploaded or AI-generated profile photo and banner, an optional short bio, and your account privacy settings (public or protected, and whether new followers need your approval).
Story interests.You may choose up to five story genres. We store those choices on your private account profile and do not show them to other players. We use the genres you selected, together with each story's global popularity, to build your For You selection. If you have not selected any genres, we use your account ID to choose a stable starter mix. We do not save that mix or infer interests from the stories you read, your searches, or the people you follow. We do not use these choices for advertising.
Social profile and follows. Every account has a profile page other signed-in players can view. It shows your username, public display name, profile photo and banner, bio, follower and following counts, and the month you joined. When you follow another player (or they follow you), we store that connection; when an account requires approval, we store the pending request until it is accepted, declined, or withdrawn. Setting your account to protected does not hide your profile page: your name, photo, bio, and counts stay visible, marked with a padlock. What protection does is pull your shared stories from the catalog, limit the lists of who follows you and who you follow to you and your approved followers, and turn every new follow into a request you approve or decline. Your bio passes the same automated moderation as usernames before it is shown.
Notifications. If you allow notifications, we store an app installation identifier, an Expo push token, device platform, chosen language, and whether you want new-follower and follow-request alerts. We also keep short-lived server-side notification event and delivery-receipt records so a social action sends only once and invalid device tokens can be removed. Daily story reminders stay on your device and are not sent by our servers.
Your content. This includes your story drafts, finished stories, playthroughs and their messages, story notes, and per-tale settings. A story draft can contain its title, premise, opening scenes, character roles, genre and visibility choices, cover prompt, and an uploaded or AI-generated cover. When you choose Save draft, we store that private draft in Firebase so you can continue it on another signed-in device. Edits made after that stay on the device until you save again or finish the story. Drafts are not playable, searchable, or visible to other players. Saving a draft does not send its text to an AI provider. If you ask an AI tool to write part of it or make an image, the relevant text or image is processed as described in section 3. When you finish a public story, the story and your username become visible to other players. Finished stories you keep private are not shared.
Characters. We store the names, pronouns, appearance, and background you add to My Characters, along with any uploaded or AI-generated character picture you choose. The library and its picture links are private to your account. The image file itself uses an unlisted link, which means someone with the exact link could view it. When you choose a character for a tale, we copy the written details into that playthrough. The picture is decorative and is never added to the Storyteller's context. Character text and pictures pass automated safety review before they are saved. Rejected text and rejected pictures are not stored.
Image links. We store uploaded and generated images in our public image bucket so the app can display them without exposing the rest of your account. Profile photos and banners are visible on your profile, and a published story's cover is visible with that story. Images for private stories, character pictures, and the generated-image archive in My Images are not listed or searchable. My Images is private to your account in the app, but anyone who obtains an exact image link could view that file.
AI image references. When you create an image, you may add up to three reference images from your device or from My Images. A device image is resized and compressed, then held in private temporary storage while it is checked and used. An image chosen from My Images is checked again before use. Every reference is sent to OpenAI for automated safety review and, if it passes, to guide that image generation. References are not added to My Images or to your uploaded-image library, and the reference images and their links are not copied into the completed generation record. We delete the temporary reference set when the generation finishes, fails, or is discarded. An automatic backstop makes any remaining set unusable within 24 hours, and scheduled cleanup then removes its private files.
Generated-image details. My Images keeps the completed image and thumbnail together with the prompt, format, aspect ratio, quality, and reference count used to create it. The record says how many references were used, but does not keep the reference images or identify which images they were.
Creators you block. If you block a creator, we store that choice with your profile so their stories stay hidden from your catalog and search. Blocking also disconnects you from each other: any follow between the two accounts is removed in both directions, along with any pending follow requests, and neither of you can follow the other while the block stands. You can unblock anyone from Settings.
Likes and engagement. When you like a public story, we store that like against your account so the app can show your choice and count the story's likes. We also tally how often a story's card is shown (impressions) and how often a story is started. These signals order and recommend stories in the catalog. The view and start tallies are kept as per-story totals, not a record of what you personally looked at.
Moderation and safety records. When our safety systems flag content, or you report a reply, we record the event: your user ID, the category, and a reference to the content, so a human can review it and so repeat violations can lead to suspension. Our operational logs reference IDs, never your message text. For a rejected character profile or picture, the safety record keeps your user ID, the category, and the affected field, but not the rejected text or picture.
Purchases. Subscriptions bought in the iOS app are processed by Apple; subscriptions bought on the web are processed by Stripe. Both are managed through RevenueCat, our subscription service, which is what lets a plan bought in one place work in the other. We receive your subscription status, the product identifier, and the dates it runs between. We never receive your payment card details: those stay with Apple or Stripe, and the web checkout is Stripe's own, not a form we built.
Advertising (Free plan, iOS app only). The website shows no ads at all and contains no advertising code. In the iOS app, the Free plan shows ads through Google AdMob. In the EEA, the UK, and Switzerland, where the law requires it, we ask for your consent before showing you a personalized ad, and you can change or withdraw that choice any time from Ad privacy choices in Settings. If you say no, you still see ads, but they are not based on a profile of you. Before Google Mobile Ads starts, iOS also asks whether you will allow tracking across other companies' apps and websites. If you do not allow it, Google does not receive Apple's advertising identifier and every ad request is non-personalized. If you allow it, Google may use that identifier to personalize and measure ads. To serve and measure ads and to prevent fraud, the AdMob software also receives device information: a device identifier, your IP address (which gives it an approximate location), which ads were shown and tapped, and technical diagnostics. Paid plans show no ads, and none of this applies to them.
Technical data. IP address (used transiently for abuse rate-limiting; stored only in hashed form), device language, and app version. We also run an integrity check that confirms a request comes from a real copy of Embertales rather than a script, through Firebase App Check. How it does that differs by platform. In the iOS app it is Apple's App Attest / DeviceCheck, which involves no third party. On the signed-in pages of this website it is Google reCAPTCHA Enterprise, which performs an automated fraud-and-abuse risk assessment using device, application, browser, and interaction signals, and which sets a _GRECAPTCHA cookie in your browser when it runs. We use it only for security, fraud, bot, and abuse prevention. Google does not use it to serve you personalized advertising.
Usage metering. Each Storyteller turn records the model used, token counts, and the credits it consumed. Each image generation records its image type, requested and delivered quality, dimensions, model, token usage or cost estimate, and credits consumed. We use these records to enforce your plan's monthly allowance. They contain no message text or image description, and they are deleted with your account.
Recent searches. The search screen keeps a short list of your recent searches on your device so it can offer them back to you, and clearing them removes them. The list itself never reaches our servers. The searches you run do, briefly, because our servers have to look through the catalog to answer them; we do not keep a history of what you searched.
What your browser stores. Signing in on the web keeps your session on your own device rather than in a cookie we read: Firebase Authentication writes your sign-in tokens to the browser's IndexedDB and local storage so a refresh does not sign you out. Your appearance choice, your age check, your recent searches, and your Voice Mode preferences are kept there too. If sign-in interrupts a link into the app, the page you meant to open is held in session storage until sign-in finishes. While you edit a signed-in story draft, IndexedDB may hold one temporary recovery copy for that account. It lets the editor offer to continue after a refresh or browser restart. We do not upload that copy automatically. Choosing Save draft writes the draft to Firebase and removes the recovery copy; choosing Discard, signing out, or clearing site data removes it without saving those changes. None of this is sent to us as a cookie.
Draft recovery on your device. The iOS app also keeps one temporary recovery copy for the signed-in account. If the app closes unexpectedly, the editor can ask whether you want to continue or discard it. This copy is not uploaded in the background. It is removed when you save the draft, finish or discard the story, sign out, uninstall the app, or clear its data. Until you choose Save draft, changing devices will not carry those edits with you.
Guest browsing and local story drafts. After the 16+ age check, you can browse a curated set of Standard-rated Embertales story previews without an account or a Firebase anonymous user. One catalog request returns that sanitized set; freeform search, genre filtering, and title sorting then happen on your device. Guest search text is not sent to Embertales. Guest mode has no ads, behavioral tracking, personalization, likes, shares, follows, social graph, or Storyteller play.
You can also type one text-only guest story draft: its title, premise, opening, optional character names, pronouns, appearance and descriptions, genre choice, visibility choice, current step, and use of the default cover. The draft remains in this app installation or browser profile for up to seven days. It is not sent to Embertales, backed up, synchronized, moderated, published, or attached to an account while you are signed out, and it is excluded from telemetry and diagnostics. Anyone else using the same unlocked device or browser profile may be able to see it. You can discard it in the creator. Uninstalling, clearing site or app data, private-browsing cleanup, denied storage, expiry, or changing devices can make it unavailable.
When you choose to begin a story, unlock an AI creator tool, save, or publish, the device stores a high-entropy nonce and routing/action metadata for up to 24 hours so sign-in, email verification, and onboarding can return you to the same story or creator step. This return intent contains no guest draft text. After successful authentication, the guest draft is sent to a private Firebase handoff file while the requested action runs. We delete that file after the handoff is consumed or cancelled, or when it expires no later than 24 hours after it was staged. A successful import adds the content to the account as a new private draft after Firebase confirms the write. It does not replace an existing account draft. If the account already has 10 drafts, the guest copy stays on that device while you make room and retry, subject to the seven-day guest expiry. A restored freeform Discover query then becomes an ordinary authenticated search and may be sent to answer that search; it is not sent while you remain a guest.
Crash reports. If the app or the website hits an error, a technical report goes to Sentry, our error-reporting service. On the web this runs only on product pages, including guest product pages when diagnostics are configured, never on the marketing or policy pages you are reading now. Guest reports contain no account identity, story-draft text, or freeform search text. These reports describe the device or browser and the failure; we configure Sentry not to include personal information.
Voice: listening. Dictation, and Voice Mode on top of it, are optional. Your speech is turned into text by the platform you are using, never by us. On iPhone that is Apple's speech recognition, on your device when your language supports it and otherwise on Apple's servers under Apple's privacy terms (apple.com/privacy). In a browser it is that browser's own speech service, and in Chrome that means the audio goes to Google under Google's privacy terms (policies.google.com/privacy). We never receive, store, or transmit your microphone audio in either case. What we receive is the text, and it becomes part of your tale when the turn is sent. The microphone is off unless you are dictating or in a Voice Mode session, and in a session it is open for the length of your turn rather than only while you hold a button, which is what makes it hands free. Closing Voice Mode releases it.
Voice: speaking. When the Storyteller reads a reply aloud, the words are spoken by Google Cloud Text-to-Speech. The text of that reply leaves our servers and the audio comes back; your microphone audio is never part of it, and Google receives no account identifier with the request. If that service cannot be reached, your device's own built-in voice reads the reply instead and nothing leaves the device. In a Voice Mode session we also record how much of a reply you actually heard before it was interrupted, because only the sentences you heard become part of the story. That record is a sentence count, not a recording.
This website. It carries no advertising analytics and no behavioral tracking, and the support form only opens a draft in your own email app; nothing is sent from the site itself. The servers that deliver the site (Google Cloud, through Firebase hosting infrastructure and its CDN) automatically keep standard technical logs of each request, including IP address, browser type, the page requested, and the time, as almost every website's infrastructure does. We use those logs only for security, abuse prevention, and keeping the site reliable, never for advertising or profiling, and their retention follows Google Cloud's logging configuration.
Guest catalog delivery uses Firebase App Check and, on the web, reCAPTCHA Enterprise, which can process browser, device, application, and interaction signals and set the_GRECAPTCHA cookie. Catalog requests also contain ordinary technical request data needed for delivery, security, fraud prevention, and rate limiting. The application does not store raw IP addresses in its rate-limit records; it stores short-lived keyed pseudonymous counters. Pseudonymization does not make the data anonymous, and ordinary Google Cloud delivery logs follow the infrastructure retention described above.
2. How we use information
To run the app: authenticate you, store the story drafts you choose to save, keep your tales available across sessions, generate the Storyteller's replies, meter your plan's monthly allowance, rank and recommend stories in the catalog using the story interests you explicitly choose, or a stable starter mix when you have not chosen any, plus aggregate likes, views, and starts, show your profile page and follow connections to other players under the privacy settings you chose, show your subscription status, and (on the Free plan) show ads. To keep the community safe: enforce age rules, run content moderation on messages in both directions, respond to reports, and meet legal safety obligations. We do not sell your personal information.
3. AI processing
The Storyteller speaks in three voices, and the voice you pick for a tale decides which AI company generates that tale. Hearth runs on OpenAI's models; it is the voice every account starts with and the only one on the Free plan. Moonfire runs on Kimi models from Moonshot AI, and Terrene runs on Claude models from Anthropic; both are optional picks on paid plans, chosen tale by tale. To generate a reply, we send the tale's relevant content to that voice's provider: your messages, the premise and story notes, the character profile selected for the playthrough, your private nickname, and your chosen language. The background work a tale produces follows the same voice, so the tappable reply suggestions, the story notes the app keeps for you, the running summary of older scenes, and the judging of typed decision attempts for a Moonfire tale are handled by Moonshot, and for a Terrene tale by Anthropic.
Some work stays with OpenAI in every tale, whichever voice narrates. The automated content-safety checks read every message you send and every reply you receive, in all three voices, so picking a different voice never changes the moderation. OpenAI also screens usernames, display names, and bios when you set them, reviews character profile text and every image you upload (story covers, profile photos, profile banners, character pictures) before they are saved, classifies public stories by genre and maturity for the catalog, drafts the premise and opening scene when you ask the app to write them, and creates every AI-generated image. When you add reference images to an image request, OpenAI receives those references first for safety review and then for image generation if they pass. Uploaded images are never sent to the Storyteller for tale generation.
Each provider handles what we send under its own terms, and they are not the same. Under OpenAI's API terms, your content is not used to train their models; see openai.com/policies. Under Anthropic's commercial API terms, your content is not used to train their models either, and Anthropic deletes API inputs and outputs within about 30 days; content their safety systems flag can be kept for up to two years. See anthropic.com/legal/privacy. Moonshot AI's platform policy is different, and you should know it before you pick Moonfire: Moonshot (Moonshot AI Pte. Ltd., Singapore) stores what it receives on servers in Singapore, its policy says submitted content may be used to improve its models, and it publishes no opt-out and no fixed deletion timeline. In plain terms, a tale told with Moonfire may be kept by Moonshot and used to make Kimi models better. If you would rather your stories never travel there, use Hearth or Terrene; tales in those voices are never sent to Moonshot. See platform.moonshot.ai for their policy.
4. Service providers
We share data only with the processors that run the app: Google Firebase (authentication, database, storage, functions, website hosting, firebase.google.com/support/privacy), OpenAI (story and image generation, safety moderation, and genre classification), Moonshot AI (story generation for tales told with the Moonfire voice, platform.moonshot.ai), Anthropic (story generation for tales told with the Terrene voice, anthropic.com/legal/privacy), Google Cloud Text-to-Speech (the spoken narration, which receives the text of a reply and no account identifier, cloud.google.com/text-to-speech), RevenueCat (subscription management), Stripe (payments made on the web, stripe.com/privacy), Expo (push-notification delivery), Apple (payments made in the app, sign-in), Google AdMob (ads, Free plan only), and Sentry (crash and error reporting). Each processes data on our behalf under its own privacy terms. Section 3 explains which tales reach Moonshot AI and Anthropic and how each handles what it receives.
5. Human review of content
No person reads your private tales, with one exception: content flagged by our automated safety systems, or content you report, may be reviewed by a human so we can act on it. Details are on our Safety page.
6. Retention and deletion
Your data is kept while your account exists. Deleting your account is immediate and permanent, and you can do it from either place: in the iOS app under Profile, then Account, then Delete account, or on the web under Settings, then Account. It removes the same things wherever you start it: it removes your sign-in record, your profile and public profile page, your My Characters library and character pictures, your tales, playthroughs and messages, story notes, your likes, your follow connections and pending follow requests in both directions, notification installations and event records, uploaded and generated images, and your username reservation. Images that finish generating are saved in My Images and kept until you delete them there or delete your account. Deleting one from My Images removes its archived image and thumbnail. If you already used it as a story cover, profile photo, banner, or character picture, that separate applied copy stays in place until you replace or delete it, or delete your account. Reference images used only to guide a generation are not saved as uploads. Their private temporary set is removed when the generation finishes, fails, or is discarded. A lifecycle backstop makes it unusable within 24 hours even if normal cleanup is interrupted, and scheduled cleanup then removes its private files. When a like of yours is removed, the story's like count drops to match, and the follower and following counts of accounts you were connected to drop the same way. Stories you published to the community may stay in the catalog after you leave, with your name and authorship removed, so other players' in-progress tales are not broken. The one thing deletion keeps is the age check saved on your device, which stays so the minimum-age gate cannot be reset by deleting and remaking an account. Safety and moderation records may be retained where the law requires it; legally mandated safety reporting uses aggregate counts, not identities. We also keep subscription event records after deletion, for accounting and fraud prevention; they hold purchase metadata (product, dates, event type), never your content.
An account story draft stays in Firebase until you delete it, finish it as a story, or delete your account. Deleting a draft removes its cloud record. Finishing one creates the finished story and removes the draft in the same server operation. A device recovery copy is removed when you save, finish, or discard the story, or when you sign out. Drafts are included when you delete your account.
A guest draft expires no later than seven days after its last validated local write. The 24-hour guest return intent is removed after its destination is restored, when you explicitly start over, or when it expires. Neither is part of an account backup.
7. Your rights
You can access everything the app holds about you inside the app itself, and delete it as described above. Depending on where you live (for example California or the EEA/UK), you may also have rights to request access, correction, deletion, or portability, and to complain to your local data-protection authority. Write to us at embertaleshelp@outlook.com and we will honor these requests.
8. Age
The interactive Embertales app, including guest browsing, is for people 16 or older. Embertales applies the age-assurance method approved for the person's platform and region; an age declaration reduces risk but cannot prove that every viewer answered truthfully. Public marketing and indexed story teaser pages are separate from entering the interactive guest/app experience. We do not knowingly collect personal information from anyone under 16; if we learn we have, we delete the account. Users 16 to 17 receive additional protections described on the Safety page.
9. Security
Data is stored in Google Firebase with access rules that restrict every record to its owner; server code is the only writer. Traffic is encrypted in transit. No system is perfectly secure, but the app is built so that even our own client software cannot read other users' content.
10. Changes
When this policy changes we will publish the new text here with a new effective date and a new policy version, keep prior versions in the archive below, and note material changes in the app and on the website.
11. Contact
embertaleshelp@outlook.com · © Embertales
Previous versions
We keep every version of this policy here as it changes.
- Effective August 22, 2026 (current). Policy version 2.6. Clarified that account drafts are saved to Firebase only when you choose Save draft or finish the story, and that one device-only recovery copy is never uploaded automatically.
- Effective August 22, 2026. Policy version 2.5. Added private account story drafts, cross-device Firebase sync, temporary recovery copies, guest-draft import behavior, and draft retention and deletion details.
- Effective August 13, 2026. Policy version 2.4. Added signed-out curated browsing, device-local guest drafts, guest return intents, local search, guest App Check and rate limiting, and age-data minimization.
- Effective August 12, 2026 · Policy version 2.3. Added temporary reference-image processing for AI image generation, including safety review, OpenAI processing, private staging, expiry within 24 hours, and the generation details retained in My Images.
- Effective August 9, 2026 · Policy version 2.2. Added Apple's tracking permission before free-plan ads. If permission is not granted, all ad requests are non-personalized. If it is granted, Google may use Apple's advertising identifier to personalize and measure ads.
- Effective August 8, 2026 · Policy version 2.1. Added the private story-interest choices used for the For You selection and clarified that personalization uses only those explicit choices plus global story popularity, not inferred reading, search, or follow behavior.
- Effective July 27, 2026 · Policy version 2.0, covering the iOS app and the website together. Published when Embertales went live on the web. Purchases now name Stripe alongside Apple; the device-integrity check is described per platform, including Google reCAPTCHA Enterprise and the
_GRECAPTCHAcookie it sets on the website; a new section describes what your browser stores; crash reporting is described as covering the website as well as the app; advertising is scoped to the iOS app, as the website carries no advertising code; and account deletion documents the web path as well as the app one. Google Cloud Text-to-Speech and Stripe were added to the service providers list. - Effective July 25, 2026 · Embertales 1.1.0 and later. The Storyteller gained two optional voices, so the AI processing section now explains that the voice you pick decides which AI company generates that tale: OpenAI for Hearth, Moonshot AI for Moonfire, Anthropic for Terrene. It also spells out each company's data practices, including that Moonshot may use submitted content to improve its models, and that safety moderation stays with OpenAI in every tale. Added Moonshot AI and Anthropic to the service providers list and a note that recent searches stay on your device.
- Effective July 23, 2026 · Embertales 1.0.1 and later. Rewrote the advertising section. Free-plan ads can now be personalized for users who consent, and the section explains how to give or withdraw that consent in the EEA, the UK, and Switzerland. The app still does not ask for App Tracking Transparency permission.
- Effective July 22, 2026 · Embertales 1.0.0