Booka Ducka Ding Dong · your controls

Privacy Choices

Nothing here is a scavenger hunt. These are the controls, what each one changes, and what Booka cannot yet do.

Last reviewed September 22, 2026 · Version 0.13 · owner Story Lab beta · Not final public-launch terms

Your routes and listening history stay on the iPhone. Apple accounts, private Story Lab jobs, explicitly submitted review revisions and remote Library releases are separate cloud records. Deleting local data does not delete those records or your account.
Owner-only beta, disclosures reviewed September 22, 2026. Story Lab, Apple sign-in and the restricted owner Library are for private testing. Use the current qualified TestFlight build for matching controls. A private story becoming ready to listen is not public publication or a claim of human editorial approval. Public creator submissions, creator payments, and external distribution remain closed.

01Location

  1. Open Booka → Settings → Location.
  2. Open iPhone Settings and choose the location access you want.
  3. Turning it off prevents new live walking routes; it does not upload or erase your saved route.

02Learned walking pace

Pace learning happens automatically and locally. During an active walk, the resume checkpoint keeps only elapsed time, moving time, qualified distance, accepted interval count, and median speed—no coordinate samples, timestamps, accuracy readings, device-reported speed values, or sample arrays. Route coordinates remain separately in the local walked-route record.

Booka begins using the learned speed after three qualifying walks. Open Settings → Walk defaults → Reset learned walking pace to remove the learned scalar, qualifying-walk count, and current pace-learning evidence. This does not erase completed story metrics or routes.

03Story, voice, and cover processing

Setup includes an AI-preferences step. “Use default settings” explicitly enables all three AI features below. “Customize settings” lets you keep any of them off. Opening the screen grants nothing and does not reset earlier choices. The same preferences remain available in Profile and custom-story setup.

  • AI stories: settings, optional premise and generated story-stage context go through Vercel AI Gateway to OpenAI. New generation requires Apple sign-in and active owner access in this beta. Off prevents new custom AI stories and new or resumed Story Lab generation. Human writing, saved story review and prepared Library stories remain available.
  • Cloud narration: selected story text and voice go to ElevenLabs through Booka. Off stops new narration requests and voice previews that require generation. Booka can use an available local Apple voice where supported; already prepared or downloaded Library audio does not need a new synthesis request.
  • Generated covers: a signed visual brief, which can include a short opening excerpt, goes through Vercel to OpenAI when you begin a story with this permission enabled. Off uses the Booka template for new custom-story art; it does not disable the story or hide an existing approved Library cover.

The recommended button does not enable analytics, Daily-choice contribution, location access, tracking or a separate training permission. It does not purchase a plan, raise generation limits or publish your work. Provider retention and account-level data-use settings remain as disclosed in the Privacy Policy.

You can withdraw AI permissions in the app. This blocks new applicable device requests, not work already received by a provider. A durable Story Lab job may continue on the server after you close the app or turn off the text switch: use that job’s separate Cancel action to stop future stages. Cancellation cannot recall completed or already-started requests.

Private jobs and their stage results expire 30 days after creation; returning to a job does not extend that period. Content-free operation tombstones remain for 180 days to prevent duplicate generation. A local copy you choose to keep has its own on-device lifetime. Private narration recovery files are unavailable after seven days and eligible for daily cleanup; technical receipts remain for up to 180 days.

04Daily comparisons

Turn Contribute my Daily choices on or off in Settings. Off means your future semantic choice path is not submitted. You can still view aggregate percentages when the service has at least one recorded path; the current beta does not enforce a minimum privacy threshold. Submitted aggregate contributions cannot be separated later because they contain no account identity.

05Optional product analytics

Analytics is off by default. Turning it off stops future optional events and deletes the local installation identifier. The current export intentionally omits that identifier, and these events are not linked to the separate Creator account, so dks.studio may be unable to locate already-submitted raw events. Raw events expire after about 30 days.

Submitting a Daily result or optional analytics event also invokes a separate abuse limiter. It uses a keyed, hourly rotating network-address hash for at most one hour, not a stored raw address or an advertising profile. The hash is not added to the event or account. Shared networks may share an allowance. This protection does not turn analytics on or require an account to listen to free prepared stories.

Private creator revisions and accounts

Deleting a local draft, signing out or removing the app does not revoke a frozen cloud submission or erase an account. Review versions and immutable releases remain separate. Remote account deletion, associated-content handling and Apple token revocation need a verified operational process before creator access expands.

For a privacy or account question, contact daniel@frwrd.team. Do not send unnecessary identity documents or confidential story text. Public creator intake remains closed.

06Delete or export local data

  • One story: Library → story details → Delete Story. This removes that playthrough, route and choices; media needed by another saved playthrough or approved release is preserved. It does not remove server/provider records or its locally saved scene-feedback event.
  • Everything local: Settings → Delete All Local Data. This also removes learned pace plus playback and ambience preferences.
  • Export: Settings → Export story history. The JSON includes actual elapsed and moving minutes, median walking speed when available, accepted interval count, and route-revision count. It omits precise routes, raw location timestamps, accuracy and speed samples, story prose/scenes, audio, cover files, checkpoint, and analytics identifier.
  • Unfinished story: Settings → Remove unfinished quest.

If a control is absent from an older internal TestFlight build, update to the current test build or delete the app to remove its local container.

07Ask for help

Contact daniel@frwrd.team with “Booka privacy” in the subject. Do not include a route screenshot, home address, story transcript, or API key. State the app version, the control you used, and what result you expected. Read the full privacy policy.

One address, no form

Say hi.
Or complain.

daniel@frwrd.team