Back to Baku

Privacy policy

Last updated:

This policy explains how Baku uses information to provide bedtime stories for parents and caregivers.

Who operates Baku

Baku is developed and operated by Dekan Studio — an independent developer. In this policy, “we”, “us” and “our” mean Dekan Studio, which is responsible for the personal information processed to provide Baku. Contact us at baku-support@dekanstudio.com.

Information used by the app

Using Baku as a guest still involves processing information. Guest mode creates an account identifier and session credentials, and stores preferences and playback progress so you can browse and listen without registering. Guest accounts do not have child profiles. App installation and notification information may also be processed before registration.

Why this information is used

Baku uses this information to manage accounts, personalize and deliver stories, remember listening activity, understand app usage and improve the experience, deliver enabled notifications and manage reminders, verify purchases, respond to support requests and protect the service.

Where applicable law requires a legal basis, we process information as needed to provide the service you request, for legitimate interests such as service security and reliability, to meet legal obligations, or with your consent where required. You may withdraw consent by contacting us; this does not affect processing that was lawful before withdrawal.

Services that help provide Baku

We use service providers that protect personal information to a standard at least equivalent to the protections described in this Privacy Policy and required by applicable app-store rules. Information is shared as needed for the features described below:

Story push notifications are sent through these delivery services. Bedtime reminders are scheduled locally on your device; their enabled status, time and days are also stored by Baku with your app installation settings.

Crashlytics collection is enabled by default. Reports include exception types and stacks, screen breadcrumbs and session phase, as well as SDK-collected information such as app version, device and operating-system details, installation identifiers and crash timing. Baku’s own diagnostic reports do not deliberately include child details, story text or raw story identifiers.

Firebase Analytics collection is enabled by default, including in guest mode. Baku sends screen names using route patterns rather than individual story identifiers or URL query parameters. These screen-view events do not include child details or story text. The Firebase SDK also collects usage and technical information automatically; retention of analytics records follows the settings of Baku’s Google Analytics property and Google’s applicable data-handling rules.

Providers may process information outside your country. Their applicable service terms, data-processing agreements and account settings govern processing and retention, subject to the protections described in this policy and applicable law. Where required by law, international transfers must use an applicable transfer mechanism or safeguard. Contact us for information about processing relevant to your account.

We may also disclose information where required by law, to respond to a valid legal request, or as necessary to protect users and the service against fraud, abuse or security threats.

Children and caregivers

Baku accounts are intended for adults who have reached the age of majority where they live. Children may enjoy stories under a parent’s or caregiver’s supervision. Child profiles are managed by adults and are not separate child accounts. Provide child information only if you are authorized to do so, and avoid including sensitive details that are unnecessary for a story.

If you believe a child has provided information without appropriate adult authorization, contact us so we can investigate and arrange its removal where appropriate.

Account deletion

You can use the in-app deletion option or follow the external request instructions. Support must verify account ownership before submitting an external request. Once accepted, deletion disables account access and starts irreversible erasure; acceptance does not mean processing has finished.

When you delete your Baku account, we erase the associated personal information from Baku’s active systems, subject to the limited retention described below. Information previously processed by service providers is subject to the retention periods and deletion mechanisms applicable to those services. Completion of Baku’s account-deletion process does not confirm that every provider-held copy has been deleted.

Erasure covers child profiles, private stories and their revisions, personal audio and images, listening activity, favorites, personal feedback, notifications, account-linked app installation records (including push tokens, notification preferences and reminder settings), account identities, sessions and related processing records. Shared stories and genuinely aggregate statistics remain. Minimal purchase fingerprints are kept to prevent reuse, without the original transaction value or an account link.

Data held by service providers after account deletion

Baku automatically erases the account data and personal media it manages. When your account-deletion request is accepted, Baku will automatically send deletion requests to Qonversion, OpenAI, ElevenLabs and Brevo for your associated personal data processed by those services. Sending a request does not mean the provider has completed deletion; processing and any retained records remain subject to the applicable retention and deletion rules described below.

Cloudflare R2: personal media
Baku sends deletion requests for the private story audio, images and related stored copies it manages, including its trash copies. Limited records used to reapply account deletion after a backup restore are retained as described below. This does not describe deletion of Cloudflare’s separate website or security records.
Qonversion: purchases and entitlements
Baku removes its own account-linked purchase and subscription records, apart from the minimal purchase fingerprints described below. Baku will automatically request deletion of your associated customer data held by Qonversion through its customer-data deletion process. Removing a Qonversion customer does not cancel a store subscription. See Qonversion’s customer deletion documentation.
OpenAI: story generation
Baku deletes its own copies of personal prompts, generated content and related processing records. For new text-generation requests through OpenAI’s Responses service, Baku asks OpenAI not to save the response for later retrieval. This does not erase older saved responses or exclude all provider security and abuse-monitoring records. Baku will automatically request deletion of saved responses associated with your account through OpenAI’s individual response-deletion mechanism. Image processing and other retained records follow the applicable OpenAI data controls.
Microsoft Azure: narration
Baku deletes the personal narration and synthesis records it stores. Microsoft states that its real-time text-to-speech service does not retain the input text or generated audio, so there is no saved synthesis content from that mode to delete at Azure. This statement does not cover batch synthesis, custom-voice training or separately stored diagnostics, which have their own controls. See Microsoft’s text-to-speech data handling.
ElevenLabs: narration
Baku deletes its own copies of personal narration and synthesis records. Baku will automatically request deletion of narration history associated with your account that is retained by ElevenLabs, using its individual history-item deletion mechanism. See ElevenLabs’ history deletion documentation.
Brevo: email delivery
Baku removes earlier account-linked authentication email records as part of erasure. If an account email address is available, Baku temporarily retains it to arrange a deletion-confirmation email after active-system erasure completes. Related delivery records may remain for delivery and troubleshooting. Brevo may hold recipient information, delivery logs and stored email previews, including for that confirmation. Baku will automatically request deletion of your associated recipient information, email logs and stored previews through Brevo’s controls for contacts and transactional logs and previews. A deletion-confirmation email may create new delivery records, which remain subject to the applicable retention and deletion rules.

Completion of erasure in Baku, including a confirmation email, refers to Baku-managed active account data and personal content, subject to the retention exceptions below. It does not certify that all provider records have been erased. For a privacy request about data processed for Baku by these services, contact baku-support@dekanstudio.com. The provider references explain available controls; they do not replace Baku’s responsibilities under applicable law.

How long information is kept

We complete erasure of personal account data from Baku’s active systems within 30 days after your deletion request is accepted, subject to the retained information described below. Account access is disabled and erasure starts on acceptance. For email requests, account ownership must be verified before acceptance; sending an email alone does not mean that your request has been accepted or erasure has finished.

Account information and personal content
Kept to provide your account and requested features, then erased through the account-deletion process, subject to the limited retention purposes described here.
Protected backups
Each backup copy is retained for no more than 90 days from its creation. Backups are isolated from ordinary use, and deletion is reapplied before any restored data is used.
Deletion records
We keep a record that your account was deleted for up to 120 days after deletion is complete. This helps us prevent your data from being accidentally restored. Your account cannot be recovered. If deletion is still in progress, we keep the request until it is complete.
Support, diagnostics and security records
Kept for the time needed to resolve requests, diagnose failures, investigate abuse or meet applicable legal obligations. Provider-held records follow the relevant service’s retention and deletion arrangements.
Purchase fingerprints
Minimal pseudonymous fingerprints, without an account link or the original transaction value, remain for as long as needed to prevent reuse of purchases belonging to a deleted account, including lifetime purchases. They are not fully anonymous.

Erasure from Baku’s active systems does not mean all protected backups or service-provider records have disappeared at the same time. Store payment and accounting records are controlled by Google Play or Apple under their own policies.

Your choices and rights

You can delete a child profile in Baku. Deleting a child profile does not automatically delete stories or narration already created using that profile, or personal information already included in those stories and recordings. Deleting your Baku account is a separate process that also erases private stories and personal media, subject to the retention exceptions described above. See the account deletion instructions, or contact support to request removal of specific personal information.

Depending on applicable law, you may request access to, correction of, deletion of or a portable copy of your personal information, object to certain processing, or request that processing be restricted. Contact baku-support@dekanstudio.com to make a request. We may need to verify your identity, and exceptions may apply under law. You may also have the right to complain to your local data-protection authority.

Baku currently has no in-app switch to turn off Firebase Analytics or Crashlytics collection. Contact support about privacy requests concerning these services. Notification settings control notifications and reminders; they do not turn off analytics or crash reporting.

You can manage story push notifications and bedtime reminders in Baku, control notification permissions through your device settings, and request account deletion without reinstalling Baku. Deletion does not cancel store subscriptions or delete your Google or Apple account. Downloaded copies may remain on your devices after account deletion. Reconnecting the app does not guarantee their removal.

Website visits

The Dekan Studio website uses Cloudflare Web Analytics to measure visits and page performance and help us improve the site. Cloudflare processes page-view and performance measurements through a script on website pages. This website analytics service is separate from Firebase Analytics in the Baku app. Read more about Cloudflare Web Analytics and Cloudflare’s privacy practices.

Cloudflare also processes connection information, such as IP addresses and requested pages, to deliver and protect the website. The website does not submit account-deletion requests itself. Email links open your email application.

How we protect information

We use HTTPS/TLS to protect information transmitted between your device and our services. Administrative access is restricted to authorized personnel, and our databases are not directly exposed to the public internet.

Protected backups are isolated from ordinary use. When a backup is restored, account deletions are reapplied before the restored data is used. See “How long information is kept” for backup retention periods.

No storage or transmission method is completely secure. Do not send passwords, sign-in codes, access tokens or unnecessary child information to support.

Changes to this policy

We may update this policy as Baku or its data practices change. The date above identifies the latest revision. Material changes will be communicated through the service or other appropriate means where required by law. See also our Terms of Use.