Effective Date: August 27, 2026

Nuvilab Co., Ltd. ("Nuvilab," "we," "us," or "our") operates Peanutkio (the "Service"), an interactive storybook app where children can talk with story characters. This Privacy Policy explains what information we collect, how we use it, and the choices you have. We designed Peanutkio to collect as little information as possible.

1. Information We Collect

We do not collect names, email addresses, phone numbers, or other information that directly identifies a child.

We collect the following limited information:

Category Details How It Is Collected
Device & usage information Device model, OS version, app version, web version, a randomly generated on-device identifier (an anonymous ID created on the device; not derived from hardware or advertising identifiers), app session identifier, story interaction events (scene and choice selections), screen orientation and viewport size, display language, store market, a two-letter country code, time zone, crash and error logs Automatically, while you use the app
Usage analytics Device information, app usage events, app instance identifier Automatically, through our own event collector and Google Analytics for Firebase
Push notification information Push registration token, device information When notification permission is granted, through Firebase Cloud Messaging
Remote configuration information App instance identifier, device information Automatically, through Firebase Remote Config
Deep link information Device information, IP address, deep link usage When a shared link is opened, through the Branch SDK
Voice input Audio spoken during interactive story scenes. Voice is streamed to OpenAI, which listens and speaks back to continue the conversation (a voice-to-voice AI conversation); we do not store the voice recording on our own servers and do not use voice to identify anyone Only when the microphone permission is granted and an interactive scene is in use
Conversation content (text) A text record of the interactive conversation — what the child says or taps and the character's replies — is saved to our activity logs so we can keep the stories safe and improve them. It is stored as text only (no audio recording) When an interactive scene is used

How country is determined. Our hosting provider derives a two-letter country code from the network request at the edge, and only that code is stored — together with a note of where it came from and when. We do not store the IP address, city, postal code, or coordinates in our own database. If the edge does not supply a country, no country is recorded rather than guessed; we never infer country from the display language.

What we do not collect. We do not collect advertising identifiers (IDFA / AAID) or device fingerprints, we do not bundle third-party advertising SDKs, and the app contains no advertising. We do not collect precise location, photos, videos, camera imagery, or contacts.

1-A. Information collected when a grown-up signs in

The Service can be used with an account, by signing in with Apple or Google. Signing in is done by a parent or guardian, not by a child.

Category Details How It Is Collected
Sign-in credentials An identity token issued by Apple or Google, the one-time value used to secure that token, the account identifier the provider uses for the grown-up, and an email address supplied by the provider When a grown-up chooses to sign in
Apple connection token For Sign in with Apple only, a single-use authorization code is exchanged for a token that is stored in encrypted form. It is used for one purpose: to revoke the Apple connection when the account is deleted At sign-in, when Apple supplies it
Account and consent records When the account was opened, and a record of the agreement made on the way in: the version of the Parent Terms and of this Privacy Policy that was shown, when it was accepted, the display language, and the store market At sign-in
Child profiles For each child a grown-up sets up: a display name they choose, an age band (3, 4, 5, 6, 7, or 8+), and selected interests When a grown-up fills in the profile screen

About child display names. The display name is free text a grown-up types, so it can contain a real name if they choose to enter one. We do not require it to be a real name, and we suggest a nickname or first name only.

What signing in does not collect. Signing in does not ask for the grown-up's name, phone number, address, or relationship to the child.

Activity is recorded per child profile. Once profiles exist, story activity events, reading progress, likes, ratings, and conversation text are associated with the child profile they belong to rather than with the account as a whole. This lets each child have their own library, and it means a grown-up can delete one child's record without touching another's.

2. How We Use Information