Privacy Policy
1. Who we are
This policy applies to Story Nest, maintained by Handstar. Effective date: 2026-09-17. Contact handstar.support@gmail.com for privacy questions.
2. Data stored on your device
The app stores saved stories, titles and story text, favorites, playback progress, deletion records, and the cached daily feed with short and long versions in app storage on this device. These data are not synchronized automatically. Only when you intentionally connect Google Drive and start a backup are saved stories, playback progress, and the language setting uploaded to Google Drive’s app-specific data folder. Device text-to-speech does not upload audio.
3. Daily stories and our backend
The app has no Story Nest account or automatic cloud synchronization. It connects over HTTPS to `https://api.hankhandstar.com` to retrieve the same shared daily stories and their two length options for everyone. The backend prepares them the previous day; favorites and playback progress remain on this device unless you intentionally use Google Drive backup.
4. AI story generation and third-party services
The app does not accept user prompts for story generation. The backend uses a scheduled, fixed bedtime-story prompt and sends it to Google Gemini to prepare the shared daily stories and their short and long versions before they appear in the app. The stories are checked before being made available.
5. Device text-to-speech
Story narration uses the operating system text-to-speech engine. Story Nest does not record through the microphone or store audio files. Apple or Android speech engines may process narration text under their own policies; connectivity and voice quality depend on the device and installed voice package.
6. Network, ads, and operational records
The app connects to `https://api.hankhandstar.com` for the daily feed. The backend provider may process IP address, request time, and error information for security and troubleshooting. The app also displays banner ads provided by Google Mobile Ads. That service may process device identifiers, IP address, ad interactions, and diagnostics under its own policies to deliver and measure ads. Ad requests in Child Mode use child age-restricted treatment; in Parent Mode, an adult handles applicable advertising privacy choices. If “Ad privacy options” appears in Settings while in Parent Mode, you can use it to review or change choices provided by UMP. Story Nest does not use this information to create an account or conduct its own cross-site tracking.
7. Retention and deletion
Delete individual saved stories from the Story Box, or remove the app and its data in device settings to clear local stories, favorites, progress, and cache. If you created Google Drive backups, disconnecting or removing the app does not automatically delete existing cloud versions; manage those separately through the backup feature or your Google account’s app-data controls. The daily story service does not maintain personal accounts or personal favorites. Provider records retained for legal requirements or security audits are handled under the provider retention policy.
8. Children’s privacy
Story Nest is a bedtime-story app for parents and children to use together; children can also operate its story features directly. Each launch starts in Child Mode. A user can enter a date of birth in User Mode settings to select the advertising treatment for the current session. Story Nest checks the date on this device only and does not store or send it. The selected mode resets to Child Mode when the app is restarted. Please confirm Child Mode is active when a child uses the app. The app does not require a child account or ask users for story ideas, photos, or recordings. However, third parties such as Google Mobile Ads may process device and advertising data as described in Section 6. Parents should handle advertising privacy choices and Google Drive backups, and review AI-generated stories with their children.
9. Permissions and OAuth
The app requires network access only; it does not request microphone, location, contacts, photos, or notification permissions. It has no general Google sign-in or Story Nest account. If you intentionally use backup, Google OAuth requests only the `drive.appdata` scope so Story Nest can create, read, and delete its own backups in Google Drive’s app-specific data folder. It does not read your name, email, or other Drive files. Disconnecting removes the local authorization credential but does not automatically delete existing cloud backups.
10. Changes and contact
We will update the effective date if our data practices or features materially change. Privacy: https://handstar-lab.web.app/en/storyteller/privacy. Support: https://handstar-lab.web.app/en/storyteller/support. Email: handstar.support@gmail.com.