Privacy Policy
Bonbon ("the app") is operated by IE Jarvis, Almaty, Kazakhstan ("we"). Bonbon is a video app for children that parents set up and control. This policy explains what information the app handles and how. The short version: we collect the minimum needed to run the app, we show no third-party ads, and we never sell personal data.
Information we collect
- Parent account (optional). If a parent chooses to sign in — with email, Google, Apple, or Facebook — we store the parent's email address, an optional display name, and sign-in identifiers from the chosen provider. An account is not required to use the app.
- Child profile details a parent adds. A name or nickname, age, and preferred language for each kid profile. These stay linked to random identifiers, not to any child's real-world identity, and we never collect information directly from children.
- Usage data. Which videos were played and basic app events (e.g., searches, screen-time settings), tied to a random installation identifier. We use this to run the catalog, improve recommendations, and produce the weekly activity report for parents.
- Device data. Device model, iOS version, app version, language, and timezone; a push-notification token if the parent enables notifications; crash reports (via Sentry) to fix bugs.
What we do NOT do
- No third-party advertising in the app, and no behavioral advertising of any kind.
- No sale or rental of personal data.
- No tracking across other companies' apps or websites: the app does not use the advertising identifier (IDFA) and does not request App Tracking Transparency because it does not track. Install attribution for our own ads uses Apple's aggregated SKAdNetwork, which shares no personal data with us or anyone else.
- No accounts, purchases, or external links for children. The parent area is gated.
Children's privacy
Bonbon is made for families. Parents set up the app; children only watch videos from a reviewed catalog. We do not knowingly collect personal information from children. Everything stored about a kid profile is entered by the parent and remains under the parent's control, including deletion at any time.
Where data is processed
Our servers are hosted on Railway (data stored in the United States). Sign-in verification is performed with the provider a parent chooses (Google, Apple, or Facebook); we receive only the account identifier, email, and name from the provider — never passwords.
Delete your account & data
In the app: Parent area → unlock → Delete account (or Delete app data to wipe content history without an account). This removes your account, kid profiles, and viewing history from our servers.
By email: send a request to [email protected] from the address linked to your account, and we will delete the associated data.
Data retention & security
Account and usage data are kept while the account or installation is active and removed on deletion as described above. Session credentials are stored using industry-standard hashing; transport is encrypted (HTTPS).
Changes & contact
If this policy changes materially, we will update this page and the date above. Questions: [email protected].