Privacy Policy — Puppet Pals 1

Consumer subscription edition. Looking for the school version? See the School Edition privacy policy or the comparison page.

For schools: use the School Edition instead

Puppet Pals 1 (this consumer subscription edition) is not appropriate for classroom use. It includes AI image generation and an Apple In-App Purchase subscription, which do not fit our classroom or school-procurement requirements. The data handling described below is for family and home use.

For schools we publish a separate Puppet Pals 1: School Edition. The School Edition has:

  • No AI features. No image or text data ever leaves the device for AI processing.
  • No subscriptions or In-App Purchases.
  • A separate Data Security & Privacy Plan aligned with school-procurement requirements.

If you are a teacher, administrator, IT staff, or procurement officer evaluating Puppet Pals for a classroom, please use the School Edition. The rest of this policy describes the consumer product and is not intended to satisfy school requirements.

Overview

Puppet Pals 1 is a creative storytelling app for children and families, distributed on the Apple App Store. We are committed to protecting the privacy of all users — especially children. This policy explains the data practices of the consumer app so families can make informed choices.

Puppet shows, recordings, drawn characters, and photos imported from the device normally remain on the device. Content leaves the device for Polished Play processing only when someone deliberately uses an online feature such as AI image processing. Exporting a finished show saves a video to Photos on the device; Polished Play does not receive, store, or host that exported video. The app and its online features also send the limited subscription, usage, diagnostic, email, and feedback information described below.

Information We Collect

First-Party Usage Analytics and Operational Diagnostics

Depending on the app version and feature being used, Puppet Pals 1 may send usage events and technical error reports to our own backend. We do not embed a third-party advertising or tracking SDK. These records are pseudonymous, not necessarily anonymous: routine product analytics uses a random session identifier and does not use the App Transaction ID. A subscription-linked operation, automatic technical error report, or support submission may include the separate Apple Original Transaction ID so we can understand entitlement, quota, and support problems. That identifier is not an Apple ID, name, email address, or payment-card number.

Usage and diagnostic information can include:

  • A random session identifier; routine usage analytics does not include a stable user or App Transaction identifier
  • Features used and product-interaction events
  • Approximate country and region derived by our hosting provider from the network request
  • Device type, operating-system version, and app version
  • Request identifiers, endpoint or feature context, provider and model names, timestamps, success or failure, quota usage, and estimated service cost
  • Bounded error categories and codes, HTTP status, request or incident identifiers, and a short trail of event names and timestamps when an operation fails

Our analytics database does not intentionally store the raw IP address. Vercel and other network infrastructure may process IP addresses, user-agent strings, and ordinary request logs as part of hosting, security, and abuse prevention. We do not use this information for targeted advertising or cross-app tracking.

AI Image Features (Subscription Only)

Puppet Pals 1 includes AI-powered features that allow subscribers to create stylized actors and backgrounds. Users can either submit a photo to be stylized into a puppet, or provide a text description to generate one from scratch. These features are only available to eligible subscribers whose paid period or Apple billing-grace deadline has not elapsed and are disclosed during the subscription sign-up flow.

When you use an AI feature, the photo or text description is sent from your device to our servers, then forwarded to our AI processing partner fal.ai. fal.ai routes the request on our behalf to a third-party image model.

In plain English: when your child uses an AI feature, a photo from the device (with location and identifying metadata stripped) or a text prompt is sent through our servers to a third-party AI model. We do not store the photo or prompt on our servers. The third-party model processes the request and returns a generated image, which is saved on the device.

The current upstream image model is described on our AI Processing details page. Different models may have different terms regarding how they use customer inputs. Today's chain (Google's Gemini paid-tier API, reached via fal.ai) contractually prohibits training on customer inputs. Before consumer content is sent to a materially different third-party processor or under materially different data-handling terms, we will update the disclosure and require a fresh explicit choice in the app. The AI Processing details page identifies the current chain.

Photos and prompts are not stored on Polished Play servers — only metadata about the request (timestamp, model, success/failure) is retained for billing and reliability monitoring.

Before sending photos to fal.ai, we strip EXIF metadata (including any GPS coordinates and device identifiers) from the re-encoded image so that embedded metadata is not forwarded to fal.ai or the upstream model. Generated images returned by fal.ai are stored on the fal CDN for 60 seconds (we set this explicitly per request — fal's default is 7 days), just long enough for our server to fetch and return the image to your device. Once on the device, generated images are stored on the device only.

Video Export

Eligible users can export a finished puppet show as a video. The app saves the exported video to Photos on the device. Polished Play does not receive, store, or host the video and does not create a browser viewing link. If the device owner later shares the video from Photos, the selected recipient or service handles it under that service's privacy practices.

Subscription Data

Puppet Pals 1 offers a subscription through Apple In-App Purchases. We store Apple original and current transaction identifiers together with subscription product, environment, status, purchase and expiration dates, renewal and grace-period state, offer information, storefront/currency and signed price facts, status history, and AI usage/cost records. We use these records to verify access, enforce fair-use limits, provide support, prevent abuse, reconcile Apple notifications, measure trials and subscription conversion, and understand revenue and service cost. All payment processing is handled entirely by Apple — we do not receive or store credit card or bank-account numbers.

Update Email Addresses (Optional)

An adult parent, caregiver, or educator may optionally provide an email address from the adult-directed Settings screen to receive notifications about Puppet Pals updates. This user-initiated feature is:

  • Completely voluntary and optional
  • Used solely for sending app update notifications
  • Processed by our email delivery provider when we send an update, with unsubscribe, bounce, and complaint suppression
  • Never sold or shared with third parties for their own marketing purposes

Feedback (Optional)

An adult parent, caregiver, or educator may choose to submit feedback from the adult-directed Settings screen. Depending on what the sender enters, a submission can include a name, email address, subject/category, message, source label, and an opaque subscription identifier. We store the submission to screen spam, route and answer support, investigate subscription issues, and improve the app. The submission may be processed by Google Gemini for spam classification, posted to a private Slack channel when classified as non-spam, and processed by Gmail if we prepare or send a reply.

The separate adult-directed Send Diagnostics action is also voluntary and user-initiated. It stores the sender's email and message together with structured app/build, device/OS, account, random session, and recent event-name context. If the issue is linked to a subscription it may include the Apple Original Transaction ID. Diagnostics bypass Gemini spam classification, and the Slack notification contains only a link to the private admin record. The app asks the sender not to include a child's personal information in the message.

Information We Do Not Ask Children to Provide

We do not ask children to provide names, contact information, accounts, advertising identifiers, or precise location. In particular, we do not request:

  • Names, usernames, or contact information from children
  • Precise location data
  • Device identifiers or advertising IDs
  • The contents of on-device puppet shows or recordings

There are no Polished Play user accounts or logins in Puppet Pals 1. A photo sent through an AI feature can itself contain identifying information, so an adult should review it before choosing that feature.

How We Use Information

Usage Analytics and Diagnostics

First-party usage and diagnostic information is used to:

  • Improve app functionality and user experience
  • Understand which features are most used
  • Identify and fix technical issues
  • Monitor quota, provider cost, reliability, and abuse
  • Make informed decisions about future app updates

AI Image Data

Photos and text descriptions submitted for AI image generation are used by Polished Play solely to generate the requested image. Polished Play does not store them on our servers or use them for any purpose other than fulfilling the request. They are forwarded to the third-party AI processing chain documented on our AI Processing details page; how the upstream provider handles inputs depends on that provider's terms, which may change over time.

Update Email Addresses

Optional update email addresses are used solely to:

  • Send notifications about app updates and new features
  • Let recipients choose to stay informed about Puppet Pals

Feedback

Feedback submissions are used to screen spam, route and answer support, investigate subscription problems, understand user needs, and improve the app.

Data Sharing and Third-Party Services

We do not sell, trade, or share user data with third parties for marketing or advertising purposes. We do not use any third-party analytics services.

The following third-party services are involved in the operation of Puppet Pals 1:

  • fal.ai — AI image processing partner. Receives the EXIF-stripped photo or text prompt at request time, returns the generated image. fal.ai forwards the request to an upstream image-model provider on our behalf; the current upstream provider is named on the AI Processing details page. Generated images are stored on fal's CDN for the 60-second window we configure per request.
  • Upstream image-model provider (reached via fal.ai) — The specific provider and model receiving the prompt and any photo at any given time is listed on the AI Processing details page. Different models have different terms regarding training and retention. Before consumer content is routed to a materially different third-party processor or under materially different data-handling terms, the in-app disclosure and permission choice will be updated.
  • Apple — Processes In-App Purchase subscriptions. Payment is handled entirely by Apple.
  • Vercel — Hosts our API and website. Vercel handles network requests and ordinary operational logs, and supplies the approximate country and region request headers used by our first-party analytics endpoint.
  • Neon — Provides our managed PostgreSQL database. It stores first-party analytics, subscription and transaction records, AI usage records, update email addresses, feedback, diagnostics, and email-delivery suppression records.
  • Google Gemini — In addition to any role as the current upstream image model described above, a Google Gemini text model may receive a limited portion of a voluntary feedback submission—including the message and any submitted name, email, and subject—to classify spam. An authorized administrator may also choose to send the stored message, name, category, and source to Gemini to prepare an editable reply draft.
  • Slack — A feedback submission classified as non-spam may be posted to our private feedback channel, including submitted contact fields and message. Private operational alerts may include technical failure details, request identifiers, and only a masked last-four subscription reference. A diagnostics notification contains only a link to the private admin record, not the submitted fields or message.
  • Resend — Delivers optional Puppet Pals update emails. It receives the recipient's email address and message, and returns delivery identifiers and complaint or permanent bounce events used to suppress future sends.
  • Google Gmail — If we reply to feedback, Gmail may process the submitted name and email address, our reply, and the resulting message thread.

See the AI Processing details page for the technical specifics of each hop, including what we cannot promise about every link in the chain.

Changes to the AI Processing Chain

We may change the upstream image-model provider or model over time — for example, to manage cost, respond to model availability, address subscriber abuse, or take advantage of a new model. Before consumer prompts or photos are sent to a materially different third-party processor or under materially different data-handling terms, we will update the disclosure and require a fresh explicit permission choice in the app. The AI Processing details page describes the current approved chain.

Parents who prefer not to continue using AI features after a change — or at any other time — may withdraw AI-processing permission through Settings → Legal → Revoke AI Processing Permission. The rest of Puppet Pals 1 — all non-AI creation, recording, and playback features — continues to work without that permission.

Data Retention and Deletion

  • Photos and prompts sent for AI processing: not persisted by Polished Play. fal.ai and the upstream model provider process them and may retain limited request, abuse-prevention, or security records under their own terms; exact provider-side log windows are not controlled by Polished Play. The 60-second setting described below applies to generated-output CDN files, not to provider security logs.
  • Generated images: held transiently on fal.ai's CDN for up to the configured 60-second window; after the app receives them, its copy is stored on the device only.
  • Raw usage analytics and automatic client-error events: automatically deleted after 90 days. Routine usage analytics is session-scoped; subscription-linked error records can include an opaque Apple Original Transaction ID as described above. This 90-day limit applies to the raw database rows. Bounded operational alert copies sent to our private Slack channel follow Slack's retention and our administrative deletion practices.
  • Subscription, transaction, status, and usage records: retained while needed to provide and reconcile the subscription and afterward as reasonably needed for refunds and disputes, fraud and abuse prevention, support, accounting and tax records, legal obligations, and aggregate trial, conversion, revenue, and profitability analysis.
  • Update email addresses: retained until the recipient unsubscribes or requests removal. Limited suppression records may remain so we do not send unwanted email again.
  • Feedback and diagnostics submissions: retained for as long as reasonably needed to answer support and improve the app. Copies already routed to Slack or Gmail follow those providers' retention and our administrative deletion practices.
  • Hosting and security logs: retained under our hosting providers' configured operational and security retention periods.

A user, parent, or guardian may request access to or deletion of data associated with an email address or opaque subscription identifier by contacting us at privacy@polishedplay.com. Because Puppet Pals 1 has no Polished Play account, we may ask for information shown in the app or previously submitted to us so we can locate the correct records and verify the request.

We will delete or de-identify data we can reasonably identify, subject to legal exceptions. We may retain records required for tax/accounting, fraud prevention, security, App Store disputes, or other legal obligations, and data may remain in protected backups until those backups age out.

Children's Privacy

Puppet Pals 1 is designed for children. We do not knowingly ask children to provide names, contact information, accounts, or advertising identifiers. AI image features can transmit user-selected content and require an eligible subscription plus an adult-facing disclosure and explicit permission. The subscription sign-up flow is intended for the adult who owns the device and Apple ID. Optional email, feedback, and diagnostics actions are labeled for parents, caregivers, and educators in Settings, but are not protected by a technical parental gate. Limited first-party usage and diagnostic processing is described above.

Data Security

We implement appropriate technical and organizational security measures to protect the limited data we handle. All data transmission between the app, our servers, and our processing partners is encrypted using industry-standard TLS encryption. Server access is restricted to authorized personnel and requires multi-factor authentication. For full details, see the Data Security & Privacy Plan.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated effective date. Changes to the AI processing chain — including changes to the upstream model or model provider reached via fal.ai — follow the separate notice commitment in "Changes to the AI Processing Chain" above.

Contact Us

If you have any questions about this privacy policy or our data practices, please contact us at privacy@polishedplay.com.

Effective: July 25, 2026