Who we are and this policy
This policy describes how Ihor Izviekov, independent developer of Evania (“EvaniaAI”, “we”, “us”) handles personal and family data when a parent or legal guardian uses EvaniaAI. It applies to the EvaniaAI iPad app, our API, and our support services.
- Data controller and app operator
- Ihor Izviekov, independent developer of Evania
Privacy contact: evania.stories@proton.me.
Data EvaniaAI collects
Parent and family account data
We process the parent’s authentication identifier, email address when supplied by the sign-in provider, display name, language, family name, time zone, consent record, Parent Gate PIN hash, onboarding state, and account/activity timestamps. EvaniaAI does not store the readable Parent Gate PIN.
Child and creative data
We process child profile data such as display name, optional birth year, language, interests, reading preferences, parent-set exclusions, stories, story drafts and pages, worlds, characters, drawings, generated images, chat messages, feedback, safety reports, reading progress, and parent approvals. EvaniaAI collects child-profile and creative data only after the account holder completes the parent-consent step in EvaniaAI.
Device and technical data
We process a persistent app-installation identifier, authenticated Child Space session records, device platform, app version, and optional push-notification registration token. We also keep security, safety, workflow, audit, and error records needed to operate and protect EvaniaAI. We redact secrets and email addresses from operational telemetry where possible.
EvaniaAI does not ask for access to the device camera, photo library, or microphone. Drawings are made in the EvaniaAI in-app canvas. Family creative content is private to the family: EvaniaAI does not make it publicly searchable or share it with other families using EvaniaAI.
Purchase data
For in-app credit packs, we process an opaque RevenueCat account identifier, product identifiers, Apple/RevenueCat transaction identifiers, purchase/refund/reversal timing, purchase state, and the family credit ledger. Apple processes the payment; EvaniaAI does not receive or store payment-card numbers.
Why we use data
- Authenticate the parent, run the parent and Child Spaces, and protect family-only access.
- Create, moderate, review, store, retrieve, and display family stories, images, worlds, characters, and chats.
- Apply parent consent, parent approvals, safety controls, reports, and age-appropriate settings.
- Process and reconcile verified credit purchases, rewards, refunds, reversals, and support requests.
- Send optional, content-free reminders about scheduled deletion of inactive never-paid family accounts.
- Maintain security, diagnose failures, prevent abuse, and meet legal, accounting, and tax obligations.
Legal bases where they apply
Depending on the law that applies to a parent or child, EvaniaAI relies on the performance of the requested service, the parent’s consent, legitimate interests in protecting EvaniaAI and its users, and legal obligations such as tax and accounting requirements. We do not use children’s data for behavioural advertising, cross-app or cross-site tracking, or data-broker activities.
Service providers and disclosures
We share data only as needed to operate EvaniaAI, provide a requested feature, comply with law, or protect rights and safety. Current service categories are:
- Clerk, for parent authentication and account identity. If a parent chooses Google sign-in, the sign-in flow also involves Google.
- OpenAI, for text generation, image generation, vision analysis of drawings, embeddings, and moderation. Relevant prompts, creative inputs, images, and context may be sent to OpenAI to provide these features.
- RevenueCat and Apple, for App Store credit-pack purchase, purchase-record checks, refunds, and transaction verification.
- Vercel Blob, for private storage of family drawings and generated assets; Neon PostgreSQL, for the managed PostgreSQL application database used by EvaniaAI; and Vercel, for hosting and API delivery.
- Langfuse, if enabled for the deployed environment, for prompt management and operational AI telemetry. EvaniaAI sends pseudonymous workflow identifiers, model/usage metadata, safety and quality metrics, and redacted error information—not a deliberate copy of full family creative content.
- Expo Push Service, if a parent enables reminders, to deliver device notifications. Retention reminders do not contain child names, story details, or other family content.
We do not sell personal data or use children’s data for behavioural advertising.
Consent and choices
A parent controls consent for a family. Revoking consent stops new AI processing, profile changes, and Child Space activity. It does not automatically delete existing data; the parent can still review, export, or delete it from the Privacy and data screen in EvaniaAI.
Push reminders are optional and can be disabled in EvaniaAI or device settings. A notification failure, a disabled notification setting, or an unopened reminder does not stop a scheduled inactivity deletion.
Depending on applicable law, a parent or other authorised account holder may request access to, correction of, deletion of, restriction of, objection to, or portability of their family’s personal data. Use the in-app Privacy and data screen or contact evania.stories@proton.me. Consent can be withdrawn at any time without changing processing that was lawful before withdrawal. A person may also complain to the data-protection authority that is competent for them.
To protect family data, we may ask for reasonable information to verify the requester’s identity and authority before acting on a request.
Retention and deletion
- A parent can export family data from the app. The export includes the parent account, child profiles, stories, chats, drawing metadata, consent history, feedback, and other family records described by the export feature.
- A parent can delete an individual child profile and its related drawings, stories, chats, characters, feedback, and learned memory.
- A parent can permanently delete the family account in the app. EvaniaAI cancels active AI work, deletes family content and private stored assets, and removes the associated parent identity where applicable.
- If a family has never completed a verified purchase and has no authenticated online EvaniaAI activity for 180 days, EvaniaAI schedules permanent deletion of the family data. We may attempt reminders about 30 and 7 days before deletion. Families with a verified purchase are exempt from this inactivity rule.
- After a family-account deletion, EvaniaAI retains pseudonymised/bounded financial ledger and transaction records for the configured accounting period: 2555, subject to applicable legal obligations. The retained billing account is detached from the deleted family.
Security and international processing
EvaniaAI uses access controls, consent and family-scoping checks, private asset delivery, signed export access, encrypted transport, and safety review processes designed to protect family data. No security measure is absolute.
Our providers may process data in countries other than the parent’s country of residence. For a current provider list, the applicable transfer safeguards where required, or questions about an international transfer, contact evania.stories@proton.me.
Your questions and updates
For privacy questions or requests, contact evania.stories@proton.me. We may update this policy when EvaniaAI changes. For material changes, we will give notice through the app or by another reasonable method before the change takes effect where required; the effective date above identifies the current version.