daily bedtime story
🌙 Daily Bedtime Story

Privacy policy

Written to be readable at 8pm, by someone who has already had a long day.

Last updated 26 August 2026

The short version

There is nothing to sign up for here, so there is no account, no password and no email list. Nobody is asked for their name, and children are never asked for anything at all. Two analytics tools count how the site is used — one of them also records a replay of how a page was scrolled and tapped. The only thing you can type on this whole site is an optional note at the end of a story, and it is stored with no name, no email and no IP address attached. Nothing is sold, and no advertising runs here.

Daily Bedtime Story is operated by Kids Games App, a sole proprietorship based in Israel. Throughout this page, we means Kids Games App. It is a small operation rather than a large company, so when this page promises something, there is a real person you can email about it at privacy@kidsgamesapp.com.

This policy covers the website dailybedtimestory.com and the podcast feed it publishes. The last section covers something separate: the private tool we use to upload episodes to our own YouTube channel. That section is there because Google requires it, and it is about our own Google account — not about you.

What we never collect

Taking these off the table first, because it is most of the answer:

  • No accounts and no sign-in. There is nowhere to register, so there is no username, password or profile.
  • No names, emails, birthdays or addresses. Nothing on the site asks for them.
  • No payments. The stories are free. No card details ever reach this site, because there is nothing to buy.
  • No newsletter or mailing list. There is no signup box.
  • No photos, no camera, no microphone, no location. The site never requests those permissions.
  • No advertising. No ad network, no sponsors, no tracking pixels from advertisers, no remarketing.
  • No selling or sharing. We do not sell, rent or trade information about visitors to anybody, and we do not share it with data brokers.

What happens when you open the site

Two analytics tools load in your browser. They are how we tell whether a story was read to the end or abandoned in the middle — which, for a small show with no other feedback loop, is the only signal there is.

Google Analytics 4

Counts pageviews and a small set of named events — a story being rated, a story being shared, feedback being sent, and an illustration failing to load. Along with each event, Google records the usual web basics: the page address, the site you arrived from, your device type, browser, screen size, language, and an approximate location worked out from your IP address. Google's own documentation states that Google Analytics 4 does not store IP addresses. Two labels are attached to every visit — client_type and app_platform — and today both are always the word "web"; they exist so this site's numbers can sit alongside our other site's numbers in the same report.

Advertising features are switched off in the code that loads Google Analytics here: Google Signals and ad personalisation are both explicitly disabled, so nothing measured on this site can be used to target advertising anywhere.

Google's handling of this data is described in the Google Privacy Policy (http://www.google.com/policies/privacy) and in How Google uses information from sites that use its services.

PostHog — including session replay

PostHog receives the same events, and it also does something most policies bury in a long sentence, so here it is in a short one: PostHog records a replay of your visit.

A replay is a reconstruction of the page — what appeared on screen, where you scrolled, where you tapped, when things moved. It lets us watch back an anonymous session and see that, say, everyone stops scrolling at the same picture. To be precise about what it is and is not:

  • It is not a video of your screen, and it cannot see other tabs, other apps, your camera or your microphone.
  • It only covers this website. It stops when you leave.
  • Text typed into form fields is masked before the recording leaves your browser, so the replay does not capture what you type as you type it.
  • It also records how long images and pages took to load, so we can tell "the art is broken" apart from "the art was slow on a train".
  • Because nobody signs in here, PostHog is never told who you are and does not build a person profile — visits are stored as anonymous sessions.
  • PostHog does receive your IP address as part of the connection and uses it to estimate a country.

PostHog is a third-party product analytics service; the data is processed on its US cloud. See the PostHog privacy policy.

If you would rather not be measured at all: both tools are ordinary third-party scripts, and any browser content blocker, or a browser with tracking protection turned on, stops them loading. Nothing on this site breaks when they are blocked — the stories play exactly the same.

When analytics do not run at all

Before either tool loads, the page checks whether the visit looks like ours rather than a real reader's. If the site is being viewed from a local development address, a private home-network address, an automated browser, or a browser whose timezone is Asia/Jerusalem, both tools are skipped entirely — no scripts are fetched, no cookies are set, and nothing is sent anywhere. That last rule means visitors in Israel are not measured either. That is deliberate: we are based in Israel, and our own testing was outnumbering the real readers.

The feedback box at the end of a story

When a story finishes, a small card asks how it was. Tapping a star sends the rating. If the rating is low, the card offers a few tick-boxes ("too long", "the art", "the voice"…) and an optional free-text note. That note is the only place on the entire site where anything can be typed.

Here is exactly what is stored when you use it, and nothing else is:

A one-time IDA random identifier generated in your browser for that single rating. It is not stored on your device, is not reused, and cannot be linked to any other visit — its only job is to let the note you type attach to the star you already tapped.
Which storyThe episode's address, e.g. the story's slug.
The ratingA number from 1 to 5.
The tick-boxesWhich of the fixed options you selected, if any.
Your noteThe free text you typed, up to 500 characters. Stored exactly as written.
Page languageThe language the page was displayed in.
The timeWhen it was sent.

No name, no email address, no IP address and no device identifier is stored with feedback. We checked this in the code rather than assuming it: the server that receives it saves those seven things and nothing more.

One honest warning

Because feedback is stored with nothing that identifies you, we usually cannot find it again later to delete it on request. So please don't type a name, an email address, a phone number or anything about your child into that box. If you want to tell us something personal, email us instead — then we know who you are and can delete it whenever you ask.

Cookies and things stored in your browser

There is no cookie banner on this site, so it is only fair to be explicit about what is set:

  • Google Analytics and PostHog each store an anonymous identifier in your browser so that a single visit is not counted as several. These are set by their scripts, not by us, and are removed if you clear your browser data.
  • A short list of stories you have already rated, kept on your device only, so the rating card does not ask twice about the same story. It is never sent anywhere.
  • Two small "already shown you this" flags — one for the scroll hint on your first story, one for the "add to home screen" nudge if you dismiss it. Also device-only, also never sent anywhere.

No advertising cookies are set, and nothing here is used to follow you to other websites.

Other companies your browser talks to

Loading a page here means your browser fetches things from a handful of other places:

  • Amazon CloudFront and Amazon S3 (Amazon Web Services) host and deliver the site. We have not switched on access logging on the delivery network, so no server log of your visit is created or kept on our side. AWS operates its own infrastructure and may process requests as its own operator.
  • Google Fonts serves two typefaces. Fetching a font tells Google's font servers your IP address and browser.
  • Google Tag Manager's script host delivers the Google Analytics library.
  • PostHog's asset host delivers the PostHog library.
  • images.kidsgamesapp.com, our own image delivery network, serves some illustrations.

The podcast

The same episodes are published as a podcast at /podcast.xml, and through Apple Podcasts and Spotify. Two things follow from that.

When your podcast app downloads an episode, it fetches the audio file from the same delivery network as the website. We receive no download logs, and there is no tracking prefix, no dynamic ad insertion and no listener beacon in the feed — it is a plain RSS file pointing at plain audio files.

If you listen through Apple Podcasts or Spotify instead, you are inside their apps and their privacy policies apply, not this one. They give us aggregate listener charts — counts by country and by episode — and never individual listener identities.

Children

This site is made for young children and written to be opened by a grown-up. That shapes what it does and, more importantly, what it does not do.

Nothing here asks a child for anything. No name, no age, no birthday, no photo, no voice recording, no location. There is no chat, no comments, no profile, no messaging and no upload anywhere on the site. The one text box that exists is the optional feedback note described above, and it is meant for the adult in the room.

No profiles are built and no advertising is run. Nobody signs in, so the analytics never create a person record; visits are counted as anonymous events. Advertising features are turned off, and no information from this site is sold, shared with data brokers, or used to target ads anywhere.

What is collected is the ordinary web analytics described further up — including the session replay, which is worth naming twice because it is the thing a parent would most want to know about. It records how a page was scrolled and tapped; it does not record who was doing the scrolling.

About COPPA and GDPR-K

You will not find a compliance badge here, because we are not going to claim a certification we do not have. What we can tell you is the honest position. Kids Games App is a sole proprietorship, not an organisation with a legal department, and we have deliberately kept this site free of the things those rules are largely written about: there are no accounts, no advertising, no behavioural targeting, no data sales, and no personal information asked of a child anywhere on the site.

We do not knowingly collect personal information from a child. If we ever learn that we have, we will delete it. And if you are a parent, a guardian, a teacher or a regulator and you think something on this site falls short of what a children's site should do, write to privacy@kidsgamesapp.com and tell us. A real person reads that inbox, and we would rather fix it than argue about it.

How long anything is kept

  • Feedback is kept for as long as the show runs. It is read, acted on, and it is the closest thing this project has to a suggestion box.
  • Analytics is kept by Google and PostHog under their own retention settings and then deleted by them. We do not hold a separate copy.
  • Browser storage (the flags listed above) stays on your device until you clear your browser data.
  • Server logs — there are none on our side, because access logging on the delivery network is switched off.

What you can ask us for

Depending on where you live you may have rights to see, correct, delete or object to the use of information about you — that includes the GDPR in the EU and UK, and similar laws elsewhere. We will honour any of them that we are able to.

The practical catch, which most policies do not admit: because nothing here is tied to a name, a login or an email address, we usually have no way to find "your" data in order to hand it over. That is a consequence of collecting so little, and it is mostly good news. What we can actually do:

  • Delete a piece of feedback — tell us roughly which story and when, and we will find it and delete it.
  • Answer a specific question about what is collected, answered by whoever wrote the code and can go and look.
  • Stop measuring you — block the two scripts in your browser and nothing is sent at all.
  • Take something down if you believe it should not be there.

For the analytics data itself, Google and PostHog are the ones holding it, and their privacy policies (linked above) describe how to approach them directly.

If you are in the EU or the UK, you also have the right to complain to your national data protection authority. We would appreciate an email first — we can usually fix things faster than a regulator can.

Daily Bedtime Story Publisher and YouTube API Services

This section is not about you

It describes a private command-line tool that runs on the operator's own computer and uploads each day's episode to our own YouTube channel. It has exactly one user — the person who operates Kids Games App — it is not distributed to anyone, and it never touches data about any visitor to this website. Google requires that it be documented here, so here it is.

Episodes of Daily Bedtime Story are also published to our own YouTube channel, @dailybedtimestoryapp. We upload them using a tool we wrote called the Daily Bedtime Story Publisher.

The Daily Bedtime Story Publisher uses YouTube API Services. By using it we agree to the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy, at http://www.google.com/policies/privacy.

What Google user data it accesses

Authorisation happens through Google's standard OAuth 2.0 consent screen, signed in as the operator's own Google account, and the tool requests exactly two permissions:

  • https://www.googleapis.com/auth/youtube.upload — to upload a video to our own channel.
  • https://www.googleapis.com/auth/youtube.readonly — to read back our own channel, and the videos the tool itself uploaded, so that a re-run cannot publish the same episode twice.

It calls five YouTube Data API methods and no others: videos.insert (the upload), thumbnails.set, videos.list (to confirm one of its own earlier uploads still exists), channels.list (to confirm which channel the credential belongs to) and videos.delete (only ever used to remove its own test uploads).

It does not search YouTube, does not read or write comments, does not read analytics or subscriber data, and never accesses information belonging to any other user, channel or viewer. There is no other user whose data it could access: it is a command-line program on one laptop with one account signed in.

What it stores, and where

Everything it stores lives as ordinary files on the operator's own computer, outside any code repository or backup, with file permissions restricted to that user account:

  • An OAuth refresh token for the operator's own Google account, so the tool does not have to ask for a fresh sign-in every day.
  • The YouTube video IDs of uploads it made itself, each recorded against the episode it belongs to, kept solely so that a retried run does not upload a duplicate.
  • Partial-upload resume records, so an interrupted upload can continue instead of starting again. These are discarded when the upload finishes.

None of this is stored on this website, on any server, or in any database. No data obtained from the YouTube API is shared with any third party, is used for advertising, or is combined with the website analytics described earlier on this page.

How to revoke its access

Access to that Google account can be revoked at any time from Google's security settings at https://myaccount.google.com/permissions ("Third-party apps & services"). Revoking takes effect immediately: the stored refresh token stops working and the tool can no longer read anything or upload anything until it is authorised again.

How stored data is deleted

Deleting the tool's local token file removes the stored Google credential. Deleting its local upload record removes the stored video IDs. Both are plain files that can be deleted at any moment, and neither is retained anywhere else, so deleting them is final. Revoking access at the link above and deleting those two files leaves nothing stored at all.

The refresh token is kept until it is revoked or deleted. The record of the tool's own uploads is kept for as long as the channel exists, because remembering what has already been published is the entire point of it. Resume records last minutes.

Questions about anything this tool handles can be sent to privacy@kidsgamesapp.com.

Changes to this policy

If what the site collects changes, this page changes with it and the date at the top moves. There is no version history to dig through; the page you are reading is always the current one.

Getting in touch

Email privacy@kidsgamesapp.com. It reaches us directly — one inbox, a real person, no ticket system.

The data controller for this site is Kids Games App, a sole proprietorship based in Israel rather than a registered company. If you need the proprietor's full legal name and postal address — for a data-protection request, or for any other formal purpose — email privacy@kidsgamesapp.com and we will provide them.

Read the terms of service →

daily bedtime story A new bedtime story, every night.
Apple Podcasts Spotify
Privacy · Terms

© 2026 Daily Bedtime Story