Legal
Privacy Policy
Effective date 29 July 2026
This policy explains what VAL processes when your child talks to it, who else is involved, how long anything is kept, and what you as a parent can do about it. It is written to be read by parents rather than by lawyers.
We will update this page and its effective date whenever our practices change materially.
About VAL, and who this policy is for
VAL is a parent-managed AI voice companion for children, built by PodQ. Parents are the account holders and the decision-makers. A parent creates the account, creates each child’s profile, gives consent, and controls every setting, purchase, and piece of data.
Children only talk with VAL. A child has no account of their own, no sign-in, and no settings they can change. The iOS app is both the parent’s control panel and, when a parent deliberately activates it, a child-facing VAL running on the parent’s iPhone.
Where this policy says “you”, it means the parent or legal guardian who holds the account.
What VAL processes
Parent account data
We hold your email address, the sign-in identity you use to reach your account (either Sign in with Apple or a one-time code that we email to you), and the session records that keep you signed in. Those are the account details we hold about you as an adult.
If you write to us through the contact form on this website, we also receive your name, your email address, and whatever you put in your message. We keep support correspondence for as long as we need it to deal with your request.
Child profile data
When you set up a child, the only profile details VAL asks for are a first name and an age (or age band). It does not ask for a surname, a date of birth, a photograph, an address, or any contact details for a child. This is deliberately minimal.
Everything else VAL holds for that child (the profile’s settings, its consent records, conversations, memories, and saved storybooks) is described in the sections below.
Your child’s voice during a conversation
When your child talks to VAL, their speech has to be turned into text so that VAL can answer. Your child’s speech usually streams directly from the device to Deepgram, our speech-to-text provider, using a short-lived access token issued by VAL’s backend. On that path it does not pass through PodQ’s own servers. When that direct connection is not available, the app instead sends the recorded clip to our servers, which pass it straight to the transcription provider and do not keep it.
Either way, raw audio from live conversations is not durably stored anywhere: not by us, and not by our providers, who are not permitted to retain it or to train models on it. Saved story narration is the one exception, and it is described next. What we do retain is operational metadata such as character counts and audio durations. Those are measurements, not recordings.
Story narration audio: the one exception
There is one exception, and we want to be explicit about it. When VAL narrates a story that becomes a saved storybook, that narration audio is stored so your family can play the story again.
Stored story audio is encrypted before it is written. Each segment gets its own freshly generated AES-256-GCM key, and those keys are themselves wrapped by AWS KMS, a key-management service that never sees the content it protects. The encrypted audio is held in encrypted object storage, which only ever holds ciphertext.
In short: live conversation audio is not kept, and saved story narration audio is kept in encrypted form until you delete the book, the child’s profile, or the account, or until an unsaved story expires unused, in which case it is cleaned up automatically.
Conversation text and VAL’s memory
Once speech has been turned into text, the text of your child’s turns and of VAL’s replies is used to generate the next reply and to build VAL’s memory of that child, so that VAL can remember a favourite dinosaur or a story begun yesterday.
This text is stored encrypted at rest, in a compartment isolated to that one child. One child’s conversations and memories are never reachable from a sibling’s profile.
Verbatim conversation turns are pruned after roughly 30 days, once their meaning has been distilled into summaries and learned facts. A scheduled sweep does this whether or not your child keeps using VAL, so turns are not left behind on a profile that has gone quiet. There is one deliberate exception: turns VAL keeps so it can recall something exactly (a story, a song, a character your child invented) are held for as long as the profile exists. Summaries and learned facts persist while the child’s profile exists, and go when the profile goes.
Safety records
VAL keeps records of how its safety rules are performing. These are deliberately content-free: counts, rule categories, and coarse timestamps. They contain no child identifier, no household identifier, and no device identifier, so they cannot be used to look at what a particular child said or did. They also never produce parent-facing reports or alerts.
One safety check is different, and we would rather name it. When VAL decides whether to stop talking because someone interrupted it, it judges the short piece of speech it just heard, and that text is stored encrypted for 30 days so the judgement can be reviewed if it goes wrong. It is deleted with the child’s profile, like everything else.
How long things are kept
- Parent email address, sign-in identity, and sessions: kept while your account exists.
- Support correspondence: kept for as long as we need it to deal with your request.
- Child first name and age: kept while that child’s profile exists.
- Live conversation audio: not durably stored.
- Saved story narration audio: encrypted, and kept until you delete the book, the child’s profile, or the account; a story that is never saved expires unused and is cleaned up automatically.
- Verbatim conversation text: pruned after roughly 30 days by a scheduled sweep, except turns kept so VAL can recall a story, song, or character exactly, which last as long as the profile.
- Interruption-safety judgements: the short piece of speech VAL judged is kept encrypted for 30 days; the content-free record that the judgement happened is kept for a year.
- Summaries and learned facts: kept while that child’s profile exists.
- Safety records: content-free, and carry nothing that identifies a child, a household, or a device.
Who else is involved
Running a conversation takes several specialist services. Each one receives only what it needs for its own single step, and each is engaged to process that data solely in order to provide its service to VAL. None of them are permitted to use your family’s data to train their models, or for any purpose of their own.
| Provider | What it is used for |
|---|---|
| Deepgram | Turns the child’s speech into text. Audio streams to Deepgram directly from the device. |
| Anthropic (Claude) | Generates VAL’s replies. |
| Cartesia | Turns VAL’s replies into speech. |
| OpenAI | Draws the picture library from a fixed set of catalogue descriptions, and matches a picture to a moment in a story using a short label VAL writes. Your child’s recordings and conversations are never sent to OpenAI. A label written for a personalised story can contain a word from that story, which may include a name. |
| Apple | Verifies parent Sign in with Apple, and processes subscription purchases. |
| Verifies parent sign-in on the Android device path only. | |
| Resend | Sends transactional email to parents, such as sign-in codes. |
| Cloudflare R2 (S3-compatible object storage) | Stores encrypted story audio. It only ever holds ciphertext. |
| AWS KMS | Wraps and unwraps encryption keys. It never sees content. |
This list is enforced in code, not just written down here. Every part of VAL that can call an outside provider (replies, speech-to-text, voice, pictures, and picture matching) is checked against this list when the service starts, and VAL refuses to start in production if any of them is pointed at a provider that is not named here.
These providers operate internationally, so processing may take place outside the country you live in.
What VAL does not do
- There is no advertising in VAL, and no advertising SDKs in the app.
- There are no third-party analytics or tracking SDKs in the app.
- Children’s data is never sold, and never used for advertising.
- Providers receive only what each needs for its single step, and are not permitted to use the data to train their models.
- The text VAL turns into the numbers that power its memory is processed on our own servers, and is not sent to an outside embedding provider.
- Production logging redacts content by default.
Parents do not get transcripts, and that is on purpose
VAL does not give parents transcripts of what their child said, conversation summaries, activity feeds, or alerts derived from conversations. There is no setting that turns such a thing on, because that surface deliberately does not exist.
This is a privacy decision in your child’s favour. A companion a child can talk to freely is a different thing from a device that reports back on them, and VAL is meant to be the first. What parents can see is the storybooks their child chose to save, which is the part of the experience that is meant to be shared. If you would like more detail on why, see the support page.
Parental consent
Before any child can use VAL, you must read and accept a consent disclosure. It is shown in the app and versioned on our servers, so we know exactly which version you agreed to. Microphone access is only requested after you have given consent.
Consent is enforced on our servers, not only in the app. Without a valid consent grant for the current policy version, no conversation session is issued and no child audio is ever processed.
You can read your current consent state and withdraw consent at any time, per child, in the app’s Data & Privacy screen. Withdrawing takes effect across our servers within about a minute, and no new conversation can begin for that child afterwards. If a speech-to-text stream is already running at the moment you withdraw, it can continue for up to five more minutes before it stops; nothing new starts in the meantime. Withdrawing does not delete anything by itself (deletion is a separate action, described below), and you can grant consent again at any time.
If the disclosure changes materially, we ask you to consent again before your child’s next session.
The in-app disclosure and this page describe the same practices. This page is the fuller version, and nothing on it contradicts what you agreed to in the app.
What you can delete, and how
All of the following exist in the app today. Every destructive action requires you to have signed in as the parent within the last ten minutes (the app quietly refreshing its own session does not count), as well as device authentication with Face ID, Touch ID, or your passcode, and a typed confirmation such as your child’s name, the book’s title, or your account email.
- Reset what VAL remembers (per child). Permanently deletes that child’s conversation history, summaries, and learned facts. The profile, settings, saved books, and devices stay as they are.
- Delete a book, or delete all books (per child). Permanently removes the storybooks and their stored narration audio, including crypto-erasure of the encryption keys, so the stored audio cannot be recovered.
- Delete the child profile. Permanently erases the profile, the conversation history and memories, all of that child’s books and story audio, the consent records, and the keys that could recover any of it.
- Delete the household account. Removes the entire account: every child, all of their data, your sign-in identities, and your sessions. We keep one minimal, content-free record that the deletion was requested and carried out: identifiers only, nothing your child ever said or made.
Deleting your account does not cancel your Apple subscription. Subscriptions are billed and managed by Apple, so cancellation happens in your Apple subscription settings. If you no longer want to be billed, please cancel there as well.
How your family’s data is protected
- Conversation text and memories are encrypted at rest and held in a compartment isolated to a single child.
- Stored story audio is encrypted with a fresh AES-256-GCM key per segment, and those keys are wrapped by a key-management service that never sees content.
- Deleting story content includes crypto-erasure of the keys, so any remaining ciphertext cannot be read.
- Production logging redacts content by default.
No system is perfectly secure, but these are the controls VAL is built around.
Changes to this policy
We will update this page when our practices change, and we will change the effective date at the top of the page when we do. If a change materially affects what happens to your child’s data, we will also ask you to review and accept the consent disclosure again in the app before your child’s next session.
Who we are, and how to reach us
VAL is built and operated by PodQ Limited (company number 000010123), registered at 16 Al Khatem Tower, Hub71, Abu Dhabi Global Market Square, Abu Dhabi, UAE.
For privacy and data-protection questions, including any request about your child’s data, email us at support@val.chat and tell us it is a privacy request. We aim to reply within 2 business days. You can also write to us at the postal address above.
Looking for something else? See our Privacy Policy, Terms of Use, and Support pages.