Your family's data, safeguarded.
This page is maintained by MindTales by NYRA™ to answer common questions about how we protect your child's information. Last updated July 10, 2026.
What we collect
- Parent's email address (used to sign in and send account notices).
- Child's first name and age (used to unlock age-appropriate stories).
- Optional child gender (used to tailor story suggestions).
- Story listening progress, likes, and Pause & Reflect answers.
- Basic device metadata (browser, timezone) for security & analytics.
We do not collect government IDs, precise location, contacts, photos, or microphone/audio recordings from your child.
Encryption & storage
- In transit: All traffic between your device and MindTales is served over TLS 1.2+ (HTTPS).
- At rest: Databases and file storage are encrypted at rest by our infrastructure provider (AES-256).
- Passwords: Never stored in plain text — hashed with a modern password-hashing scheme by our authentication provider.
- Parental PIN: Stored only as a SHA-256 hash of the digits you enter; we cannot read the original.
Access & row-level security
The child profile fields — name, age, and gender — are locked at the database level after your account is created. Only an administrator can change them. This prevents anyone from bypassing your subscription's age tier by editing their own profile.
All personal data is protected by row-level security policies: a signed-in user can only read and write rows tied to their own account.
Retention, deletion & your rights
- Data is kept while your account is active.
- You may request deletion of your account and associated data at any time — email us and we'll remove it within 30 days.
- You may request an export of the data we hold about your account.
- Admins may deactivate accounts found abusing the service (spam, automated signups). Deactivation is reversible on request.
What we store on your device
MindTales uses no advertising or third-party tracking cookies. Everything below is stored on your own device — here is exactly what, and why.
| What | Why | Consent |
|---|---|---|
| Sign-in session (local storage) | Keeps you logged in and enforces one device at a time. | Strictly necessary |
| Installed app files (PWA cache) | Lets the app open from your home screen and load quickly. | Strictly necessary |
| Build-version check | Confirms you are on the latest version of the app. | Strictly necessary |
| Parental PIN & preferences | Remembers your settings, reminders and PIN gate. | Strictly necessary |
| Usage & app analytics | Pseudonymous stories played, quiz completions, device type, app version. | Optional — off until you agree |
| Video playback quality telemetry | Helps us fix buffering and playback errors. | Optional — off until you agree |
Optional analytics stays switched off until you say yes. We ask once, record your answer in your account's consent audit log, and never ask again — you can change it anytime in Settings → Preferences. Declining never limits any part of MindTales.
Anti-abuse (CAPTCHA)
We use Cloudflare Turnstile during signup and profile setup to detect automated abuse. Turnstile is a privacy-preserving CAPTCHA that does not use tracking cookies and does not share data with Google or other advertising networks. It processes minimal browser signals under Cloudflare's Privacy Policy.
Contact
Privacy questions, deletion requests, or data-export requests: privacy@mindtalesbynyra.com.