Mukashi Stories — Privacy Policy

Effective date: May 4, 2026

This policy explains what data Mukashi Stories collects, why, and the choices you have. Mukashi Stories is a reading app made for children, so this policy is written in plain English on purpose — parents and guardians should be able to read it in a few minutes.


1. Who we are

Mukashi Stories is an iOS app for reading bilingual children's folk tales — a side-by-side reader where each line shows the source language and the reader's native language together. It is developed and operated by Abdullah Al Hadi ("we", "us"). For the purposes of the EU / UK / EEA General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA), Abdullah Al Hadi is the data controller for personal data collected through the Mukashi Stories app. For any privacy questions, contact us at mukashi.dev@gmail.com.

This policy covers the Mukashi Stories iOS app (also published for iPadOS, macOS, and visionOS).


2. Data we collect

Stays only on your device — never sent anywhere

Everything below is stored locally on your device using Apple's SwiftData framework. If you have iCloud Backup enabled, Apple includes this data in your encrypted iCloud backup — that backup is between you and Apple; we have no access to it.

A parent or guardian can clear any of this at any time from Parents → Reset Reading Progress / Clear Saved Words / Reset Onboarding. Uninstalling the app removes all of it.

Sent to Firebase (Google)

We use two Firebase services from Google to improve the app: Analytics and Crashlytics. Both are configured for the strictest privacy settings appropriate for a children's app — no advertising identifiers used for personalization, no cross-app tracking, no ads.

Firebase Analytics collects:

We do NOT request App Tracking Transparency permission. Ad personalization, ad-related data storage, and ad-user-data sharing are explicitly disabled in the app's Info.plist (GOOGLE_ANALYTICS_DEFAULT_ALLOW_AD_PERSONALIZATION_SIGNALS=false, GOOGLE_ANALYTICS_DEFAULT_ALLOW_AD_STORAGE=false, GOOGLE_ANALYTICS_DEFAULT_ALLOW_AD_USER_DATA=false). Your child's IDFA is never read.

We never call setUserID(). There is no account, no login, and no persistent identity tied to your child across devices.

What we do NOT send: the contents of any story, full sentences from the reader, translations the child reads, search queries, photo library content, microphone input, contact info, payment info, location, or any name or personal identifier you or your child enters anywhere. The app does not have a microphone, camera, or photo library permission at all.

In-app purchases

Mukashi Stories offers an optional Mukashi Premium subscription and a one-time lifetime unlock through Apple's standard In-App Purchase system. We use Apple's StoreKit 2 framework to handle the entire purchase flow.

Firebase Crashlytics collects data only when the app crashes or reports a non-fatal error:


3. Permissions the app asks for

The app does not request access to the camera, microphone, photo library, contacts, location, or motion data.


4. How we use this data

We do not sell your or your child's personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined under the California Consumer Privacy Act). We do not share data with advertisers, and we do not build profiles across other apps.


5. Children's privacy (COPPA)

Mukashi Stories is directed to children, and we treat all users as if they were under 13. This affects everything in this policy:


6. Third parties

The only third-party service the app communicates with is Firebase, operated by Google LLC. Google processes Analytics and Crashlytics data as our service provider, under the Firebase Data Processing and Security Terms. Google's own privacy practices are covered by the Google Privacy Policy.

Google primarily processes this data on servers located in the United States. For users in the EEA, UK, or Switzerland, international transfers rely on Google's Data Processing and Security Terms, which incorporate the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.

No other third-party analytics, advertising, or tracking SDK is bundled in the app.


7. How long we keep it


8. Your rights and choices


9. Security


10. Changes to this policy

If we change this policy, the new version will replace this page at https://hadicuet.github.io/mukashistories-legal/ and the "Effective date" at the top will be updated. Material changes (e.g. a new third-party service, a new category of data) will be called out in the app's release notes.


11. Contact us

Questions, requests, or complaints: mukashi.dev@gmail.com.