|
Back to Home

Privacy Policy

Effective Date: September 6, 2026

The Santa AI ("the App") is operated by rafcolm_ Software, operated by Rafael J. Colón, based in Caguas, Puerto Rico, USA ("we," "us," or "our").

This Privacy Policy explains how we collect, use, and protect information when you and your child use the The Santa AI mobile application (the "App"), and when you visit our website at https://thesanta.ai (the "Website"). Because our App is designed for use by children, we take privacy especially seriously and comply with the Children's Online Privacy Protection Act (COPPA) and other applicable laws.

Sections 1 through 10 describe the App. Section 11 describes the Website, which is a separate service with different data practices — most importantly, the Website uses cookies and displays advertising.


1. Information We Collect

We collect only the minimum data necessary to provide the service. Below is a complete description of the information we collect and how it is handled.

1.1 Information Provided by Parents/Guardians

When you create an account and set up a child profile, we collect:

  • Parent email address — used for authentication and violation notifications
  • Child's first name — used to personalize Santa's conversations
  • Child's age and birthday — used for age-appropriate responses
  • Wish list items — used to personalize conversations
  • Interests — used to personalize conversations
  • Good deeds — used to personalize conversations
  • Language preference — English or Spanish

1.2 Information Generated Through Use

  • Conversation text — messages between your child and Santa (text only; no audio is stored)
  • Usage time — daily minutes spent chatting, used to enforce time limits
  • Subscription status — whether the account is Free or Premium
  • Content moderation records — flagged messages and violation categories, stored for parental review
  • Enforcement records — if an account is suspended (banned) from the App for violating our Terms, we store the ban status, its reason, and its expiry (for a temporary ban) to enforce the suspension and support any appeal
  • Theme preferences — light/dark mode selection
  • Coarse location — city-level device location is used on-device by the Santa Tracker feature to estimate Santa's arrival time. The same coarse location may also be sent with chat requests so Santa can reference your child's city when relevant. We do not store location as a profile field in our database, and we do not share it with third parties beyond the AI provider that generates Santa's reply.
  • Device identifier — a platform-provided device ID (identifierForVendor on iOS, ANDROID_ID on Android, or a locally generated UUID fallback when those are unavailable) is sent in an X-Device-Id request header and mirrored to a devices document in our database. This is used solely to enforce the daily time-limit cooldown across sign-outs so a child cannot reset their daily limit by creating a new account on the same device. It is not used for advertising, profiling, or cross-app tracking. On iOS, because that identifier resets when the app is deleted and reinstalled, we additionally use Apple's DeviceCheck framework for this same single purpose: the app requests a per-device token from Apple, and Apple stores two bits of data for the device — a flag indicating whether the free daily limit is currently in its cooldown — that persist across app reinstalls. This DeviceCheck data lives with Apple, is scoped to our developer account, contains no personal information, and is used only to stop the free daily-time limit from being reset by deleting and reinstalling the app — never for advertising, profiling, or tracking your child across apps.

1.3 Information We Do NOT Collect or Store

  • Audio recordings — your child's voice is recorded temporarily on the device, sent to our servers for transcription, and immediately discarded after transcription. We do not store any audio files. Santa's generated voice responses are streamed to the device and are also not stored on our servers.
  • Photos or videos — the Photo Booth feature uses the device camera so your child can take a picture with Santa. That picture is captured, decorated, and saved entirely on the device — it is never uploaded to our servers, never sent to any third party, and we operate no endpoint that could receive it. Keeping it (saving it to your photo library or sharing it) is always your choice, through your device's own controls. The App requests only add-to-library access, so it cannot read, browse, or import the photos already on your device. The camera is used only while the Photo Booth screen is open, and permission is requested at that moment — never at launch.
  • Contacts — the App does not access the address book
  • Browsing or search history — the App does not track browsing or search activity

1.4 Advertising Identifier

When the AdMob banner is shown to Free-tier users, Google's Mobile Ads SDK collects the device's advertising identifier (Google Advertising ID on Android, IDFA on iOS) for ad delivery and frequency capping. We tag every ad request as child-directed (COPPA), non-personalized, and rated G (General Audiences) — but the identifier is still collected by Google. We do not receive, store, or use this identifier ourselves, and we do not perform any behavioral profiling. Premium subscribers do not see ads and the SDK does not run for them.

1.5 App Store Campaign Attribution (iOS only)

On iOS, the App sends Apple an attribution token provided by Apple's own AdServices framework, and shares it with RevenueCat, solely to measure which App Store ad campaign led to an install or purchase. This token is not the IDFA: it is issued by Apple, is specific to this one install of this one app, expires, and identifies no person or device across apps. It requires no App Tracking Transparency prompt because it is not tracking — it is never combined with data from other companies, is never used to build a profile, and reveals nothing about your child. It exists only so we can tell whether an advertisement worked. There is no equivalent collection on Android.

1.6 Meta App Events (Advertising Measurement)

The App uses Meta's (Facebook) App Events SDK to measure the effectiveness of our app-install advertising campaigns on Facebook and Instagram. When the App is installed, an account is created, or a purchase is made, the SDK reports the corresponding event (and, for purchases, the amount and currency) to Meta. We run the SDK in a privacy-safe, child-directed configuration: advertising-identifier collection is disabled (no Google Advertising ID or IDFA is collected or sent to Meta), there is no App Tracking Transparency prompt, and no cross-app tracking or behavioral profiling is performed. On iOS, install and conversion measurement runs only through Apple's privacy-preserving SKAdNetwork / Aggregated Event Measurement. Meta receives the app event, basic technical metadata (such as app version, operating system, and the IP address of the request), and an anonymous, app-scoped identifier — never a persistent cross-app advertising identifier, and never your child's personal information.


2. How We Use Information

We use the information we collect to:

  • Provide the service — generate personalized Santa conversations using AI
  • Enforce safety — moderate all messages for inappropriate content using keyword filters and AI-based moderation
  • Manage accounts — authenticate users, manage subscriptions, enforce daily time limits
  • Notify parents — send email alerts when content moderation violations occur
  • Improve the service — diagnose errors and improve reliability (via crash reporting)

We do not use children's personal information for marketing, advertising profiling, or any purpose unrelated to the App's core functionality.


3. Detailed Data Handling by Type

The following table provides a detailed breakdown of every data type collected, how it is handled, whether it is stored, and who it is shared with:

Data Type What We Collect Purpose Stored Where Shared With
Email Address Parent's email from account signup Account authentication and violation notification emails Firebase/Firestore Firebase Auth, Sentry (error tracking), Zoho (notification emails)
Child Profile First name, age, birthday, interests, wish list, good deeds Personalize Santa's conversations to be age-appropriate and relevant Firestore Never shared with any third party
Conversation Text Text messages between your child and Santa Provide the conversation service and moderate content for safety Firestore Anthropic (Claude — for AI response generation and the moderation classifier)
Audio (Voice Input) Child's voice recording during conversations Transcribed to text using speech-to-text, then immediately and permanently deleted Never stored — discarded after real-time transcription Deepgram (real-time speech-to-text only; audio is not retained beyond transcription)
TTS (Santa's Voice Output) Text of Santa's reply Synthesized into spoken audio that is streamed to the device Not stored One of Fish Audio, Cartesia, or ElevenLabs (only one is active at a time, configured via the TTS_PROVIDER setting)
Coarse Location City-level device position (low accuracy) Used on-device by the Santa Tracker; also sent with chat requests so Santa can reference your child's city when relevant Not stored as a profile field; transmitted with each chat request and discarded after the response is generated Anthropic (passed only as conversational context; not retained as a profile attribute)
Device Identifier Platform device ID (identifierForVendor on iOS, ANDROID_ID on Android) or a locally generated UUID fallback, sent in the X-Device-Id request header; on iOS, additionally an Apple DeviceCheck token Enforce the daily time-limit cooldown across sign-outs and (on iOS) app reinstalls so the limit follows the physical install, preventing abuse via creating new accounts or reinstalling Firestore (devices collection); the DeviceCheck cooldown flag is stored by Apple Firebase Firestore (storage backend); Apple (DeviceCheck — a per-device cooldown flag that persists across reinstall, used only for the daily limit; no personal data); also implicitly visible to Google AdMob's SDK on-device (Google AdMob also independently collects its own advertising identifier)
Usage Time Daily chat minutes consumed Enforce daily time limits (1 minutes free / 18 minutes premium per day) Firestore Never shared with any third party
Purchases Subscription status, product ID, purchase dates Manage premium access and subscription lifecycle Firestore RevenueCat (subscription management), Apple App Store / Google Play Store
Advertising Data Google Advertising ID (Android) / IDFA (iOS) — collected directly by Google's Mobile Ads SDK on-device when the banner is shown to Free-tier users; we do not receive, store, or process this identifier Display contextual, non-personalized ads to Free tier users Not stored by us — handled entirely within Google's SDK Google AdMob (non-personalized, child-directed, COPPA-tagged, max content rating G)
App Store Attribution Token An opaque, per-install token issued by Apple's AdServices framework (iOS only) — not the IDFA, and not tied to any person or device across apps Measure which App Store ad campaign led to an install or purchase Not stored by us Apple, RevenueCat (attribution only; no ATT prompt, no cross-app tracking, no profiling)
Meta App Events Standard app events (install, registration, purchase, with purchase amount/currency), basic technical metadata, and an anonymous app-scoped identifier — never the advertising identifier (GAID/IDFA) and never child profile data Measure and optimize our app-install advertising campaigns on Facebook/Instagram Not stored by us Meta Platforms (advertiser-ID collection disabled, no ATT prompt, no cross-app tracking, no behavioral profiling)
User ID Firebase-assigned unique identifier Link account data and authenticate API requests Firestore Firebase, RevenueCat, Sentry
Crash & Diagnostics Error logs, stack traces, performance data Identify and fix bugs, improve app reliability Sentry Sentry (Functional Software, Inc.)
Moderation Records Flagged text, violation category, timestamp Enable parental review of safety incidents Firestore Sentry (as error context for debugging)

4. No Sale of Data

We do not sell, rent, lease, or trade any personal information — including children's data — to any third party, for any purpose, ever.

  • We do not share data with data brokers.
  • We do not use children's data for advertising profiling or behavioral targeting.
  • We do not build marketing profiles based on any user's activity.
  • Data shared with the third-party services listed in Section 5 is strictly limited to what is necessary to operate the App and provide its core functionality. No third-party service receives more data than required for its specific function.

5. Third-Party Services

We use the following third-party services to operate the App. Each receives only the data necessary for its function:

Service Provider Data Shared Purpose
Firebase Authentication Google Parent email, auth credentials Account creation and sign-in
Cloud Firestore Google User profile, conversation data, device identifier Database storage
Cloud Functions Google Request data Backend API processing
Anthropic Anthropic Conversation text, child's first name and age, optional coarse location (as conversational context) Generate Santa's responses (Claude language model) and run the AI content moderation classifier
Deepgram Deepgram Audio (for real-time transcription only) Speech-to-text — audio is transcribed and not retained beyond transcription
Fish Audio / Cartesia / ElevenLabs Fish Audio, Cartesia, or ElevenLabs Text of Santa's reply Text-to-speech voice generation. Only one provider is active at a time, configured via the TTS_PROVIDER setting. No user profile data or input audio is shared.
RevenueCat RevenueCat Subscription/purchase data, user ID Subscription management
Google AdMob Google Advertising identifier (GAID/IDFA) and standard ad request data, collected by Google's SDK Display non-personalized, child-directed ads (Free tier only). Ads are COPPA-tagged with a maximum content rating of G (General Audiences). No behavioral profiling is performed.
Google AdSense Google Standard ad request data from website visitors, including IP address, browser user-agent, and cookie or similar identifiers Display advertising on the Website only (not in the App). All requests are tagged for child-directed treatment and requested as non-personalized. See Section 11.
Meta App Events Meta Platforms App events (install, registration, purchase + amount/currency), basic technical metadata, and an anonymous app-scoped identifier Measure and optimize our app-install advertising campaigns. Configured privacy-safe and child-directed: advertiser-ID collection disabled (no GAID/IDFA), no ATT prompt, no cross-app tracking, no behavioral profiling.
Sentry Functional Software Error data, user ID, device and OS metadata, IP address (in request metadata) Crash reporting and error tracking
Zoho Mail Zoho Parent email address Send violation notification emails

Each third-party service is governed by its own privacy policy. We encourage you to review them:


6. Children's Privacy (COPPA Compliance)

The Santa AI is directed at children and is designed to be set up and supervised by a parent or legal guardian. We comply with the Children's Online Privacy Protection Act (COPPA).

We collect only the minimum data necessary to provide the service. Child profile data (name, age, birthday, interests, wish list, and good deeds) is used exclusively for personalizing Santa's conversations and is never shared with advertisers, data brokers, or any third party.

6.1 Parental Consent

  • A parent or legal guardian must create the account and complete the onboarding process before a child can use the App.
  • During onboarding, the parent provides explicit consent for the collection of their child's information (name, age, birthday, interests, wish list, and conversation data).
  • Parental consent is recorded with a timestamp.

6.2 Parental Controls

Parents have the following controls, protected behind biometric authentication (Face ID / Touch ID) or device passcode:

  • View conversation history — review all messages between the child and Santa
  • Review moderation violations — see flagged content, categories, and timestamps
  • Acknowledge violations — chat remains paused until the parent reviews and acknowledges flagged content
  • Update child profile — modify name, age, interests, and other personalization data
  • Manage account settings — change language, theme, and other preferences

6.3 No Behavioral Advertising to Children

We do not serve behaviorally targeted advertising to children. Ads displayed in the Free tier are contextual only (Google AdMob), are non-personalized, are tagged for child-directed treatment (COPPA), carry a maximum content rating of G (General Audiences), and are not based on the child's personal information or activity.

6.4 Parental Rights

As a parent or legal guardian, you have the right to:

  • Review your child's personal information by accessing the Profile section (protected by biometric lock)
  • Request deletion of your child's data by contacting us at support@thesanta.ai
  • Revoke consent at any time by contacting us, which will result in account deactivation and data deletion

To exercise these rights, contact us at support@thesanta.ai. We will verify your identity before processing any request.


7. Content Moderation

All conversations are monitored by a three-layer moderation system:

  1. Keyword filtering — blocks known inappropriate terms in English and Spanish
  2. AI input moderation — analyzes the child's messages using an Anthropic Claude classifier before processing
  3. AI output moderation — analyzes Santa's responses before delivery using the same classifier; flagged responses are automatically replaced with a safe fallback message

When a child's message is flagged:

  • The chat is temporarily paused (default: 2-hour cooldown)
  • The parent receives an email notification with details of the violation
  • The parent must review and acknowledge the violation in the App before chat resumes

Moderation records (flagged text, category, timestamp, and source) are stored for parental review. These records are accessible only to the parent through biometric-protected parental controls.


8. Data Retention

  • Conversations and messages are retained as text only, indefinitely, unless the parent requests deletion.
  • Moderation violation records are retained indefinitely for parental review and safety purposes.
  • Audio recordings are never retained — user audio is transcribed in real-time and immediately discarded. Generated Santa voice responses are streamed to the device and not stored on our servers.
  • Account data is retained as long as the account is active.
  • Location data is not retained — coarse location is used on-device by the Santa Tracker and may be passed to the AI provider as conversational context with each chat request, but it is not stored as a profile field in our database.

To request deletion of your data, contact us at support@thesanta.ai.


9. Data Security

We implement the following security measures:

  • All data transmitted between the App and our servers is encrypted via HTTPS/TLS
  • User authentication is managed by Firebase Authentication (Google)
  • Parental settings are protected by biometric authentication (Face ID / Touch ID) or device passcode
  • Backend access is restricted to authenticated API calls with Firebase ID token verification

No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.


10. Your Rights

Depending on your jurisdiction, you may have additional rights regarding your personal data:

  • Access — request a copy of the data we hold about you and your child
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your data
  • Portability — request your data in a portable format

To exercise any of these rights, contact us at support@thesanta.ai.


11. The thesanta.ai Website

This section applies to our website at https://thesanta.ai, which is a separate service from the App. The Website has no accounts and no sign-in, and it is written for parents and guardians deciding whether to use the App. Unlike the App, the Website uses cookies and displays advertising.

11.1 Cookies and Similar Technologies

We and our advertising partners use cookies and similar technologies — including browser local storage and device identifiers — on the Website. They are used to:

  • remember a visitor number, so the home page visitor counter is not counted twice for the same browser (stored in your browser's local storage);
  • remember your music player preference;
  • serve, cap, and measure advertising, as described in Section 11.2;
  • measure whether a visit to the Website came from one of our own ads, as described in Section 11.2.

You can block or delete cookies and clear local storage through your browser settings. The Website continues to work if you do; the visitor number and player preference simply will not persist.

11.2 Advertising on the Website

The Website displays advertising served by Google AdSense. Third-party vendors, including Google, use cookies and similar identifiers to serve and measure ads.

Because our audience is families, every ad request from the Website is tagged for child-directed treatment and requested as non-personalized. Non-personalized ads are selected using contextual signals — such as the content of the page and coarse location — rather than a profile built from a visitor's past behavior. We do not provide any advertiser or ad network with information about a child.

We also advertise the App ourselves, and we use the Google Ads tag on the Website to measure how many visits our own ads produce. The tag sets a cookie that records that a visit followed one of our ads, so we can tell which ads are worth paying for.

That measurement is limited on purpose. We instruct Google, in every country and for every visitor, that this data may not be used for ad personalization and may not be shared with Google for its own advertising uses. We do not build or feed remarketing audiences, and we do not use the tag to follow anyone around the internet. It counts visits; it does not profile them.

You can review and control this:

11.3 Consent (EEA, UK, and Switzerland)

Visitors in the European Economic Area, the United Kingdom, and Switzerland are shown a consent message before advertising or measurement cookies are set, using Google's Funding Choices consent management platform. You may accept or refuse, and you may change your choice at any time using the control the consent message provides. Refusing consent does not restrict access to any part of the Website.

11.4 Hosting and Server Logs

The Website is hosted on Firebase App Hosting (Google). Standard server logs — including IP address, browser user-agent, and requested URL — are processed by the hosting provider for security, abuse prevention, and reliability. We do not run a general-purpose analytics product on the Website — there is no Google Analytics property and no visitor-behavior tracking. The only measurement we run is the advertising conversion measurement described in Section 11.2.

11.5 Contacting Us Through the Website

If you send us a message through the Website, we receive that message and any contact details you choose to include, and we store them so that we can reply. Retention and contact details are described in the Contact Us section below.


12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on our website at https://thesanta.ai/privacy and within the App. The "Effective Date" at the top will be updated accordingly. Continued use of the App after changes constitutes acceptance of the updated policy.


13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

rafcolm_ Software Operated by Rafael J. Colón Caguas, Puerto Rico, USA

Email: support@thesanta.ai Website: https://thesanta.ai

The Santa AI — Privacy Policy