Overview
Qissa: Bedtime Story Maker, operated by Ark Horizon LLC, keeps information only for the purpose and period below. When information is no longer reasonably necessary, we delete it, de-identify it, or isolate it where a limited legal or security record must remain. Most of your child's data lives only on your device and is never uploaded to us.
Retention Schedule
| Information | Where it lives | Retention | How it's deleted |
|---|---|---|---|
| Child profile choices (name, age range, language, trait) | Your device only | Until you delete the profile, clear app data, or uninstall | In-app deletion / OS app-data deletion |
| Saved stories, images, audio | Your device only | Until you delete them or uninstall | In-app deletion |
| Story-generation request content | Qissa backend | Processed in memory; not written to ordinary logs. If a failed request must be quarantined to debug, it is deleted within 72 hours | Automatic purge + log redaction |
| Story text sent to the AI story provider (child's name is not sent) | Anthropic / OpenAI | ~30 days for abuse monitoring, or zero-retention where enabled, then auto-deleted; not used to train models | Provider auto-expiry / Zero-Data-Retention |
| Illustration prompt (child's name is not sent) | OpenAI | ~30 days for abuse monitoring, or zero-retention where enabled, then auto-deleted | Provider auto-expiry |
| Narration text — Storyteller voice | Google Cloud Text-to-Speech | Google does not log Cloud TTS text or audio — effectively no retention | Not stored |
| Narration text — Cinematic voice (child's name replaced with a placeholder before sending) | Microsoft Azure AI Speech | Azure does not retain Speech input text or synthesized audio when abuse-logging is disabled — effectively no retention | Not stored |
| Parent email & account ID | Supabase / Qissa | Active account + 30 days after a verified deletion request | Account/database deletion |
| Usage counters & entitlements | Qissa / RevenueCat | Active account + 30 days | Delete / disassociate records |
| Store transaction records | Apple / Google / RevenueCat | Up to 7 years (payment, refund, tax, and fraud records) | Isolate record; delete unnecessary profile links |
| Parent consent record (verifiable parental consent) | Qissa | Active account + 1 year after closure (policy, subject to review) | Secure archive then deletion |
| Support messages | Email / support provider | 24 months after closure, unless a dispute or security matter remains | Ticket / mail deletion |
| Security, authentication & abuse logs | Hosting / auth provider | 90 days, extended only for a documented incident | Automatic rotation / incident-case closure |
| Pseudonymous product analytics | Qissa backend | Kept in aggregate; tied to a random install identifier, not to your name or your child | Aggregation / identity-link removal |
| Backups | Our providers | No more than 30 days (policy, subject to review); deleted data is not restored to active use | Backup aging / overwrite |
Our Rules
- No indefinite retention by default. "We might need it later" is not a retention purpose.
- Content logging is off by default. Child names, prompts, stories, and narration text do not appear in ordinary analytics, crash, or security logs.
- Deletion propagates. A valid account or child-data deletion request is passed to the applicable processors and tracked.
- Backups are not active use. Deleted information remaining briefly in encrypted backups is not returned to production, and the deletion is re-applied if a backup is ever restored.
- Provider periods are verified. We rely on each provider's documented retention terms, not marketing phrases.
- Annual review. This schedule is reviewed at least yearly and whenever a provider or feature changes.
Contact
Questions or deletion requests:
Ark Horizon LLC
935 Windy Garden Way, Richmond, Texas 77406-7218
+1 (281) 384-3221
hello@qissa-stories.com
qissa-stories.com/data-deletion