Privacy Policy – SoyleStories / SoyleApps
Last updated: 9 July 2026
1) Controller
SoyleApps
Am Feger 5, 71063 Sindelfingen, Germany
Email: support@soyle.online
We have not appointed a Data Protection Officer (DPO).
2) Scope
This Privacy Policy applies to the SoyleStories mobile app and the related website pages at soyle.online (including legal pages and the contact form).
3) Data we process
3.1 Account identifier and authentication
We process a pseudonymous account identifier (for example, the Google or Apple token subject "sub") and authentication/session data required to sign you in and keep you signed in.
3.2 Character profile data
We process profile data you provide, such as hero/parent descriptors (for example, name, age, interests, and appearance settings) and optional avatar reference data.
For signed-in users, profile data may also be stored on our backend and synchronized across the user's devices to support restore, continuity, and deletion synchronization.
3.3 Generation requests
To generate stories and optional images or narration, we process prompts assembled from your inputs and app templates/settings (for example, language, cultural style, duration, and whether images and/or narration are enabled).
When you request narration, the story text is additionally processed to generate spoken audio (text-to-speech). See Section 6 for the providers involved.
3.4 Server-side storage for delivery, restore, and sync
To deliver results reliably, our backend stores generated story payloads, image files, and narration audio files in temporary server-side caches. By default, story cache entries are retained for a short period (currently up to 24 hours) and may be deleted earlier once delivery is acknowledged. Image files are also temporary and are removed through acknowledgement, cache sweeps, or operational cleanup, depending on configuration. Narration audio is generated and held in temporary server-side storage only to deliver it to your device; once a narration is successfully stored on your device (where the final audio is kept locally) and delivery is acknowledged, the temporary server-side audio is removed, and any remaining temporary audio is cleared through cache sweeps or operational cleanup. If a narration is delivered only partially, the already-delivered audio may remain on your device while the rest is re-requested or discarded.
In addition, for signed-in users, we may retain an archived server-side copy of generated story text and related metadata to support history restore, cross-device synchronization, and recovery after reinstall or cache cleanup. This archived storage is text-first: original generated image and audio files are not retained there.
3.5 Purchases and entitlements
We process entitlement and purchase-related data, for example coin balance, subscription status/tier/expiry date, product identifiers, purchase tokens, transaction identifiers (if available), acknowledgement status, and timestamps.
3.6 Security and session metadata
We process security and session metadata such as refresh-token hashes, device identifiers (if provided), user agent, request timestamps, and related operational metadata.
3.7 Technical logs and diagnostics
For reliability and security, we process technical logs (for example, request type, success/failure, error codes, and timestamps).
Depending on infrastructure, logs may also include IP address (server log files), referrer URL, requested resources, and potentially request IDs, as generated by hosting/infrastructure.
In troubleshooting/debug scenarios (especially failed generations), diagnostic artifacts may contain prompt fragments, context fields, and related technical metadata.
3.8 App analytics and campaign measurement
On Android, the app uses Google Firebase Analytics to measure Google Ads campaign performance and understand whether users reach important app milestones. The app records only predefined events such as tutorial progress, sign-in/sign-up, character or avatar creation, story request, completed story generation, reader opening, narration start, coin-shop opening, and purchase events.
Android analytics parameters are limited to coarse metadata such as source, app/story locale, story length, whether images or narration were requested, format, purchase type/provider, currency, and value where applicable. We do not send prompts, story text, child names, child profile descriptors, avatar data, generated images, or generated audio to Firebase Analytics.
Android analytics is enabled by default to help measure advertising effectiveness, but you can disable it at any time in the app under Settings > Privacy. When disabled, the app asks Firebase Analytics to stop collection on that device. Screenshot/test automation builds do not send analytics events.
On iOS, the app does not include Firebase Analytics. iOS campaign attribution is limited to Apple's SKAdNetwork conversion-value mechanism, which sends coarse campaign postback information through Apple rather than app-level Firebase event tracking.
3.9 Contact form data (website)
If you use the website contact form, we process the topic, name, optional SoyleStories User ID, and message text, and forward it to our support mailbox.
For abuse prevention and operational security, we also process limited technical form-submission data such as client IP address, rate-limit metadata, and anti-spam form fields.
3.10 Cookies and local browser storage on the website
The soyle.online website does not set any cookies and does not use any analytics, tracking, or advertising scripts.
The website uses your browser's localStorage only to remember your preferred user-interface language across visits. This is a strictly necessary, functional storage entry within the meaning of Section 25(2)(2) TTDSG and does not require consent. No personal data, no identifier, and no tracking value is stored.
All scripts, styles, fonts, and other assets are served directly from soyle.online. The website does not embed third-party content or CDN resources.
4) What we do not do
- We do not sell personal data.
- We do not intentionally publish your private prompts, stories, or images.
- We do not send story prompts, story text, child names, child profile descriptors, avatar data, generated images, or generated audio to Firebase Analytics.
- We do not store complete generated story/image payloads in our relational user/purchase database. Delivery payloads are handled through temporary caches, and a separate archived story store may retain story text and related metadata for restore and synchronization. Original generated image and audio files are not retained in that archived store.
5) Purposes and legal bases (GDPR)
- Providing the service / performing the contract (generation, delivery, account handling, synchronization, and entitlement checks) – Art. 6(1)(b) GDPR
- Security, abuse prevention, and reliable operations – Art. 6(1)(f) GDPR
- Android app analytics and campaign measurement – Art. 6(1)(f) GDPR. You can object by disabling analytics in Settings > Privacy.
- Compliance with legal obligations (for example, accounting/tax obligations where applicable) – Art. 6(1)(c) GDPR
- Contact requests (contact form/email): Art. 6(1)(b) GDPR (handling your request) and/or Art. 6(1)(f) GDPR (support and abuse prevention).
- Server log files / security logs: Art. 6(1)(f) GDPR.
6) Recipients / service providers
-
Google (Gemini API) for text, image, and narration (text-to-speech) generation.
Generative AI (Google Gemini API): We transmit prompt content (including text fields you enter, character profile descriptors, and any optional avatar reference data) to Google for generation, and we receive the generated text and images. When you request narration, the story text is also sent to Google's Gemini text-to-speech service to produce the narration audio. We use the paid tier of the Gemini API. Under Google's terms applicable to paid Gemini API usage, prompt content and generated outputs are not used to train Google's machine-learning models. Processing is otherwise governed by Google's contractual data protection terms (data processing terms and standard contractual clauses where applicable). -
Google Firebase Analytics for Android app analytics and Google Ads campaign measurement.
We send only predefined app events and limited coarse metadata as described in Section 3.8. We do not send story prompts, story text, child names, child profile descriptors, avatar data, generated images, or generated audio to Firebase Analytics. Firebase Analytics is not included in the iOS app. -
Google Play / Apple App Store for payment processing and purchase/subscription validation (depending on platform).
Note: App store providers (Google/Apple) typically process payment data as independent controllers. We only receive the purchase/subscription information needed for entitlement validation (for example, tokens, status, and timestamps). - Hosting and infrastructure providers used to operate the backend and website services.
- Email/SMTP provider for support and contact processing.
7) International transfers
Our own backend operations are hosted in Germany/the EU. Some processors (for example, Google services) may process data outside the EU/EEA under their contractual and legal safeguards.
8) Retention
- Account/profile/entitlement data: retained as long as needed for account operation, synchronization, restore, and entitlement handling, unless deleted earlier upon a verified request.
- Temporary story/image caches: short-term retention for delivery (story cache currently configured for up to 24 hours by default; image cache deletion depends on acknowledgement and cleanup jobs).
- Narration audio: the final narration is stored locally on your device. Temporary server-side audio is short-lived and is removed after successful device storage and acknowledgement, or through cache sweeps and operational cleanup. Archived story records do not retain generated audio files.
- Archived story records: retained as needed to provide history restore, cross-device synchronization, and recovery functionality. Archived records currently retain story text and related metadata, but not original generated image or audio files.
- Technical logs: short-term, retained only as long as necessary for security, reliability, and abuse-prevention purposes.
- Android analytics events: retained according to our Firebase/Google Analytics retention settings and Google's service terms. You can stop further collection on your device by disabling analytics in Settings > Privacy.
- Diagnostic artifacts: retained only as needed for troubleshooting and removed during operational cleanup.
- Purchase records: retained as needed for entitlement checks and, where applicable, legal/accounting obligations.
- Contact requests: retained until processed, then kept only as needed for follow-up, abuse prevention, and/or legal obligations.
9) Your rights
You have GDPR rights, including access, rectification, erasure, restriction, data portability, objection, and the right to lodge a complaint with a supervisory authority.
Competent supervisory authority (example): The State Commissioner for Data Protection and Freedom of Information Baden-Wuerttemberg (LfDI BW). You may also lodge a complaint with any supervisory authority.
10) Account deletion
You can delete your account in two ways:
- In the app: use the account-deletion option in the app settings. This triggers an immediate server-side removal of your account and the associated profile and story-archive data on our backend.
- By email: write to support@soyle.online and include your SoyleStories User ID (shown in the app settings).
Story content stored locally on your device, including downloaded narration audio, is removed when you delete the relevant story in the app or uninstall the app.
After a deletion, some data may still need to be retained for a limited period where required for legal obligations, purchase/accounting records, security purposes, or the technical synchronization of deletions across devices.
11) Children / family use
SoyleStories is intended for family use. Purchases/subscriptions should only be made by adults.
Parents or guardians provide and control any child-related profile details used by the app, such as a child character name, age, interests, and appearance descriptors. We use this data only to provide story generation, illustration, account restore/sync, safety, support, and deletion features described in this policy. We do not sell children's data, use child profile details for third-party advertising, or build behavioural profiles for advertising. Android campaign measurement uses only predefined app-event metadata, not child profile content.
12) Changes to this policy
We may update this policy. The latest version is published at the same URL.
13) Automated decision-making / profiling
We do not use automated decision-making under Art. 22 GDPR (no decisions producing legal or similarly significant effects).