Introduction
Owlee (“Owlee,” “we,” “us,” or “our”) is a mobile application, developed and operated by Quikvard Studio (“Quikvard”), that lets a parent or legal guardian generate illustrated, AI-narrated bedtime stories starring their own child. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have.
Owlee is designed for use by parents and legal guardians on behalf of their children. The app account holder must be an adult (18 years or older). Owlee is not directed at children as independent users, is not listed under any “Made for Kids” or children's app category, and does not knowingly allow a child to create or control their own account.
By creating an account or using Owlee, you agree to the collection and use of information as described in this Privacy Policy.
Who we are / Controller
- App name: Owlee
- Operator: Quikvard Studio
- Registered address: İstanbul, Türkiye
- Contact: admin@quikvard.com
- Package identifiers:
com.quikvard.owlee(Android and iOS)
Information we collect
1. Account information (parent/guardian)
When you create an account (via email/password or Google Sign-In), we collect:
- Email address
- First and last name (optional)
- Birth year (optional)
- Preferred app language
2. Child profile information
Entered by you, the parent/guardian, never by the child directly:
- Child's first name
- Age band (3–5, 6–8, or 9–12 — we do not collect an exact birthdate for children)
- Pronoun (he/she), used to keep story grammar consistent
- A reference photo of your child (see “Child photos” below — this is handled completely differently from other data and is never stored at rest)
3. Child reference photos — Zero-Retention promise
This is the most sensitive data category we handle, and we treat it accordingly:
- The photo is stored encrypted, locally on your device only (Drift/SQLite database encrypted with
sqlite3mc, key held in the device's secure keystore/keychain viaflutter_secure_storage). On iOS, saved photo files are explicitly excluded from iCloud and local device backups. - When you generate a story, the photo is uploaded transiently to a temporary cloud storage bucket (
reference_photos_tmp) solely so our image-generation provider can produce face-consistent illustrations of your child as the story's hero. - That temporary copy is hard-deleted immediately after the generation call completes (success or failure) by server-side cleanup logic. As a backstop, an automated database job (
pg_cron) permanently deletes anything left in that bucket older than 30 minutes, even in the case of a crash mid-request. - Your child's photo is never stored at rest in our cloud infrastructure, never used to train any AI model, never used for facial recognition/identification purposes beyond that single story-illustration request, and never shared with advertisers.
4. Story content
- The generated story text (in the language you selected) and the AI-generated illustrations for each page.
- Story metadata: title, topic, art style, length (short/medium/long), language, creation date.
- Optional narration audio (see “Narration” below).
5. Credits and transaction history
- An append-only ledger of credit-affecting events tied to your account: purchases, story generations, PDF exports, book exports, page re-rolls, refunds, and welcome grants.
- We do not collect or store your payment card, bank, or other financial account details. Purchases are processed entirely by Google Play / Apple App Store and validated server-side via RevenueCat (see “Third parties” below) — we only receive confirmation that a purchase occurred and its product identifier.
6. Narration audio
If you use the read-aloud feature, the story text for a given page/voice combination is sent to a cloud text-to-speech provider and the resulting audio clip is cached (server-side, keyed to that story page and voice) so it is only generated once, and locally on your device for offline playback.
7. Usage and diagnostic data
- Product analytics: anonymized/pseudonymous in-app usage events (e.g., which screens are used, feature engagement) via PostHog, to help us understand and improve the app.
- Crash and error reports: technical crash logs and error traces via Sentry, to help us find and fix bugs. These may include device type, OS version, app version, and the technical state of the app at the time of the crash.
- Standard technical/log data generated by our backend (Supabase) as part of normal request handling (timestamps, request metadata).
How we use your information
We use the information described above to:
- Create and manage your account
- Generate the story text and illustrations you request
- Provide narration/read-aloud audio
- Maintain your credit balance and transaction history
- Sync your library across your devices
- Provide customer support when you contact us
- Diagnose and fix technical problems (crash reports)
- Understand feature usage in aggregate to improve the app (product analytics)
- Enforce our Terms of Service and content-moderation safeguards
- Comply with legal obligations
We do not use your data, your child's data, or your child's photo to serve targeted/behavioral advertising, and we do not sell personal data to third parties.
Third parties we share data with (subprocessors)
We use the following service providers to operate Owlee. Each receives only the data necessary to perform its function:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database (Postgres), authentication, file storage, and serverless backend functions | Account data, child profile data, stories, transactions, temporary photo storage |
| OpenAI (GPT-4o-mini) | Primary story-text generation | Story parameters (topic, style, child's name/age-band/pronoun) — no photos |
| Google (Gemini Flash) | Fallback story-text generation if the primary model is unavailable | Same as above |
| Fal.ai (flux-pulid model) | Face-consistent AI illustration generation | Child's reference photo (transient, per “Zero-Retention promise” above), story image prompts |
| Microsoft Azure (Neural TTS) | Cloud text-to-speech narration | Story paragraph text, selected voice |
| RevenueCat | In-app purchase validation and entitlement management | Purchase/transaction identifiers, product IDs, device platform |
| Google Sign-In | Optional authentication method | Google account email/name, per Google's own consent flow |
| PostHog | Product analytics | In-app usage events |
| Sentry | Crash and error reporting | Technical crash/error data |
| Resend | Delivering in-app support ticket emails to our support inbox | Your account email, the support message you submit |
| Google Play / Apple App Store | Payment processing for credit-pack purchases | Handled entirely by Google/Apple — we never see your payment details |
We require each of these providers to handle data securely and only for the purpose of providing their service to us. Some of these providers may process data on servers located outside your country of residence, including in the United States.
Data retention
- Child reference photos: never retained in the cloud — see “Zero-Retention promise” above. On-device, retained locally (encrypted) until you delete the child's profile or the app's local cache.
- Account, child profile, and story data: retained for as long as your account is active.
- Credit/transaction ledger: retained as an append-only financial record for the lifetime of the account (and as required for legal/accounting purposes), consistent with standard bookkeeping practice.
- Deleted account: when you delete your account (see the Deletion page), your profile, children's profiles, stories, and associated data are permanently removed from our production database via cascading deletion.
Your rights
Depending on your jurisdiction (including under GDPR for EU/EEA/UK users), you may have the right to:
- Access the personal data we hold about you — contact us at admin@quikvard.com and we'll send you an export of your stories, profile, and transaction history (GDPR Art. 15/20 data portability).
- Rectify inaccurate data (editable directly in-app for most fields).
- Erase your data — see the Deletion page.
- Restrict or object to certain processing.
- Data portability — the export we send you is provided in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, use the in-app tools where available, or contact us at admin@quikvard.com.
Children's privacy
Owlee is built around the principle that the parent or legal guardian is the account holder — children do not create their own accounts, do not directly provide personal information to us, and cannot access account, billing, or settings functionality. All child profile information (name, age band, pronoun, reference photo) is entered by the parent/guardian, who consents to its use on the child's behalf as described in this policy. The app is intentionally not published under a children's/“Made for Kids” category.
If you believe a child has provided us with personal information other than through a parent/guardian-managed profile as described above, please contact us at admin@quikvard.com so we can address it.
Data security
- All user-facing database tables use row-level security (RLS), so a user can only ever read or write their own data.
- Data in transit is encrypted (HTTPS/TLS).
- Locally cached child reference photos are stored in an encrypted local database, with the encryption key held in the device's secure storage (Android Keystore / iOS Keychain).
- Access to production infrastructure is restricted to authorized personnel.
No method of transmission or storage is 100% secure; we work to protect your data but cannot guarantee absolute security.
International data transfers
Because we rely on global infrastructure providers (see the subprocessor table above), your data — including, transiently, your child's reference photo during story generation — may be processed in countries outside your own, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above, and where appropriate, communicated in-app.
Contact us
Questions about this Privacy Policy or your data: admin@quikvard.com, or through the in-app Support form (Settings → Support).