Privacy Policy

Last updated: Jun 06, 2026

Welcome to Story Of The Day! Your privacy is important to us. This Privacy Policy explains how we collect, use, protect, and share your information when you use our web and mobile applications.

Quick Summary: We collect only what's needed to provide personalized stories, quizzes, and app functionality. We don't sell your data. You have control over your information and can delete your account anytime.

Quick Overview

Here's what you should know at a glance:

What We Collect

Account Info Email, name, avatar from sign-in providers (Google, Apple, etc.)
Your Preferences Languages, topics, difficulty levels you select
Quiz & Story Activity Answers, scores, favorites, progress tracking
Device & App Info Device model, OS version, app version (for compatibility)
Usage Analytics Screen views, feature usage (aggregated & anonymized)
Crash Reports Error logs to fix bugs and improve stability
Ads Data (Optional) Advertising ID for personalized ads (with consent)
User Content Stories you create or save within the app

How We Use It

Your Rights

Contact: [email protected]

1. Who We Are (Data Controller Information)

Data Controller: umuts.dev (Umut Serifler)

Contact Email: [email protected]

Website: umuts.dev

Jurisdiction: European Union (EU) regulations apply where relevant

Story Of The Day is a platform providing personalized language learning through interactive stories and quizzes, available as both web and mobile applications.

EU Representative: For users in the European Union, if you need to contact a local representative regarding data protection matters, please email us at [email protected] and we will provide appropriate contact information as required under GDPR Article 27.

2. Information We Collect

We collect several types of information to provide and improve our services:

2.1 Information You Provide Directly

Data Type Examples Purpose
Account Identifiers Firebase UID, provider ID, internal user ID Authentication, session management, abuse prevention
Contact Information Email address, display name, profile picture Sign-in, account display, support communications
Profile Preferences Languages, topics, difficulty levels Personalized content recommendations
Content Interaction Favorite stories, quiz submissions, answers, scores Progress tracking, feature functionality
User-Generated Content Stories you create or save App functionality, content moderation

2.2 Information Collected Automatically

Data Type Source/Tool Purpose
Device Information device_info_plus (mobile) Device model, OS version, locale for compatibility & troubleshooting
Usage Analytics firebase_analytics Screen views, feature usage, session duration (aggregated)
Crash Reports firebase_crashlytics Stack traces, error messages for debugging
Advertising ID google_mobile_ads Serve personalized ads (mobile only, with consent)
Technical Logs Backend servers Request metadata (time, path, status) for security & reliability

2.3 Information from Third Parties

What We DON'T Collect: Passwords (federated login only), government IDs, sensitive categories (health, religion, political opinions, biometric data).

3. How We Use Your Information

We use your information for the following purposes:

Purpose Description
Provide & Maintain Service Create/manage account, deliver core features, ensure app functions correctly
Personalization Tailor stories, quizzes, and content based on your preferences and progress
Communication Send important updates, respond to support requests
Improvement & Analytics Understand usage patterns, gather feedback, optimize user experience
Security & Fraud Prevention Monitor for abuse, prevent unauthorized access, protect platform integrity
Advertising (Mobile) Display relevant ads to support free access (with appropriate consent)
Legal Compliance Respond to lawful requests, enforce terms of service

5. Information Sharing & Disclosure

We do NOT sell your personal information.

We share information only in these limited circumstances:

5.1 Service Providers

Third-party vendors who help operate our services (see Section 6 for details). These providers are contractually obligated to protect your data.

5.2 Legal Requirements

When required by law, court order, or government request; to enforce our terms; or to protect rights, property, and safety.

5.3 Business Transfers

If involved in a merger, acquisition, or asset sale, your information may be transferred (you'll be notified).

5.4 With Your Consent

Any other sharing will only occur with your explicit permission.

6. Third-Party Services & Processors

We use the following third-party services that may collect and process your information:

Service Purpose Data Processed Privacy Policy
Firebase Authentication User sign-in & identity management Email, name, provider IDs, auth tokens Firebase Privacy
Firebase Analytics Usage analytics (aggregated) Event names, timestamps, device info Firebase Privacy
Firebase Crashlytics Crash reporting & diagnostics Stack traces, device state, app version Firebase Privacy
Google AdMob Mobile advertising (if enabled) Advertising ID, device signals, context Google Ads Policy
Google Sign-In OAuth authentication Email, name, profile picture Google Privacy
device_info_plus Device capability detection (local) Model, OS version, locale Package Info
flutter_secure_storage Secure local storage (on-device only) Auth tokens (encrypted locally) Package Info

Note: Data processing locations vary by service (typically USA/global). Standard Contractual Clauses or equivalent safeguards apply where required by law.

7. Data Security

We take security seriously and implement industry-standard technical and organizational measures to protect your information:

7.1 Technical Measures

7.2 Organizational Measures

7.3 Data Breach Notification (GDPR Art. 33-34)

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  1. Notify Supervisory Authority: Report the breach to the relevant data protection authority within 72 hours of becoming aware (GDPR Art. 33)
  2. Notify Affected Users: If the breach poses a high risk, we will notify you directly without undue delay (GDPR Art. 34), including:
    • Nature of the breach and categories of data affected
    • Likely consequences of the breach
    • Measures taken or proposed to address the breach
    • Contact information for further inquiries
  3. Maintain Records: Document all data breaches (regardless of notification requirement) as required by GDPR Art. 33(5)

Important: No system is 100% secure. If you suspect unauthorized access to your account, please contact us immediately at [email protected].

Responsible Security Disclosure

If you discover a security vulnerability, please report it responsibly:

8. Data Retention

We retain your information only as long as necessary:

Data Type Retention Period
Active Account Data While your account exists and you use the service
Deleted Account Data Removed or anonymized within 30-90 days of deletion request
Quiz & Progress Data Retained during account lifetime; may be aggregated/anonymized after deletion
Analytics & Logs Typically 30-90 days (unless needed for investigations or legal requirements)
Backups Purged on next rotation cycle after deletion event
Legal/Accounting Records As required by applicable law (varies by jurisdiction)

9. International Transfers (GDPR Chapter V Compliance)

Story Of The Day operates globally. Your data may be processed in countries outside your residence, including the United States and other regions where our service providers operate.

9.1 Transfers from EU/EEA to Third Countries

When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that do not have an adequacy decision from the European Commission, we implement appropriate safeguards as required by GDPR Article 44-50:

Safeguard Mechanism Description GDPR Reference
Standard Contractual Clauses (SCCs) We use EU Commission-approved Standard Contractual Clauses (2021 version) with our data processors and service providers to ensure adequate data protection. GDPR Art. 46(2)(c)
Adequacy Decisions Where available, we rely on European Commission adequacy decisions for specific countries (e.g., UK under the UK GDPR transition, Switzerland, Japan). GDPR Art. 45
Processor Agreements All third-party processors (Firebase, Google Cloud, AdMob) have Data Processing Agreements (DPAs) in place with appropriate safeguards. GDPR Art. 28
Supplementary Measures In accordance with Schrems II ruling, we assess transfer risks and implement technical measures (encryption, access controls, data minimization) where necessary. CJEU C-311/18

9.2 Countries of Processing

Your data may be processed in the following regions:

9.3 Your Rights Regarding International Transfers

You have the right to:

For questions about international transfers or to request documentation, contact us at [email protected].

Important: We regularly review our international data transfers to ensure compliance with evolving EU data protection requirements, including guidance from the European Data Protection Board (EDPB).

10. Your Rights & Choices

Depending on your location, you may have the following rights. EU/EEA, UK, and Swiss residents have comprehensive rights under GDPR and equivalent laws:

10.1 Right of Access (GDPR Art. 15)

Request confirmation of whether we process your personal data and obtain a copy of your data, including:

Response time: Within 1 month (may be extended by 2 months for complex requests, with notification).

10.2 Right to Rectification (GDPR Art. 16)

Correct inaccurate or incomplete personal information. You can also update most data directly in app settings.

10.3 Right to Erasure / "Right to be Forgotten" (GDPR Art. 17)

Request deletion of your account and associated personal data when:

Note: Certain data may be retained if required for legal obligations, exercising legal claims, or public interest.

10.4 Right to Restriction of Processing (GDPR Art. 18)

Request that we limit how we process your data when:

10.5 Right to Object (GDPR Art. 21)

Object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

10.6 Right to Data Portability (GDPR Art. 20)

Receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON, CSV) and transmit it to another controller where:

10.7 Right to Withdraw Consent (GDPR Art. 7(3))

For consent-based processing (ads, non-essential analytics), you can withdraw consent anytime without affecting the lawfulness of processing before withdrawal.

10.8 Right to Lodge a Complaint (GDPR Art. 77)

File a complaint with your local data protection supervisory authority (DPA/ICO). EU residents can contact their national authority:

10.9 Automated Decision-Making & Profiling (GDPR Art. 22)

We do not currently use automated decision-making or profiling that produces legal or similarly significant effects. If this changes, we will:

10.10 Advertising & Analytics Controls

How to Exercise Your Rights

  1. Email [email protected] with your request
  2. Specify which right(s) you're invoking (access, deletion, portability, etc.)
  3. Provide sufficient account details to verify your identity (we may request additional verification)
  4. We'll respond within 1 month (GDPR requirement; may extend by 2 months for complex requests with notification)
  5. All requests are handled free of charge unless manifestly unfounded or excessive

EU Users: These rights are guaranteed under GDPR. We will not discriminate against you for exercising these rights. If you're unsatisfied with our response, you have the right to lodge a complaint with your supervisory authority.

11. Cookies & Tracking Technologies (ePrivacy Directive Compliance)

11.1 Web Application

The backend does not set marketing or tracking cookies. Session/authentication is handled via Firebase tokens and standard HTTP headers. Essential cookies (if any) are used solely for functionality and do not require consent under the ePrivacy Directive.

Essential Cookies Only: We only use strictly necessary cookies required for core functionality (authentication, security). These do not require consent under EU ePrivacy Directive Article 5(3) and GDPR Recital 30.

11.2 Mobile Application

We use the following SDKs and technologies (mobile app identifiers are similar to cookies for tracking purposes):

Technology Type Consent Required (EU)? Purpose
Firebase Authentication Essential No (strictly necessary) User authentication and session management
Firebase Analytics Performance/Analytics Yes (unless anonymized) Screen views, feature usage, session duration
Firebase Crashlytics Functional Debatable (legitimate interest possible) Crash reports and error diagnostics
Google AdMob Advertising Yes (behavioral advertising) Personalized advertisements
flutter_secure_storage Essential (local only) No (on-device storage) Encrypted token storage

11.3 Consent Management (EU ePrivacy & GDPR Compliance)

For users in the EU/EEA, we implement consent mechanisms compliant with:

Consent Mechanisms:

  1. First Launch: Mobile app requests consent for non-essential tracking (analytics, personalized ads) before SDK initialization
  2. Granular Choices: Users can accept/reject different categories (analytics, advertising) separately
  3. Easy Withdrawal: Consent can be withdrawn anytime via:
    • Device settings (iOS/Android privacy controls)
    • Contacting us at [email protected]
    • In-app privacy settings (future implementation)
  4. No Cookie Walls: We do not deny service if you refuse non-essential cookies/tracking

11.4 Third-Party Tracking

We do not allow third-party advertising networks to place tracking cookies on our web application. Mobile SDKs (Firebase, AdMob) are configured to respect user consent preferences.

EU Users: Under the ePrivacy Directive and GDPR, you have the right to refuse cookies and tracking technologies. We respect "Do Not Track" signals and consent preferences. Essential functionality will remain available regardless of consent choices.

12. Children's Privacy

Story Of The Day is not directed to children under the age requiring parental consent (typically 13-16 depending on jurisdiction).

We do not knowingly collect personal information from children under the applicable age. If we discover that a child has provided personal data without parental consent, we will delete it immediately.

Parents/Guardians: If you believe your child has provided us with personal information, please contact us at [email protected] so we can take necessary action.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

Notification: We'll notify you of material changes by:

Continued use of Story Of The Day after changes indicates acceptance of the updated policy.

Version History

Date Version Changes
13 Oct 2025 2.1 Enhanced EU/GDPR Compliance: Added detailed legal bases (Art. 6), comprehensive user rights (Art. 15-22), international transfer safeguards (SCCs, Art. 44-50), data breach notification procedures (Art. 33-34), ePrivacy Directive compliance, DPA contact information, automated decision-making disclosures
13 Oct 2025 2.0 Unified web & mobile privacy policies; added comprehensive mobile SDK disclosures; enhanced user-friendly formatting
13 Oct 2025 1.2 Added Third-Party Processors section
13 Oct 2025 1.1 Added mobile analytics, crash reporting, advertising details
13 Oct 2025 1.0 Initial detailed privacy policy

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data:

Email: [email protected]

Website: umuts.dev

Important: Do not include sensitive information (passwords, payment details) in initial correspondence. We'll provide secure channels if needed.

If you're in the EEA or UK and wish to lodge a complaint, you can contact your local supervisory authority.