Last updated: 19 September 2026
Short parent summary
- The ToyPal account is for an adult. Children do not create accounts or make purchases.
- An adult may provide limited information about a child to personalise requested stories or other family content.
- The current App uses service providers for login, cloud delivery, payments, notifications, diagnostics and app measurement. These providers are described below.
- ToyPal does not sell child-profile, story or voice information or use it for behavioural advertising.
- The public community/social feature is not part of the current supported service.
- Voice cloning is not active as a supported production feature.
- An authorised adult can ask to access, correct or delete applicable family information.
- Contact support@toypal.ai.
1. Who is responsible
Heartoid Ltd, trading as ToyPal, is the controller for personal information processed through the ToyPal App and our own service.
Company number: 14102802
Registered office: 338A Regents Park Road, Office 3 and 4, London, England, N3 2LN
Privacy contact: support@toypal.ai
Apple, Google and other providers may also act as independent controllers for parts of their own services, such as an app-store account, payment, social login or advertising/attribution choice. Their own notices explain those activities.
2. Adult-managed family service
The App is intended to be managed by an adult. The adult creates the account, chooses content, manages purchases and permissions, and supplies any child-profile information. A child must not create an account or make privacy and purchase decisions.
When an adult supplies information about a child, the adult confirms that they are the parent or legal guardian or have appropriate authority from the person with parental responsibility.
3. Information processed and why
- Adult account and login: name, email, account identifier, encrypted authentication state, recovery and optional Apple, Google or Facebook login information, used to create, authenticate, protect and recover the adult account.
- Child profile supplied by the adult: first or display name, age or age band, pronouns or gender and parent-selected preferences, used to personalise and age-calibrate content requested by the adult.
- Stories and family content: story choices, prompts, text, narration, playlists, phrases, favourites, recordings or images when the adult activates those features, used to create, store, deliver and manage requested family content.
- Purchases: store product and transaction identifiers, subscription or credit state and refund or restoration status, used to validate purchases, restore access, prevent duplicate value and provide support.
- Device and app operation: app and operating-system version, device type, language, network status, notification token, audio or playback state and technical request identifiers, used to operate the App, deliver requested notifications, maintain compatibility and protect the service.
- Diagnostics and measurement: crash reports, performance data, app interactions, install or referral and attribution information, and identifiers made available by the platform or SDK, used to diagnose failures, understand App performance and measure adult acquisition and campaigns.
- Support and rights requests: support messages, account references, complaint details and access or deletion communications, used to answer requests, resolve problems and meet legal obligations.
Do not enter a child's surname, address, school, contact details, precise location, medical or SEND information, photographs or other sensitive information into an ordinary story field unless a specific feature clearly requests it and explains why it is needed.
4. Our legal reasons for processing
Depending on the activity, we rely on:
- performance of the adult's contract to create the account, provide content and deliver paid features;
- legitimate interests in operating, securing and improving a parent-managed family service, after considering children's rights and expectations;
- legal obligations for accounting, consumer protection, safety, rights handling and regulatory compliance; and
- consent where the law requires a separate choice, including certain device permissions, optional marketing or tracking or future higher-risk features.
Where consent is required, it can be withdrawn without affecting processing already carried out lawfully. Withdrawing a required permission may stop the related optional feature from working.
5. Personalised stories and automated providers
When an adult requests generated content, the App or ToyPal backend may send the minimum information needed for that request to an approved text, image or speech provider. Depending on the feature in the released App, this may include the child first or display name, age or age band, pronoun, selected story choices, story text, narration instructions or an adult-provided recording.
The current operational App contains integrations capable of using OpenAI for text, image and speech generation; Microsoft Azure or Google Cloud for text-to-speech; and Stability AI for image generation. A provider receives data only when the adult uses the related feature or ToyPal performs the requested generation.
Account email, payment-card details and unrelated support history should not form part of a story-generation request. We do not use solely automated decisions about a child that have legal or similarly significant effects.
6. Recordings, camera and photos
The released App may request microphone access for an adult-initiated recording feature and camera or photo access where the adult chooses an image or profile-photo feature. The App should request the operating-system permission when the feature is used. You can change permissions in device settings.
Do not record another person or submit their photograph without authority. Voice cloning is not an active supported production feature. If it is introduced, ToyPal will provide a separate explanation and consent or deletion controls before activation.
7. App providers and SDKs
The current operational App includes the following provider categories. The exact data available to a provider depends on platform settings, consent, SDK configuration and the feature used.
- Google Firebase: authentication, analytics, crash reporting, messaging or notification tokens and dynamic links.
- Apple and Google: app distribution, social sign-in where selected, in-app purchase and subscription processing.
- Facebook or Meta: optional Facebook login. Automatic Facebook app-event logging and Android advertiser-ID collection are configured off in the current Android source.
- AppsFlyer, Adjust and AppMetrica or Yandex: app install, referral, campaign attribution, performance and app-event measurement. These services may process app-instance, device, network, install or referral and event information. Android advertising-ID permissions are removed in the current Android manifest, and Adjust is configured for COPPA and Google Play Kids compliance. iOS may display Apple's App Tracking Transparency prompt; denying it prevents access to Apple's advertising identifier but does not stop essential or non-advertising device and app measurement permitted by the platform.
- OpenAI, Microsoft Azure, Google Cloud and Stability AI: text, image or speech generation when the adult uses the related content feature.
- ToyPal hosting and delivery providers: account, content, database, storage, security and API delivery for the App.
We must keep App Store and Google Play privacy disclosures consistent with the providers and SDKs actually included in each released build. If an SDK is removed or a provider changes, this notice and the store disclosures must be updated.
8. Children, advertising and the community feature
ToyPal does not sell child-profile, story, recording or listening information. We do not use that information to build behavioural-advertising profiles or combine it with Shopify, Klaviyo, Meta, TikTok or website advertising profiles.
App measurement and attribution must relate to the adult-managed App and must not receive story text, child names, recordings or private media. The current Android build removes advertising-ID permissions. iOS tracking permission is controlled through Apple's prompt and device settings.
The public community or social feature is not part of the current supported service. There are no supported public child profiles, public feed or child-to-stranger chat. Historical or disabled community code does not change this position.
9. Notifications and local storage
The App may use a push token to send service or content notifications where permission is given. Local reminders and preferences may be stored on the device. Lock-screen or notification content should avoid unnecessary child names and private story details.
The App also stores information locally to keep you signed in, remember preferences, support playback and provide downloaded or cached content. Removing the App may remove some local data but does not by itself delete server-side account information.
10. Purchases
Apple or Google processes payment-card and app-store payment information. ToyPal receives limited product, transaction, entitlement, subscription and status information needed to validate or restore purchases, prevent duplicate value, manage refunds or revocations and provide support. ToyPal does not receive your full payment-card number from an app-store purchase.
11. International processing
Some providers process information outside the United Kingdom. Where UK data-protection law requires safeguards, we rely on an applicable adequacy regulation, contractual safeguards such as the UK International Data Transfer Agreement or Addendum, or another lawful transfer mechanism. Contact support@toypal.ai for information about applicable safeguards.
12. How long information is kept
We keep information only for as long as reasonably necessary for the purpose described, including:
- account and child-profile information while the adult account remains active and for the period required to complete a verified deletion request;
- family stories and media while needed to provide the requested library or until the adult deletes them, subject to technical backup expiry and lawful retention;
- purchase and transaction records for reconciliation, fraud prevention, tax, accounting, refunds and legal claims;
- security, diagnostic and attribution information for the period needed to investigate incidents, maintain the service and measure campaigns, subject to provider settings; and
- support, consent and rights-request records for the period needed to answer the request and demonstrate compliance.
Exact periods can differ by system and provider. A deletion request does not require us to delete a minimal record that must lawfully be kept, but we will not keep the underlying child content merely because a compliance receipt remains.
13. Your and your child's rights
An authorised adult may ask to access, correct, export, restrict, object to or delete applicable family information and may withdraw consent. These rights depend on the circumstances and are not absolute.
We verify identity and parental authority before disclosing or deleting child information. Use an available in-App control or email support@toypal.ai. Do not include unnecessary child information in the first email.
Account deletion may involve the ToyPal account database, child profiles, private content and media, authentication, notifications and relevant processors. We will not tell you deletion is complete until the applicable process has completed. Removing the App, signing out or changing a local flag is not the same as erasing the server account.
14. Security
We use measures intended to protect information, including encrypted network connections, access controls and separation between operational systems. No online service can guarantee absolute security. Please protect the adult account and contact support@toypal.ai if you suspect unauthorised access.
15. Website and marketing information are separate
Website orders, support forms, newsletters and website analytics are explained in the ToyPal Website Privacy Notice and Cookie Notice. We do not intentionally place child names, private stories, recordings or child-profile information into Shopify, Klaviyo, Meta, TikTok or website analytics.
16. Complaints and contact
Contact support@toypal.ai first. You may also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint/.
We update this notice when the released App, providers or data flow materially changes. We do not treat silence or continued use as consent where a fresh affirmative choice is required.
Heartoid Ltd, trading as ToyPal
Company number: 14102802
Registered office: 338A Regents Park Road, Office 3 and 4, London, England, N3 2LN
Email: support@toypal.ai
Email support@toypal.ai.