Fudge & Gandol is a children's reading and story-creation app. This policy explains what data we collect about children and parents, how it is used, who we share it with, and the rights parents have. If you have questions, contact us at privacy@fudgeandgandol.com.
1. Who this policy applies to
Fudge & Gandol is designed for children. All accounts are created and managed by a parent or legal guardian. Children under 13 may use the app only through a parent-managed profile, and only when the parent has granted consent for the specific features being used.
2. What we collect
We collect two kinds of information:
- About the parent: the email address you sign in with and basic account metadata.
- About each child profile: the child's first name, age, favorite color and animal, avatar configuration, stories they have written or had generated, and characters they have created.
We do not ask for a child's last name, address, phone number, school, or any other identifier beyond what is listed above.
3. How we use this data
The child's profile data is used to personalize stories (so Ember can write a story about a ten-year-old who loves otters, for example) and to track the child's creative work across sessions.
We use AI services from the following third parties to power features in the app:
- Anthropic (Claude) — story generation and Ember coach conversations.
- OpenAI — card scanning, drawing analysis (fallback), text-to-speech narration.
- ElevenLabs (Flux) — character portrait generation.
- Google (Gemini) — drawing and card vision analysis (fallback).
- Supabase — database and file storage.
- Vercel — hosting and content delivery.
When one of these features is used, the relevant child data is sent to the vendor for processing. We only send the data needed for that specific feature — for example, a story-generation request includes the child's name, age, and preferences, but not data from other children on the same account.
4. Parental consent
Because each AI feature involves sending child data to a third party, we require explicit, per-feature parental consent. No AI feature will run until the parent has granted consent for that feature. You can view the current consent state, grant new consent, or revoke existing consent at any time from Settings → Privacy.
Consent is version-tracked. If we materially change this policy, prior consents are invalidated and we will ask you to consent again.
5. Data retention
- Profiles and stories are retained for the lifetime of the account unless you delete them.
- AI interaction logs contain only metadata (route, model, token counts, a SHA-256 fingerprint of the prompt, and timestamps). The raw prompt text is not stored.
- Character images generated by AI are stored privately and are accessible only via signed URLs scoped to the owning profile.
6. Your rights
Parents can at any time:
- Access — download an export of all data associated with a child profile.
- Delete — request deletion of a child profile and all associated data (stories, characters, AI log metadata, consent records).
- Revoke — withdraw consent for any AI feature, which immediately blocks that feature for the profile.
All three actions are available from Settings → Privacy. You may also contact us at privacy@fudgeandgandol.com and we will respond within 30 days (GDPR standard).
7. Security
Data is stored in Supabase with row-level security enforced per-account. Character images live in a private bucket, accessible only via signed URLs. Access from the app to the database uses authenticated, session-scoped clients wherever possible. All traffic between the client and our servers is encrypted via HTTPS.
8. Contact
Questions, data requests, or concerns? Reach out to privacy@fudgeandgandol.com.
This policy will be updated as the app evolves. The current version is 2026-04-09-v1. Material changes will trigger a re-consent request the next time you use an AI feature.