Privacy
Last changed 13 September 2026.
The short version: we keep what an account needs to work, we measure nothing unless you say yes, we never take a single measurement from a child's profile, and you can take your data away or have the whole account deleted from inside the app or from this website.
Who we are
Aviary Radio is a small studio that makes narrated audio and an Android app to listen to it. For anything on this page, write to [email protected]. A postal address and the name of the company responsible will be added here before the app is published.
What we keep, and why
| Your account | Email address, first and last name, and a password that is stored only as a hash we cannot reverse. If you sign in with Google we keep the account identifier Google gives us so we can recognise you next time, and the email address and name it returns. We keep whether your email has been confirmed. |
|---|---|
| The listeners in your house | Each profile's name, which audience it is for (children, grown-ups), and whether it is the main one. If you set a four-digit PIN we store it hashed, never in a form we can read back. |
| Listening | Per listener: the queue, how far into a title each listener has reached, saved titles, shelves and series followed, which titles have been played and when, and download permissions while a membership is running. This is what makes the app resume where you were and show what is finished. |
| Membership | Whether a membership is running, which plan, when it renews or ended. Payment happens inside Google Play. We never see a card, and we never receive a card number, an expiry date or a billing address. |
| Notifications | The device token Google gives the app for push messages, which kinds of notification you want, and the quiet hours you set. |
| Requests and messages | Stories you ask for on the request board and the votes you cast, messages you send us, and reports about a problem with a title. |
| Errors | When the server or the app fails, we record the type of failure and where in the code it happened. These reports carry no account identifier, no request body and no file paths from our machines, and database errors have their message stripped because a message can quote your data. |
| Measurements, only if you agree | The app asks once, plainly, whether we may count how the app is used. If you decline, or never answer, nothing is sent. If you agree you can change your mind at any time under You in the app, and the counting stops. |
Children
Aviary Radio is bought and set up by a grown-up. A child listens through a profile inside your account; a child does not have an account of their own, cannot sign in on their own, cannot write to us, cannot post on the request board and cannot buy anything.
No measurement is ever taken from a child's profile. That is not a setting, it is how the app is built: even with an account that has agreed to measurement, nothing is recorded while a children's profile is the one listening. What we do keep for a child's profile is the name you gave it, the audience you chose, its queue and the places it reached in a story.
Once a children's profile exists, a four-digit PIN is required. It keeps the grown-ups' side of the house, the account settings, deletion and buying, behind the PIN.
Who else sees anything
We use a small number of companies to run the service. None of them is allowed to use your data for anything of their own.
| Cloudflare R2 | Stores audio files, cover art and the data exports we make for you, in the European Union. Files are never public: the app is handed a link that works once and expires. |
|---|---|
| Cloudflare Turnstile | Checks that the contact form on this website is filled in by a person. It runs on the contact page only, and only when you open that page. |
| PostHog (EU) | Receives the usage counts you agreed to, and the error reports described above, on servers in the European Union. Never anything from a child's profile. |
| Resend | Sends our email: confirming an address, resetting a password, membership notices, the link to your data export, and the note that an account has been closed. |
| RevenueCat | Keeps track of whether a membership is running, on top of Google Play. It receives your account identifier, which is a random string, not your name or address. |
| Google Play and Firebase | Google Play takes the payment and tells us a membership started, renewed or ended. Firebase Cloud Messaging carries push notifications to the device. Google's own terms cover what Google does with the purchase. |
| ElevenLabs | Our narrators' voices are produced in the studio with speech technology from ElevenLabs, before a title is ever published. It is part of making the audio, not part of the app: nothing about you, your listeners or your listening is ever sent to it. |
The servers, the database and the file storage are in the European Union. Some of the companies above are American and may process data outside the EU under the standard contractual terms their own agreements set out.
How long we keep things
Account and listening data stay while the account exists. A data export is deleted from storage 24 hours after it is made. When a membership ends, the extra listeners in a household are kept for seven days and then removed, with an email at the start and at the end of that week. Deleting your account removes the rest, as described below.
Getting your data
Under You, the app builds a copy of everything your account holds: the account, the listeners, the listening history and positions, the saved and followed lists, the requests and votes, the notification settings, and the messages and reports you sent. It arrives as a link by email that works for 24 hours. One export a day.
Deleting your account
There are two ways, and both do exactly the same thing.
- In the app, under You: ask to delete the account. Behind the PIN if the household has one.
- On this website: aviaryradio.com/account/delete. Type the address the account uses and we email a link that lasts half an hour. Owning the address is the proof.
Deletion, once confirmed, does all of this:
- Every sign-in token is revoked, so every device is signed out.
- If a membership bought through Google Play is still running, we ask Google Play to cancel it through RevenueCat so it does not renew. There is no refund for time already paid for. If that cancellation cannot be completed, the deletion still goes ahead and the last email we send tells you to cancel it yourself under Subscriptions in the Play Store.
- Every listener in the household is deleted, with their queues, positions, saved lists, follows and play history.
- Devices, push tokens and notification settings are deleted.
- Anything you posted on the request board stays on the board, with your name removed from it, so the counts and the discussion do not fall apart.
- Reports you sent us about a title keep their description of the fault, without your name, so the studio can still fix it.
- Messages you sent us are deleted with the account.
- The account itself is deleted, and one last email goes to the address that is leaving.
Backups of the database are taken nightly and kept for a short period; a deleted account disappears from those as they age out. Error reports, which carry no identifier, are not searchable by account and are not deleted.
Your rights
You can ask for a copy of your data, correct it, have it deleted, object to what we do with it, or withdraw the consent you gave for measurement. Most of that is a button in the app. For anything else, write to [email protected]. If we handle it badly you can complain to your national data protection authority.
This website
These pages set no cookies, run no measurement and load nothing from anyone else, which is why you are not being asked about cookies. The one exception is the contact form, which loads Cloudflare Turnstile to check that a person is filling it in.
Changes
When this page changes in a way that matters, we say so in the app before the change takes effect. The date at the top always says when it was last touched.