Anga: Reading for Kids Privacy Policy
A children’s reading app with stories, words, and phonics support.
For Parents and Guardians: Before Anga starts account services, the person setting it up confirms that they are an adult parent or guardian authorised to consent for the family. Anga then checks the selected Apple or Google account and, when needed, sends a code to confirm control of its email.
Information We Collect
Anga collects limited information to provide account-backed reading features:
- Account Information: Email address, account identifier, and sign-in provider. Anga does not request an account name or profile picture and removes the top-level Firebase name and photo fields before family content opens. Anga does not ask for or create a child account, child email address, or child profile name.
- User-Created Content: Custom stories, word themes, text, pronunciation spellings, and images created or selected within Anga. Parent-authored text can include names or family details the parent chooses to write.
- Generated Audio:Read-aloud output generated by Google Cloud Text-to-Speech, an AI voice-generation service, from custom story or word text, including timing information used for highlighting. This is not a user's voice or sound recording.
- Service Records: Anga Space membership, invite and share records, timestamps, security and quota counters, the verified parental consent version, and email-verification challenge and rate-limit records. Limited challenge status, a keyed code digest, attempt counts and rate-limit timestamps necessarily exist before account-bound permission is complete so Anga can deliver and validate the code without abuse. Anga never stores the verification code in readable form.
- Subscription Information: Anga Plus entitlement status, product and transaction identifiers, expiration dates, and custom-content allowance usage. Apple handles payment details; Anga does not receive payment card or bank account information.
How We Use Information
- Authenticate the account and keep its Anga Spaces available.
- Confirm control of the email attached to the signed-in account and bind the adult declaration and agreement to that account.
- Save and sync custom stories, word themes, selected images, and generated audio.
- Generate reading audio for custom story and word text.
- Enable account and Anga Space sharing features.
- Verify and restore Apple-managed Anga Plus subscriptions and unlock paid features.
- Protect the service against abuse and enforce content and generation limits.
- Provide customer support when requested.
Privacy Protections
- We do not collect precise location data.
- Anga includes no advertising SDK and shows no advertising.
- We do not sell or share data with third-party advertisers or data brokers.
- Anga does not include Firebase Analytics or another user-behaviour analytics product.
- We do not track users, profile individual readers, or collect diagnostic data for analytics. Anga disables Firebase's optional automatic data collection. Firebase processes only the request and security metadata needed to operate authentication, storage, App Check and Cloud Functions.
- Firebase App Check processes app and device-integrity material to reject unauthorised clients. Firebase says attestation material and ordinary successful tokens are not retained; replay-protected tokens may be retained for up to 30 days.
- We do not save reading, word, or phonics progress to the cloud.
- We do not collect payment card or bank account information.
- In the iOS app, the parental PIN is stored only in the device Keychain and is never sent to Anga or another service.
- We do not use data for tracking across other apps or websites.
Third-Party Services and Data Sharing
Anga uses the following service recipients. On the web companion, Anga presents the disclosure and waits for the adult's confirmation before starting Apple or Google sign-in. The iOS app does the same before Apple, Google, or the sandbox-receipt App Review email/password path. Firebase App Check may process browser or device-integrity information when the site loads, but this does not open family content or start cloud voice processing.
- Google Firebase:Receives the account identifier, email, sign-in provider, and the custom-content, Space, sharing, security, verification, and subscription records described above. Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, and App Check provide sign-in, secure storage, synchronisation, sharing, parental email verification, access control, and abuse prevention. Anga clears Firebase Auth's top-level display name and photo before account data opens and does not request or copy those fields into Firestore or Cloud Storage. App Check processes app and device-integrity material used to reject unauthorised clients; attestation material and ordinary successful tokens are not retained, while replay-protected tokens may be retained for up to 30 days. Anga disables Firebase's optional automatic data collection. In iOS builds running with an App Store sandbox receipt, Firebase Authentication also handles the dedicated reviewer email and password entered through App Review Sign In. The password is cleared when sign-in succeeds or the reviewer cancels and is not sent to Anga's backend, family records or logs; this option is not shown in the public App Store build.
- Google Cloud Text-to-Speech: This AI voice-generation service receives custom story and word text, including pronunciation spellings, solely to generate requested reading audio. Parent-authored text may include names or family details the parent chooses to write. Anga does not attach an account identifier, email, pictures, payment information, reader progress or a voice recording to the synthesis request. Google states in its Cloud Text-to-Speech data-logging documentation that the service is stateless and does not log customer text or audio. The generated audio is stored with the custom content in Firebase.
- Google account sign-in: Provides account authentication when selected by the grown-up.
- Google Photos Picker (web companion only): If a grown-up chooses Google Photos in the web story editor, Anga requests separate, read-only Picker permission. Google displays the picker and makes only the one photo that person explicitly selects available to Anga; videos are not supported. Anga downloads the selected image for the editor and stores the resulting story image in Firebase only if the grown-up saves it. The iOS app does not use this Google Photos Picker integration.
- Sign in with Apple: Provides account authentication when selected by the grown-up.
- App Review Sign In: In iOS builds running with an App Store sandbox receipt, provides Firebase email/password authentication for the dedicated reviewer account whose credentials are supplied privately to Apple in App Store Connect.
- Resend:Receives the parent account's email address and the fixed-format message containing a one-time six-digit code solely to deliver the parental verification email. Resend also processes operational delivery metadata needed to route, attempt, and report delivery. It receives no child information, story content, parent account name, advertising data, or reader activity. See Resend's Privacy Policy.
- Apple App Store and StoreKit: Handle Anga Plus subscription presentation, payment authorisation, purchase verification, restoration, cancellation, and refunds.
Google services are governed by Google's Privacy Policy. Anga does not provide account or custom-content data to advertisers, data brokers, or behavioural analytics services.
Grown-up Permission
- On the adult web companion, Anga first presents a local disclosure. Apple, Google, and Firebase Authentication provider sign-in do not start until the person confirms that they are an adult parent or guardian authorised to consent for the family and chooses I confirm and agree. Children do not sign in or make this choice.
- The web companion keeps that choice only in the current browser session so it can survive the provider redirect. It is not stored as server-verified consent, in a cookie, or in persistent browser storage. If an unfinished signed-in session is restored without that temporary choice, Anga shows the disclosure again.
- After confirmation, the grown-up chooses Apple or Google and Firebase Authentication establishes the parent account and email. Anga then checks the server's current account-bound permission status before reading browser caches, Firestore, or protected Cloud Storage, opening family content, or starting cloud voice processing.
- An account with current account-bound permission continues directly. Otherwise, Anga sends a six-digit email code and asks the grown-up to confirm control of the account, without presenting the full disclosure or another adult confirmation. Entering the code binds the earlier browser-session choice to that account, records the current consent version for iOS and web server-side enforcement, and prepares the account's private My Library before the web companion opens.
- Anga confirms parent or guardian permission through an explicit adult declaration, control of the adult account email and, in the iOS app, creation of a device-local parent PIN. Anga does not perform age assurance: it does not estimate or independently verify a person's age or government identity document.
- In the iOS app, the grown-up creates a four-digit PIN for Settings, purchasing opportunities, and external story sharing. The PIN is account-specific, remains only in that device's Keychain, and can be reset only after another email verification. The web companion does not create or store this PIN.
- Anga requests renewed permission if the service providers, transmitted data, or purposes materially change.
- Entering the PIN for Settings, purchasing opportunities, or cross-Space story-link creation starts a short, in-memory grown-up access period so related actions do not cause repeated prompts. Leaving the foreground, changing account, choosing Lock now, or letting the period expire ends it.
- On the web companion, choosing Not now before sign-in simply leaves setup without selecting an account. After sign-in, Not now cancels the pending setup and signs out without opening family content or starting cloud voice processing. Authenticated cancellation removes verification codes immediately; a brand-new unfinished account is also eligible for deletion, while an existing account and its data are left unchanged and signed out. A grown-up can return and review the choice again at any time.
Data Storage, Retention, and Security
- Firebase encrypts data in transit and at rest.
- A verification code expires after ten minutes. Anga stores only a keyed cryptographic digest rather than the readable code, and the challenge cannot be used after expiry or successful verification. Cancelling parent setup removes active or expired code challenges and their digests. Account deletion immediately removes UID-scoped verification challenges. A separate HMAC-keyed recipient abuse-prevention record contains only recent email-send timestamps and an automatic-cleanup timestamp—not the readable email, verification code, or account UID—and may remain for up to 24 hours after cancellation or deletion to prevent rate-limit bypass.
- In the iOS app, the parental PIN is protected by the device Keychain and is not backed up or synchronised by Anga.
- My Library content is private to the signed-in account.
- Anga Group Space content is visible to members of that Space.
- Account data is kept while the account is active. Private generated audio and custom content remain available until the account or the specific content is deleted. Content already shared inside a multi-member Anga Space may remain available to those members after one account is deleted, with the deleted account identifier removed.
Sharing Features
Content saved in an Anga Group Space is automatically available to members of that same Space. This ordinary Space synchronisation does not create an external sharing link and does not ask for another grown-up check.
A story owner can separately create a time-limited link for a story to be imported into a different Anga Space. Creating that link is a grown-up action. A linked story may include:
- Its title, text, selected pictures, and generated audio.
- No account details added to the shared package.
- Content filtering for inappropriate language before the link is created.
- An independent imported copy; later edits are not synchronised between Spaces.
Parental Rights
- Review: View account, Space, and custom content stored in Anga.
- Delete: Delete the account and associated custom content from Settings in the iOS app.
- Refuse: Choose Not now before sign-in to leave without selecting an account. After sign-in, choose Not now to cancel pending setup and sign out before family-content access or cloud voice processing begins. A new unfinished account may be deleted; an existing account and its data are preserved.
- Reset access: Verify the parent email again to replace a forgotten local PIN in the iOS app.
Account Deletion
In the iOS app, open Settings, choose Delete Account, and confirm the deletion.
This permanently removes account data, private stories and word themes, account-scoped generated-audio cache, quota records, and owned external share links. It immediately removes UID-scoped verification challenges. A separate HMAC-keyed recipient abuse-prevention record contains only recent email-send timestamps and an automatic-cleanup timestamp—not the readable email, verification code, or account UID—and may remain for up to 24 hours before automatic cleanup. Anga also creates a server-only deletion-safety record keyed by the Firebase account ID. It blocks stale in-flight writes and stores only deletion timing plus affected Anga Space and share identifiers needed for a final Storage sweep. After deletion completes, the record becomes eligible for removal within 24 hours of deletion starting; cleanup runs every 15 minutes and retains it longer only when cleanup must be retried. If deletion is interrupted while the Auth account still exists, the record remains until deletion is safely retried instead of expiring. Content in a surviving multi-member Anga Space remains for its members, with the deleted account identifier removed. This action cannot be undone.
Changes to This Policy
If Anga materially changes its service providers, the data transmitted, or the purposes for using it, we will update this policy and request renewed grown-up permission before the changed processing starts.
Contact Us
If you have questions about this privacy policy or your data, please contact us:
Email: [email protected]
Developer: Vincent Debast
Last Updated: August 8, 2026