Who We Are
Qissa is operated by Ark Horizon LLC.
What We Collect
We collect limited information needed to provide the app. This is adult account-holder information — it is separate from your child's profile and stories, which stay on your device.
- Your email address, if you create an account
- Your name, if you sign in with Google or Apple (used only to greet you in the app). We do not retain your Google/Apple profile photo.
- Account and subscription status
- Story usage counts, such as how many stories have been generated
- Purchase and subscription information processed through Apple, Google, and RevenueCat
Child Information and Story Content
Parents may enter a child's name, age range, language, personality trait, story theme, story length, and optional story companion to generate a personalized story.
This information is used only to create the story. We do not sell this information. We do not use it for advertising. We do not store generated story content on our servers.
Child profiles (name, age range, reading theme) are stored only on your device and are never uploaded to our servers. Generated stories also remain only on your device. Because this data lives solely on your device, deleting or reinstalling the app permanently removes your child profiles and saved stories — they cannot be recovered. Your subscription and account are unaffected and can be restored.
Text-to-Speech Narration
When you use voice narration, story text is sent to our backend and then to a third-party voice provider to generate audio. The provider depends on the narration tier selected:
- Story narration — story text (which may include your child's name, so the voice can say it) is sent to Google Cloud Text-to-Speech (Neural2 voices).
- Cinematic narration — story text is sent to Microsoft Azure AI Speech, with your child's name replaced by a neutral placeholder ("Star") before it is sent, so the child's name is never sent to the cinematic voice provider.
- Natural narration — your device's built-in text-to-speech is used. No story text — and therefore no child's name — ever leaves your device.
The two server voices (Story and Cinematic) are unlocked only after the parent gives verifiable consent — see Parental Consent for Server Narration below. Natural (device) narration is the default and needs no consent, because nothing leaves the device. Audio is cached locally on your device after the first play; re-listening never re-sends text to any provider.
Story Generation
When a story is generated, the story theme, the age range, the trait, the companion, and the language are sent to our AI story provider (Anthropic's Claude). For stories in English, Spanish, French, German, and Portuguese, your child's name is not sent to the story model — it is replaced with a neutral placeholder before the request leaves your device, and your child's real name is substituted back into the finished story locally, on your device.
For languages written in non-Latin scripts (such as Arabic, Hindi, Korean, Japanese, Malayalam, and Chinese), the placeholder technique cannot reproduce a child's name correctly in the native script, so your child's first name only is included in the request to the story provider. Anthropic acts as a contractually-bound processor on our behalf: it does not use this data to train its models, retains request data only transiently for abuse monitoring before deletion, and uses it solely to generate your story. Your child's name is never combined with an account identifier, and the request is proxied through our own servers so the provider never receives your device or network identity.
Story Illustrations
When a story illustration is generated, the story theme and the story companion are sent transiently to OpenAI's image generation API. Your child's name is not sent to the image provider — it is replaced with a placeholder. This information is used only to create the illustration and is not stored by us beyond the current request.
AI-Generated Content
Stories, illustrations, and narration generated by Qissa are created using artificial intelligence based on information provided by the user.
Because content is generated automatically, Qissa does not guarantee that any story, illustration, narration, character, theme, or story element will be unique or exclusive. Similar content may be generated for other users.
Generated content is intended for personal and family use. Users may not sell, sublicense, redistribute, publish, or commercially exploit generated content without prior written permission from Qissa.
Qissa will not publicly use a child's name, profile information, or other personally identifying information for marketing purposes without explicit parental consent.
Third-Party Services
Qissa uses third-party services to operate the app:
- Supabase for authentication and usage limits
- RevenueCat for subscription management
- Apple and Google for in-app purchases
- Anthropic (Claude) for story generation
- Google Cloud Text-to-Speech for Story narration
- Microsoft Azure AI Speech for Cinematic narration
- OpenAI for story illustrations
- Cloudflare for backend hosting
- Resend for support form email delivery
What We Do Not Collect
- Precise location data
- Contacts
- Photos
- Microphone recordings
- Advertising tracking data
Parental Consent for Server Narration
Qissa is a child-directed service, so we obtain verifiable parental consent before a child's personal information (the child's name, inside the narration text) is sent to a server voice provider.
Default — no consent needed: narration uses your device's built-in voice ("Natural"), and your child's name never leaves the device.
Server voices — consent required: to unlock the richer "Story" (Google) and "Cinematic" (Microsoft Azure) voices, the parent is shown a direct notice (what is shared, with whom, and how it is used) and gives consent using the "email plus" method — an in-app consent followed by a confirmation email that contains a one-tap link to withdraw. Server voices unlock only after that consent.
Withdrawing consent: you can withdraw at any time in the app under Account → Parental controls, or by tapping the link in the confirmation email. Withdrawing reverts all narration to your device's voice, so the child's name is no longer sent to any voice provider.
We keep a record that the account holder gave (or withdrew) consent, the method, and the date — no child data, only the consent event itself.
Children's Privacy
Qissa is a child-directed service: children experience the stories through audio playback and read-along. The account is always held and controlled by an adult (a parent or guardian), who creates the child profiles, generates the stories, manages the data, and provides the verifiable parental consent described above. Children do not create or control accounts; the parent operates the account on the child's behalf. The age ranges (2–3, 4–5, 6–9, 10+) are chosen by the parent for the child the story is for.
The only child personal information that leaves the device is the child's name, and only as part of the story text sent to the Story (Google) server voice after parental consent (and never to the Cinematic voice, where it is replaced with a placeholder before the text is sent to Microsoft Azure). The child's name is not sent to the AI story or illustration models. We do not knowingly collect any other personal information from or about a child, and we do not use a child's information for advertising — Qissa contains no ads and no ad tracking.
Data Retention
We keep personal information only as long as needed for the purpose it was collected. Our retention periods:
- Child profiles & saved stories (name, age range, language, trait) — stored only on your device; never uploaded to us. Removed permanently when you delete or reinstall the app.
- Parent account (email, name) & usage counts — retained while your account is active; deleted within 30 days of an account-deletion request.
- Parental-consent record — the consent event (method + date, no child data) is retained while the account is active and deleted with the account.
- Text sent to AI / voice providers at generation time — not retained by us; the providers act as our processors and retain it only briefly under their terms (for example, up to 30 days for abuse monitoring, and shorter or zero-retention where we have arranged it). Google Cloud Text-to-Speech does not log the text at all; the Cinematic voice (Microsoft Azure) never receives the child's name.
- Pseudonymous product analytics — tied to a random app-install identifier (not your name or your child), so it is pseudonymous rather than fully anonymous; retained in aggregate.
Account data can be deleted by deleting your account in the app or contacting us at hello@qissa-stories.com.
Security
All communication between the app and our servers uses HTTPS encryption. API keys that power story generation and narration are stored securely on our backend servers and are never exposed to the app or its users.
Contact
Qissa is operated by the following business. Under COPPA, this is the operator you can contact about your child's information — by mail, phone, or email:
Ark Horizon LLC
935 Windy Garden Way, Richmond, Texas 77406-7218
+1 (281) 384-3221
hello@qissa-stories.com
For how long we keep each type of data, see our Data Retention Policy.