Who this policy covers and how to contact us
Maelorei is an independently developed iPhone and iPad app for families. This policy explains information handled through the app, the public website at maelorei.app, optional analytics, feedback, and privacy requests. Neither the app nor the website requires a Maelorei account.
The website Feedback page is the primary contact point. Choose Privacy questions and requests there if you need a response about your information. That separate form asks for a reply email. Ordinary feedback is for observations, problems, and ideas; it is not a support or reply service.
Family information on your device
Maelorei stores family information locally so the Journey can work offline. This can include child names and profile choices, optional avatar photos, Quests, Journeys, Side Quests, rewards, completion history, preferences, installed Quest Pack information, and a protected parent-passcode verifier. Maelorei does not store or transmit the four-digit passcode itself.
The developer does not receive household records through analytics. Optional iCloud Sync and private household sharing transfer approved family information through Apple's CloudKit service as described below. Feedback contains family information only if a person chooses to include it.
Optional iCloud Sync and private household sharing
Maelorei Family unlocks private iCloud Sync across devices signed into the same Apple Account. It also lets a household owner invite trusted family members to a private CloudKit household with read and write access after Maelorei Family is verified on each participating device. An invitation shares household information with the invited people. It is separate from Apple Family Sharing, which can share a purchase; Maelorei cannot verify that an invited CloudKit participant belongs to the owner's Apple Family Sharing group.
CloudKit records use encrypted fields for household information, including versioned parent-passcode verifier material. Optional child profile photos and parent-created Quest or reward artwork can synchronize as encrypted CloudKit assets. The four-digit passcode itself is never synchronized. StoreKit transactions or receipts, feedback drafts or attachments, feedback deletion codes, analytics identifiers, logs, diagnostics, Calendar-source state, weather coordinates, and downloaded Quest Pack asset bytes are excluded from the household snapshot.
Changes and deletions synchronize to the active private or shared household. iCloud Sync is not a versioned backup service and does not provide restore points. If Maelorei Family access is lost, private and shared iCloud access pauses without deleting local or CloudKit records; eligible pending edits can resume after access is restored.
Optional Calendar access
A parent with Maelorei Family can enable Calendar sync on one designated primary parent device and select the Calendars to review. Selecting a Calendar does not create Journeys. A parent first chooses New Journey, Existing Journey, or Not a Journey for an event or recurring series. After a parent links an event to a Journey, later changes to that event can update the linked Journey's title and timing.
Selected Calendars, pending event reviews, event-to-Journey links, and Not a Journey decisions stay on the primary device and are excluded from household sync and analytics. Journey information created or updated from a linked event can synchronize if iCloud Sync is enabled. Calendar permission can be changed in system Settings.
Photos, camera, and image creation
Avatar photos and custom Quest or reward images are optional. Camera access is used only when a parent chooses to take a photo. The system photo picker gives Maelorei access to selected images without requiring broad Photo Library access. On supported devices, Apple provides the Image Playground creation experience; Maelorei saves the final image the parent accepts.
Before local storage or iCloud Sync, Maelorei reduces and re-encodes child profile photos and parent-created Quest or reward artwork, so full-size originals and hidden image details are not synchronized. These images can synchronize through CloudKit when enabled. A feedback screenshot is a separate submission choice and is prepared as described in the feedback section.
Approximate location and Apple Weather
A parent may enable approximate location in Parent Hub to show local Apple Weather conditions. Apple processes the location to provide the weather request. Maelorei does not retain coordinates, associate them with household information, include them in analytics or feedback technical details, or use them for advertising or tracking. Location access can be turned off in system Settings. The moon-phase display is calculated on the device from the date and time.
Purchases and Quest Pack downloads
Apple handles payments and StoreKit transactions. Maelorei uses verified entitlements to make purchased features available. Maelorei Family and optional Quest Packs are one-time purchases; Quest Packs do not require Maelorei Family. Optional pack artwork is delivered through Apple's Managed Background Assets service without child names, family photos, Quest text, progress, or passcode material.
For a purchase started while analytics is enabled, Maelorei may give StoreKit a fresh random operation identifier also used in that purchase's analytics events. It is an operation-only appAccountToken, not an Apple Account, customer, receipt, product, or transaction identifier. A pending match is held only in memory. A later success is measured only when StoreKit returns the matching verified, non-revoked transaction during the same running process and consent period. Maelorei does not report the product or transaction identifier and does not infer a decline or expiration that StoreKit does not report.
Optional app analytics
App analytics remains off until a parent chooses Share analytics. The first Parent Hub visit presents a choice; declining is remembered. Sharing requires an existing parent passcode or setting one during the choice. The choice can later be changed in Parent Hub > Settings > Privacy. Core use and purchased features do not require analytics consent. After acceptance, collection continues until the parent turns it off.
Usage records can include fixed screen, feature-action, workflow-step, result, and failure categories; app version, build, and verified App Store or TestFlight distribution; operating-system major and minor version; phone or tablet class; free or unlocked purchase tier; parent, child, setup, or recovery mode; event and receipt times; and rounded duration or count ranges. Examples include Quest completion outcomes, water check-in progress ranges, reward categories and approval outcomes, Calendar review choices, navigation choices, and whether a save or sharing operation succeeded. These are predefined categories, not entered family content.
Maelorei creates a random, resettable identifier for this installation and random session and operation-attempt identifiers. Ordered screens and workflow steps let the developer measure paths, repeated actions, completion, retention, and affected installations. Usage and detailed diagnostics can be linked within that installation. These identifiers are not derived from an Apple advertising or device identifier, an Apple Account, Keychain, CloudKit, a child profile, or a household. Website and app identities remain separate and are never joined.
These records are pseudonymous, not a guarantee of anonymity. In a small beta, a report can show a fixed category from one consenting installation. The developer may infer which known tester contributed it using timing or other outside context, even though the report does not expose an installation identifier or family content.
- Analytics excludes names, email addresses, birthdays, child or household records, entered Quest, Journey, and reward names or text, feedback messages, photos, location, raw web addresses, query strings, full browser identification strings, and exact hardware models.
- Maelorei does not use these records for advertising, marketing, data brokerage, cross-site tracking, session replay, screen recording, or a profile of an identified child.
App diagnostics and performance
With app analytics enabled, Maelorei can send rounded health summaries for launch or resume time, hangs or hitches, memory, processor or graphics use, disk and network activity, energy-related performance, and runtime. These summaries omit persistent installation and session identifiers and are not joined to a usage history.
Separate detailed diagnostics can include a fixed crash, hang, resource, launch, or exit category; signal and termination classifications; app version and build; a crash-group fingerprint; bounded Maelorei binary identifiers and code offsets used to resolve app function names; a short ordered list of fixed activity markers; and subsystem, operation, failure, impact, and retry categories. An immediate operation failure can be associated with its consented session and workflow attempt.
Raw MetricKit payloads are reduced in memory and discarded. Maelorei does not upload raw call stacks, absolute addresses, system or third-party frames, exception messages or arguments, virtual-memory descriptions, arbitrary unified-log messages, error descriptions, file paths, request contents, screenshots, or view hierarchies. Private release symbol indexes contain Maelorei code metadata and let the developer interpret the bounded code references.
Optional website analytics and browser storage
Website analytics stays off unless a visitor chooses Allow analytics. Maelorei's own website code then creates separate random browser and session identifiers and sends limited events to analytics software operated in Maelorei's AWS account. It measures fixed public-page transitions, backtracking, repeated-page loops and exits, clearly marked action exposure and selection, sections, FAQ expansion, recent page engagement, scroll ranges, broad browser and screen classes, approved campaign or referral categories, event and receipt times, and rounded page-performance ranges.
Engagement grows only for a bounded interval after a recent click, key, pointer, or scroll action. Hiding or closing a page does not extend a session. A website failure may produce a fixed error or failed-operation category, page label, release identifier, broad browser family, random request correlation number, one-way error-group fingerprint, and up to eight hashed Maelorei script references with line and column numbers. Private source maps let the developer resolve those references. Events contain no exception message, raw stack, source code, form content, or raw web address.
The browser remembers an allow or decline choice for up to 180 days. To preserve a decline when local storage fails, the website may keep a fixed, non-identifying first-party withdrawal cookie for up to 180 days or until a new allowance. After consent, two first-party security cookies lasting up to 15 minutes help authenticate intake and reject forged requests. They are restricted to Maelorei and are expired on withdrawal. Analytics does not use advertising or cross-site cookies.
Failed analytics batches can remain in a consent-bound browser retry area for up to 12 hours, capped at three batches or 48 KiB. Bounded retry timers and later activity or lifecycle opportunities can retry delivery while consent remains active. Withdrawal clears that area. The separate privacy-request page does not run optional website analytics.
- Website analytics excludes feedback and privacy-request content, reply emails, screenshots, reference numbers, deletion codes, raw URLs or referrers, query strings, fragments, raw IP addresses, full browser identification strings, and family records.
- There is no automatic recording of arbitrary clicks, session replay, advertising, cross-site tracking, HTTP tracing, or polling to track a visit.
Analytics authentication and security information
After a parent accepts app analytics, Maelorei uses Apple's App Attest service to help verify that analytics comes from a genuine app. Apple processes the attestation request. The Maelorei gateway retains a hashed key reference, public verification key and counter, and hashed recovery or completion information for authentication and abuse prevention. A registered key has a maximum 90-day lifetime; challenges last five minutes and an upload credential lasts 15 minutes. Private keys and raw authentication secrets are not stored by the gateway.
The app keeps its analytics identity, bounded offline queue, deletion proof, and necessary attestation state in protected files excluded from backups. A short-lived upload credential remains only in memory. Failed or unsupported attestation does not permit unauthenticated analytics. Withdrawal removes ordinary local identity and attestation state and starts erasure; minimal protected proof may remain while deletion needs retry.
Feedback and TestFlight submissions
A parent or caregiver can submit a category, a message of up to 4,000 characters, up to three selected screenshots, and optional basic technical details. Nothing is submitted until the person chooses Submit feedback. In-app submission requires a configured parent passcode. Ordinary feedback asks for no name, email, account, or reply address, so it cannot receive a reply. The app does not automatically attach household records, photos, Quest text, progress, logs, or raw crash diagnostics.
Messages and screenshots may contain identifying information, so they are treated as linked to the submitting person or family even when no identity is requested. They are used to understand feedback, investigate problems, operate Maelorei, and evaluate product improvements. They are not sold or used for advertising, marketing, tracking, or data brokerage.
Screenshots submitted through the Maelorei app or website are resized to at most 2,048 pixels on the longest edge and encoded as JPEG before upload. The service prepares accepted images again before storage, removing source filenames, GPS, EXIF, and other embedded metadata. Visible details remain visible unless the sender removes or covers them. App technical details can include app version and build, operating-system version, general device family, viewport size and orientation, and submission time. Website details can include operating-system and browser family, screen size, orientation, and time. These details omit stable identifiers, Apple Account information, passcode material, app logs, and family records.
When Apple makes TestFlight feedback available, Maelorei can import feedback text, app build and version, device model, operating-system version, time, and relevant screenshot or crash references. The import discards tester identity fields and excess diagnostics; identifying details a tester writes in the message or includes in an image may remain. TestFlight images are retained as supplied by Apple; the image preparation described above applies to submissions through Maelorei's own app and website forms.
Feedback is reviewed privately by the developer. Under this policy, submissions are excluded from automated third-party AI review because the submission forms do not obtain separate informed permission for that sharing. Before this policy version, ordinary feedback text and limited reference, source, time, category, and review-tag fields could be exported to OpenAI’s Codex for grouping, problem analysis, and draft product issues. That earlier export excluded screenshots, private attachment links, and structured tester identity fields, but identifying details written into feedback text could remain. A human reviewed proposed issues before approving creation in GitHub. The privacy-request form is excluded from product-feedback exports.
Privacy questions and requests
The Feedback page links to a separate Privacy questions and requests form. It asks for an adult reply email, a request type, and a message. This information is used to respond to the request, identify the relevant records where possible, and carry out any proportionate verification required before disclosing, changing, or deleting information. Do not provide a child's email, passcode, identity document, or private family details in the initial request. There is no screenshot upload on this form.
The request type, reply email, and message are stored together as a private submission in the same protected system as feedback. The developer can reply using the supplied email; no marketing list or Maelorei account is created. Email correspondence is processed by the email providers involved. Optional website analytics is disabled on this page, and neither request contents nor contact details enter analytics or the automated product-feedback review export.
The form keeps unsent contents only in the active browser page. After submission, the browser retains only a reference, submission date, and deletion code. The email and message are cleared from the form. Keep the deletion code to remove the stored request early. Deleting a stored request does not remove earlier email correspondence or itself complete the underlying privacy action. Ask through the privacy-request form if you also want correspondence removed.
How long information is kept
Maelorei uses separate retention periods because family content, optional measurements, security records, and submitted requests serve different purposes. Local family information remains until a parent changes or removes it. CloudKit information remains in the private or shared household until removed through the available household controls; synchronized deletions apply to that household.
- App and website usage events and associated pseudonymous usage state: a 90-day retention period, to understand adoption and retention over that period.
- Detailed app and website diagnostics and health or performance summaries: a 30-day retention period, to investigate recent failures and performance. A daily verified cleanup removes analytics after their age limits; physical removal can follow the threshold at the next sweep. If cleanup fails or becomes stale, the affected analytics service becomes unavailable until its retention checks recover.
- Rotating analytics backups: deleted rows may remain for up to 14 additional days. Age limits and erasure records must be reapplied before restoration.
- Feedback, TestFlight feedback, privacy requests, and their attachments: scheduled for deletion 365 days after receipt, or deleted sooner after a valid deletion request, to review and act on the submission. Storage providers perform expiry in the background, so physical removal may occur after the scheduled date. The report store has no separate application-managed report backup or version history. The developer applies the same 12-month limit to copies of submission text in AI review records and privacy-request correspondence, with manual removal from those tools, unless an applicable legal obligation requires a specific longer retention.
- Approved product issues and implementation records are kept while needed to track a problem, its resolution, and maintenance of the change. These records should contain the product problem and necessary technical context, with personal details removed. A submission deletion code removes the stored submission and attachments; it does not automatically remove an earlier AI review record, email, or approved issue. Use the privacy-request form to ask for those related copies to be located and removed where applicable.
- Unfinished upload slots and pending attachments: up to 24 hours. Unsent app feedback drafts: up to seven days, excluded from device backups and CloudKit. Unsent website forms: active-page memory only.
- Application service logs: up to 14 days, with submitted contents, raw IP addresses, full browser identification strings, credentials, and private attachment links excluded. Short-lived abuse counters generally last up to 48 hours; delivery and erasure records generally last up to 30 days. Minimal erasure work persists until deletion completes.
- Private code symbol indexes and website source maps: the supported-release lifetime plus one year. These contain Maelorei code metadata, not customer submissions or event histories.
Your choices and deletion controls
Turn app analytics off in Parent Hub > Settings > Privacy. Use Analytics choices in the website footer to withdraw website analytics. Withdrawal immediately stops ordinary collection, clears or starts protected cleanup of queued events and the old identifier, and requests erasure of linked usage and detailed diagnostics. If local app cleanup cannot be verified, analytics stays off and cannot be enabled again until cleanup finishes. An offline or unsuccessful deletion is retried at a later app or page lifecycle opportunity using minimal retained proof. A server deletion block prevents delayed events from recreating an erased profile. Health summaries without an installation identifier cannot be located for individual erasure and expire on their normal schedule.
The app also offers Reset analytics identifier. Use the analytics controls before uninstalling or clearing browser data: losing the local proof can prevent Maelorei from identifying which pseudonymous analytics records are yours. A name or email alone cannot locate that installation's events.
Use Sent Reports in the app or website, or the saved privacy-request deletion control, to request earlier deletion of a submission. Removing the app, clearing browser storage, or discarding a receipt does not delete a submission already sent and can remove its deletion code. Maelorei may need additional proportionate evidence for a request without the code.
Parents can remove children, Quests, images, and other household content through app controls. Erase household and restart setup removes family profiles and setup content while keeping installed Quest Packs and the parent passcode. Losing an entitlement does not delete family data. Uninstalling does not itself delete already-synchronized CloudKit records or feedback received by Maelorei. Camera, Calendar, and location permissions can be changed in system Settings.
Service providers, recipients, and security
Apple provides the optional CloudKit, Calendar permission, photo picker, Image Playground, Weather, StoreKit, Managed Background Assets, App Attest, and TestFlight features described above. Invited household members receive the family information the owner chooses to share. Apple processes information through its services under its applicable terms and privacy information.
Maelorei uses Amazon Web Services for website delivery, private storage, API processing, first-party analytics hosting, security, private review access, and notification email. Maelorei-operated storage and processing are in US East (N. Virginia), United States. Content-delivery infrastructure may process requests in other locations. Google processes the developer's private Gmail inbox and any privacy-request correspondence sent through it. Routine feedback notifications contain only an opaque notice and private inbox link, not the submitted message, screenshots, category, or per-report deletion code.
OpenAI’s Codex was available for the earlier ordinary-feedback review described above; related review records may remain subject to the retention and deletion procedures in this policy. GitHub stores human-approved product issues and implementation records. The automated export of submissions to third-party AI is disabled under this policy. These services may process information in locations covered by their service arrangements; Maelorei-operated AWS hosting in the United States does not mean every provider processes information only there.
The systems use HTTPS, encryption at rest, restricted access, and protected operator authentication. Maelorei limits provider processing to the purposes described here and requires providers handling information on its behalf to protect it consistently with this policy and applicable requirements. Submitted contents and secrets are excluded from application logs. The ordinary website and API necessarily process network addresses to deliver requests; edge security may transiently use them for abuse protection. Feedback rate limits use short-lived one-way network codes rather than storing raw IP addresses.
CloudFront provides aggregate delivery reports about requests, paths, referring domains, approximate viewer geography, bandwidth, errors, and cache performance. These measure service delivery rather than consenting people or sessions. A feedback submission also uses a first-party security cookie lasting up to 30 minutes or one submission attempt. These operational protections are separate from optional product analytics.
The developer and authorized service providers access information only as needed for the described purposes. Information may also be disclosed where necessary to comply with a legal obligation or protect rights and security. Maelorei does not sell personal information, share it for targeted advertising, or use a data broker.
Purposes, regional rights, and international processing
Optional app and website analytics rely on your choice to allow collection. Family sharing, Calendar access, weather, and feedback occur when you request those features. Security processing is used to protect the service and prevent abuse; privacy requests are processed to answer questions and meet applicable obligations. Where a law requires a legal basis, these purposes may involve consent, providing a requested service, legitimate interests in security and responding to feedback, or compliance with legal obligations, as applicable. Withdrawing analytics consent does not affect the lawfulness of earlier processing based on that consent.
Depending on the law that applies to you, you may have rights to access, correct, delete, or receive a copy of personal information, restrict or object to processing, withdraw consent, or complain to a privacy regulator. Use the privacy-request form linked from Feedback. The developer may need proportionate verification and may be unable to identify device-local data or pseudonymous records without your saved proof. Requests are subject to applicable exceptions and response requirements. Maelorei does not make automated decisions with legal or similarly significant effects about people.
Using the website or sending information may involve processing in the United States and by the Apple, Google, OpenAI, and GitHub services described above. Privacy protections can differ between countries. Where international-transfer requirements apply, the relevant legal requirements must be met; this policy does not treat merely using Maelorei as consent to waive those protections.
Children and parent choices
Maelorei is designed for families. Purchases, private household invitations, feedback submission, and app analytics choices are available in parent-facing surfaces. A child is not asked to provide contact details or enable analytics. Once a parent opts in, predefined analytics may describe activity in both child and parent modes, without a child identifier or family content.
Analytics is used to understand and improve Maelorei's operation, reliability, and feature use. It is not used to contact a child, advertise, or build a profile of an identified child. A parent passcode or parental gate is not a substitute for verifiable parental consent where the law requires it. Parents can use the privacy-request form to ask about collection or request review or deletion of information; only an adult reply email should be supplied.
Policy changes
The version and effective date identify this policy. The website publishes the complete policy; the app shows a summary and can display a downloaded or bundled copy of the full policy when offline. A cached or bundled copy shows its own version and effective date. The current published policy is available on the website.
Maelorei will update this policy before materially changing what it collects, why it uses information, who receives it, or how long it is kept. Material changes will be brought to people's attention as required, and new consent will be requested where required before the changed processing begins. An editorial policy update does not itself enable analytics or expand an existing analytics choice.