Privacy at Tuck & Tales

Last reviewed: 17 August 2026

Tuck & Tales turns a parent's own voice into bedtime stories for their child. Here is exactly what that requires us to record, keep, and protect — in plain language, and every sentence below is something we can point to real, running code to back up, not just a promise.

What we record, and only there

The only audio we ever capture is your own voice, recorded live inside the app on two screens: when you first record your voice, and when you record a short greeting your child hears at the start of every story. We ask for microphone access only on those two screens — there is no background listening, and no microphone access anywhere else in the app.

There is no way to upload a recording of someone else

You cannot upload an audio file to create a voice — recording only happens live, in the app, while you are present. That means Tuck & Tales cannot be used to recreate the voice of someone who is absent, unable to consent, or who has passed away. We built it this way on purpose, not as a workaround.

We cannot read your enrollment recording — including while it's waiting

Your recording is encrypted in your own browser, before it ever leaves your device, under a key only our rendering hardware holds. Because that hardware is not always turned on, your recording sometimes waits before it is processed — and even then, we cannot open it. This is true by construction, not by policy: our client is shipped as source code, so it can be checked, not just taken on faith.

What we keep, and for how long

We keep a compact voice profile — not your original recording — used only to render your child's stories. Because part of that profile can currently be used to reconstruct audio close to your original recording, we treat and protect it exactly like a voice recording: encrypted, accessible only for rendering, deleted the moment you ask.

Today that means the same retention and deletion rules as your original recording, and protection from Cloudflare's own automatic storage encryption. It does not yet mean the same browser-side encryption your original recording gets before it ever reaches us — closing that gap is real, named, ongoing work, not a claim we are making today.

Rendering happens on hardware we own, with no door in from the internet

Stories are generated on studio hardware we run ourselves, not a shared cloud service. That hardware never accepts an incoming connection from the internet — it only ever reaches out, over an authenticated connection, to ask for work and report it back. There is nothing listening for a stranger to knock.

Your child is never recorded

There is no feature, screen, or setting anywhere in Tuck & Tales that records your child's voice — and no server endpoint exists that would accept it even if one tried. Your child does not sign in and does not have an account; the only information we hold about them is a first name and a small profile you create.

Deletion is one tap, and it's real

Deleting a voice, a child's profile, or your whole account starts a tracked job with a real, permanent, recorded outcome — not a flag that just hides something on a screen. Most of the time it finishes right away. If our rendering hardware happens to be offline at that moment, deletion finishes as soon as it is back online, and we tell you plainly that it is in progress rather than pretending it is already done. Closing your account fully purges everything within 30 days.

A voice you stop using expires on its own

If a voice profile goes unused for 12 months, we warn you a month before, then automatically delete it — including the consent record described above, since at that point the voice itself is gone too.

Every story carries an invisible watermark

Every voice Tuck & Tales generates carries an inaudible digital watermark from the underlying voice model, meant to help prove where a recording came from. We tested this ourselves and confirmed it survives our entire production pipeline — fades, loudness normalization, and the same MP3 encoding your stories actually ship as — intact and detectable. We have not tested whether it survives someone deliberately trying to strip it out.

No third-party trackers near your child's story

The screen where your child listens to a story loads no third-party analytics, advertising, or tracking code of any kind. Any usage data we collect about how the product is used is collected directly, by us — never handed to an ad network or analytics vendor.

Your data stays in the region you choose, with one honest caveat

We record which region your account belongs to, and your data is stored only in that region's storage bucket — enforced by the storage system itself, not only by application code that could have a bug. One thing worth knowing plainly: our storage provider, Cloudflare, is a US company, so even data stored in our EU bucket can in principle be reached by a US legal request. If that matters for your situation, ask us.

Your child's voice is out of scope, by design

Voiceprints are personal information, and children cannot meaningfully consent to giving one up. That is exactly why there is no path, anywhere in this product, for a child's voice to reach our servers — only a parent's, given knowingly and recorded live.


The longer, legal-facing version of this page is the data policy. It adds detail; it never adds a claim that contradicts this page.