Privacy Policy
Playful Software, Inc. · Effective September 3, 2026 · Replaces the version dated January 2026
The short version
This summary is here to help you read the policy. It isn't a substitute for it, and if the two ever differ, the full policy controls.
- What we collect: your account details, what you build, including prompts and Apps, the data your Apps store, billing details through our payment processor, and information about how you use Playful.
- What we do with it: run Playful, build and host your Apps, bill you, keep the Service secure, and improve it. We may analyze prompts and other interactions with the creator platform to improve Playful, but we don't use them to train or fine-tune generative AI models. We don't use App Data to improve Playful, sell personal information, or use it for targeted advertising.
- AI providers: your prompts and app content are sent to AI providers such as Anthropic, Google, and OpenAI, and to hosting providers that run models such as DeepSeek, to generate results. They process what we send under their own published terms, not agreements negotiated with Playful. None of them use prompts or results to train their own models, though they may retain data for a limited time for safety, legal, or service-specific reasons.
- Apps built on Playful: the person who built an app decides what it collects. We host it on their behalf. If you're using someone else's app, that person is your first point of contact for privacy questions.
- Personal health information: personal Apps, and Apps a Creator uses in their own work under our Terms of Use, may store medical and wellness information as App Data. An App used in a Creator's work may not store protected health information regulated by HIPAA. Playful is not a HIPAA-compliant or HIPAA-eligible service and may not be used on behalf of a healthcare provider, health plan, or anyone else when doing so would require Playful to handle protected health information under HIPAA.
- Kids and teens: Playful accounts and creator tools are for adults 18 and older. Apps may not target children under 13, except that a parent or legal guardian may build a private Family App for their own child under our Terms of Use. Apps using Playful-provided AI may not target or knowingly serve anyone under 18 unless Playful approves appropriate safeguards.
- Your choices: you can access, correct, export, or delete your information. Email contact@playful.app.
1. Who we are and what this policy covers
Playful Software, Inc. ("Playful", "we", "us", or "our") makes a platform that lets people create apps with the help of AI. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. It applies to the playful.app website, the Playful platform, the apps we host, and our communications with you (together, the "Service"). It doesn't cover third-party services, including the AI providers described in Section 5, which have their own privacy policies.
Some capitalized words have specific meanings, and they match the ones in our Terms of Use:
- "App" is an application created using the Service. A "Creator" is a user who creates, edits, or publishes an App, and an "End User" is anyone who uses an App, whether or not they have a Playful account.
- "Input" is anything a user submits to the Service, such as prompts, text, images, files, code, and data. "Output" is what the Service generates in response.
- "App Data" is data that an App stores or processes, including information End Users submit to an App.
- "Platform Content" means a Creator's Input, Output, Apps, and the code, design, configuration, and content created through Playful's creator-facing features, but excludes App Data.
- "Your Content" means your Platform Content and your App Data.
- "AI Providers" are the third-party companies whose AI models power the Service, such as Anthropic and OpenAI, and any others we use from time to time.
Playful plays two different roles, and it helps to know which one applies to you:
- If you have a Playful account (for example, as a Creator), we decide how your personal information is collected and used, and this whole policy applies to you.
- If you use an App that someone else built, the Creator of that App decides what it collects and why. We process App Data on the Creator's behalf as their service provider or "processor." Section 2 explains what that means for you.
2. If you use an app someone else built
When you use an App built by a Creator, the Creator is responsible for that App and for the information it collects from you. Creators agree in our Terms of Use to give you the privacy notices the law requires, obtain any necessary consents, and honor your privacy rights. Playful hosts the App and stores its App Data on the Creator's behalf, following the Creator's instructions, our Terms of Use, and our Data Processing Addendum. We use App Data only to host, operate, maintain, secure, and support the App; provide features and respond to requests the Creator initiates; investigate abuse, fraud, or security incidents; comply with law; and follow the Creator's other documented instructions. We don't use App Data to improve Playful or to train or fine-tune generative AI models.
Separately from the App itself, we collect a limited amount of technical information whenever anyone visits an App we host, such as IP address, browser and device details, and server logs (see Section 3.2). We use that information for our own purposes of running and securing the platform, as described in this policy.
If you have questions about an App's privacy practices, or want to access, correct, or delete information you gave an App, please contact its Creator first; they control the data and are best placed to help. If you can't reach the Creator, or you believe an App violates our rules, contact us at contact@playful.app and we'll forward your request to the Creator or take action ourselves where appropriate.
If an App includes AI features, what you type into them is sent to our AI Providers on the Creator's behalf and handled as described in Section 5.
3. Information we collect
3.1 Information you give us
- Account and profile information. Your name, email address, password, and any profile details you choose to add, such as a display name or avatar. If you sign in using a third-party account (for example, Google or Apple), we receive the information that provider shares with us, such as your name and email address.
- Billing information. If you buy a paid plan or credits, our payment processor collects your payment details. We receive limited information such as your name, billing address, the type and last four digits of your card, and the status of your payments. We don't store full payment card numbers.
- Platform Content. The prompts and instructions you write, the files and images you upload, the web addresses you ask the AI to read, the code and other Output the Service generates for you, and the Apps you build through Playful's creator-facing features.
- App Data. Information that your Apps store or process, including information your End Users submit. We process personal information in App Data on the Creator's behalf under our Data Processing Addendum.
- Communications. Messages you send us, support requests, survey responses, and feedback.
3.2 Information we collect automatically
- Device and log information. IP address, browser type and version, operating system, device identifiers, language settings, referring pages, the pages and features you use, timestamps, and error and crash reports. We collect this when you use the Service and when anyone visits an App we host.
- Usage information. How you use the Service, such as the features you use, the number and type of AI actions you run, credits consumed, Apps created and published, and aggregate traffic to your Apps.
- Approximate location. We may infer a general location (such as city or country) from your IP address. We don't collect precise geolocation.
- Cookies and similar technologies. See Section 8.
3.3 Information from other sources
- Sign-in and integration providers. If you sign in with, or connect, a third-party service, we receive the information you authorize that service to share.
- Payment processors. Confirmation of payments and fraud signals.
- Analytics providers. Aggregated and event-level usage information, as described in Section 8.
4. How we use information
We use the information we collect to:
- Provide the Service. Create and manage your account, generate and edit Apps using AI, host and run your Apps, store App Data, and deliver the features you use.
- Process payments. Bill you for plans and credits, track credit usage, and prevent fraud.
- Communicate with you. Send service and account notices (such as security alerts, billing messages, and changes to our terms), respond to your requests, and, if you haven't opted out, tell you about product updates and features.
- Keep the Service safe. Detect, investigate, and prevent abuse, fraud, security incidents, and violations of our Terms of Use and Platform Rules, including by using automated tools and the safety systems of our AI Providers.
- Improve and develop the creator platform. Analyze Platform Content and creator interactions, including prompts, Output, project files, feature usage, and feedback, to evaluate quality, debug problems, improve workflows, and develop new features. This may involve automated analysis and limited access by authorized personnel. We do not use App Data for this purpose.
- Comply with the law. Meet our legal, tax, accounting, and regulatory obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
- Do things you ask us to do. For example, connect an integration you choose or share an App you decide to publish.
We don't use Platform Content or App Data to train or fine-tune generative AI models. Product improvement described above is separate from model training. AI Providers process what we send them under their own published terms. None of the AI Providers or model hosts we use train or improve their models on the inputs and outputs we send them, and we don't opt your content into any provider's training program. Section 5 explains which providers we use and where they are. We don't sell personal information, and we don't use it for targeted advertising.
Legal bases (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases: performance of a contract (to provide the Service under our Terms of Use); legitimate interests (to secure and improve the Service, prevent fraud and abuse, communicate with you, and run our business, where those interests aren't outweighed by your rights); consent (for non-essential cookies and marketing messages, which you can withdraw at any time); and legal obligations. We don't make automated decisions that have legal or similarly significant effects on you.
5. AI providers
The Service generates Apps by sending your Input, along with the relevant parts of your Platform Content (such as the current code and files of the App you're working on), to one or more AI Providers, which return Output. If a Creator builds AI features into an App, End Users' inputs to those features are App Data and are sent to AI Providers on the Creator's behalf. App AI features currently use Anthropic models only. Our current AI Providers include Anthropic, Google, and OpenAI. We also use DeepSeek models. Third-party hosts run them for us, and requests aren't sent to DeepSeek itself. We reach those hosts through OpenRouter, a routing service that sends each request to one of several hosts offering the selected model. The current list is on our Subprocessors page, and we may add, remove, or switch providers as described in our Data Processing Addendum.
Here's what you should know about how AI Providers handle your information:
- They process data under their own terms. We don't have negotiated agreements with AI Providers. They process what we send under their published API terms and privacy policies, which we don't control and which can change. We can't guarantee that their services will never change or experience an incident.
- They don't train on what they receive. None of the AI Providers or model hosts we use retain the prompts, content, or results they handle for training, or use them to train or improve their models. We don't opt your content into any provider's training program.
- They may keep data for a limited time. AI Providers may retain inputs and outputs for a limited period to detect abuse, enforce their policies, and comply with the law, and their automated safety systems may review or flag content.
- They are in the United States and other countries. Anthropic, Google, and OpenAI are based in the United States. A request sent through OpenRouter may be answered by a host in the United States or another country. Data sent to AI Providers may be processed in any of those places.
- Web pages you ask the AI to read. If you give the AI a web address, we send that address to a web-fetching service, which retrieves the page and returns its content and a screenshot to us. The retrieved content is then sent to an AI Provider together with your Input, and is handled as described above.
- Only include what's needed. Please don't put personal information about yourself or others into prompts or Apps unless it's necessary for what you're building, and never include Restricted Data (see Section 7).
We rely on our AI Providers' built-in safety systems to help prevent misuse of AI features; we don't independently review Input or Output before it's delivered.
6. How we share information
We share personal information only in these situations:
- Service providers. Companies that help us run the Service, including cloud hosting and infrastructure providers, AI Providers (Section 5), payment processors, email and messaging providers, analytics providers, customer support tools, web-fetching services that retrieve pages you ask the AI to read, and security and fraud-prevention services. They may use personal information only to provide services to us and are bound by contractual obligations to protect it.
- Creators. If you use an App, the information you submit to it (App Data) is available to the Creator of that App, who is responsible for it as described in Section 2.
- Other users and the public. If you publish or share an App, its content is visible to the people you share it with or, for public Apps, to anyone. Your display name or other profile details may appear alongside Apps you publish, depending on the features you use.
- Legal reasons and safety. When we believe in good faith that disclosure is necessary to comply with a law, regulation, legal process, or government request; to enforce our Terms of Use; to detect or address fraud, abuse, or security issues; or to protect the rights, property, or safety of Playful, our users, or the public. This includes reporting apparent child sexual abuse material to the National Center for Missing & Exploited Children and cooperating with law enforcement.
- Affiliates. Companies in our corporate group, now or in the future, that help us provide the Service, which must handle personal information in line with this policy.
- Professional advisors. Lawyers, auditors, accountants, insurers, and similar advisors, where needed for the services they provide to us.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, insolvency, receivership, or sale of all or part of our business, personal information may be transferred to the successor or to those involved in the transaction, subject to this policy.
- With your direction or consent. For example, when you connect a third-party integration or ask us to share information.
- Aggregated or de-identified information. We may share information that doesn't identify you, such as usage statistics.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We don't run third-party advertising on the Service.
7. Sensitive information and HIPAA
Personal Consumer Health Data is allowed as App Data. A personal App, or an App a Creator uses in their own work under our Terms of Use, may store or process medical, mental-health, wellness, medication, symptom, disability, or genetic information about its Creator or End Users. An App used in a Creator's work may not store or process protected health information regulated by HIPAA. We process that information on the Creator's behalf under our Data Processing Addendum. We don't use it to improve Playful or to train or fine-tune generative AI models.
Health information placed in a creator prompt, project file, feedback message, or other creator-facing feature is Platform Content rather than App Data. Platform Content may be analyzed to operate, secure, evaluate, and improve Playful as described in Section 4. Creators who want personal health information handled as App Data should store it through the running App rather than put it in creator-facing prompts or project files.
The Service is not offered as a HIPAA-compliant or HIPAA-eligible service. Playful does not enter into business associate agreements. Creators may not use Playful for or on behalf of a healthcare provider, health plan, healthcare clearinghouse, employer health plan, business associate, or another person when doing so would require Playful to create, receive, maintain, or transmit protected health information under HIPAA. Whether information is protected health information and whether an entity is a covered entity or business associate depend on the actual facts and relationships, not merely an App's label or whether it is free.
Our Terms still prohibit Restricted Data, including payment-card and financial-account information, government identification numbers, biometric identifiers, precise geolocation used to track people, third-party credentials, personal information of children under 13 (except in a Family App built by the child's parent or guardian under our Terms of Use), HIPAA-regulated protected health information, and information requiring a compliance framework Playful does not offer. Other sensitive information is permitted as App Data for lawful personal purposes, or for a Creator's own work as permitted by our Terms of Use, subject to applicable notice, consent, security, deletion, and other requirements.
Consumer Health Data that falls outside HIPAA may be protected by other laws, including the FTC Health Breach Notification Rule and state consumer-health privacy laws such as Washington's My Health My Data Act. The Creator determines what an App collects and is responsible for providing required notices, obtaining required consent, and honoring End User rights. Playful processes App Data under the DPA and assists as required there. If we learn that an App is processing prohibited data or operating in a prohibited regulated context, we may restrict access, securely return or delete affected data where appropriate, disable the App, or suspend the account.
8. Cookies and analytics
We and our service providers use cookies, local storage, and similar technologies for these purposes:
- Essential. Signing you in, keeping your session active, remembering your settings, balancing traffic, and protecting against fraud and abuse. These are required for the Service to work.
- Functional. Remembering preferences such as language or theme.
- Analytics. Understanding how the Service is used so we can improve it. We use third-party analytics providers that may set their own cookies and receive information about your use of the Service, such as the pages you visit, the features you use, your IP address, and device details.
We don't use advertising cookies or tracking pixels from advertising networks.
Your choices. Most browsers let you block or delete cookies through their settings; blocking essential cookies may prevent parts of the Service from working. Where the law requires it, we treat a Global Privacy Control signal from your browser as a request to opt out of the sale or sharing of personal information (even though we don't sell or share personal information in that sense). Because there is no common industry standard for "Do Not Track" signals, we don't currently respond to them.
9. How long we keep information
We keep personal information only as long as we need it for the purposes described in this policy, unless a longer period is required or permitted by law. In general:
| Type of information | How long we keep it |
|---|---|
| Account and profile information | While your account is active, and for up to 30 days after you delete it. |
| Platform Content (Input, Output, Apps, code, and project files) | Until you delete it or delete your account. We remove it from active systems within 30 days after deletion, and from backups within 90 days. |
| App Data | Until the Creator deletes it, deletes the relevant App, or deletes the account. We remove it from active systems within 30 days after deletion, and from backups within 90 days, subject to the Data Processing Addendum and legal exceptions below. |
| Device, log, and usage information | Typically up to 12 months, after which it is deleted or aggregated. |
| Billing and transaction records | As long as needed for tax, accounting, and legal requirements, generally 7 years. |
| Support communications | Up to 3 years after the conversation ends. |
| Aggregated or de-identified information | May be kept indefinitely, because it doesn't identify you. |
We may keep information longer when required by law, to resolve disputes, to enforce our agreements, or to investigate abuse or security incidents. Content that you shared publicly or with other users may remain with them after you delete it. Information held by AI Providers is retained according to their own policies (see Section 5).
10. How we protect information
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption of data in transit, access controls that limit who can reach production systems and data, logging and monitoring, and reputable cloud infrastructure providers. Even so, no system is completely secure, and we can't guarantee the security of your information. You can help by using a strong, unique password, keeping your credentials confidential, and telling us right away at contact@playful.app if you suspect unauthorized access to your account. If a security incident affects your personal information, we will notify you and any relevant authorities as required by law.
11. Where we process information
Playful is based in the United States, and we process and store information there. Our service providers may process information in the United States and other countries whose data-protection laws may differ from those where you live (for AI Providers, see Section 5). If you are in the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards for transfers, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, in our agreements with service providers where they are required. By using the Service, you understand that your information will be transferred to and processed in the United States and may be processed in other countries.
12. Your rights and choices
12.1 Choices available to everyone
- Access and update. You can view and edit your account information in your account settings.
- Export. You can export your Apps and App Data using the tools available in the Service, or by asking us.
- Delete. You can delete individual Apps and Content in the Service, and you can delete your account in your settings or by emailing us. Section 9 explains what happens next.
- Marketing emails. You can opt out by using the unsubscribe link in any marketing email or by contacting us. We'll still send service and account messages.
- Cookies. See Section 8.
- End Users. If your request concerns information you gave to an App built by someone else, please contact the Creator first (see Section 2).
12.2 Rights under privacy laws
Depending on where you live, you may have the right to: know what personal information we collect, use, and disclose, and receive a copy; correct inaccurate information; delete your information; receive your information in a portable format; restrict or object to certain processing; withdraw consent where processing is based on consent; opt out of the sale or sharing of personal information, targeted advertising, and certain profiling (we don't do these things); and not be discriminated against for exercising your rights. You may also have the right to appeal a decision we make about your request and to complain to a regulator.
To exercise your rights, email contact@playful.app with the subject line "Privacy request" or write to us at the address in Section 17. We'll need to verify your identity, usually by confirming that you control the email address on your account, and we may ask for more information if needed. You can also have an authorized agent make a request for you if you give them written permission and we can verify their authority. We respond within the time the law requires (typically 30 to 45 days) and don't charge a fee unless requests are excessive or repetitive. If we deny your request, we'll explain why and how you can appeal by replying to our response.
12.3 Additional information for California residents
The California Consumer Privacy Act (CCPA) requires us to describe our practices using its categories. In the past 12 months we have collected the following categories of personal information, from the sources and for the purposes described in Sections 3 and 4, and we have disclosed each of them to the service providers described in Section 6 for business purposes:
| CCPA category | Examples | Collected? |
|---|---|---|
| Identifiers | Name, email address, username, IP address, account and device identifiers | Yes |
| Customer records | Name, billing address, payment card type and last four digits | Yes |
| Commercial information | Plans and credits purchased, transaction history | Yes |
| Internet or network activity | Pages and features used, prompts submitted, Apps created, log data, interactions with our emails | Yes |
| Geolocation data | Approximate location inferred from IP address (not precise geolocation) | Yes |
| Audio, visual, or similar information | Images or other media you upload as Input | Yes, if you upload it |
| Professional or employment information | Company name or role, if you tell us | Yes, if you provide it |
| Inferences | Preferences derived from how you use the Service | Limited, for product improvement |
| Sensitive personal information | Account login credentials; permitted Consumer Health Data and other sensitive information may also appear in user-supplied Platform Content or App Data | Yes for login credentials; otherwise only if supplied by a Creator or End User |
| Protected classifications, biometric information, education information | Protected classifications and education information may appear in user-supplied Platform Content or App Data; biometric identifiers remain Restricted Data | Not intentionally, except as supplied by a Creator or End User |
We do not "sell" personal information or "share" it for cross-context behavioral advertising, and we have not done so in the past 12 months. We don't knowingly sell or share the personal information of anyone under 16. We use sensitive personal information for the purposes described in this policy, including providing and securing the Service and, for sensitive information a Creator places in Platform Content, improving the creator platform. California residents may exercise any right to limit the use or disclosure of sensitive personal information that applies to our practices by contacting us as described in Section 12.2. They also have the rights described there to know, delete, correct, and not be discriminated against.
12.4 Other U.S. states
Residents of states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others) have the rights described in Section 12.2, subject to those laws. If we deny a request, you may appeal by replying to our response; if we deny your appeal, we'll tell you how to contact your state attorney general.
12.5 EEA, United Kingdom, and Switzerland
Playful Software, Inc. is the controller of the personal information of Playful account holders. You have the rights described in Section 12.2 under the GDPR, UK GDPR, and Swiss Federal Act on Data Protection, and Section 4 describes the legal bases we rely on. Where we rely on legitimate interests, you may object, and we'll stop unless we have compelling grounds to continue. You also have the right to lodge a complaint with your local data protection authority: in the EEA, the supervisory authority of the country where you live or work; in the United Kingdom, the Information Commissioner's Office; and in Switzerland, the Federal Data Protection and Information Commissioner. We'd appreciate the chance to address your concern first, so please contact us before you do.
12.6 Canada
Canadian residents may access and correct their personal information and withdraw consent (subject to legal or contractual restrictions) by contacting us. You may also contact the Office of the Privacy Commissioner of Canada or your provincial commissioner.
13. Children and teens
Playful accounts and creator-facing features are for people 18 and older. We don't knowingly permit a minor to create an account, and we will close an account if we learn that its holder is under 18.
We do not verify the age of every person who visits an App built by a Creator, and we cannot guarantee that a minor will not misrepresent their age. Creators may not build Apps directed at children under 13 or knowingly collect personal information from children under 13, with one exception: a Creator who is a child's parent or legal guardian may build a private Family App for that child's personal use, on the conditions in Section 3.4 of our Terms of Use. The parent or guardian consents to the App's collection of the child's information, decides what it collects, and can review or delete it at any time. Playful handles the child's information only as App Data, as described in Section 2: to host, operate, secure, and support the App, never for advertising, profiling, or training AI models. The technical information described in Section 3.2, such as IP address and device details, is used only to run and secure the platform. An App that exposes Playful-provided AI features may not target or knowingly serve a person under 18 unless Playful has approved the use in writing after appropriate age, consent, safety, moderation, monitoring, and privacy safeguards have been implemented. If we learn that an App is serving minors contrary to these rules, we may disable the App or its AI features and delete affected information as appropriate. A parent or guardian who believes a minor has provided information through Playful may contact us at contact@playful.app.
A parent or guardian can ask us to delete a child's information from a Family App by emailing contact@playful.app. We will confirm that the request comes from the account holder or the child's parent or guardian.
14. Third-party links and integrations
The Service may contain links to, or let you connect, third-party websites and services, such as sign-in providers, databases, payment providers, and other tools. Those services have their own privacy policies, and we aren't responsible for their practices. When you connect a third-party service, we exchange information with it as needed to provide the integration and according to the permissions you grant. Apps built by Creators may also use third-party services that the Creator chooses.
15. Changes to this policy
We may update this policy from time to time. Whenever we change this policy, we will notify you by email or in the Service and post the new version here with a new effective date. This policy is a notice of our practices, not a request for consent; where consent or another action is legally required for a new use, we will request it separately.
16. SMS and text messaging
If you provide your mobile phone number or contact Playful via text message, we use your mobile information only to respond to your support requests and manage your account.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
Message frequency varies based on your support interaction. Message and data rates may apply. Reply HELP for help or STOP to opt out.
Need help? Text Playful Support at 350-305-4974.
By texting this number, you agree to receive customer support and account-related text messages from Playful. Message frequency varies based on your support request. Message and data rates may apply. Reply STOP to opt out or HELP for help.
Playful does not send marketing or promotional SMS messages. Your consent to receive SMS messages is not required to use Playful.
17. Contact us
If you have questions about this policy or how we handle your information, please get in touch.
Playful Software, Inc. Attn: Privacy 1904 3rd Ave, Suite 910 Seattle, WA 98101, United States Email: contact@playful.app