LULLABOOK
A product of Aid Ignite Sdn. Bhd. · English version (governing)
Privacy Policy
Effective: 21 September 2026 · Last updated: 21 September 2026
The English version of this document governs. Any Bahasa Melayu translation is provided for convenience; if there is any inconsistency between the two, the English version prevails.
1. Who We Are
LullaBook is an AI-powered Islamic bedtime-storytelling app for Muslim families. The app and the website lullabook.io are published and operated by Aid Ignite Sdn. Bhd. (“AidIgnite”, “we”, “us”, “our”), a private limited company incorporated in Malaysia under the Companies Act 2016, company registration no. 202501021377 (1622790-T).
Principal place of business: Domain 3, D-11-03, The Domain, Lingkaran Cyber Point Barat, Cyber 12, 63000 Cyberjaya, Selangor, Malaysia.
Registered office: 38, 3rd Floor, Jalan Radin Anum, Bandar Baru Sri Petaling, 57000 Kuala Lumpur, Malaysia.
For the purposes of Malaysia's Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 (“PDPA”), AidIgnite is the data controller of the personal data described in this Policy. For users elsewhere, AidIgnite is the equivalent “controller” — for example, under Indonesia's Personal Data Protection Law, Law No. 27 of 2022 (“UU PDP”).
Language. Under the PDPA's Notice and Choice Principle, this notice is provided in both English and Bahasa Melayu. The English version governs; if there is any inconsistency between the two versions, the English version prevails.
App languages. LullaBook is currently available in English and Bahasa Melayu. Bahasa Indonesia and Arabic are forthcoming and are shown in the app as “Coming Soon”; they are not yet available for use.
2. How to Contact Us
For all questions about this Policy, and to exercise any privacy or data-protection right, contact us at:
- support@aidignite.io (support, privacy and data-protection requests, and deletion requests)
- Telephone
- +60 11-1556 1156
- Post
- Domain 3, D-11-03, The Domain, Lingkaran Cyber Point Barat, Cyber 12, 63000 Cyberjaya, Selangor, Malaysia
Please mark privacy and data-protection requests clearly — for example, with the subject line “Privacy Request” — so we can prioritise them. We aim to respond to privacy and data-rights requests within 21 days.
Our Data Protection Officer
We have appointed a Data Protection Officer (“DPO”) for LullaBook. The DPO oversees our compliance with the PDPA and the other privacy laws that apply to us, and is the person responsible for handling your privacy questions, requests and complaints.
- Data Protection Officer
- Muhammad Anas Abd Razak, Director, Aid Ignite Sdn. Bhd.
- dpo@aidignite.io
- Post
- Domain 3, D-11-03, The Domain, Lingkaran Cyber Point Barat, Cyber 12, 63000 Cyberjaya, Selangor, Malaysia
You can raise any privacy concern with the DPO directly, in English or Bahasa Melayu. We will acknowledge your message and tell you what we are doing about it.
If you are not satisfied with our answer. You may complain to the Personal Data Protection Commissioner in Malaysia (Jabatan Perlindungan Data Peribadi, JPDP). If you live outside Malaysia, you may also complain to the data-protection authority for your country — for example, the Indonesian authority responsible for UU PDP.
3. A Family App — Who Uses LullaBook
LullaBook is designed for Muslim families: parents and guardians, and their children (typically aged 3–13). Accounts may only be created and managed by a parent or guardian aged 18 or older. Children use the app together with, and under the supervision of, their parent or guardian.
Because we know children use the app, we apply child-protective privacy standards throughout, drawing on the strictest of the applicable regimes — Malaysia's PDPA, the United States Children's Online Privacy Protection Act (“COPPA”) as amended by the Federal Trade Commission's 2025 Rule amendments, and Indonesia's UU PDP.
4. What We Collect, Why, and Our Legal Basis
We collect only what we need to run LullaBook. There is no third-party advertising in the app, we do not sell personal data, and we do not use behavioural advertising.
| Data | Why we collect it | Legal basis (PDPA) |
|---|---|---|
| Account email address; sign-in method (email or Google Sign-In) | To create and secure the parent's account and enable log-in | Performance of contract; consent |
| Parent's birth year | To confirm the account holder is an adult, and for demographic analytics and product improvement. We ask for the year only — never a full date of birth for the parent | Consent |
| Referral source — how you heard about LullaBook, and any accompanying detail you choose to give | To understand which channels bring families to LullaBook, and to operate referral and affiliate codes | Consent |
| Child's first name | To personalise stories (the child becomes the main character) | Parental consent |
| Country and chosen language | To deliver content in the right language for your region | Performance of contract |
| Inferred age range (gender and age band — no date of birth is collected from you) | To keep stories age-appropriate | Parental consent |
| Derived date of birth stored on the profile | This is not a real birth date. It is a value our system calculates from the age range you select, stored in a profile field of that name so the app can apply age-appropriate settings consistently | Parental consent |
| Voice sample and cloned voice (optional, parent-only) | To generate a personalised narrator voice that reads stories in the parent's own voice | Explicit consent (sensitive / biometric data) |
| Content data: generated stories, saved characters, favourites, offline downloads, star ratings, content reports, XP and levels, Story Sparks balance | To provide app features and save your family's progress | Performance of contract |
| Purchase and subscription data (processed by our billing providers) | To manage subscriptions, the free trial, and Story Sparks | Performance of contract; legal obligation |
| Notification preferences (reading-reminder time, on or off) | To send optional reminders you set yourself | Consent |
Data minimisation — no child's date of birth. We deliberately do not collect a child's exact date of birth. We ask only for a broad age range so we can make content age-appropriate; the “derived date of birth” described above is calculated from that range and is not a real birth date. This is a deliberate data-minimisation choice, consistent with the PDPA, COPPA, and the international best practice of collecting no more data than necessary.
5. Children's Data
- Accounts are created and managed by a parent or guardian, who consents on the child's behalf. Under Malaysian law — Regulation 3(3) of the Personal Data Protection Regulations 2013, read with the Age of Majority Act 1971 — a person under 18 cannot give valid consent to the processing of their personal data, so the parent or guardian consents on the child's behalf.
- No behavioural advertising to children. There is no third-party advertising in the app. We never sell personal data — of children or of adults.
- We minimise what we collect about a child: first name and an inferred age band only. No exact birth date, no contact details, no location tracking of the child.
- Consistent with COPPA and the FTC's 2025 COPPA Rule amendments, we provide notice to parents, rely on parent-initiated collection, limit retention to what is reasonably necessary, do not condition use of the app on collecting more data than needed, and give parents the right to review and delete their child's data. Under those amendments, children's “personal information” expressly includes biometric identifiers such as voiceprints — which is one reason the voice-cloning feature is restricted to parents only (see Section 6).
How we check that a parent or guardian is giving consent
We take reasonable steps to satisfy ourselves that the person creating the account and giving consent is an adult with responsibility for the child:
- Age and role declaration. When you create an account you must confirm that you are 18 or older and that you are the parent or guardian of the child whose first name you enter.
- Verified email address. We verify your email address before the account becomes fully active. Any request to see, correct or delete a child's data is accepted only from that verified address.
- Adult age check. We ask for your birth year at sign-up and use it as an age check. An account cannot be completed with a birth year that would make the account holder under 18.
- A second confirmation for voice cloning. Voice cloning is the only feature that involves sensitive data, so we ask you to confirm again, inside the app, that you are the account holder and that the voice you are recording is your own adult voice. Voice cloning also costs Story Sparks, which are obtained only through a subscription, a trial or a purchase made with a payment method held by an adult at the app store.
- No child accounts. We do not knowingly allow a child to create or control an account. If we learn that an account was created or is controlled by someone under 18, we will close it and delete the personal data held under it.
We keep a record of the consent that was given, when it was given, and what it covered. Malaysia is in the process of introducing more detailed rules on verifying parental and guardian consent. If a specific verification method becomes mandatory, we will adopt it and update this Policy.
If you believe a child has given us personal data without a parent's or guardian's involvement, email support@aidignite.io and we will delete it.
6. Voice Cloning and Biometric Data (Optional, Parent-Only)
Voice cloning is strictly opt-in and parent-initiated. It costs 10 Story Sparks per voice, with a limit of 2 cloned voices per account.
- A parent records a short voice sample. We use it solely to create and operate a personalised narrator voice that reads stories in the parent's own voice.
- Cloned voices are private by design. They are never shared with other users and are never attached to any story that becomes public. Stories in the public library always use standard narrators.
- We treat the voice sample and the resulting voiceprint as sensitive personal data. The PDPA 2024 amendments brought biometric data expressly within the definition of sensitive personal data, requiring explicit consent and heightened security. We apply the same standard for all users, wherever they live.
- Purpose limitation. The voice sample is used only for your narrator voice. It is never used for advertising, for profiling, or to identify your child.
- No training on your voice. We do not use your voice sample or your cloned voice to train or improve any model, and our contracts with our speech-technology providers prohibit them from doing so.
- Children's voices are never cloned. The feature is available only to the adult account holder, for their own voice.
Deleting a cloned voice
You can delete a cloned voice at any time in the app. When you do:
- We delete the voice sample, the generated voice, and every narration created with it from the systems we control. We do this immediately, and in any event within 7 days.
- We send a deletion instruction to our speech-technology provider within 7 days of your request, and we keep a record that we did so.
- Our contracts with speech-technology providers require them to delete voice data when we instruct them to, and prohibit them from using it for any purpose other than generating narration for you.
- Because those providers operate their own systems, we cannot control the exact moment deletion completes on their side. As soon as a provider gives us a committed deletion timeframe in writing, we will state that timeframe here.
A cloned voice and its voice sample are also deleted when you delete your data or delete your account. See Section 10.
7. Service Providers (Processors) and Sub-Processors
We use a small number of trusted providers to run LullaBook. They process personal data only on our instructions and only to deliver the service. Under the PDPA 2024 amendments, data processors also carry direct statutory security obligations, and we additionally bind our processors by contract. Our current sub-processors, by category:
- Database, hosting and authentication: Supabase — database, hosting and authentication.
- Email: Resend — transactional and support email, for example verification, reminder and support messages.
- Subscriptions and payments: RevenueCat — subscription management; Google Play Billing and Apple In-App Purchase — payment processing. AidIgnite never sees or stores your card number.
- AI generation: Third-party AI model providers, used server-side to generate story text, story illustrations, and voice narration including voice cloning.
About AI inputs. Inputs such as the child's first name, story preferences, and the parent's voice sample may be processed by these AI providers strictly to generate your stories and narration. They are not used to build advertising profiles and are not used to identify your child. Our AI providers do not receive your email address, your payment details, or any contact details for your child.
No training on your family's data. Our contracts with our AI providers, or the terms on which we use their services, prohibit them from using the content you and your child put into LullaBook, or the content generated for you, to train or improve their own models.
Ask us who they are
We describe our AI providers by category here so that this Policy stays accurate when we change or add a provider. The current list of named providers is available to you on request: email support@aidignite.io with the subject line “Sub-processors” and we will send you the up-to-date list. The list we send is always current, even if this page has not changed.
Changes to our providers. If we add or change a sub-processor in a way that materially affects how your family's data is handled, we will update this Policy and tell you in the app or by email before the change takes effect.
8. Cross-Border Transfers
Some of our providers process personal data outside Malaysia — for example, cloud hosting, email delivery and AI generation.
Section 129 of the PDPA, as amended with effect from 1 April 2025, allows a transfer outside Malaysia where the receiving country provides a comparable level of protection, or where one of the conditions set out in Section 129(3) applies. For our transfers we rely on the following, and we record which one applies to each provider:
- Due diligence and contractual safeguards — our primary basis. Before we appoint a provider we assess how it protects personal data. We then put a written data-processing agreement in place requiring the provider to apply protections equivalent to those the PDPA requires, to process data only on our instructions, to keep it secure, and to delete or return it when we ask.
- Necessary to perform our contract with you. Where the transfer is needed to deliver something you have asked for — generating a story, producing narration, sending you a verification email, or managing your subscription.
- Your explicit consent. Additionally, for the voice sample and cloned voice, which we treat as sensitive personal data.
We assess our transfers before we make them. Before we begin using a new offshore provider, we carry out and record a written transfer assessment covering the data involved, the country it goes to, the safeguards in place, and the risks to your family. We assess our transfers against the Commissioner's Cross-Border Personal Data Transfer Guidelines issued in April 2025, we review each assessment at least once a year, and we review it again whenever we change provider.
You can ask us which countries your family's data is transferred to. Email support@aidignite.io.
9. Security
- All AI calls and all wallet or payment changes happen server-side — never on the phone.
- No API keys are shipped inside the app.
- Users cannot edit their own Story Sparks or wallet balances.
- Personal data is encrypted in transit (HTTPS) and at rest.
- Access to production data is limited to the people who need it to run the service.
No system is perfectly secure, but we design LullaBook so that the most sensitive operations never leave our servers.
10. Data Retention and Deletion
We keep personal data only as long as needed for the purposes described in this Policy, or as long as the law requires. We do not keep a child's personal data indefinitely.
How long we keep things
| What | How long we keep it |
|---|---|
| Parent's account data — email address, sign-in method, birth year, country, language, referral source | For as long as your account is open |
| Child's first name, age range and derived date of birth | For as long as your account is open, or until you ask us to delete your data |
| Stories, characters, favourites, offline downloads, ratings, XP and level progress | For as long as your account is open, or until you ask us to delete your data |
| Voice sample and cloned voice | Until you delete the voice, delete your data, or delete your account |
| Notification and reminder preferences | For as long as your account is open |
| Transaction and tax records relating to purchases | 7 years, because Malaysian law requires it |
| Support and privacy correspondence | 24 months from the date the matter is closed |
Inactive accounts. If you do not sign in to LullaBook for 24 months, we will email you at the address on the account and then close the account and delete the personal data held under it, other than the records we are required by law to keep.
Delete your data, or delete your account
You have two separate options. You can delete your data while keeping your account, or delete your account entirely:
| Delete Data | Delete Account | |
|---|---|---|
| Your account | Stays active | Permanently closed |
| Your stories, characters and favourites | Deleted | Deleted |
| Cloned voice and voice sample | Deleted | Deleted |
| Can it be undone? | No | No |
| Full instructions | lullabook.io/delete-data | lullabook.io/delete-account |
How to make a request. In the app: open Profile → Account, then choose Delete My Data or Delete Account. From anywhere, including after you have uninstalled the app: email support@aidignite.io with the subject line “Data Deletion Request” or “Account Deletion Request”, from the email address on the account.
Timing. We confirm and complete deletion within 30 days of receiving a verified request.
What we delete. Personal data held in the systems we control, including the child's first name, the age range and derived date of birth, saved characters, generated stories, favourites, offline downloads, ratings, XP and level data, notification preferences, and any cloned voice and voice sample.
Copies held by our providers. Where a third-party provider holds a copy — for example a speech-technology provider holding a cloned voice — we send it a deletion instruction within 7 days of your request and keep a record that we did so. Our contracts require those providers to delete the data on our instruction. Because they operate their own systems, we cannot control the exact moment deletion completes on their side.
What we keep, and why. We retain only what the law requires us to keep. In practice this means transaction and tax records relating to purchases, which Malaysian law requires us to retain for seven years. Anything retained on this basis is stored securely, is not used for any other purpose, and is deleted at the end of the retention period. Deleted data may persist briefly in routine encrypted backups, which are overwritten on our normal backup cycle.
Subscriptions. Deleting your account does not cancel a paid subscription. Cancel your subscription in your Google Play or Apple App Store settings before deleting your account. See the Terms of Use, Section 4.
12. Data Breach Notification
If a personal data breach occurs, we will act in line with Section 12B of the PDPA and the Commissioner's Data Breach Notification Guideline, in force since 1 June 2025. We will notify the Personal Data Protection Commissioner as soon as practicable and no later than 72 hours after the breach occurs. Where the breach causes or is likely to cause significant harm, we will notify affected users without unnecessary delay and within 7 days of notifying the Commissioner. We maintain an internal breach register.
13. Your Rights
Depending on where you live, you — and, for a child, the parent or guardian — may:
- Access the personal data we hold about you and your child;
- Correct inaccurate or incomplete data;
- Withdraw consent to processing that is based on consent, and delete the child's name, a cloned voice, or the account;
- Port your data — ask that your data be transmitted to another controller, where technically feasible (a right introduced by the PDPA 2024 amendments);
- Object to or limit certain processing.
To exercise any right, email support@aidignite.io with the subject line “Privacy Request”, or contact our DPO at dpo@aidignite.io. We aim to respond within 21 days. Exercising a right is free; we will tell you in advance if a request is repetitive or excessive and we need to charge a reasonable fee.
Indonesian users have equivalent rights under UU PDP, under which children's data is “specific” (sensitive) personal data whose processing requires parental or guardian consent. If LullaBook becomes available in the EU or the UK, users there would additionally hold the rights conferred by the GDPR and UK GDPR, and we would apply the UK Age Appropriate Design Code to child users.
14. Changes to This Policy
We may update this Policy from time to time. For material changes we will notify you in the app and by email before the changes take effect, and we will update the “Last updated” date above.