Skip to content
Rhino Kids
Features How it Works Premium FAQ
Get Notified
← Back to Rhino Kids

Legal

Privacy Policy

Last updated: August 29, 2026 · Applies to the Rhino Kids app and this website

Plain-language summary: Rhino Kids is built for children to use with a parent nearby. A parent creates the account by verifying their own phone number, then adds their child's profile. We collect the minimum needed to run the app — account details, the child profile a parent enters, and a one-time location reading used to personalize content — and we do not show ads or use advertising/tracking SDKs. Details below.

1. Who we are 2. Information we collect 3. How we use information 4. Children's privacy & parental consent 5. How information is shared 6. Data retention 7. Your rights & choices 8. Security 9. International data 10. Changes to this policy 11. Contact us 12. Google Play Data Safety summary

1. Who we are

Rhino Kids is a bedtime-story app for children, published by Gray Parrot ("Gray Parrot," "we," "us," or "our"). This policy covers the Rhino Kids mobile app and this website (together, the "Service"). It explains what information we collect, why, how it's used and shared, and the choices parents and guardians have — including how to request that an account and its data be deleted.

Rhino Kids does not knowingly allow a child to create their own account. Every account is created and controlled by a parent or guardian, who verifies their own phone number and then adds a profile for their child. Where this policy says "you," it means the parent or guardian who controls the account, unless stated otherwise.

2. Information we collect

a. Information a parent provides directly

  • Phone number — used to sign in. We verify it with a one-time code (OTP) sent by SMS; there is no password to set or remember.
  • Parent details — your name (required), and optionally your age, gender, and relationship to the child (e.g. mother, father, guardian) — used only to personalize the account.
  • Child profile — the name, age, and (optionally) gender of each child you add. This is entered by you, not collected from the child directly. It's used to tailor which categories and stories are shown.
  • Approximate/precise location — during account setup we ask for location access to suggest a starting city/region. If you allow it, we capture a one-time device location reading (which includes precise coordinates as well as a human-readable city/state) and store it on your account; if you decline or it's unavailable, you can type your city instead, or skip it. We do not track location on an ongoing basis — only this one onboarding reading is taken.
  • Favorites and listening activity within the app — which stories you or your child mark as favorites and where you left off, so playback can resume and recommendations make sense.
  • Support requests — anything you send us by email (e.g. the address you email from, and the content of your message).

b. Information collected automatically

  • App version — checked at launch against the minimum supported version, so we can prompt an update if needed. No other device fingerprinting is performed.
  • Basic infrastructure identifiers — the Firebase services we run on (authentication and database sync) generate their own internal installation/session identifiers to make sync and security rules work. These are a standard part of how Firebase operates and are not used to build an advertising profile.

c. Information kept only on your device

Your Night Mode preference and whether you've already seen the first-launch welcome screens are stored locally on your device only. They are never transmitted to us.

d. Information we do not collect

We do not access the camera, microphone, contacts, or SMS/call logs. We do not collect persistent advertising identifiers, and we do not use any third-party advertising or analytics SDK in the app today. There is no in-app chat, comments, or any way for a child to exchange messages with another person through the Service.

3. How we use information

We use the information above to: create and secure your account (phone verification); show age- and interest-appropriate categories and stories; remember favorites and playback progress across sign-ins and devices; let you manage more than one child's profile; operate customer support; keep the Service working and secure (for example, Firestore security rules that only let a signed-in parent read or write their own account); and meet legal obligations. We do not use your or your child's information for behavioral advertising, and we do not sell personal information.

4. Children's privacy & parental consent

Rhino Kids is designed to be used by children under adult supervision, and we build the account model around that: a child cannot sign up on their own. An account only exists once an adult verifies a real phone number by OTP, and every child profile under that account is entered by that adult. We treat this parent-gated sign-up — a real, OTP-verified phone number belonging to an adult, followed by the adult entering the child's details — as our mechanism for obtaining consent before any information about a child is collected.

Because rules on what counts as sufficient verifiable parental consent differ by country (for example COPPA in the United States, GDPR-K in the EU/UK, and the DPDP Act in India) and can be interpreted strictly, we recommend this mechanism be reviewed by counsel before the app is submitted for Families/child-directed review, particularly if the app's target-audience declaration is later changed from "mixed audience" to "primarily child-directed."

Parents can review and edit their child's profile at any time from the Profile tab in the app, remove a child's profile (an account must keep at least one), and request full account and data deletion at any time — see Section 7. We do not knowingly collect more information from or about a child than is described in Section 2, and we do not condition access to any part of the app on a child (or parent) disclosing more information than is reasonably needed for that part of the app to work.

5. How information is shared

We do not sell personal information, and we do not share it with advertisers. We share information only with the service providers that help us run Rhino Kids, and only to the extent needed for that purpose:

  • Google Firebase / Google Cloud — hosts our authentication, database (Cloud Firestore), file storage, and backend functions (Cloud Functions, run from the asia-south1/Mumbai region). This is our core infrastructure provider and processes data on our behalf under Google's standard data-processing terms.
  • Fast2SMS — an SMS delivery provider based in India that we use to send the one-time OTP code to the phone number you provide. Fast2SMS receives only the phone number and the code needed to deliver that one message; it is not used for marketing.
  • App marketplaces — if you purchase a Premium subscription, Google Play (Android) or the Apple App Store (iOS) processes that payment. We receive your subscription status and a transaction identifier from them — we do not receive or store your card or payment account details.
  • Legal & safety — we may disclose information if required by law, or to protect the rights, safety, or property of Rhino Kids, our users, or others.

If this ever changes — for example, if we add an analytics or crash-reporting tool, or a new payment or messaging provider — we will update this policy before that change takes effect, and we will keep any child-directed surfaces restricted to providers that meet Google Play's Families Ads/SDK requirements.

6. Data retention

We keep account information for as long as the account is active. If an account is deactivated (for example, at the request of the account holder, or for a safety or policy reason), the underlying data is retained for a limited period in case the account holder wants to reactivate, and is deleted on request as described in Section 7. OTP verification records are short-lived and are not kept once a code has been used or has expired. We may retain a minimal record (such as that a deletion request was made and processed) where needed to meet a legal obligation or resolve a dispute.

7. Your rights & choices

As the parent or guardian who controls an account, you can:

  • Access and correct your account and any child profile at any time from the Profile tab in the app.
  • Remove a child's profile from your account from the same screen (every account must keep at least one child profile).
  • Request deletion of your entire account and all associated data — see our Account & Data Deletion page for how, and what happens to your data once you do.
  • Withdraw location access at any time from your device's app permission settings; this does not remove a location reading already saved to your account, which you can clear by contacting us or by deleting your account.

Depending on where you live, you may also have additional rights under local law (for example, to data portability, or to object to certain processing). Contact us using the details in Section 11 to exercise any of these.

8. Security

We use Firebase/Google Cloud infrastructure with industry-standard protections: data is encrypted in transit (HTTPS/TLS), Cloud Firestore security rules restrict each account's data to that account's authenticated owner, and secrets such as our SMS provider's API key are stored server-side as a Cloud Functions secret rather than inside the app. No method of transmission or storage is completely secure, but we work to protect information using practices appropriate to its sensitivity.

9. International data

Our backend infrastructure currently runs in Google Cloud's asia-south1 (Mumbai, India) region. Because we rely on global infrastructure providers, information may be processed or stored in other countries where those providers operate, with safeguards consistent with their standard data-processing terms.

10. Changes to this policy

We may update this policy as the app changes. We'll update the "Last updated" date above, and where a change is material — especially anything affecting children's data — we'll take reasonable steps to bring it to your attention, such as an in-app notice.

11. Contact us

Questions about this policy, or about your or your child's information? Email us at privacy@rhinokids.app. To request account or data deletion specifically, see the Account & Data Deletion page, which has the fastest path and what to include in your request.

12. Google Play Data Safety summary

This table mirrors how we've answered Google Play's Data Safety form, for anyone comparing our store listing against this policy. It reflects the app's current build; see Section 3 of the companion publishing checklist for the plain-English version of these same facts.

Data typeCollectedSharedPurposeRequired?User can request deletion
NameYesNoAccount management, app functionalityParent's name: yes. Child's name: yes.Yes
Phone numberYesYes — sent to Fast2SMS solely to deliver the OTPAccount management (sign-in)YesYes
Precise locationYesNoPersonalization (one-time reading at onboarding)No — a typed city, or skipping, is offered insteadYes
Approximate location (city/state)YesNoPersonalizationNoYes
App activity (favorites, playback progress)YesNoApp functionalityNoYes
User IDs / account identifiersYesNoAccount management, app functionalityYesYes
Financial / payment infoNo (Premium purchases, once enabled, are processed entirely by Google Play/Apple)————
Photos, videos, audio, contacts, calendar, messages, web browsing historyNoNo———
Device or other IDsFirebase-internal only (installation/session identifiers)NoApp functionalityNoHandled via account deletion
Advertising IDNo————
App info and performance (crash logs, diagnostics)Not currently collected————

All data above is encrypted in transit. This summary is provided for convenience and does not replace completing Google Play's own Data Safety form in the Play Console, which should be filled in directly from your current build at submission time.

Not legal advice. This policy was drafted from this project's actual code and data flows to be accurate and specific, but it is not a substitute for review by a lawyer familiar with children's privacy law (COPPA, GDPR-K, India's DPDP Act, and any other laws that apply to where your users are) before this app is submitted for Google Play's Families program or App Store review.

Rhino Kids

Magical bedtime stories for little dreamers.

Product

Features How it Works Premium FAQ

Legal

Privacy Policy Delete My Account Contact

© Rhino Kids. All rights reserved.

Made with 💤 for bedtime.