Moonfox
Privacy Policy
Last updated 14 September 2026
Moonfox makes a new bedtime story each night. A parent or guardian sets it up and controls it, and a child listens, looks and answers the story. This policy explains exactly what Moonfox keeps on your iPhone, what leaves it, who receives it and why, and how to delete it.
No account
Moonfox has no sign-up, login or password, and never asks for your email address, phone number, contacts or location. The first time it runs, the app creates a random identifier and keeps it in the device keychain. It isn't derived from your hardware or advertising identifier. Our server uses it to apply story limits, check whether you have a subscription, and stop abuse.
What you enter, and where it stays
A parent enters a child profile:
- an optional first name or nickname;
- an age, which the app turns into an age group (3–5, 6–8 or 9–12);
- interests, such as “foxes” or “space”;
- how the hero looks (hair, skin tone, eye colour, pyjama colour, and optionally glasses, freckles, hearing aids or a wheelchair);
- the chosen story friends;
- story preferences, and optionally a favourite toy and colour;
- optionally, the bedtime routine steps and bedtime.
The profile, the story library and every picture and voice clip are stored on your iPhone. Deleting the app, or using Delete everything in Parent settings, removes them from the device.
What is sent to make a story
Writing, illustrating and narrating a story needs AI models, which run on servers. When Moonfox makes a story, it sends the following to our server, which forwards it to wiro.ai:
- the child's name (or nothing, in private mode);
- the age group, interests, hero appearance and friends;
- story preferences, and the season and map stop the story belongs to;
- the random identifier described above.
wiro.ai runs the models that do the work: models made by OpenAI write the story, run the safety checks and draw the pictures, and a model made by Google records the narration.
- Private mode: the name is never sent, and the narrator says “little dreamer” instead.
- Something from today (optional): if you add one sentence about the child's day, it is sent with that night's story. It goes through a safety check first and is dropped if the check flags it.
- Bedtime Quest (optional): the routine steps you choose (for example “pyjamas, teeth”) are sent once, to write and record the friend's lines.
We do not use your information to train AI models, and we do not send photos of your child, their voice, contact details or location to make a story.
Photos of a toy, pet or drawing (optional)
If you choose to turn a favourite toy, a pet or a drawing into a story friend, that one photo is sent through our server to wiro.ai. A safety check refuses any photo with a person in it, and an accepted photo is redrawn as an illustration. Our server passes the photo through without storing it; only the finished illustration is kept. The photo stays wherever you took it from.
The child's voice
When the child answers the story (“the glowing flowers!”), the words are recognised by Apple's speech recognition on the iPhone whenever the device supports that. On devices that don't, Apple's own speech service is used under Apple's privacy policy. The microphone is only on while its light is lit. No recording of the child's voice is sent to us or to any AI provider, and none is kept. Live spoken conversation with the story is switched off. If we ever offer it, it will stay off until the provider confirms zero-data-retention terms, and this policy will change first.
Family goodnights (optional)
If you invite a relative, Moonfox creates a private link with a label you choose (for example “Grandma”). The voice messages they record on that page are stored on our server so your app can download them. Invite links expire after 60 days. Recordings are deleted when you remove that person in Parent settings. Please only invite people who are happy for their recordings to be played to your child.
Reporting a story
If you report a story from the app, we receive the story's identifier, the scene, the reason you chose and any note you type, so that we can review it and improve the safety rules.
Where information is kept, and for how long
| What | Where | How long |
|---|---|---|
| Profiles, story library, pictures, narration | Your iPhone | Until you delete them or the app |
| Generated pictures and narration files, and friend illustrations | Our storage provider, Vercel (Frankfurt, EU). Files are addressed by random identifiers, so a story can finish if the connection drops and be re-downloaded | Until you ask us to delete them |
| A story being prepared ahead of bedtime (the request, including the profile details above, and its progress) | Our database provider, Upstash (Redis) | Deleted automatically after 14 days |
| Story counters and rate limits, keyed by the random identifier | Upstash | As long as they are needed to apply the free-story limit |
| Family goodnight recordings | Vercel (Frankfurt, EU) | Until you remove that person |
| Story reports | Upstash | 12 months |
Purchases
Subscriptions are sold by Apple. We use RevenueCat to confirm them: it receives the random identifier and Apple's purchase receipts, and is configured not to collect device or advertising identifiers. We never see your payment details. See RevenueCat's privacy policy.
Notifications
The optional bedtime reminder and the trial reminder are scheduled on your iPhone by the app itself. No push-notification token is sent to us.
What we never do
- No advertising, and no advertising identifier (IDFA): Moonfox never asks to track you.
- No third-party analytics, crash-reporting or tracking SDKs.
- No selling or sharing of personal information, and no profiling.
Children
Moonfox is operated by a parent or guardian for their child. We collect only what's needed to personalise a story, and settings, links and purchases sit behind a grown-ups-only check. If you believe we hold information about a child that should be removed, or you want the server copies of your stories and recordings deleted, email menan@titanix.dev from Parent settings → Support. Include the support code shown there so we can find the right files, and we will delete them.
Your rights
You can see, change or delete the profile at any time in Parent settings. Private mode leaves the name out, and you can turn off the microphone, the Bedtime Quest, the reminder and family goodnights. You can also ask us to access or delete the server copies described above. Depending on where you live (for example the EU, UK or California) you may have further rights, and we will honour them.
Changes
If this policy changes, we will update it here and mention it in the app before the change affects you.