Booka Ducka Ding Dong · privacy
Privacy Policy
Booka needs your location to pace a walk and uses named AI services to create stories, voices, and optional covers. It does not need your real name for the current beta.
Owner beta: accounts, recovery and reporting
These disclosures cover the owner-only Story Lab beta and its generation services. Older app builds may lack the matching controls; use the current qualified TestFlight build. Public creator intake and general-customer distribution remain closed.
- Generation accounts: new cloud story, cover and custom narration requests require Sign in with Apple. Supabase verifies the account; Story Lab additionally requires active owner access in this beta. Server-side safety counters use a hashed account identifier, not your name or email. Daily counters last up to 48 hours and monthly counters up to 62 days. These are pseudonymous records, not anonymous data. Free prepared Library stories remain accessible without signing in; restricted previews retain their access checks.
- Limited optional telemetry: a strict field allowlist excludes measured walking speed, moving or elapsed walking time, accepted pace samples, route progress and remaining-route time. Pace learning remains on your phone. This does not erase previously submitted events, which retain the existing 30-day limit. Optional analytics remains off by default and is separate from Daily contributions.
- Short-lived abuse protection: when an optional analytics event or Daily result is submitted, the server derives a keyed hash from the network address, report type and current hour. The limiter stores a count under that rotating hash for at most one hour. It does not store the raw address or attach the hash to event, account or story records, application logs or responses. A separate overall count contains no network identifier and expires within 24 hours. Hashing minimizes this processing; it does not make network information anonymous. Hosting providers still process ordinary connection and security logs under their own settings.
- Limits without mandatory sign-in: people sharing a network may temporarily share a reporting allowance. Rejected reports do not consume generation credits or prevent guest access to free stories. This abuse protection does not grant analytics permission or start collecting events by itself.
- Private narration recovery: generated private recordings are stored in access-controlled server storage for seven days from the request’s recovery record so the same authenticated account can recover a completed request after an interrupted connection. After seven days they are no longer served and become eligible for daily cleanup. A failed cleanup can delay physical deletion; its status must be monitored. Content-free technical receipts and duplicate-purchase protection remain for up to 180 days. An uncertain or expired result does not automatically trigger a replacement purchase within that receipt lifetime. These retention limits are separate from audio you keep in your on-device Library and from ElevenLabs’ own records.
- Public offline downloads: iOS may continue an explicitly requested public release download in the background. Temporary retry files and pinned download records have size limits and a 24-hour reuse window; expired items are removed during the next applicable app cleanup, not by a guaranteed wall-clock deletion task. Completed Library downloads remain until removed. Restricted previews do not use this public background queue. iOS controls transfer scheduling, and force-quitting the app can stop transfers.
- Deleting a playthrough: removing one local history entry preserves approved release assets or files still needed by another saved playthrough. Delete All Local Data remains the broader local clearing action; neither action deletes cloud accounts, published releases or providers’ records.
Questions or requests: daniel@frwrd.team. Private test readiness is not editorial approval, public publication or a legal-compliance certification.
01Who operates Booka
Booka Ducka Ding Dong is operated by frwrd.team LLC, doing business as dks.studio. Contact Booka support and privacy at daniel@frwrd.team. Public distribution remains gated on the operational and legal decisions below.
This notice covers the Booka iPhone app, its generation backend, the Creator at bookaducka.com, and the Booka pages on dks.studio. Launch terms and jurisdiction-specific notices remain under review.
Apple sign-in, creator drafts and remote releases
Generation and Creator access use Sign in with Apple and Supabase authentication. Apple can provide an account identifier and the name or email you choose to share, including a private relay address. Supabase holds authentication records and the restricted creator membership. Signing in is not publication and does not automatically upload a local draft.
Ordinary web drafts remain in that browser; native drafts remain on the device. An explicit private-review submission stores a frozen manuscript, branches, metadata, declarations and ownership records in Supabase. Submitted revisions and approved releases do not currently have an automatic expiry. Draft edits do not rewrite a frozen release or another listener’s saved history.
Preparing a human-authored release does not require a prose-writing model. With separate approval, Booka sends the exact selected text and voice to ElevenLabs, stores returned audio and the approved uploaded cover in private object storage, and records the immutable release. Story, audio and cover origins remain separate. Adding a release to the owner test Library is a further explicit action, not public publication.
Private Story Lab jobs: Create and the owner Story Lab use the same staged story engine. The submitted setup, generated concepts, names, plans, branch prose, critic notes and saved results are private server records with a fixed 30-day lifetime from job creation; using or resuming a job does not extend it. Operation tombstones contain identifiers and request digests, not manuscript text, and prevent duplicate generation for 180 days. Queue messages contain job identifiers, not manuscripts or sign-in tokens. These limits do not delete submitted creator revisions, published releases, on-device stories, separately retained media or a provider’s own records. A ready private draft does not become a public Library release.
Signing out or deleting local data does not delete the Apple/Supabase account, cloud review revisions, releases, provider history or already-running server jobs. Self-service remote account deletion and a verified request contact remain release gates; do not treat local deletion as cloud deletion.
02Location and routes
- Booka requests location while you are using an active walk so it can plan a route, show your position, pace scenes, detect route progress, and save the walked trace.
- After a directional choice, Booka asks Apple maps and directions to replace the remaining route from your current position. In loop mode, the original start remains the finish.
- During an active walk, updates may continue in the background so route progress and story pacing can continue. Booka shows the iOS background-location indicator and stops updates when the walk ends.
- During a walk, the resume checkpoint stores only elapsed time, moving time, qualified distance, accepted interval count, and median speed for pace learning. It does not store coordinate samples, timestamps, accuracy readings, device-reported speed values, or sample arrays in that checkpoint.
- The separate walked-route record still stores route coordinates locally for the map and Library. Raw estimator evidence is not persisted after the walk.
- A learned walking-speed scalar and qualifying-walk count persist locally. Route estimates begin using it after three qualifying walks; each requires at least four moving minutes, 300 meters of qualified distance, and 20 accepted intervals.
- The dks.studio story, narration, cover, statistics, and optional analytics services do not receive your precise route geometry. OpenAI and ElevenLabs do not receive your route or pace data.
- Apple and its MapKit/directions services may process coordinates and related device information to provide maps and walking directions under Apple’s own terms and privacy policy.
- Your active checkpoint and completed route remain in the app’s local Library until you delete the story, delete all local data, or remove the app.
- Story records, active checkpoints, choices, and walked routes are not explicitly excluded from Apple device backups and may be retained or restored under Apple’s backup settings. Generated-audio and generated-cover cache directories are explicitly marked as excluded from backup.
- You can deny or revoke location in iPhone Settings. Home, Settings, saved-story information, and available offline replay remain usable; starting or pacing a new route does not.
03Custom stories
The app sends the complete custom setup to the dks.studio backend, including genre, mood, prose style, intensity, audience, perspective, duration, narrator alias, route shape, control mode, and optional premise. Through Vercel AI Gateway, OpenAI receives a story brief containing genre, mood, prose style, intensity, audience, perspective, duration, route-shape label and premise, followed by the generated fictional names, concepts, character and world details, branches, prose and review instructions needed for each stage. It does not receive route coordinates, walking pace or your Apple sign-in token. Do not put secrets, medical details, precise addresses, or other personal information into the optional premise.
Booka saves server-stage results for the private job’s 30-day lifetime and stores the returned story graph and your later choices locally so the story can resume and replay. Routine product analytics do not contain the premise, prose, or transcript.
Booka pins story routing to OpenAI through Vercel AI Gateway and sets the Gateway option that disallows prompt training, but it does not currently request zero-data-retention. OpenAI states that API inputs and outputs are not used for model training by default, while abuse-monitoring logs may retain content for up to 30 days unless stronger controls apply; some endpoints also retain application state. See OpenAI API data controls.
04Narration
The app sends selected scene text, voice alias, story ID, scene ID, and shared-cache instruction to the dks.studio backend. The backend maps the alias to a provider voice and sends ElevenLabs the scene text, voice ID, eleven_multilingual_v2 model ID, output format, and voice settings. Story and scene IDs remain in dks.studio’s technical receipt; they are not included in the ElevenLabs request. Booka may use an on-device Apple system voice when cloud narration is unavailable or not permitted.
The current integration uses ElevenLabs’ ordinary logged Text-to-Speech mode and does not send the enable_logging=false Zero Retention option. ElevenLabs says text input and audio output are retained by default for service improvement, troubleshooting, and security. It also says certain submitted data may be used to improve its audio models unless the workspace’s Data Use setting is turned off. The production workspace setting has not been verified, so dks.studio does not promise that opt-out. See ElevenLabs Zero Retention and model-improvement disclosure.
Custom narration is stored on the iPhone and in access-controlled server recovery storage for seven days from its recovery record. Expired recordings are not served and are eligible for daily cleanup; delayed cleanup can delay physical deletion. Content-free recovery receipts last up to 180 days. Shared Featured and approved release narration are stored separately in private object storage and currently have no automatic expiry.
05Optional generated covers
After a private story passes the listening checks, the backend derives and signs a small visual brief from an excerpt of the accepted opening, the title and selected genre or mood. Refreshing the story renews the authorization without generating an image. If generated-cover permission is on and you begin the story, the app returns the signed token and OpenAI receives only setting, focal subject, symbolic object, atmosphere, and palette, which can include that short opening excerpt. It does not receive route geometry, complete prose, choices, or endings. A premise detail may be reflected in the brief, so do not put personal information in the optional premise. Declining keeps the Booka Ducka template.
If the backend feature is enabled, dks.studio stores a private server copy for delivery. It becomes eligible for deletion after seven days and is removed by a daily cleanup job, so it may remain until the next scheduled cleanup—roughly eight days if that job runs as scheduled. Local deletion does not immediately delete this temporary server copy. The downloaded copy remains until the story, all local data, or the app is deleted. The bundled fallback may use the Booka Ducka template. A remotely published Library release instead carries its separately approved canonical cover. Turning off new cover generation does not remove approved art already included in a Library release.
06Daily comparisons and analytics
- Daily comparisons: if you choose to contribute, Booka sends semantic choice IDs and a random attempt ID—not prose or route geometry—so aggregate percentages can be calculated. You can view results without contributing. The current beta has no minimum cohort threshold: percentages appear after one recorded path, so a tiny cohort can effectively reveal an individual path.
- Optional analytics: this is off by default. If enabled, the server accepts a fixed allowlist of events and fields such as app/build, story and scene IDs, genre, target duration, route shape, control mode, rating, narration source, choice count, technical preparation timing and route-revision count or reason. It does not accept measured walking speed, elapsed or moving walk time, accepted pace samples, route progress or remaining-route seconds. No route geometry is sent. Completed walking summaries remain local in this release.
- Local feedback: scene ratings and local diagnostic fields remain on the iPhone even when remote analytics is off. Deleting one story does not delete its saved feedback event; Delete All Local Data does.
- Operational records: story and narration receipts can record model or voice, usage, latency, request identifiers, cache result, bytes, and shadow cost. Cover records can also include quality, policy versions, dimensions, file hash, warnings, and spoiler-safe alt text. They exclude the full premise, story prose, narration text, route geometry, audio bytes, and cover bytes. Story and scene IDs may be semantic.
- Network and coarse location: hosting and security systems receive ordinary connection data such as IP address and may derive approximate city or country. Booka does not send your GPS route to those systems.
07Retention
| Record | Retention |
|---|---|
| Local routes, stories, choices, audio, and covers | Until you delete them, delete all local data, or remove the app. |
| Active aggregate pace checkpoint | Until the unfinished quest is removed, all local data is deleted, or the app is removed. |
| Learned walking-speed scalar and qualifying-walk count | Until Reset learned walking pace, Delete All Local Data, or app removal. |
| Completed per-walk timing, pace, and route-revision summaries | Until the story is deleted, all local data is deleted, or the app is removed. |
| Raw optional product events | Up to 30 days. |
| Aggregate optional-analytics event counts | Up to one year. |
| Aggregate narration request, character, and cost counters | No automatic expiry in the current backend; these counters contain no story text or route geometry. |
| Story, narration, and cover technical receipts | Up to 180 days. |
| Private Story Lab job, submitted setup and generated stage results | Fixed 30 days from job creation; resuming does not extend it. |
| Content-free private-job operation tombstones | 180 days from job creation; they prevent the same operation buying another generation. |
| Private custom-narration recovery file | Not served after seven days from its recovery record; eligible for daily cleanup after expiry. |
| Hashed-account generation safety counters | Daily counters up to 48 hours; monthly counters up to 62 days. |
| Rotating hashed-network report counters | At most one hour; separate non-identifying overall counters expire within 24 hours. |
| Private generated-cover delivery file | Daily deletion after seven days; normally removed within eight days. |
| Daily duplicate-prevention IDs | Up to 90 days. |
| Daily aggregate choice counts | Expire one year after the most recent contribution to that quest. Later contributions refresh the key, so an older contribution’s effect can remain longer than one year. |
| Shared Featured audio | No automatic expiry in the current backend. |
| OpenAI story prompt/output abuse-monitoring copy | Up to 30 days under the current standard API data controls, unless a stricter approved setting applies. |
| ElevenLabs request history/provider copy | Under the current ElevenLabs account and service settings; zero-retention is not claimed for this beta. |
| Infrastructure security and request logs | Under the hosting provider’s service and security retention settings. |
Backups and provider deletion can take additional time. Hosting, network, and provider logs follow each provider’s configured plan and policy; dks.studio does not promise a fixed deletion period for those logs until production settings are verified. Records may be retained longer when reasonably necessary for security, fraud prevention, a legal obligation, or an active dispute.
08Providers and disclosures
- Apple: iOS, TestFlight/App Store, location permission, maps, and directions.
- Vercel: backend hosting, AI Gateway, private object storage, approximate location derived from IP, and ordinary service/security logs.
- OpenAI: pinned story generation and, when enabled by the backend, cover generation.
- ElevenLabs: synthetic narration, including its account-level retention and model-improvement settings.
- Upstash: Redis storage for private Story Lab jobs and stage results, Daily deduplication and aggregates, optional analytics events and counts, generation receipts, recovery metadata, cover metadata, locks, budget counters, and short-lived abuse counters.
- Supabase: Apple authentication, creator memberships, explicitly submitted frozen revisions and immutable Library release records.
- GitHub / Microsoft: public dks.studio static-site hosting and ordinary website request and security logs.
These companies process data under their own applicable terms and dks.studio’s service configuration. Booka does not allow these transfers for targeted advertising.
09Your choices
Settings lets you control location access, cloud story/narration/cover processing, Daily contribution, and optional analytics. Library and Settings provide story deletion, delete-all, and export controls in supported builds. See the step-by-step Privacy Choices page.
Creator accounts and a remote release catalog exist; automatic cross-device syncing of private drafts and personal listening history is not promised. Booka has no advertising profile.
AI setup: the recommended “Use default settings” button explicitly enables new story generation, ElevenLabs narration and generated covers. “Customize settings” preserves separate choices and explains what each switch disables. No permission is granted merely by opening setup. Existing choices are not silently reset. Analytics, Daily contributions and iOS location permission remain separate. See Privacy Choices.
Reset learned walking pace removes the learned speed scalar, qualifying-walk count, and current pace-learning evidence. It does not delete completed Library records or optional analytics already sent.
Delete Story removes the local playthrough, route and choices, and removes its media when no other retained story or release needs those files. Approved release assets and files used by another saved playthrough may remain. It does not remove prior Daily aggregates, optional analytics already sent, private server jobs, technical receipts, provider history, temporary server media, shared Featured audio, or that story’s locally saved feedback event.
Delete All Local Data also removes completed records, checkpoint, learned pace, local feedback, audio and cover caches, analytics identifier, playback and ambience preferences, and the app’s temporary export file.
Export story history creates JSON containing story metadata, provenance, choices, actual elapsed and moving minutes, median walking speed when available, accepted interval count, and route-revision count. It intentionally omits precise route coordinates, raw location timestamps, accuracy and speed samples, story prose and scenes, audio, cover files, active checkpoint, and analytics identifier.
10Security and launch limits
The internal beta is being tested by an adult. The launch age rating, eligibility rule, territories, jurisdiction-specific rights, and Apple EULA selection have not been finalized. Booka is not in Apple’s Kids Category; do not submit a child’s personal information.
dks.studio keeps provider credentials off the device, uses HTTPS in the Release build, stores shared assets privately, signs custom-cover generation and delivery requests, fully decodes cover files, and enforces a global Daily cover-attempt ceiling. The current owner Creator, Story Lab and restricted Library routes check authenticated membership. Cloud generation requires an authenticated account and finite account/service limits; anonymous Daily submissions and optional analytics have separate short-lived abuse limits. Guest access to prepared free stories does not imply access to paid generation. Owner-only qualification is not evidence that public-customer abuse, billing or entitlement testing is complete.
Material changes update the version and date on this page. If a change materially expands optional processing, the app will request permission again where appropriate.
11What must close before external release
- Verify a working privacy and support mailbox and document support-message handling.
- Confirm the public legal address and dks.studio DBA details.
- Approve launch territories, jurisdiction-specific rights, age rating, and EULA selection.
- Qualify authenticated generation, account/service limits, reporting abuse controls and cleanup monitoring for the intended public audience.
- Verify the production provider, retention, and ElevenLabs Data Use settings.
One address, no form