Diorama
Privacy Policy
How Diorama handles information. Effective September 11, 2026.
Overview
Diorama is a learning app designed for children ages 6–8, with AI discovery creation, subscriptions, external links, and settings controlled by a grown-up. This policy describes the current discovery experience and explains how earlier saved stories are treated. The child area offers reading, prepared questions, and optional activities; it has no live AI chat, web search, advertisements, or child account.
This policy applies to the Diorama mobile application and its related support services.
Sources and permissions
Most information is provided directly by you or created as you use the app. Device, diagnostic, and transaction information may come from your device, Apple, Google, or the service providers used to operate the app.
Permission-controlled information is accessed only after you grant the relevant device permission. You can revoke a permission in system settings, although the related feature may stop working.
Information we process
- On this device: welcome completion, read-aloud preference, the parent-preview setting and whether its first-time choice has been completed, saved AI discoveries, discovery history and opening/finish times, favorites, and whether a question or model was tried. Diorama does not save which answer the child selected or calculate a learning score. Progress is shared within this installation, without separate child profiles.
- For AI creation only: a grown-up’s general educational question is sent to Diorama’s service on Google Cloud, then to OpenAI for generation, moderation and content review. The service uses an anonymous Firebase installation identifier and app attestation to authorize the request and enforce limits. OpenAI receives the question and generated text, without the installation identifier, purchase information, child answers, history, images, audio or location fields. Google receives ordinary connection information such as the IP address; OpenAI receives the backend connection rather than a direct app connection.
- For membership: Apple and RevenueCat process purchase, transaction and subscription information. When using online paid features, Diorama links the existing anonymous RevenueCat customer to an anonymous Firebase installation identifier so the server can verify membership. Diorama does not receive payment-card details. Subscription access and its verified expiry are cached on the device.
- For optional crash reports: if a grown-up enables Share crash reports, Google Firebase Crashlytics processes crash stack traces, app and operating-system versions, device characteristics, timestamps, and installation identifiers. Network requests include ordinary connection information such as the IP address. We do not attach questions, generated lessons, child answers, learning events, names, customer IDs, or advertising identifiers. Firebase Auth and App Check also support secure online features independently of optional crash reporting. Crash uploads remain off unless a grown-up enables them. Google Analytics is not included.
- For adult access: a salted digest of the grown-up code and attempt-limit state are stored in the device Keychain. The code is not stored as plain text or sent to our server. Device-owner authentication may be used to reset it; Diorama does not receive biometric data.
- For diagnostics and support: local event names and counts, and any information a grown-up chooses to send to support or share using the system share sheet. Automatic local counters do not contain prompt text, lesson text, names, child answers, or advertising identifiers and are not uploaded by the app.
- For the online collection: Firebase Hosting delivers compact catalog updates, illustrations and prepared English narration; Diorama’s API delivers requested lesson details. Search normally runs on the device using the bundled index. If local search is unavailable, the API can receive the search words and content filters. New-to-me, favorites, finished state and learning history are not included in those requests. Network providers receive ordinary connection information.
How we use information
- Provide the bundled library, locally saved discoveries, read-aloud controls, favorites, and the grown-up recap.
- Create a requested learning discovery and run content checks before it can be added to the child library.
- Remember whether the parent wants to preview future AI discoveries. Turning previews off changes when checked lessons are added; it does not grant permission to send future questions.
- Retrieve and restore membership access, process subscriptions through Apple, maintain subscription records through RevenueCat, and respond to support, privacy, and content concerns.
International processing
Gamina and its service providers may process information in countries other than the country where you live. Where applicable law requires it, we use contractual and organizational safeguards intended to protect information during those transfers.
Storage and retention
Local progress, preferences, and saved discoveries remain in app storage until removed, cleared, or the app is deleted, subject to Apple backup and restore behavior. Clearing progress does not remove saved discoveries or change the preview preference. Saved AI discoveries can be removed individually in Grown-ups and remain readable after membership expires. Unsaved questions and drafts remain in memory and are discarded when leaving creation or backgrounding the app; the raw question is not written to discovery storage. A save already started may finish. Canceling cannot retract data already sent to a provider. Daily local diagnostic counters retain up to 90 UTC days; older cumulative counters may remain from earlier versions. The grown-up code digest can remain in Keychain after reinstalling. Purchase, security, and support records are kept as needed to administer access, respond to requests, meet legal obligations, and resolve disputes; provider-held records follow the applicable provider retention rules. Contact support for a request concerning records that cannot be removed in the app.
Security
We use reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. No storage or transmission method can be guaranteed completely secure.
Your choices and rights
- Leave crash reporting off or change it at Grown-ups → Help fix crashes → Share crash reports. Turning it off prevents future report uploads and deletes unsent reports; it cannot recall an upload already in progress or erase provider-held reports. Re-enabling discards reports from before the new choice. Contact support about reports already sent.
- Use bundled discoveries without sending a question to an AI provider. The app does not ask for a child’s name, birthday, email, or location to use the library.
- Read the OpenAI disclosure and agree separately before sending each question. You can withhold or uncheck that agreement before sending. Editing the question clears the agreement; no ongoing AI permission is saved.
- Preview the first generated discovery and approve it before adding it. After it is added, choose whether to keep parent previews on. With previews off, future discoveries are added automatically after content checks. Change the preference at Grown-ups → AI discoveries → Preview before adding. The first discovery always includes a preview, even if the setting was changed earlier. AI can make mistakes; automated checks and parent review do not guarantee accuracy or suitability.
- Remove individual AI discoveries, clear discovery progress, or change read-aloud and preview preferences from Grown-ups. Removing local data does not cancel a subscription or delete provider-held records. Manage or cancel subscriptions through Apple.
- Keep questions general. Do not include a child’s or another person’s name, school, address, contact details, health information, or other personal data. Local checks catch some obvious personal information but cannot guarantee detection.
- Contact support@gamina.app to ask about access, correction, or deletion, including questions submitted to providers or records from earlier app versions. Parents may ask about information concerning their child and request its deletion or that further collection stop. We may need proportionate information to verify the request and locate the relevant records; do not send passwords, full payment-card numbers, or unnecessary child information.
Depending on where you live, applicable law may also give you rights to request access, correction, deletion, restriction, objection, or portability, and to complain to a data-protection authority. These rights can be subject to legal exceptions.
Instructions for app-data removal are available on the Delete App Data page.
Children, parent controls, and read-aloud
The child area can search prepared discoveries; it does not contain AI creation prompts, microphone input, photos or uploads, videos, advertising, live AI conversations, or outbound source links. A grown-up enters AI questions in the protected area. Children’s answers and learning interactions do not trigger generation or get sent to OpenAI.
The first generated discovery includes a complete parent preview with the explanation, answer, feedback, and activity. After adding it, the parent is asked whether to keep previews. When enabled, each discovery must be reviewed and approved before adding. When disabled, a checked result is saved automatically. Content checks still run for every request. The preview preference and first-time choice are stored locally, separately from per-question agreement to use OpenAI.
A grown-up code limits access to adult controls; it is not identity verification, age assurance, or legally verified parental consent. Do not use the question box to provide personal information about a child. If you believe such information has been submitted, contact support so we can investigate and handle the request with the relevant provider as applicable.
Read-aloud uses installed Apple system speech voices. Diorama does not request microphone access or record speech in the discovery experience. Saved lessons and the bundled library can be read offline; creating new lessons and refreshing membership require internet access.
Earlier app versions and saved stories
Existing stories from an earlier installation are preserved separately and can be read as text in the grown-up area. The current child experience does not send or regenerate those stories. Clearing discovery progress does not delete them. Earlier versions may have processed prompts, generated stories, imagery, or other submitted material through the providers used at that time. Updating the app does not erase historical provider records; contact support for questions or deletion requests concerning earlier processing.
Children
Diorama is directed to children ages 6–8 with grown-up controls. It does not require a child account or request child identity information for the learning library. AI questions and purchase controls are for grown-ups. Children should not enter personal information or contact support themselves. A parent or guardian should choose appropriate material and supervise use as needed. Where applicable law requires additional parental notice or verified consent for processing a child’s personal information, a preview setting, question checkbox, or grown-up code does not replace those requirements.
Third-party services and links
The app may link to or interoperate with services controlled by other companies. Their privacy practices apply to information they collect independently, so review their notices and controls before using those services.
Changes to this policy
We may update this policy as the app, providers, or legal requirements change. We will post the revised policy here, update the effective date, and provide additional notice when required.
Contact
Questions or privacy requests can be sent to support@gamina.app.
Gamina Teknoloji ve Yazılım Hizmetleri A.Ş., Esentepe Mah. Talat Paşa Cad. No: 5, İç Kapı No: 1, Şişli, İstanbul, Türkiye.