|
Back to Home

Privacy Policy

Effective Date: May 4, 2026

The Santa AI ("the App") is operated by rafcolm_ Software, operated by Rafael J. Colón, based in Caguas, Puerto Rico, USA ("we," "us," or "our").

This Privacy Policy explains how we collect, use, and protect information when you and your child use the The Santa AI mobile application. Because our App is designed for use by children, we take privacy especially seriously and comply with the Children's Online Privacy Protection Act (COPPA) and other applicable laws.


1. Information We Collect

We collect only the minimum data necessary to provide the service. Below is a complete description of the information we collect and how it is handled.

1.1 Information Provided by Parents/Guardians

When you create an account and set up a child profile, we collect:

  • Parent email address — used for authentication and violation notifications
  • Child's first name — used to personalize Santa's conversations
  • Child's age and birthday — used for age-appropriate responses
  • Wish list items — used to personalize conversations
  • Interests — used to personalize conversations
  • Good deeds — used to personalize conversations
  • Language preference — English or Spanish

1.2 Information Generated Through Use

  • Conversation text — messages between your child and Santa (text only; no audio is stored)
  • Usage time — daily minutes spent chatting, used to enforce time limits
  • Subscription status — whether the account is Free or Premium
  • Content moderation records — flagged messages and violation categories, stored for parental review
  • Theme preferences — light/dark mode selection
  • Coarse location — city-level device location is used on-device by the Santa Tracker feature to estimate Santa's arrival time. The same coarse location may also be sent with chat requests so Santa can reference your child's city when relevant. We do not store location as a profile field in our database, and we do not share it with third parties beyond the AI provider that generates Santa's reply.
  • Device identifier — a platform-provided device ID (identifierForVendor on iOS, ANDROID_ID on Android, or a locally generated UUID fallback when those are unavailable) is sent in an X-Device-Id request header and mirrored to a devices document in our database. This is used solely to enforce the daily time-limit cooldown across sign-outs so a child cannot reset their daily limit by creating a new account on the same device. It is not used for advertising, profiling, or cross-app tracking.

1.3 Information We Do NOT Collect or Store

  • Audio recordings — your child's voice is recorded temporarily on the device, sent to our servers for transcription, and immediately discarded after transcription. We do not store any audio files. Santa's generated voice responses are streamed to the device and are also not stored on our servers.
  • Photos or videos — the App does not access the camera
  • Contacts — the App does not access the address book
  • Browsing or search history — the App does not track browsing or search activity

1.4 Advertising Identifier

When the AdMob banner is shown to Free-tier users, Google's Mobile Ads SDK collects the device's advertising identifier (Google Advertising ID on Android, IDFA on iOS) for ad delivery and frequency capping. We tag every ad request as child-directed (COPPA), non-personalized, and rated G (General Audiences) — but the identifier is still collected by Google. We do not receive, store, or use this identifier ourselves, and we do not perform any behavioral profiling. Premium subscribers do not see ads and the SDK does not run for them.


2. How We Use Information

We use the information we collect to:

  • Provide the service — generate personalized Santa conversations using AI
  • Enforce safety — moderate all messages for inappropriate content using keyword filters and AI-based moderation
  • Manage accounts — authenticate users, manage subscriptions, enforce daily time limits
  • Notify parents — send email alerts when content moderation violations occur
  • Improve the service — diagnose errors and improve reliability (via crash reporting)

We do not use children's personal information for marketing, advertising profiling, or any purpose unrelated to the App's core functionality.


3. Detailed Data Handling by Type

The following table provides a detailed breakdown of every data type collected, how it is handled, whether it is stored, and who it is shared with:

Data Type What We Collect Purpose Stored Where Shared With
Email Address Parent's email from account signup Account authentication and violation notification emails Firebase/Firestore Firebase Auth, Sentry (error tracking), Zoho (notification emails)
Child Profile First name, age, birthday, interests, wish list, good deeds Personalize Santa's conversations to be age-appropriate and relevant Firestore Never shared with any third party
Conversation Text Text messages between your child and Santa Provide the conversation service and moderate content for safety Firestore Anthropic (Claude — for AI response generation and the moderation classifier)
Audio (Voice Input) Child's voice recording during conversations Transcribed to text using speech-to-text, then immediately and permanently deleted Never stored — discarded after real-time transcription Deepgram (real-time speech-to-text only; audio is not retained beyond transcription)
TTS (Santa's Voice Output) Text of Santa's reply Synthesized into spoken audio that is streamed to the device Not stored One of Fish Audio, Cartesia, or ElevenLabs (only one is active at a time, configured via the TTS_PROVIDER setting)
Coarse Location City-level device position (low accuracy) Used on-device by the Santa Tracker; also sent with chat requests so Santa can reference your child's city when relevant Not stored as a profile field; transmitted with each chat request and discarded after the response is generated Anthropic (passed only as conversational context; not retained as a profile attribute)
Device Identifier Platform device ID (identifierForVendor on iOS, ANDROID_ID on Android) or a locally generated UUID fallback, sent in the X-Device-Id request header Enforce the daily time-limit cooldown across sign-outs so the limit follows the physical install, preventing abuse via creating new accounts Firestore (devices collection) Firebase Firestore (storage backend); also implicitly visible to Google AdMob's SDK on-device (Google AdMob also independently collects its own advertising identifier)
Usage Time Daily chat minutes consumed Enforce daily time limits (2 minutes free / 18 minutes premium per day) Firestore Never shared with any third party
Purchases Subscription status, product ID, purchase dates Manage premium access and subscription lifecycle Firestore RevenueCat (subscription management), Apple App Store / Google Play Store
Advertising Data Google Advertising ID (Android) / IDFA (iOS) — collected directly by Google's Mobile Ads SDK on-device when the banner is shown to Free-tier users; we do not receive, store, or process this identifier Display contextual, non-personalized ads to Free tier users Not stored by us — handled entirely within Google's SDK Google AdMob (non-personalized, child-directed, COPPA-tagged, max content rating G)
User ID Firebase-assigned unique identifier Link account data and authenticate API requests Firestore Firebase, RevenueCat, Sentry
Crash & Diagnostics Error logs, stack traces, performance data Identify and fix bugs, improve app reliability Sentry Sentry (Functional Software, Inc.)
Moderation Records Flagged text, violation category, timestamp Enable parental review of safety incidents Firestore Sentry (as error context for debugging)

4. No Sale of Data

We do not sell, rent, lease, or trade any personal information — including children's data — to any third party, for any purpose, ever.

  • We do not share data with data brokers.
  • We do not use children's data for advertising profiling or behavioral targeting.
  • We do not build marketing profiles based on any user's activity.
  • Data shared with the third-party services listed in Section 5 is strictly limited to what is necessary to operate the App and provide its core functionality. No third-party service receives more data than required for its specific function.

5. Third-Party Services

We use the following third-party services to operate the App. Each receives only the data necessary for its function:

Service Provider Data Shared Purpose
Firebase Authentication Google Parent email, auth credentials Account creation and sign-in
Cloud Firestore Google User profile, conversation data, device identifier Database storage
Cloud Functions Google Request data Backend API processing
Anthropic Anthropic Conversation text, child's first name and age, optional coarse location (as conversational context) Generate Santa's responses (Claude language model) and run the AI content moderation classifier
Deepgram Deepgram Audio (for real-time transcription only) Speech-to-text — audio is transcribed and not retained beyond transcription
Fish Audio / Cartesia / ElevenLabs Fish Audio, Cartesia, or ElevenLabs Text of Santa's reply Text-to-speech voice generation. Only one provider is active at a time, configured via the TTS_PROVIDER setting. No user profile data or input audio is shared.
RevenueCat RevenueCat Subscription/purchase data, user ID Subscription management
Google AdMob Google Advertising identifier (GAID/IDFA) and standard ad request data, collected by Google's SDK Display non-personalized, child-directed ads (Free tier only). Ads are COPPA-tagged with a maximum content rating of G (General Audiences). No behavioral profiling is performed.
Sentry Functional Software Error data, user ID, device and OS metadata, IP address (in request metadata) Crash reporting and error tracking
Zoho Mail Zoho Parent email address Send violation notification emails

Each third-party service is governed by its own privacy policy. We encourage you to review them:


6. Children's Privacy (COPPA Compliance)

The Santa AI is directed at children and is designed to be set up and supervised by a parent or legal guardian. We comply with the Children's Online Privacy Protection Act (COPPA).

We collect only the minimum data necessary to provide the service. Child profile data (name, age, birthday, interests, wish list, and good deeds) is used exclusively for personalizing Santa's conversations and is never shared with advertisers, data brokers, or any third party.

6.1 Parental Consent

  • A parent or legal guardian must create the account and complete the onboarding process before a child can use the App.
  • During onboarding, the parent provides explicit consent for the collection of their child's information (name, age, birthday, interests, wish list, and conversation data).
  • Parental consent is recorded with a timestamp.

6.2 Parental Controls

Parents have the following controls, protected behind biometric authentication (Face ID / Touch ID) or device passcode:

  • View conversation history — review all messages between the child and Santa
  • Review moderation violations — see flagged content, categories, and timestamps
  • Acknowledge violations — chat remains paused until the parent reviews and acknowledges flagged content
  • Update child profile — modify name, age, interests, and other personalization data
  • Manage account settings — change language, theme, and other preferences

6.3 No Behavioral Advertising to Children

We do not serve behaviorally targeted advertising to children. Ads displayed in the Free tier are contextual only (Google AdMob), are non-personalized, are tagged for child-directed treatment (COPPA), carry a maximum content rating of G (General Audiences), and are not based on the child's personal information or activity.

6.4 Parental Rights

As a parent or legal guardian, you have the right to:

  • Review your child's personal information by accessing the Profile section (protected by biometric lock)
  • Request deletion of your child's data by contacting us at support@thesanta.ai
  • Revoke consent at any time by contacting us, which will result in account deactivation and data deletion

To exercise these rights, contact us at support@thesanta.ai. We will verify your identity before processing any request.


7. Content Moderation

All conversations are monitored by a three-layer moderation system:

  1. Keyword filtering — blocks known inappropriate terms in English and Spanish
  2. AI input moderation — analyzes the child's messages using an Anthropic Claude classifier before processing
  3. AI output moderation — analyzes Santa's responses before delivery using the same classifier; flagged responses are automatically replaced with a safe fallback message

When a child's message is flagged:

  • The chat is temporarily paused (default: 2-hour cooldown)
  • The parent receives an email notification with details of the violation
  • The parent must review and acknowledge the violation in the App before chat resumes

Moderation records (flagged text, category, timestamp, and source) are stored for parental review. These records are accessible only to the parent through biometric-protected parental controls.


8. Data Retention

  • Conversations and messages are retained as text only, indefinitely, unless the parent requests deletion.
  • Moderation violation records are retained indefinitely for parental review and safety purposes.
  • Audio recordings are never retained — user audio is transcribed in real-time and immediately discarded. Generated Santa voice responses are streamed to the device and not stored on our servers.
  • Account data is retained as long as the account is active.
  • Location data is not retained — coarse location is used on-device by the Santa Tracker and may be passed to the AI provider as conversational context with each chat request, but it is not stored as a profile field in our database.

To request deletion of your data, contact us at support@thesanta.ai.


9. Data Security

We implement the following security measures:

  • All data transmitted between the App and our servers is encrypted via HTTPS/TLS
  • User authentication is managed by Firebase Authentication (Google)
  • Parental settings are protected by biometric authentication (Face ID / Touch ID) or device passcode
  • Backend access is restricted to authenticated API calls with Firebase ID token verification

No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.


10. Your Rights

Depending on your jurisdiction, you may have additional rights regarding your personal data:

  • Access — request a copy of the data we hold about you and your child
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your data
  • Portability — request your data in a portable format

To exercise any of these rights, contact us at support@thesanta.ai.


11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on our website at https://thesanta.ai/privacy and within the App. The "Effective Date" at the top will be updated accordingly. Continued use of the App after changes constitutes acceptance of the updated policy.


12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

rafcolm_ Software Operated by Rafael J. Colón Caguas, Puerto Rico, USA

Email: support@thesanta.ai Website: https://thesanta.ai