1. Who we are (data controller)

BeeBee Tones AB (org. nr. 559589-2323), a Swedish limited company, is the data controller for the Fabeligo app under the EU General Data Protection Regulation (GDPR) and equivalent laws.

Because BeeBee Tones AB is established within the EU, we act as your direct point of contact for privacy matters and do not appoint a separate Article 27 representative. For data-protection questions you may also contact the Swedish supervisory authority, the Integritetsskyddsmyndigheten (IMY).

2. The short version

3. What we collect (and what we don’t)

Fabeligo processes only what is strictly required to deliver stories to your device and to operate subscriptions through the App Store and Google Play.

What we process:

What we do not collect: name, email address, phone number, precise or coarse location, contacts, photos, microphone audio, listening history, favourites, advertising identifiers, or anything tied to a child’s identity.

Crash and diagnostic data. Fabeligo contains no third-party crash-reporting or analytics SDK. The only diagnostic data that may be produced is the standard operating-system crash and performance reporting that Apple (iOS) and Google (Android) collect at the platform level. That data goes to Apple or Google under their privacy policies and platform settings (not to BeeBee Tones AB), and you can disable it in your device’s privacy settings (iOS: Settings → Privacy & Security → Analytics & Improvements; Android: Settings → Google → Usage & diagnostics).

4. Who receives data (sub-processors)

We keep the recipient list as short as the product allows. Each recipient receives only the narrow, mostly anonymous data described below.

RecipientWhat they receiveWhyLocation / safeguard
Cloudflare (R2 + CDN)Content-file requests; device IP transiently; short-lived security logsDeliver story audio and illustrations; protect the serviceGlobal edge network; EU/US transfers under Standard Contractual Clauses (SCCs)
RevenueCatAnonymous App User ID, transaction/entitlement identifier, subscription stateValidate and restore subscriptions across devicesUnited States, under SCCs
Apple (App Store)Your payment and account data, handled entirely by AppleProcess purchases and subscriptionsPer Apple’s privacy policy
Google (Play)Your payment and account data, handled entirely by GoogleProcess purchases and subscriptionsPer Google’s privacy policy

We do not sell, rent, or share personal data with anyone for advertising, marketing, or profiling. We have no other sub-processors. RevenueCat’s policy is at revenuecat.com/privacy; payment data is governed by Apple’s and Google’s policies respectively.

5. Legal basis for processing (GDPR Article 6)

For users in the EU/EEA and UK, we rely on the following legal bases:

We do not rely on consent for advertising or profiling, because we do none. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects (Art. 22).

6. Children’s privacy (COPPA, GDPR-K, DSA, UK Children’s Code)

Fabeligo is designed for children aged 2–9, but is purchased and managed by a parent or guardian. Protecting children is the central design principle of the app.

7. How long we keep data (retention)

Our default is to keep nothing tied to you.

We retain no other categories of personal data.

8. Where data is processed and international transfers

Story content is served from Cloudflare’s global edge network, with EU edge locations used where available. Subscription-status data is processed by RevenueCat in the United States. Where personal data is transferred outside the EU/EEA, the transfer is covered by Standard Contractual Clauses (SCCs) and, where applicable, supplementary measures. Apple and Google process payment data under their own published policies and transfer mechanisms. No personal data leaves your device for any other purpose.

9. Your rights

Under the EU GDPR, the UK GDPR, and equivalent laws, you have the right to access, rectify, erase, restrict, port, and object to the processing of personal data we hold about you, and to withdraw consent where processing is based on it. Because we deliberately hold almost no personal data tied to you, most of these rights have little or nothing to act on, but you may exercise them at any time.

10. Regional addenda

European Economic Area & United Kingdom

The whole of this policy applies. For UK users, references to the GDPR should be read as the UK GDPR, and the relevant authority is the Information Commissioner’s Office (ICO). The UK Children’s Code (Age Appropriate Design Code) is met by the by-design measures described in §6.

California (CCPA / CPRA)

If you are a California resident:

Other regions

If you are located elsewhere, your local data-protection law may grant you similar rights; we honour applicable equivalents on request.

11. Changes to this policy

We will update this page if anything material changes, and we record the date at the top. Where a change affects how we process personal data, we note it in the changelog below and, where appropriate, surface it in the app.

Changelog

12. Contact

For any privacy question, request, or concern, email hello@beebeetones.com. A parent or guardian may contact us on a child’s behalf. We aim to respond within 30 days, and usually much sooner.