1. Who we are (data controller)
Sweet Tales is provided by Pavel Leonov, an individual (sole proprietor) established in Indonesia. Sweet Tales is operated by an individual developer and is not a registered company.
- Controller / responsible party: Pavel Leonov, an individual (sole proprietor).
- Establishment / jurisdiction: Indonesia.
- Privacy contact email: pav228.id@gmail.com
- Postal address: not published; a postal address is available on request by emailing the address above.
We are the entity named in the app's Google Play listing. If you have any question about this policy or your data, contact us at the email above.
2. What Sweet Tales does (in plain language)
Sweet Tales is a tool for adults (parents and guardians). An adult records their own voice (or the voice of a consenting family member), and the app uses AI voice-cloning text-to-speech to narrate children's bedtime fairy tales in that voice, with soft background music, for night-time listening. Stories are available in English, Russian, Spanish, Vietnamese, and Arabic. The adult can optionally enter a child's first name so it can be inserted into the stories. The adult sets everything up and operates the app.
The app is declared 18+ / not designed for children. It is a parent-facing creation tool, not a service directed to children. See Section 13 (Children's data).
3. Important: your voice and data are processed and stored in the cloud
We want to be clear and accurate: Sweet Tales does not run the voice cloning or story generation on your device.
- When you record a voice, that audio recording is uploaded over the internet to our cloud servers (GPU compute workers).
- On those servers we build a voice model ("voice clone") from the recording and use it to generate narrated story audio.
- The generated story audio, the child's first name, your account data, and certain operational records are stored in the cloud (object storage and a database) so the app can deliver and replay your stories.
We do not claim to be "fully offline" or "on-device only," because that would not be true, and your voice does not stay only on your phone. We do, however, limit what we collect, protect it in transit, and use it only to provide the app to you. See Section 10 (Security) and Section 14 (No sale of personal data).
4. The personal information we collect
4.1 Voice recordings (sensitive / biometric data)
When an adult records a voice for cloning, we collect the audio recording and a derived voice model (voiceprint) used to synthesize narration. A recording of a person's voice used to generate a clone of that voice is sensitive personal data and a biometric identifier. We treat it accordingly — see Section 6 (legal bases and explicit consent), Section 7 (voice-cloning consent rules), Section 11 (retention and destruction), and Section 12 (US biometric notice).
4.2 Child's first name (and any child profile details)
If the adult chooses to personalize stories, we collect the child's first name (and any optional profile detail the adult enters, such as the language for the stories) solely to insert the name into generated narration. The child's first name is required to complete onboarding/personalization — the app cannot generate a personalized story without it.
4.3 Account and authentication identifiers
- An anonymous session identifier is created so the app can work before (or without) you sign in.
- If you sign in, we receive an account identifier and email address from your chosen single-sign-on (SSO) provider (Sign in with Google or Sign in with Apple).
- We generate internal identifiers and short-lived capability/session tokens to operate the service securely.
- If you enable notifications, we hold an opaque push-notification token so we can deliver app notifications (see Section 9).
4.4 Purchase and subscription data
Sweet Tales includes one free story and then offers a "Sweet Tales Premium" subscription (monthly / annual, with a 7-day free trial) through Google Play Billing (Android) and the App Store (iOS). We receive purchase and subscription status (for example, whether an entitlement is active) and transaction identifiers. We do not receive or store your full payment-card number — payment is processed by Google or Apple. See Section 9.
4.5 Device, usage, and diagnostics data
- Device locale / language setting: sent when an anonymous session is created so we can determine the appropriate content region. We do not use GPS or precise location.
- Network/operational data: like any internet service, our servers receive technical connection data such as IP address, which we process to operate the service, maintain security, and prevent abuse. We do not use it to determine your precise location.
- Diagnostics / crash and error data: the app itself ships no third-party analytics, advertising, attribution, or crash-reporting SDK, and requests no advertising identifier. Our backend generates server-side operational logs and uses an error/crash-diagnostics service (Sentry) to capture exception and stack-trace data plus technical tags (such as a component name, job/flow identifier, and environment) so we can detect and fix failures. No audio and no voice data are sent to our diagnostics service.
We do not request precise location, contacts, calendar, photos, or an advertising identifier.
5. How and why we use your information
We use the information above to:
| Purpose | What this means |
|---|---|
| Build your voice model | Process the uploaded recording on cloud GPU workers to create the voice clone. |
| Generate narrated stories | Synthesize story audio in the cloned voice, mix in background music, and store the result so it can be played back. |
| Personalize stories | Insert the child's first name into narration when provided. |
| Operate your account | Create anonymous sessions, authenticate SSO sign-in, manage entitlements and consent records. |
| Process subscriptions | Validate and manage Premium subscriptions and the free trial via Google Play Billing and the App Store. |
| Provide support | Respond to your questions and requests. |
| Security & abuse prevention | Protect accounts, prevent fraud and misuse of the voice-cloning feature, moderate reported AI output, diagnose errors, and meet legal obligations. |
We do not use your voice, your stories, or the child's name to train general-purpose AI models for other users, and we do not use them for advertising.
6. Legal bases for processing
Where data-protection law requires a lawful basis — and as a matter of good practice everywhere — we rely on the following:
- Voice recordings and the derived voice model (sensitive / biometric data): your explicit consent, obtained in-app before any recording is uploaded. You may withdraw consent at any time (see Section 15); withdrawal does not affect processing already carried out before withdrawal.
- Child's first name and profile detail: consent of the operating adult and/or performance of the contract to deliver the personalization feature you requested.
- Account, authentication, and subscription data: performance of a contract (to provide the app and your subscription) and compliance with legal obligations (e.g., tax/record-keeping for purchases).
- Security, abuse-prevention, diagnostics, and service operation: our legitimate interests in keeping the service safe, reliable, and functioning, balanced against your rights.
7. Voice-cloning consent (you may only clone a consenting person's voice)
Sweet Tales may be used to clone only:
- your own voice, or
- the voice of a family member who has given their informed consent to be recorded and cloned for this purpose.
You must not record or clone anyone's voice without their knowledge and consent. You must not clone the voice of a public figure, a celebrity, or any non-consenting third party. Misusing voice cloning — for example, to impersonate a person, deceive others, or commit fraud — is strictly prohibited and may result in suspension and deletion of your account. Generated voice content is intended only for that family's private bedtime stories within the app.
Before any recording is uploaded, the app shows a prominent in-app disclosure explaining that the audio is recorded, uploaded to the cloud, and used to build a voice clone, and asks for your affirmative consent. For each additional family member whose voice is recorded, that person's informed consent is required as well.
8. AI-generated narration and content reporting
Sweet Tales narration is AI-generated: the app synthesizes speech from the recorded voice to read a curated catalog of public-domain fairy tales, with the child's first name inserted into fixed slots. The narration is created by artificial intelligence and is not a real recording of the person reading that specific story.
- AI-synthesis disclosure: we make clear, in the app, that the narration is AI-generated from the recorded voice.
- Closed catalog: the app narrates a pre-vetted catalog of public-domain texts with name-slot insertion only; there is no open-ended prompt that could be steered toward harmful content.
- Reporting concerns: if you ever encounter narration or AI-generated output you find offensive or inappropriate, you can report it by emailing us at pav228.id@gmail.com. We use those reports to inform content moderation and filtering, and we prohibit using Sweet Tales to clone the voice of any non-consenting third party, public figure, or celebrity (see Section 7).
9. How we share information (sub-processors and third parties)
We do not sell your personal information (see Section 14). We share information only with service providers ("processors") who help us run the app, and only as needed to provide it. Our recipients are:
| Provider | Role | What they receive |
|---|---|---|
| DigitalOcean | Cloud hosting (servers running our API, gateway, and TLS edge); object storage (Spaces, region ams3 / Amsterdam) for uploaded voice recordings and generated story audio; managed PostgreSQL (account data, child first name/profile, consent records, entitlements, voice/job metadata); managed Redis (queues, pub/sub, and operational state). |
Voice recordings and generated story audio (object storage); account, child-name, consent, and metadata records (database); queue/operational state (cache). No card numbers. |
| RunPod | Rented GPU compute where our self-hosted voice-cloning and text-to-speech model runs. The cloning model is ours, not a third-party voice API. Data-center region varies. | Downloads your uploaded recording, builds the voice model, generates narrated story audio, and writes results back to object storage. |
| ElevenLabs | Third-party text-to-speech used only for the onboarding "teaser" sample. | Only the child's first name (as text), voiced by a pre-licensed sample voice. Your or your family's voice recording is never sent to ElevenLabs. |
| Sentry | Backend error/crash diagnostics. | Exception and stack-trace data plus technical tags (component, job/flow identifier, environment). No audio, no voice. |
| Google Play Billing (subscriptions/IAP) and Sign in with Google (authentication). | Purchase/subscription status and transaction tokens; on sign-in, an account identifier and email. We never receive full card numbers. | |
| Apple | App Store billing (subscriptions/IAP) and Sign in with Apple (authentication). | Purchase/subscription transaction data; on sign-in, an account identifier or relay email. We never receive full card numbers. |
| Expo (Expo Application Services / 650 Industries) | Push-notification delivery. | An opaque push-notification token and the notification text/copy (relayed onward to Apple APNs / Google FCM). Never audio. |
These providers act on our instructions as processors / service providers and are bound by contract to protect your data and use it only to provide their service to us. They are not permitted to use your personal information for their own purposes. (Google and Apple also process some data as independent controllers under their own privacy policies when you authenticate or transact through them.)
No advertising or analytics tracking. The app contains no analytics, advertising, or attribution SDK, requests no Advertising ID, performs no third-party ad tracking, and we engage in no sale of personal data.
We may also disclose information when required by law, to enforce our terms, or to protect the rights, safety, and security of our users, the public, or us.
10. Security
We take reasonable technical and organizational measures to protect your information, including:
- Encryption in transit: traffic to and from the app is sent over HTTPS/TLS, including secure WebSocket (WSS) connections and time-limited pre-signed URLs for audio uploads/downloads, terminated at a TLS reverse proxy.
- Access controls: access to systems and stored data is restricted to authorized processing on our behalf.
- At-rest protection: stored voice audio, generated stories, and account data reside on access-controlled managed cloud infrastructure. Our managed database and cache are encrypted at rest at the provider level. Access to voice audio and generated stories in object storage is restricted to short-lived, pre-signed URLs.
- Standard of care for biometric data: we store and protect voice recordings and voice models using a reasonable standard of care that is at least as protective as the standard we use for our other confidential and sensitive information (see Section 12).
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach materially affects your rights, we will notify you and the relevant authorities as required by law.
11. Data retention and destruction
We keep personal information only as long as needed for the purposes described in this policy, or as required by law, and then delete it or irreversibly de-identify it. This schedule also serves as our written retention-and-destruction schedule for biometric data under US biometric laws (see Section 12).
| Data category | Retention period | Destruction trigger |
|---|---|---|
| Raw / uploaded voice recording | Deleted within ~30 days of successfully building your voice model. | Deleted on voice deletion, account deletion, or consent withdrawal — whichever is earliest. |
| Derived voice model / voiceprint (biometric identifier) | Kept while your account and that voice are active. | Permanently destroyed on voice deletion, account deletion, or consent withdrawal. As a backstop, destroyed when the purpose is satisfied or within 3 years of your last interaction (the Illinois BIPA limit), whichever is first; voiceprints are also auto-purged after ~24 months of account inactivity. |
| Generated story audio | Retained while your account is active so you can replay your stories. | Deleted on account deletion or when you delete the voice/story. |
| Child's first name / profile | Retained while your account is active and personalization is on. | Anonymized/blanked on account deletion or when personalization is turned off. |
| Account and authentication records | Retained while your account is active. | Deleted/revoked on account deletion. Session/capability tokens are short-lived and expire automatically. |
| Purchase / subscription records (entitlement status and transaction IDs — not card numbers) | Retained after account deletion for the tax/accounting period we are legally required to keep — approximately 10 years under Indonesian bookkeeping rules (we are confirming the exact statutory period with our accountant). | Deleted after the legally required retention period expires. |
| Diagnostics / operational logs (server logs and backend error/crash-diagnostic events) | Short rolling window of approximately 90 days. | Deleted on rolling expiry. |
When you delete your account (see Section 15), we delete the associated data — including your uploaded voice recordings, the derived voice model/voiceprint, generated stories, and the child's first name/profile — except for limited information we are required to retain for legal, accounting, security, or fraud-prevention reasons, which we will keep only as long as necessary and then delete. Deactivating or signing out is not the same as deletion.
12. US biometric privacy notice (Illinois BIPA, Texas CUBI, Washington, and similar laws)
For users in US states with biometric-privacy laws — including Illinois (Biometric Information Privacy Act, BIPA), Texas (Capture or Use of Biometric Identifier Act, CUBI), and Washington (RCW 19.375) — a recording of a voice and the voiceprint / voice model derived from it are treated as a biometric identifier / biometric information. We are committed to the following:
- Purpose: we collect and store the voice recording and the derived voiceprint only to build a voice clone and synthesize personalized story narration for that family's private use, as described in this policy.
- Informed consent before capture: we obtain the speaker's informed consent before any voice is recorded or uploaded (see Section 7). We inform the speaker, in writing/in-app, that a biometric identifier (voiceprint) is being collected and stored, the specific purpose, and the length of term for which it will be kept.
- Written retention-and-destruction schedule: we maintain a written schedule and guidelines for retaining and permanently destroying voiceprints and voice recordings (see Section 11). We destroy the voiceprint and voice recordings when the purpose for which they were collected is satisfied or within 3 years of your last interaction with Sweet Tales, whichever occurs first; we also auto-purge voiceprints after ~24 months of account inactivity, and on any voice/account deletion or consent withdrawal.
- No sale or profit: we do not sell, lease, trade, or otherwise profit from your voice recordings or voiceprints, and we do not disclose them except to the processors that operate the service on our behalf (see Section 9), as required by law, or with your consent.
- Security: we store and protect biometric data using a reasonable standard of care (see Section 10).
- Your control: you may withdraw consent and request deletion of your voice recording and voiceprint at any time (see Section 15).
13. Children's data
Sweet Tales is intended for adults and is declared "not designed for children" (18+) on Google Play. It is a parent-facing creation tool; the people who set up and operate the app are adults.
- The child's first name is provided by the adult who operates the app, solely to personalize stories the adult creates for that child. It is information the operating adult enters about their child, not information collected from a child. There is no child-facing account or sign-up.
- We do not show third-party advertising in the app, do not use an advertising identifier, and do not use children's data for advertising or sell it.
- We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information without an operating adult's involvement, contact us at pav228.id@gmail.com and we will delete it.
Where applicable, we handle this in line with children's-privacy laws such as the U.S. COPPA, recognizing that the operating adult is the one who provides the child's first name and that the app is parent-operated and not directed to children.
14. No sale of personal data; no ads to children
- We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are used under California and other US-state laws.
- We do not sell, lease, trade, or profit from biometric data (see Section 12).
- We do not show third-party advertising to children, and Sweet Tales does not include third-party advertising networks.
- We do not use an advertising identifier.
15. Your rights and choices
We honor the rights granted by your local law, and we extend the core rights below to all users as a matter of good practice, wherever you live.
15.1 Rights we honor for all users
- Access — obtain confirmation of whether we process your personal data and a copy of it.
- Correction — have inaccurate or incomplete personal data corrected.
- Deletion — have your personal data deleted, including your voice recording and voiceprint (see Section 15.3).
- Withdraw consent — withdraw any consent (including consent to voice/biometric processing) at any time, without affecting processing already carried out before withdrawal.
- Object / restrict — object to or restrict certain processing based on our legitimate interests.
- Portability — receive the personal data you provided in a structured, commonly used, machine-readable format where technically feasible.
- Complain — where one exists, you may lodge a complaint with your local data-protection authority.
15.2 Rights under US state privacy laws
If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know/access, delete, correct, opt out of the "sale" or "sharing" of personal information and of targeted advertising, limit the use of sensitive personal information, and be free from discrimination for exercising these rights. We do not sell or share personal information, so there is nothing to opt out of (see Section 14). We honor these requests regardless of whether the relevant statute strictly applies to us — submit them as described below.
15.3 How to delete your data
You can delete your account and associated data in two ways:
- In the app — use the account/data-deletion option in Settings; or
- By email — send a deletion request to pav228.id@gmail.com.
Deletion removes your uploaded voice recordings, the derived voice model/voiceprint, your generated stories, and the child's first name/profile, subject to the limited legal-retention exceptions noted in Section 11. Step-by-step instructions — including how to request deletion if you no longer have the app installed — are on our account & data deletion page.
15.4 How to exercise any other right and our response time
To exercise any other right above, email pav228.id@gmail.com. We aim to respond within 30 days. Where a US state privacy law applies to us, we respond within the period that law requires (generally 45 days, extendable once as the law permits). We may need to verify your identity before acting on a request, and we will not charge a fee except where the law permits.
16. International data transfers and where data is processed
Sweet Tales is not offered to users in the European Economic Area (EEA) or the United Kingdom (UK), and we do not target users in those regions.
We operate in the cloud, and your information may be stored and processed in countries other than the one where you live:
- Object storage (voice recordings and generated audio): DigitalOcean Spaces, region
ams3(Amsterdam). - Account database and cache: DigitalOcean Managed PostgreSQL and Redis.
- Voice/story processing: runs transiently on rented GPU compute (RunPod), whose data-center region varies and is not pinned to any one country.
- Service administration: the data controller administers the service from Indonesia.
Because we do not offer the service in the EEA or UK, the EU/UK cross-border-transfer regime (EU Standard Contractual Clauses, the UK International Data Transfer Agreement, and the Art. 27 EU/UK representative requirement) does not apply to us. This section describes our storage and processing locations so you understand where your data lives.
17. Region-specific disclosures
17.1 California (CCPA / CPRA)
In the past 12 months we have collected the categories of personal information described in Section 4 (including identifiers, audio / voice recordings (sensitive personal information), internet/usage activity, and commercial/purchase information), for the business purposes in Section 5, and disclosed them only to the service providers in Section 9. We do not sell or share personal information as those terms are defined under California law, and we do not use sensitive personal information for purposes beyond providing the service. California residents may exercise the rights to know, access, delete, correct, and limit the use of sensitive personal information, and we will not discriminate against you for exercising them. We honor these requests regardless of whether the statute strictly applies to us. Submit requests as described in Section 15.
17.2 Other US states
If you are in another US state with a comprehensive privacy law (for example, Virginia, Colorado, Connecticut, Utah, Texas, and others), the same access/correction/deletion/opt-out mechanisms in Section 15 apply, and we will honor the rights granted by your local law to the extent those laws apply to us. US state biometric obligations are addressed in Section 12.
18. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, provide additional notice (for example, an in-app notice or, where the law requires, a request for renewed consent before the change takes effect). For any change that expands processing of already-collected voice/biometric data, we will obtain renewed explicit consent before the new processing. We encourage you to review this policy periodically. Your continued use of Sweet Tales after an update means you accept the revised policy, except where additional consent is required by law.
19. Contact us
If you have questions, requests, or complaints about this policy or your personal information, contact:
- Pavel Leonov — Sweet Tales (an individual / sole proprietor, established in Indonesia)
- Email: pav228.id@gmail.com
- Data deletion: in the app (Settings), on our account & data deletion page, or by emailing the address above.
- Postal address: available on request.