Anga: Reading for Kids Privacy Policy

A children’s reading app with stories, words, and phonics support.

For Adults Setting Up Anga: New account setup starts with a local disclosure and confirmation by a parent, guardian, or authorised adult. Returning adults can sign in so Anga can check the account's saved permission. Private content remains unavailable unless that permission is current.

Android support is in pre-release testing. The Android features below apply only where enabled in a test build. You can request deletion of an Anga account without opening or installing the app.

Information We Collect

Anga collects limited information to provide account-backed reading features:

  • Account Information: Email address, account identifier, and sign-in provider. Apple or Google may also process basic profile information during sign-in. Anga does not save the provider name or profile picture in Anga account records. Anga does not ask for or create a child account, child email address, or child profile name.
  • User-Created Content: Custom stories, word themes, text, pronunciation spellings, and images created or selected within Anga. Adult-authored text can include names or personal details the adult chooses to write.
  • Generated Audio: Read-aloud output generated by Google Cloud Text-to-Speech, an AI voice-generation service, from custom story or word text, including timing information used for highlighting. This is not a user's voice or sound recording.
  • Service Records: Space membership, invite and share records, timestamps, security and quota counters, the verified privacy-permission version, and email-verification challenge and rate-limit records. Limited challenge status, a keyed code digest, attempt counts and rate-limit timestamps necessarily exist before account-bound permission is complete so Anga can deliver and validate the code without abuse. Anga never stores the verification code in readable form.
  • Educator and Class Records: When Educator Access or Class Pass is used, Anga stores Story Studio and Class Space records, educator relationships, Reader Grants, Class Stories, optional private educator names or labels, private pass labels, optional report details, reports, and the access and entitlement records needed to operate those features. An accepted invitation's name or label moves to the active educator record. Anga removes invitation details when an invitation is claimed or revoked, during expired-invitation cleanup, or when the class is closed or removed.
  • Subscription Information: Anga Plus and Teacher Class Pass entitlement status, product and transaction identifiers, expiration dates, and allowance usage. Apple handles iOS payment details. Where Google Play billing is enabled in an Android test build, Google handles payment details and Anga uses purchase records to verify access. Anga does not receive payment card or bank account information.

How We Use Information

  • Authenticate the account and keep its Anga Spaces available.
  • Confirm control of the email attached to the signed-in account and bind the adult declaration and agreement to that account.
  • Save and sync custom stories, word themes, selected images, and generated audio.
  • Generate reading audio for custom story and word text.
  • Enable account and Anga Space sharing features.
  • Provide optional Educator Access, Story Studio, Class Spaces, educator collaboration, and Class Story access.
  • Verify and restore Apple-managed Anga Plus and Teacher Class Pass subscriptions and unlock paid features. Android test builds use Google Play purchase verification only where that feature is enabled.
  • Protect the service against abuse and enforce content and generation limits.
  • Provide customer support when requested.

Privacy Protections

  • We do not collect precise location data.
  • Anga includes no advertising SDK and shows no advertising.
  • We do not sell or share data with third-party advertisers or data brokers.
  • Anga does not include Firebase Analytics or an analytics product for tracking reading behaviour.
  • We do not track users or profile individual readers. Anga disables Firebase's optional automatic data collection. This does not disable the request and security metadata needed to operate Firebase services. Android service diagnostics, including the optional code scanner's usage analytics, are described below.
  • Firebase App Check processes app and device-integrity material to reject unauthorised clients. Firebase says attestation material and ordinary successful tokens are not retained; replay-protected tokens may be retained for up to 30 days.
  • We do not save reading, word, or phonics progress to the cloud.
  • We do not collect payment card or bank account information.
  • In the iOS app, the grown-up PIN is stored only in the device Keychain and is never sent to Anga or another service.
  • In Android test builds, the grown-up PIN also stays on the device and is not sent to Anga or another service.
  • We do not use data for tracking across other apps or websites.

Third-Party Services and Data Sharing

Anga uses the following service recipients. In the iOS Get Started path, Anga presents the disclosure and waits for the adult's confirmation before starting provider sign-in. Returning adults can choose Sign In in the iOS app or on Anga Web. App Check and Firebase Authentication process the integrity material, account identifier, and email needed to authenticate and check saved permission. Neither route opens private content or starts cloud voice processing unless that permission is current. Firebase App Check may also process browser or device-integrity information when the web companion loads.

Android test builds offer account features only when configured. They use the same adult-account permission checks and Firebase services described here. Configured Android test builds require adult sign-in and account setup before reading. Separate offline development previews can show bundled reading content without an account.

  • Google Firebase: Receives the account identifier, email, sign-in provider, and the custom-content, Space, educator, class, sharing, security, verification, and subscription records described above. Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, and App Check provide sign-in, secure storage, synchronisation, sharing, account email verification, access control, and abuse prevention. Anga clears Firebase Auth's top-level display name and photo before account data opens. Apple or Google may process basic profile information during sign-in, but Anga does not save the provider name or profile picture in Anga account records or copy those fields into Firestore or Cloud Storage. An adult can separately add an optional private name or label for an educator. App Check processes app and device-integrity material used to reject unauthorised clients; attestation material and ordinary successful tokens are not retained, while replay-protected tokens may be retained for up to 30 days. Anga disables Firebase's optional automatic data collection. In iOS builds running with an App Store sandbox receipt, Firebase Authentication also handles the dedicated reviewer email and password entered through App Review Sign In. The password is cleared when sign-in succeeds or the reviewer cancels and is not sent to Anga's backend, family records or logs; this option is not shown in the public App Store build.
  • Google Cloud Text-to-Speech: This AI voice-generation service receives custom story and word text, including pronunciation spellings, solely to generate requested reading audio. Adult-authored text may include names or personal details the adult chooses to write. Anga does not attach an account identifier, email, pictures, payment information, reader progress or a voice recording to the synthesis request. Google states in its Cloud Text-to-Speech data-logging documentation that the service is stateless and does not log customer text or audio. The generated audio is stored with the custom content in Firebase.
  • Google account sign-in: Provides account authentication and may process basic profile information when selected by the grown-up.
  • Google Photos Picker (web companion only): If a grown-up chooses Google Photos in the web story editor, Anga requests separate, read-only Picker permission. Google displays the picker and makes only the one photo that person explicitly selects available to Anga; videos are not supported. Anga downloads the selected image for the editor and stores the resulting story image in Firebase only if the grown-up saves it. The iOS app does not use this Google Photos Picker integration.
  • Sign in with Apple: Provides account authentication and may process basic profile information during sign-in.
  • App Review Sign In: In iOS builds running with an App Store sandbox receipt, provides Firebase email/password authentication for the dedicated reviewer account whose credentials are supplied privately to Apple in App Store Connect.
  • Resend: Receives the adult account's email address and the fixed-format message containing a one-time six-digit code solely to deliver the account verification email. Resend also processes operational delivery metadata needed to route, attempt, and report delivery. It receives no child information, story content, account name, advertising data, or reader activity. See Resend's Privacy Policy.
  • Apple App Store and StoreKit: Handle Anga Plus and Teacher Class Pass subscription presentation, payment authorisation, purchase verification, restoration, cancellation, and refunds.
  • Google Play (Android pre-release only): Where billing is enabled, handles subscription checkout and payment details. Anga's server checks the purchase token, product, subscription state and expiry with Google Play to confirm paid access.
  • Android app security: Firebase App Check uses Google Play Integrity to protect online features. Google processes app metadata, Play licence status, integrity requests and device-attestation information for these security checks. Firebase also processes device, app and SDK metadata to operate and improve its services. These security checks do not track reading progress. See the Play Integrity data disclosure and Firebase Android data disclosure.
  • Google Code Scanner (Android only): A grown-up can scan a Pupil Access Pass or enter its code manually. Google Play services processes scan images on the device and returns the scanned code to Anga. Google states that it does not store scan images or results. The scanner's ML Kit service collects device and app information, device and installation identifiers, performance, configuration, event and error information for diagnostics and usage analytics. Anga enables auto-zoom, which also sends a generated scanning-session identifier, zoom changes and the estimated barcode position. These technical records are separate from Anga's stories, photos and reader progress. See the Google Code Scanner documentation and ML Kit data disclosure.

Google services are governed by Google's Privacy Policy. Anga does not provide account or custom-content data to advertisers, data brokers, or behavioural analytics services.

Grown-up Permission

  • In the iOS app, Get Started first presents the local disclosure. Firebase Core, App Check, and provider sign-in do not start until the person confirms that they are a parent or guardian, or an adult they authorised to use Anga with a child, and explicitly chooses to continue.
  • Returning adults can instead choose Sign In without repeating the new-account disclosure. App Check and Firebase Authentication identify the adult account so Anga can check its saved permission. An existing account with current permission continues; a new account, or one with missing or stale permission, must complete the current disclosure and verification flow before My Library opens.
  • On the adult web companion, Apple or Google sign-in identifies an existing Anga account so Anga can check its saved permission. Adults use the same provider and account as in the mobile app. Children do not sign in.
  • Anga Web does not complete account setup, request verification codes, record a new permission grant, or create My Library. Accounts with missing or outdated permission must complete setup or renewal in the mobile app before opening private stories on the web. Educator Access setup also takes place in the mobile app.
  • A first provider sign-in can create a Firebase Authentication record even when mobile setup is unfinished. This record does not grant access to private content. Anga removes unnecessary profile fields and checks the server's current account-bound permission before reading browser caches, Firestore, or protected Cloud Storage, or starting cloud voice processing. New, data-free unfinished accounts remain subject to the pending-setup cleanup described below.
  • After completing setup in the mobile app, the adult can return to the same browser and check access again. Accounts already set up on either platform remain eligible when their saved permission is current.
  • Anga records an explicit adult declaration, confirms control of the adult account email and, in the iOS app, requires a device-local grown-up PIN. Anga does not independently verify adulthood, professional status, authority, or a government identity document.
  • Educator Access is optional and additive. Anga asks for a separate adult confirmation before preparing an account for teacher features. It does not replace My Library or verify that a person is employed as an educator.
  • In the iOS app, the grown-up creates a four-digit PIN for Settings, purchasing opportunities, and external story sharing. The PIN is account-specific, remains only in that device's Keychain, and can be reset only after another email verification. The web companion does not create or store this PIN.
  • Anga requests renewed permission if the service providers, transmitted data, or purposes materially change.
  • Entering the PIN for Settings, purchasing opportunities, or cross-Space story-link creation starts a short, in-memory grown-up access period so related actions do not cause repeated prompts. Leaving the foreground, changing account, choosing Lock now, or letting the period expire ends it.
  • On the web companion, Use another account signs out so the adult can choose a different Apple or Google account. It does not cancel setup on another device, delete an existing account, or remove its stories. No verification code is requested by this web flow.

Data Storage, Retention, and Security

  • Firebase encrypts data in transit and at rest.
  • A verification code expires after ten minutes. Anga stores only a keyed cryptographic digest rather than the readable code, and the challenge cannot be used after expiry or successful verification. Cancelling account setup removes active or expired code challenges and their digests. Account deletion immediately removes UID-scoped verification challenges. A separate HMAC-keyed recipient abuse-prevention record contains only recent email-send timestamps and an automatic-cleanup timestamp—not the readable email, verification code, or account UID—and may remain for up to 24 hours after cancellation or deletion to prevent rate-limit bypass.
  • In the iOS app, the grown-up PIN is protected by the device Keychain and is not backed up or synchronised by Anga.
  • My Library content is private to the signed-in account.
  • Anga Group Space content is visible to members of that Space.
  • Group Space owners and admins can see members' verified account emails to manage access. Anga retrieves these from Firebase Authentication when the member list opens; it does not copy them into Space membership records.
  • Story Studio content is separate from My Library. Class Space records and Class Stories are limited to authorised educators and Reader Accounts according to their current access.
  • Anga removes a private pass label when the pass is revoked or the class is closed or removed. An expired pending educator invitation is deleted during the next invitation-management action, or when the class is closed or removed. Removing a class also removes its reports. Deleting an account removes unresolved reports made by that account and removes the account identifier from records that must remain in a surviving class.
  • When Anga resolves a Class Story report, it immediately removes the reporter account identifier and optional details. It retains only the reason, decision, Class Space and publication references, and report timing for 90 days. After that period, it marks the audit record for automatic deletion.
  • Account data is kept while the account is active. Private generated audio and custom content remain available until the account or the specific content is deleted. Content already shared inside a multi-member Anga Space may remain available to those members after one account is deleted, with the deleted account identifier removed.

Sharing Features

Content saved in an Anga Group Space is automatically available to members of that same Space. This ordinary Space synchronisation does not create an external sharing link and does not ask for another grown-up check.

A story owner can separately create a time-limited link for a story to be imported into a different Anga Space. Creating that link is a grown-up action. A linked story may include:

  • Its title, text, selected pictures, and generated audio.
  • No account details added to the shared package.
  • Content filtering for inappropriate language before the link is created.
  • An independent imported copy; later edits are not synchronised between Spaces.

Your Choices and Rights

  • Review: View account, Space, and custom content stored in Anga.
  • Delete: Delete the account and associated custom content from Settings in the iOS app, or request deletion without the app. On Android, choose Delete account in account settings.
  • Leave setup: In the iOS app, Back returns to the welcome screen before sign-in without selecting an account or saving setup progress. On the web companion, Use another account signs out without cancelling mobile setup. Cancelling pending setup in the mobile app signs out before private-content access or cloud voice processing begins. A new unfinished account may be deleted; an existing account and its data are preserved.
  • Reset access: Verify the adult account email again to replace a forgotten local PIN in the iOS app.

Account Deletion

In the iOS app, open Settings, choose Delete Account, and confirm the deletion.

On Android, open account settings and choose Delete account. If you cannot use the app, follow the account deletion request page. It provides an email request option without requiring the app to be installed or an app sign-in.

This permanently removes account data, private stories and word themes, account-scoped generated-audio cache, quota records, and owned external share links. It immediately removes UID-scoped verification challenges. A separate HMAC-keyed recipient abuse-prevention record contains only recent email-send timestamps and an automatic-cleanup timestamp—not the readable email, verification code, or account UID—and may remain for up to 24 hours before automatic cleanup. Anga also creates a server-only deletion-safety record keyed by the Firebase account ID. It blocks stale in-flight writes and stores only deletion timing plus affected Anga Space and share identifiers needed for a final Storage sweep. After deletion completes, the record becomes eligible for removal within 24 hours of deletion starting; cleanup runs every 15 minutes and retains it longer only when cleanup must be retried. If deletion is interrupted while the Auth account still exists, the record remains until deletion is safely retried instead of expiring. Content in a surviving multi-member Anga Space remains for its members, with the deleted account identifier removed. This action cannot be undone.

For Class Pass, deletion removes the account's Story Studio, owned Class Spaces, educator and Reader Grant access, transaction claims, and unresolved reports. Content that must remain in a surviving class is kept without this account identifier. A resolved report audit record is not linked to the account and follows the separate automatic-deletion process above.

Deleting an Anga account does not cancel a store subscription. Manage any subscription with the store that bills you.

Where Google Play billing is enabled, account deletion also removes Anga's account-linked purchase records and purchase tokens. Separate records used to avoid processing the same Google Play notification twice may remain. These contain a hashed notification identifier and processing timestamps, not your Anga account identifier or purchase token. Google retains its own purchase records under its policies.

Changes to This Policy

If Anga materially changes its service providers, the data transmitted, or the purposes for using it, we will update this policy and request renewed grown-up permission before the changed processing starts.

Contact Us

If you have questions about this privacy policy or your data, please contact us:

Email: [email protected]

Developer: Vincent Debast

Last Updated: September 19, 2026