Privacy Policy
Privacy Policy
1. Operator
MoonTale is operated personally by Konieczny Miłosz, an individual located in Poland. MoonTale is not currently a registered company or separate legal entity.
Contact MoonTale at contact@moontaleapp.com.
2. Who MoonTale is for
MoonTale is designed for adult parent- or guardian-guided use. Children should not independently use forms or submit personal information. MoonTale does not provide child accounts.
Parents and guardians should use only a nickname for a child and must not enter full legal names, child email addresses, telephone numbers, home or school addresses, precise location, medical information, photographs, voice recordings, biometric information, identification numbers, or other sensitive information.
3. Information currently processed
- Parent email address and authentication information when an adult creates an optional parent account.
- Parent email address, adult confirmation and marketing-consent status when voluntarily submitted for waitlist or product-update communications.
- Child nickname, age group, home language, target learning language and interests when a signed-in adult explicitly creates or updates a private child profile.
- Additional child nickname, story settings, generated story and saved-story information stored only in the current browser for the anonymous story flow.
- Language preference, account-session data and cookie-consent choice stored in the browser.
- Optional Google Analytics identifiers and events after analytics consent.
- Basic technical request data processed by GitHub Pages and service providers when the website is requested.
4. Where information is stored or sent
| Information | Location or provider | Notes |
|---|---|---|
| Parent account email and authentication data | Supabase Auth | Processed when an adult explicitly creates or uses an optional parent account. Passwords are submitted directly to Supabase Auth and are not placed in MoonTale website files. |
| Private child profile | Supabase child_profiles table | Stored only after an authenticated parent creates or updates a profile. Row Level Security restricts each parent to rows linked to that parent's authenticated user ID. |
| Anonymous story profile and generated stories | Current browser localStorage | Stored on the visitor's device until deleted by the visitor, browser, or browser settings. Signing in does not upload this existing browser data. |
| Parent email and waitlist consent details | Formspree | Sent only if the adult voluntarily opts in to product updates or submits a waitlist form. |
| Website files and technical request data | GitHub Pages | GitHub Pages hosts the static website. |
| Optional usage analytics | Google Analytics, measurement ID G-716GP23C93 | Loads only after optional analytics consent. MoonTale does not intentionally send child nickname, story text, interests, account credentials or child-profile fields to analytics. |
| Story prompts and story information | No external AI provider | No external AI API or AI provider is currently connected; stories are generated locally in the browser from predefined templates and vocabulary. |
5. Purposes and legal bases
MoonTale uses information to authenticate optional parent accounts, create and manage parent-controlled child profiles, generate and display a personalised story locally, remember story settings in the browser, save local story previews, manage voluntary waitlist and product-update communications, respond to support, safety, privacy and IP enquiries, operate and secure the website, and measure website usage after optional analytics consent.
Depending on the situation, the legal basis may include processing requested by the adult to provide the prototype and account features, consent for optional analytics, consent for optional product-update emails, legitimate interests for basic security, abuse prevention and responding to enquiries, and compliance with legal obligations where applicable. MoonTale does not claim that consent is the legal basis for every operation.
6. Retention
- Browser story profiles and saved stories remain until the user deletes them, clears browser storage, or the browser removes them.
- Parent accounts and private child profiles remain in Supabase until the relevant profile is deleted, the account data is deleted following a verified request, or retention is otherwise required by law or security needs.
- Waitlist email addresses remain until unsubscribe or deletion, or for a maximum of 12 months after the person's last meaningful interaction, whichever occurs first.
- Support and privacy correspondence may be retained only as long as reasonably necessary to answer the request and document its resolution.
- Minimal unsubscribe suppression records may be retained solely to prevent accidental future promotional emails.
- Google Analytics retention must match the real dashboard setting; that setting must be confirmed before relying on a specific period.
7. Privacy rights and requests
Users may request access, correction, deletion, restriction, objection, withdrawal of consent, and information about processing by emailing contact@moontaleapp.com. MoonTale will respond without undue delay and normally within one month.
MoonTale may ask that a request be sent from the email address associated with the submission, but will not request unnecessary identity documents.
8. Browser deletion
Browser-only story profiles and saved stories can be deleted through the control below. This applies only to the current browser and device. It does not delete the parent account, authenticated child profiles, Formspree submissions or other provider-held records. Signed-in parents can delete individual child profiles on the Account page. Other provider-held information can be requested for deletion by emailing contact@moontaleapp.com.
9. Children
The prototype is being kept parent-directed while legal classification is reviewed. MoonTale does not knowingly request child email addresses, telephone numbers, precise locations, photographs, or other sensitive child information. An adult who believes a child submitted information may email contact@moontaleapp.com for deletion.
MoonTale does not claim full COPPA compliance and does not state that COPPA definitely does or does not apply.
10. International providers
Supabase, GitHub, Formspree and Google may process information outside Poland or the European Economic Area according to their service arrangements. MoonTale does not invent or claim specific transfer mechanisms or contractual details that have not been verified.