Data Security & Privacy Plan — Puppet Pals 1
Consumer subscription edition. The classroom-deployable version has a separate plan: see Puppet Pals 1 School Edition Data Security & Privacy Plan.
For schools: this plan does not apply to you
Puppet Pals 1 (this consumer subscription edition) is not appropriate for classroom or district use. This Data Security & Privacy Plan describes practices for the family/home product — which includes AI image generation and Apple In-App Purchase subscriptions. Those do not fit our school-procurement requirements.
Schools and districts evaluating Puppet Pals should review the School Edition Data Security & Privacy Plan instead. The School Edition has no AI features, no subscriptions, and no student-created media/content uploads in its normal creation and export flow.
The provisions below are written for an individual family subscriber, not for an institutional data controller.
1. Overview
Puppet Pals 1 is a creative storytelling app developed by Polished Play LLC and distributed on the Apple App Store. This plan describes how we protect data associated with the app, aligned with the NIST Cybersecurity Framework (CSF). The companion Privacy Policy describes what we collect; this document describes how we protect it.
Puppet Pals 1 (consumer) is for family and home use only. It is not appropriate for classroom or district deployment. The dedicated School Edition has materially stricter data handling (no AI features, no subscriptions, and no student-created media/content uploads in its normal creation and export flow) and is the only edition appropriate for classroom use.
2. Data Collected
Puppet Pals 1 does not ask children to create accounts or provide names, contact information, or advertising identifiers. The consumer app and its optional online features handle:
- First-party usage analytics and diagnostics — feature interactions, device/OS/app versions, approximate country/region, bounded error context, and a random session ID. Routine analytics does not use the App Transaction ID. A subscription-linked error or support record may include the Apple Original Transaction ID. These records are pseudonymous, not necessarily anonymous.
- AI image data (transient, subscribers only) — when a subscriber uses an AI feature, the photo or text prompt is sent through our API to fal.ai, which forwards it to the current upstream image model (see the AI Processing details page). EXIF metadata is stripped server-side before forwarding. Generated images are returned through fal's CDN (60-second lifecycle, configured per request). No image bytes are stored on Polished Play servers.
- Exported videos — a finished-show export is saved to Photos on the device. Polished Play does not receive, store, or host the exported video.
- Subscription identifiers — Apple transaction IDs for verifying subscription status and enforcing fair-use quotas. No payment information is collected.
- Update email addresses (optional) — provided voluntarily by a parent, caregiver, or educator through an adult-directed, user-initiated action in Settings.
- Feedback and diagnostics (optional) — provided voluntarily by a parent, caregiver, or educator through adult-directed, user-initiated Settings actions and may include submitted contact details, message content, structured app/device/session context, and an opaque subscription reference. Diagnostics bypass the third-party spam classifier, and Slack receives only a link to the private admin record.
Puppet shows and recordings are stored on the device and are not transmitted to our servers. A user can deliberately send a selected photo, drawing, or text prompt through an AI feature; exported show videos are saved to Photos on the device.
3. Administrative Safeguards
- All Polished Play employees and contractors with access to any stored data are bound by confidentiality agreements.
- Access to production systems is restricted to authorized personnel on a least-privilege basis.
- Polished Play personnel are trained on applicable privacy laws, including COPPA and GDPR.
- We do not sell, rent, or share user data with third parties for marketing or advertising purposes.
4. Technical Safeguards
- All data in transit between the app, our servers, and our subprocessors is encrypted using TLS 1.2 or higher.
- Server infrastructure is hosted on Vercel with industry-standard security controls.
- Server access requires multi-factor authentication.
- First-party analytics and diagnostic records are pseudonymous, not necessarily anonymous. Routine analytics is linked only to a random session; subscription-linked errors or support records may use the Apple Original Transaction ID as described in the Privacy Policy. They are not used for advertising or cross-app tracking.
- EXIF and GPS metadata are stripped from uploaded photos before they are forwarded to any AI processing partner, so embedded location and device metadata is not sent to fal.ai or the upstream model.
- Generated images on fal.ai's CDN are configured per-request to expire after 60 seconds (fal's default is 7 days). This minimizes the window during which generated content lives at a publicly-addressable URL.
- Production AI traffic is routed only through fal.ai. Other AI providers supported in admin tooling (Replicate, OpenAI direct) are not reachable from the consumer app — this is enforced at the API layer, not the client. The upstream model fal.ai routes to at any given time is named on the AI Processing details page. Different upstream models may have different terms regarding training and retention. Before consumer content is sent to a materially different processor or under materially different data-handling terms, we update the disclosure and require a fresh explicit permission choice in the app.
- Image bytes (input photos and generated outputs) are never persisted by Polished Play servers. Only request metadata (timestamp, model, success/failure, cost estimate) is logged for billing and reliability monitoring.
- No third-party analytics or tracking SDKs are used in the app.
5. Data Sharing and Subprocessors
The following third-party services are used in the operation of Puppet Pals 1:
- fal.ai — receives EXIF-stripped photos and text prompts from our API at request time, returns generated images. We use the standard fal.ai service tier; the dedicated no-training contractual guarantee that fal.ai offers is part of their enterprise tier and does not currently apply to our account. See the AI Processing details page for the full chain and the current upstream model.
- Upstream image-model provider (reached via fal.ai) — receives the photo or prompt from fal.ai for processing. The current provider and model are named on the AI Processing details page. Today's upstream (Google Gemini paid tier) contractually prohibits training on customer inputs. Before a materially different processor or set of data-handling terms is enabled for consumer traffic, we update the disclosure and require a fresh explicit permission choice in the app.
- Apple — App Store distribution and In-App Purchase subscription processing.
- Vercel — hosts our public website and API routes.
- Neon and optional communication providers — Neon provides the managed database. Resend delivers optional update emails; Google Gemini, Slack, and Gmail may process voluntary feedback and replies as detailed in the Privacy Policy.
We do not sell user data or share it with third parties for their own advertising. The Privacy Policy contains the complete, current description of subprocessors and purposes.
6. Incident Response
In the event of an unauthorized release, disclosure, or acquisition of data:
- Polished Play will investigate the incident immediately upon discovery.
- Affected parties will be notified within 72 hours of confirmation.
- The notification will include a description of the incident, the types of data involved, and contact information.
- Polished Play will take immediate steps to contain and remediate the incident.
7. Data Retention and Disposal
- Photos and prompts sent for AI processing are not retained by Polished Play. fal.ai and the upstream model provider may retain limited abuse-prevention or security logs under their terms; exact provider-side windows are not controlled by Polished Play. Generated-output CDN files use the configured 60-second lifecycle.
- Raw usage analytics and automatic client-error events are automatically deleted from our analytics database after 90 days. Bounded operational client-error alert copies in our private Slack channel follow Slack's retention and our administrative deletion practices.
- Update email addresses are retained until unsubscribe or a deletion request; limited suppression records may remain to prevent unwanted future delivery.
- Subscription, transaction, status, and usage records are retained while needed to provide and reconcile the subscription and afterward as reasonably needed for refunds, disputes, fraud prevention, support, accounting, tax, and legal obligations.
- Voluntary feedback and diagnostics are retained as reasonably needed to respond, provide support, and improve the app; routed copies follow the applicable Slack or Gmail retention.
- Deletion requests can be made at any time by contacting privacy@polishedplay.com.
8. NIST Cybersecurity Framework Alignment
Polished Play's security practices are aligned with the NIST Cybersecurity Framework (CSF). Given the minimal data we actually handle, our alignment is summarized below:
Identify (ID)
We maintain an inventory of the limited data we process. Our data collection is limited by design: we do not ask children for names, contact details, accounts, or advertising identifiers. We do persist pseudonymous Apple transaction identifiers, and user-selected photos sent through optional AI features can themselves contain identifying information. Risk assessments are conducted relative to the data we actually hold, with explicit attention to AI-processing data flows.
Protect (PR)
Access to production systems requires multi-factor authentication and is restricted to authorized personnel. All data in transit is encrypted via TLS. EXIF metadata is stripped before forwarding. Generated-content CDN retention is shortened to 60 seconds. The production AI provider chain is restricted at the server to fal.ai as the gateway; the current upstream model is described on the AI Processing details page. No third-party tracking SDKs are embedded in the app.
Detect (DE)
We monitor our server infrastructure for anomalous activity. Our hosting and database providers provide logging and alerting for unauthorized access attempts. Per-request analytics on AI usage make it easy to detect abuse patterns.
Respond (RS)
Our incident response process includes identification, containment, notification within 72 hours, and remediation. We cooperate with affected parties and regulatory bodies as required.
Recover (RC)
Given the minimal data we handle, recovery primarily involves restoring service availability. Lessons learned from any incident are incorporated into our security practices.
9. Contact
For questions about this Data Security & Privacy Plan or our data practices, contact us at privacy@polishedplay.com.
Effective: July 25, 2026