Ask Agam
Privacy Policy
Last updated: June 15, 2026
The short version: Ask Agam is a voice app where children talk with Agam, a voice-first companion. We collect the minimum needed to make her remember conversations across sessions. We do not store voice recordings. Children's data is never shared with anyone for advertising. When a parent installs from a Facebook or Instagram ad and opts in to App Tracking Transparency during onboarding, we send a small set of parent-only events (install, onboarding completion, subscription) to Meta so Meta can measure the ad — kids' sessions never touch this. Parents can decline ATT or delete everything anytime.
Who we are
Ask Agam is operated by Tomer Saar ("we", "us"). For privacy questions, contact hello@askagam.com.
What we collect
From the parent during onboarding:
- The child's first name (provided by you, the parent)
- A 4-digit PIN you set to protect parent settings
- Parent email address (required) and phone number (optional) for account recovery
- Apple ID (Apple's payment system handles this — we do not see your credit card)
From the device:
- A randomly-generated device identifier (we never link this to your real identity)
From conversations:
- Text transcripts of conversations between your child and Agam (stored for 30 days, then auto-deleted)
- A short "memory note" Agam writes about each conversation (e.g., "loves hard puzzles, finished magic square fast") — kept until you delete it
- App diagnostic events (which puzzles were shown, session length, errors) — kept for 30 days
What we do NOT collect:
- Voice recordings — audio is processed in real time and discarded
- The child's full name, address, photos, videos, or biometrics
- Location data
- Any tracking identifier from your child's session — IDFA, fingerprints, behavioral profiles, all off-limits during the kid-facing parts of the app
Ad attribution (parent only)
If you found Ask Agam through a Facebook or Instagram ad, we want to know that — so we can show Ask Agam to other parents like you. Here's exactly how that works and what it touches:
- Only during your (the parent's) onboarding. The Meta SDK is initialized when the app launches, and it is configured to send nothing automatically. We manually fire three events: an install ping when the app opens for the first time, a "completed registration" event when you finish setting up, and a "subscribe" event if you start a subscription. That's it.
- Your child's sessions are not part of this. Voice conversations, transcripts, memory notes, session lengths, puzzle outcomes — none of these are sent to Meta. They live in our infrastructure (and Mixpanel for product analytics, see below) and never leave it for advertising.
- You decide whether IDFA is shared. Right after you grant the microphone permission, iOS shows the App Tracking Transparency prompt. If you allow tracking, your IDFA travels with the parent events above so Meta can deterministically link your install to the ad you saw. If you decline (or never installed from an ad), Meta falls back to Apple's privacy-preserving SKAdNetwork, which is aggregate-only and contains no per-user data.
- What Meta gets, in plain terms. A hashed copy of the parent email you entered, the IDFA (only with your ATT consent), and the three event names above. No kid name, no kid age, no transcripts, no audio, no behavior data.
Why we collect it
- So Agam can remember. Each conversation builds on the last. The memory note is what makes Agam feel like a real ongoing relationship, not a chat session.
- To run the app. Device ID and signed requests prevent abuse and keep your child's data tied to your device.
- To improve quality. We review aggregated diagnostic data (e.g., which puzzles fail) to fix bugs.
- For safety alerts. If a parent provides an email or phone, we use it only to alert the parent if a session contains content that suggests distress or danger, or for account recovery.
How we collect it
We process voice input through ElevenLabs Conversational AI, which transcribes speech to text in real time. The audio stream is processed live and not retained by us. ElevenLabs may briefly buffer audio for processing — see ElevenLabs' Privacy Policy.
How we share it
We do not sell, rent, or share your child's data with third parties for marketing, advertising, or analytics. The third parties involved fall into two groups:
Infrastructure providers — required to run the service. None of them are permitted to use your child's data for advertising or model training, and they are bound by data processing agreements requiring COPPA-compliant handling.
- ElevenLabs (voice processing) — see their privacy policy
- Amazon Web Services (data storage) — encrypted at rest, US East region
- Apple (payment processing) — see Apple's privacy policy
- Cloudflare (DNS and email forwarding) — see Cloudflare's privacy policy
- Mixpanel (product analytics) — receives diagnostic events about app use, including the kid's session length and which features were used. Bound to product-analytics use only; cannot use the data for cross-app advertising.
- Google Analytics (website analytics, askagam.com only) — receives anonymized page-view data from visits to our marketing site (pages viewed, country/region, device type, referring source). IP addresses are anonymized at collection. Google Analytics is not present in the iOS app and never receives data about your child or their sessions.
Advertising partner — parent events only
- Meta (Facebook/Instagram) — receives the three parent-only events described in Ad attribution (parent only) above. Used solely to measure the effectiveness of Ask Agam's ad campaigns and to find similar parents who would benefit from Ask Agam. Meta is contractually bound by their Business Tools Terms; we do not send children's data to Meta and the SDK is configured to disable automatic event collection.
How long we keep it
- Voice audio: not stored. Discarded after real-time processing.
- Conversation transcripts: auto-deleted after 30 days.
- Memory notes: kept until you delete them or close the account.
- Diagnostic events: 30 days.
- Account and subscription records: kept until account deletion plus standard tax and legal retention (typically 7 years for receipts).
Your rights as a parent
Under COPPA and applicable privacy laws, you have the right to:
- Review your child's data — open the parent settings (PIN-protected) in the app, then "Privacy".
- Delete your child's data — same place, "Delete All My Child's Data" button. Erases memory, transcripts, sessions, and the device record. The app resets.
- Refuse further collection — uninstall the app, or delete the data and do not restart sessions.
- Get a copy — email hello@askagam.com and we will send a JSON export within 7 days.
Verifiable Parental Consent
Before your child uses Ask Agam, we require Verifiable Parental Consent through Apple's payment system. The parent enters their Apple ID and accepts the subscription terms (including a 7-day free trial). Apple verifies the parent's identity through their existing account. This method satisfies the FTC's COPPA "credit card transaction" verification standard.
Security
- All data is transmitted over HTTPS / WSS (TLS 1.2+).
- Storage is encrypted at rest (industry-standard encryption).
Children's Online Privacy Protection Act (COPPA)
Ask Agam is designed for children under 13. We comply with COPPA. We collect only the personal information needed to operate the service. We never use children's data for advertising or share it with anyone outside the operational service providers listed above. The parent-only ad attribution flow described in Ad attribution (parent only) involves the parent's events and identifiers (collected with parental consent during onboarding) — never the child's. Parents have full control over their child's data and can delete it at any time.
App Tracking Transparency
During parent onboarding, immediately after you grant the microphone permission, iOS shows the App Tracking Transparency (ATT) system prompt. This is one decision the parent makes; the child never sees it. The choice controls one thing: whether your IDFA (Apple's per-device advertising identifier) is shared with Meta together with the three parent-only events listed earlier.
- Allow: Meta gets your IDFA, can deterministically attribute your install to the ad you saw, and ad measurement is more accurate. The IDFA is the parent's, on the parent's device, before any kid session.
- Decline: No IDFA leaves the device. Meta still receives the three parent events for measurement, falling back to Apple's SKAdNetwork (privacy-preserving aggregate, no per-user data). Nothing about your child's app use is affected either way.
You can change your mind at any time in iOS Settings → Privacy & Security → Tracking → Ask Agam.
International transfers
Data is stored in the United States (AWS us-east-1). If you are outside the US, data may be transferred there. By using the app, you consent to this transfer.
Changes to this policy
If we make material changes, we will notify subscribed parents via the email associated with their Apple ID and post a notice in the app. The "Last updated" date at the top reflects the most recent revision.
Contact
Questions, requests, or complaints about your child's privacy:
hello@askagam.com
We respond within 7 days.