Privacy Policy
Effective date: 3 June 2026 · Version: 2
Whisperly, by SleepyLama Creations ("the app", "we", "us"), is a parent-operated service that makes personalized bedtime stories for children. Parents and guardians set up and control the account, and they decide what information their child shares with us. This policy explains what we collect, why, who helps us run the service, and the choices and rights you have. Questions or requests can go to support@whisperly.qzz.io.
For a plain-language summary of what we store, what we never store, and the controls you have, see our Privacy Report Card.
Who controls the account
Whisperly is built to be operated by a parent or guardian. An adult creates the account, adds a child profile, and chooses the details that personalize the stories. We rely on that adult to give consent before any information about a child is provided to us. Children do not create their own accounts.
Information we collect
From the parent or guardian:
- Email address, provided when you create an account or sign in.
- Display name, used to personalize the account.
About the child, provided by the parent to personalize stories:
- First name, so the story (and the narration) can speak to the child directly.
- Age band, so the language and themes fit the child.
- Interests and favorite characters, used to shape story ideas the child will enjoy.
- Avatar made from an emoji and a color, a playful way to identify the profile. No photos are used.
From normal use of the app:
- Listening activity, such as which story was played and the playback position, so we can offer "Continue listening" and improve recommendations.
- A first-party device identifier we generate to keep the app working on your device (for example, syncing playback). This is not an advertising identifier and is not used for advertising or cross-app tracking.
If you choose the optional day-note recorder, Whisperly uses the microphone only after you tap record. The recording is used to transcribe the note for that story and the audio recording is not stored.
We do not use advertising identifiers, ad SDKs, or attribution trackers. We use product analytics for app functionality, reliability, and safety, with session replay turned off. We never sell or share personal data, and we never sell or share children's data.
Why we use this information
- To create personalized stories and narration for the child.
- To authenticate the parent and keep the account secure.
- To sync "Continue listening" progress across sessions.
- To operate, maintain, and improve core app functionality.
- To handle subscriptions and send essential service emails.
Our legal bases
Where the law (such as the GDPR) requires a legal basis, we rely on the following. For any information about a child, and for creating personalized stories, we rely on the consent of the parent or guardian, which you give when you set up a child profile and which you can withdraw at any time. For keeping the account secure, preventing abuse, and operating the core service, we rely on our legitimate interests, balanced against your rights. For subscriptions, we rely on performing our contract with you.
The categories of services that help us run Whisperly
We use a small set of trusted, vetted service providers (processors) to operate the app. They only handle data on our instructions and only for the purposes below. We describe them by category here; the specific current providers are available on request (email support@whisperly.qzz.io).
- Secured server infrastructure and authentication — stores account and app data and handles sign-in.
- AI text generation — generates the text of the personalized stories.
- AI voice narration — turns story text into audio, which includes saying the child's first name.
- Subscriptions and billing — manages subscriptions and purchases.
- Cloud storage and content delivery network — stores and delivers audio and cover images.
- Transactional email — sends account and security messages.
International data transfers
Some of these providers may process data outside your country, including outside the UK and the European Economic Area. When that happens, we use appropriate safeguards, such as the European Commission Standard Contractual Clauses (SCCs) and the UK addendum, so your data stays protected.
How long we keep data
- Listening events are kept for up to 18 months, then deleted or anonymized.
- Inactive accounts are purged after 24 months of inactivity, along with their associated data.
- Generated audio is deleted when an account is deleted.
We may keep limited records longer where the law requires it, for example for tax or to resolve disputes.
Your rights and choices
Depending on where you live, you and your child have rights over the information we hold. These include the right to access a copy, export it, request deletion, correct (rectify) inaccurate details, object to certain processing, and withdraw consent at any time. Withdrawing consent does not affect processing that already happened.
You can exercise many of these rights directly in the app, including editing or removing a child profile and deleting your account. You can also contact us any time at support@whisperly.qzz.io and we will help. You have the right to complain to your local data protection authority.
Children's privacy and parental consent
Whisperly is made for children, and it is designed to be run by a parent or guardian. We collect a child's information only after a parent provides it and consents, and we collect only what is needed to create the stories described above. We follow the U.S. Children's Online Privacy Protection Act (COPPA), the GDPR and its protections for children (GDPR-K), and the UK Age Appropriate Design Code. We do not require a child to share more than is reasonably necessary, we do not profile children for advertising, and we keep settings private by default. A parent can review, change, or delete their child's information at any time, and can withdraw consent, which stops further collection.
Where data is stored and how it is secured
Data is stored with our providers above and transmitted over encrypted connections (HTTPS/TLS). Access is restricted, and row-level security limits each account to its own profiles and history.
If something goes wrong (data breach)
We take security seriously. If a breach affects your personal data, we will act promptly to contain it, and we will notify the relevant authorities and affected users without undue delay, in line with applicable law (including the GDPR 72-hour expectation where it applies).
Representatives and EU/UK enquiries
If you are in the EU or UK and have a question or request about your data rights under the GDPR or UK GDPR, contact us at support@whisperly.qzz.io and we will respond.
Changes to this policy
We may update this policy. Material changes are reflected by the effective date and version number above, and we will let you know when the change is significant.
Contact
SleepyLama Creations (maker of Whisperly) — support@whisperly.qzz.io