HeyGilli is operated as an independent project, not a company. Throughout this policy, "we," "us," and "HeyGilli" refer to that project, reachable at [email protected].
Only a parent or guardian creates a HeyGilli account and signs in. A child never signs in to anything, is never asked to enter information, and is never shown a way to leave their own screen without the parent's PIN. Everything in this policy about "you" refers to the parent.
HeyGilli offers two ways to start a household, and what is collected differs between them.
| Sign-in method | What is collected |
|---|---|
| Continue with Google |
Your Google account's basic profile (name, email address, profile
photo — the standard openid, email, and
profile scopes), and, with your consent, a read-only
OAuth token for your YouTube subscriptions
(youtube.readonly). The token is exchanged and stored on
our server; it is never sent to or stored on your device.
|
| Set up without Google |
A random identifier generated on your device (for example
trial-3c994baf52eab4ec…). No name, email, or Google
account is collected. This identifier is stored only on your device
and sent to our server to find your household on later visits.
|
You create this; your child does not enter any of it themselves.
Neither YouTube nor YouTube Kids exposes an API that reads a child's profile directly, so HeyGilli reaches your household's subscriptions in one of two ways, both initiated by you:
Watch history is opt-in, every single time, and is never stored as a list. If you tick the history option during an import, we read the exported "watch-history.json" only long enough to compute a small aggregate — total videos, the date range, a per-hour-of-day pattern, and the channels most and least watched — and then discard the underlying list of individual videos entirely. We do not retain a video-by-video watch history for any child, on our servers or otherwise.
We do not use your or your child's information to build advertising profiles, and we do not run any advertising or third-party analytics or tracking SDKs of any kind in the app.
We do not sell personal information, and we do not share it with anyone for their own marketing purposes. Information passes through the following service providers, strictly to run the app:
| Provider | What it handles |
|---|---|
| Google (Sign-In & YouTube Data API) | Authenticates the parent; supplies the subscription list you've granted access to. |
| Amazon Web Services — Bedrock | The AI model that screens videos and drafts Gilli's questions. It sees video metadata and transcripts, not your account identity. |
| Amazon Web Services — Polly | Converts Gilli's scripted lines to speech audio. |
| Amazon Web Services — DynamoDB | Stores household, child, and session records described above. |
| Render & Vercel | Host the server and the app itself. Standard web server logs (IP address, timestamp, requested address) are generated at this layer, as with any web service. |
We may disclose information if required to by law, or to protect the safety of a child, ourselves, or others — this is a standard reservation, not something we expect to need.
Google API Services User Data Policy. HeyGilli's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Your YouTube subscription data is used only to run the features described in this policy — never for advertising, never to train general-purpose AI or machine-learning models, and never read by a person except where the law requires it.
HeyGilli is built around the requirement that a child never creates an account, never signs in, and never provides information directly — every child profile is created and configured by a parent, and every consent to connect a Google account or upload an export is given by that parent. We do not knowingly collect personal information directly from a child.
If you believe a child has provided us with personal information other than through a parent's own account setup, contact us at [email protected] and we will investigate and delete it.
We keep household and child records for as long as the account exists, so the app can keep working the way you left it. Some things you can remove yourself right now inside the app:
Full account deletion is not yet self-serve. HeyGilli does not currently have an in-app "delete my account" button. To request deletion of a household, a child's profile, or your connected Google token, email [email protected] from the address associated with the account (or describe the household so we can locate it) and we will delete the underlying records. We aim to complete this within 30 days of a verified request.
You can also revoke HeyGilli's access to your Google account at any time, independently of us, from myaccount.google.com/permissions . This immediately stops the app from being able to read your subscriptions; existing app data is removed only once we act on a deletion request as above.
Data is transmitted over encrypted connections (HTTPS/TLS). This project is at an early, actively developed stage — as with any software at this stage, our security practices continue to evolve, and we do not claim a specific certification or guarantee against every possible failure. We ask that you use a household-specific Google account and PIN you don't reuse for anything sensitive elsewhere.
Our infrastructure runs on servers located in the United States (AWS
us-east-1). If you use HeyGilli from outside the United
States, your information is transferred to and processed there.
If this policy changes in a way that meaningfully affects what we collect or how we use it, we will update the date at the top of this page. Continuing to use HeyGilli after a change means you accept the updated policy.
Questions, deletion requests, or concerns about a child's information: [email protected].