Draft. This text has not had a legal review yet.
This policy explains what the wonderwhy app and the wonderwhy.net website collect, why, who processes it, how long it is kept and what you can do about it. It describes how the app works today. When that changes, we update this page and the date above.
Who we are
wonderwhy is published by [Publisher name], [Postal address] (“we”). We are the data controller for the personal data described here. For anything about your data, write to privacy@wonderwhy.net.
Summary
- No ads, no analytics, no tracking across other apps or websites. We don’t sell or share your personal data.
- You can use the app without an account. An account (email and password) lets your lists and settings sync between devices.
- When you ask a question by voice, the recording goes to Google’s Gemini service to be understood and answered. We don’t store it.
- AI writes the news summaries from public news feeds. None of your data is sent for that.
- You can delete your account in the app.
| Data | Why | Where it goes | How long |
|---|---|---|---|
| Email, password, optional name | Account and sign-in | Google Firebase Authentication | Until you delete your account |
| Synced lists and settings | Keep them in step across your devices | Google Cloud Firestore (Belgium) | Until you delete your account |
| Votes and poll answers | Count them once and show totals | Google Cloud Firestore (Belgium) | Until you delete your account |
| Voice question (up to 15 seconds) and the sentence playing | Understand and answer your question | Google Gemini API | Not stored by us |
| Live mode audio | Spoken conversation about your briefing | Google Gemini, through Firebase | Not stored by us |
| Daily usage counters (your ID and a number) | Fair-use limits | Google Cloud Firestore (Belgium) | See How long we keep data |
| Server logs (IP address, app and device details) | Security and fixing problems | Google Cloud (Belgium) | 30 days |
Your account
You can use the app as a guest. If you create an account, we process your email address, your password and, if you enter it, your name. Google’s Firebase Authentication stores them; we never see your password. Sign in with Apple and Sign in with Google are prepared but not switched on yet. When they are, Apple or Google will share your name, your email address (Apple may give a private relay address) and a sign-in token with us.
Some features need an ID even for guests. The first time you vote, have a story read aloud or ask a question, the app creates a random guest ID (a Firebase anonymous account). It isn’t linked to your name or email, but it is still personal data, because what is stored under it can be linked back to your phone. If you then create an account, your guest ID becomes your account ID. If you sign in to an account you already have, the app stops using the guest ID.
What syncs to your account
When you are signed in with an account (not as a guest), the app keeps the following in Google Cloud Firestore so it follows you to your other devices. Only you can read it.
- Preferences: your topics, languages, story depth, text size, listening settings and notification choices.
- Saved stories (up to 50), stories you recently read or listened to (up to 30) and your listening queue (up to 20). These are copies of the stories inside the app.
- Topics and sources you follow or mute.
- Your votes and poll answers and the stories you reported.
- Your word list (up to 1,500 words), with the sentence and headline where you found each word.
- Today’s listening progress: which stories you heard, how long you listened and how many questions you asked. Only the number of questions is kept, not the questions.
Votes and reports
When you react to a story or answer a poll, your vote is stored with your account or guest ID, so that it counts once and you can change it. Other people see only the totals.
When you report a problem with a story, we store the story, the reason you picked and any note you write (up to 500 characters). The report isn’t linked to your ID. Please don’t put personal information in the note: because it isn’t linked to you, we can’t find it later to delete it.
Microphone and questions
Push-to-talk questions
While a briefing plays, you can hold the microphone button and ask a question. The app records only while you hold the button, for up to 15 seconds. It sends the recording, together with the sentence that was playing, to our server. Our server sends them to the Google Gemini API, which works out your question and writes an answer. Google’s text-to-speech then reads the answer in the briefing’s voice.
We don’t store the recording, what you said or the answer, and we don’t write them to our logs. Our logs keep only numbers, such as the length of the answer and how long it took. Your voice is not used to identify you.
We use the Gemini API as a paid service. Under Google’s terms for paid services, Google doesn’t use this data to improve its products; it keeps prompts and answers for a limited time only to detect misuse and to meet legal obligations.
Ready-made questions
Some questions are buttons, such as asking for more detail on a story. Their answers are about the story, not about you, so we save them with the story and reuse them for everyone.
Live mode
In some cases the app uses a live conversation mode instead of recorded audio. We switch it on from our side, or the app uses it when a story’s audio can’t be prepared. In live mode:
- the app streams microphone audio directly from your phone to Google’s Gemini service through Firebase, for as long as the live session is open;
- the microphone listens whenever the app isn’t speaking, so you don’t need to hold a button;
- Google transcribes both sides of the conversation;
- to set up the conversation, the app also sends the stories in your briefing and your language and depth settings;
- if you ask about a word, the app may add it to your word list.
We don’t store live-mode audio or transcripts.
iOS asks for your permission before the app can use the microphone. You can turn it off at any time in the iPhone’s Settings.
How the news is made
Our server collects stories from news outlets’ public feeds. It sends them to OpenAI to write the summaries and to Google to read them aloud. These requests contain only news text, none of your data. Story audio files are deleted from our storage after 7 days.
Your personal briefing is put together on your phone from the shared edition, so your topics aren’t sent to any AI service (except in live mode, above).
News images load directly from the publishers’ servers, and source links open the publisher’s page in a browser inside the app. Those publishers can see your IP address and apply their own privacy policies.
On your phone
- Your lists, settings and sync state, in the app’s own storage.
- A cache of story audio, in a temporary folder that iOS may clear.
- Your sign-in session, in the iPhone’s Keychain. Keychain items can remain after you delete the app.
- An offline copy of your synced data, kept by Firestore.
When you sign out or delete your account, the app removes your lists, votes, words and progress from the phone. It keeps your app settings (topics, languages, text size) so the app keeps working. Deleting the app removes them.
To protect our servers from misuse, the app uses Firebase App Check with Apple’s DeviceCheck to confirm that requests come from the genuine app. We don’t store device identifiers.
Notifications
Notifications aren’t switched on yet. When they are, and only if you allow them, your phone subscribes to topics (such as your morning briefing time) through Firebase Cloud Messaging and Apple’s push service. We don’t store a device token.
Usage limits and server logs
To keep the service fair and affordable, we count how many questions you ask and how many story audios you have generated each day. Each counter holds your account or guest ID, the date and a number. While a story’s audio is being made, the job is recorded with your ID.
Our servers run on Google Cloud in Belgium (europe-west1). Google Cloud keeps request logs with IP addresses and app and device details for 30 days. When you delete your account, our logs record the deletion with your account ID.
No ads, analytics or selling
The app has no advertising, no analytics and no crash-reporting tools, and it doesn’t track you across other companies’ apps or websites. We don’t sell or share personal data, as California law defines those terms. We don’t make decisions about you by automated means that have legal or similarly significant effects.
Who processes your data
- Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, App Check, Cloud Messaging, Gemini API and Firebase AI Logic): hosting, sign-in, sync, questions and audio. Firestore, Cloud Functions and Cloud Storage are in Belgium; sign-in, Gemini and some other services may process data in the United States and other countries.
- OpenAI: writes the news summaries. It receives no personal data.
- Apple: DeviceCheck and push notifications, and Sign in with Apple once it is switched on.
- GitHub: hosts this website.
- [Email provider]: forwards the email you send to our addresses.
These providers process data on our behalf under their data processing terms, which require them to protect it at least as well as this policy describes.
Some of them process data outside Türkiye and the European Economic Area, including in the United States. These transfers rely on the safeguards the law requires: for the EEA, the providers’ standard contractual clauses; for Türkiye, the mechanisms in Article 9 of the Personal Data Protection Law No. 6698 (KVKK).
How long we keep data
- Account and synced data: until you delete your account.
- Votes: until you delete your account. Votes you cast as a guest and then left behind by signing in to an existing account stay with that guest ID.
- Guest data: the guest ID and its votes stay until you ask us to delete them. Guest IDs don’t expire on their own yet.
- Reports: kept, because they aren’t linked to anyone.
- Daily usage counters and audio job records: these currently remain after you delete your account. They hold your former account ID and numbers, nothing else about you. We are changing this so they are deleted with the account.
- Voice questions: not stored.
- Story audio: 7 days.
- Server logs: 30 days.
- Emails you send us: as long as we need to deal with your message. If you ask us to tell you when the app is out, we keep your address until we have done so, then delete it.
Deleting your data
In the app, open your account and choose Delete account. This deletes your account, everything stored under it in Firestore (lists, settings, words and progress) and all your votes. If you used Sign in with Apple, the app also revokes its access to your Apple ID. On your phone, the app removes your lists and keeps its settings, as described above.
What remains afterwards is listed under How long we keep data: usage counters and audio job records, anonymous reports and 30 days of server logs.
If you used the app only as a guest, there is no delete button in the app yet. Write to privacy@wonderwhy.net and we will help as far as we can find your data. To do that we may need to ask when you used the app and what you did in it.
Your rights
Depending on where you live, you have some or all of these rights:
- Türkiye (KVKK, Article 11): to learn whether we process your data and request information about it; to learn the purpose and whether it is used for that purpose; to know who it is shared with in Türkiye or abroad; to have it corrected or deleted and have those you shared it with told; to object to a result against you that comes only from automated analysis; and to claim compensation for damage caused by unlawful processing. You can apply to us in writing or by email; we answer within 30 days, free of charge. If you aren’t satisfied, you can complain to the Personal Data Protection Authority (KVKK).
- EEA and UK (GDPR): to access, correct or delete your data; to restrict or object to its use; to receive it in a portable format; to withdraw consent at any time; and to complain to your data protection authority.
- California (CCPA/CPRA): to know what we collect and how we use it, to delete and correct it, and not to be treated differently for using these rights. We don’t sell or share personal information. We use sensitive information, such as your account login, only to provide the service.
To use any of these rights, write to privacy@wonderwhy.net. We may ask you to confirm the request comes from you.
Legal bases
- Providing the service you ask for (account, sync, answering questions, votes): performing our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- Security, misuse prevention, usage limits and logs: our legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Microphone and notifications: your permission, which you can withdraw in the iPhone’s Settings (GDPR Art. 6(1)(a)).
- Legal obligations, where they apply (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)).
Age
The app is for adults. You must be at least 18 to use it: its question and live features use Google’s Gemini API, whose terms don’t allow services aimed at, or likely to be used by, people under 18. If you think someone under 18 has given us personal data, write to us and we will delete it.
This website
wonderwhy.net is a static site hosted by GitHub Pages. It uses no cookies, no browser storage, no analytics and no third-party scripts or fonts. GitHub processes visitors’ IP addresses to deliver the site and keep it secure, under the GitHub Privacy Statement. Audio samples load only when you press play. If you email us, we use your address to reply.
Changes to this policy
We update this page when the app or the law changes, and change the date at the top. For significant changes we will also let you know in the app.
Contact
[Publisher name], [Postal address]
privacy@wonderwhy.net