HeyGilli — Privacy Policy

Effective: 7 September 2026  ·  Last updated: 7 September 2026
Contact: [email protected]
HeyGilli is an app for parents that screens YouTube channels for a child and keeps a buddy character alongside them while they watch. This page explains, in full, what information the app collects, why, who it is shared with, how long it is kept, and how to have it deleted. It is written for a parent to actually read — where something is not built yet, it says so, rather than describing a promise instead of the product.

1. Who this covers

HeyGilli is operated as an independent project, not a company. Throughout this policy, "we," "us," and "HeyGilli" refer to that project, reachable at [email protected].

Only a parent or guardian creates a HeyGilli account and signs in. A child never signs in to anything, is never asked to enter information, and is never shown a way to leave their own screen without the parent's PIN. Everything in this policy about "you" refers to the parent.

2. Information we collect

2.1 Account identity

HeyGilli offers two ways to start a household, and what is collected differs between them.

Sign-in methodWhat is collected
Continue with Google Your Google account's basic profile (name, email address, profile photo — the standard openid, email, and profile scopes), and, with your consent, a read-only OAuth token for your YouTube subscriptions (youtube.readonly). The token is exchanged and stored on our server; it is never sent to or stored on your device.
Set up without Google A random identifier generated on your device (for example trial-3c994baf52eab4ec…). No name, email, or Google account is collected. This identifier is stored only on your device and sent to our server to find your household on later visits.

2.2 Your child's profile

You create this; your child does not enter any of it themselves.

2.3 YouTube subscriptions and viewing history

Neither YouTube nor YouTube Kids exposes an API that reads a child's profile directly, so HeyGilli reaches your household's subscriptions in one of two ways, both initiated by you:

Watch history is opt-in, every single time, and is never stored as a list. If you tick the history option during an import, we read the exported "watch-history.json" only long enough to compute a small aggregate — total videos, the date range, a per-hour-of-day pattern, and the channels most and least watched — and then discard the underlying list of individual videos entirely. We do not retain a video-by-video watch history for any child, on our servers or otherwise.

2.4 What happens while your child is watching

2.5 What never leaves your device

3. How we use this information

We do not use your or your child's information to build advertising profiles, and we do not run any advertising or third-party analytics or tracking SDKs of any kind in the app.

4. Who we share information with

We do not sell personal information, and we do not share it with anyone for their own marketing purposes. Information passes through the following service providers, strictly to run the app:

ProviderWhat it handles
Google (Sign-In & YouTube Data API) Authenticates the parent; supplies the subscription list you've granted access to.
Amazon Web Services — Bedrock The AI model that screens videos and drafts Gilli's questions. It sees video metadata and transcripts, not your account identity.
Amazon Web Services — Polly Converts Gilli's scripted lines to speech audio.
Amazon Web Services — DynamoDB Stores household, child, and session records described above.
Render & Vercel Host the server and the app itself. Standard web server logs (IP address, timestamp, requested address) are generated at this layer, as with any web service.

We may disclose information if required to by law, or to protect the safety of a child, ourselves, or others — this is a standard reservation, not something we expect to need.

Google API Services User Data Policy. HeyGilli's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Your YouTube subscription data is used only to run the features described in this policy — never for advertising, never to train general-purpose AI or machine-learning models, and never read by a person except where the law requires it.

5. Children's privacy

HeyGilli is built around the requirement that a child never creates an account, never signs in, and never provides information directly — every child profile is created and configured by a parent, and every consent to connect a Google account or upload an export is given by that parent. We do not knowingly collect personal information directly from a child.

If you believe a child has provided us with personal information other than through a parent's own account setup, contact us at [email protected] and we will investigate and delete it.

6. How long we keep information, and how to delete it

We keep household and child records for as long as the account exists, so the app can keep working the way you left it. Some things you can remove yourself right now inside the app:

Full account deletion is not yet self-serve. HeyGilli does not currently have an in-app "delete my account" button. To request deletion of a household, a child's profile, or your connected Google token, email [email protected] from the address associated with the account (or describe the household so we can locate it) and we will delete the underlying records. We aim to complete this within 30 days of a verified request.

You can also revoke HeyGilli's access to your Google account at any time, independently of us, from myaccount.google.com/permissions . This immediately stops the app from being able to read your subscriptions; existing app data is removed only once we act on a deletion request as above.

7. Security

Data is transmitted over encrypted connections (HTTPS/TLS). This project is at an early, actively developed stage — as with any software at this stage, our security practices continue to evolve, and we do not claim a specific certification or guarantee against every possible failure. We ask that you use a household-specific Google account and PIN you don't reuse for anything sensitive elsewhere.

8. Your choices

9. International use

Our infrastructure runs on servers located in the United States (AWS us-east-1). If you use HeyGilli from outside the United States, your information is transferred to and processed there.

10. Changes to this policy

If this policy changes in a way that meaningfully affects what we collect or how we use it, we will update the date at the top of this page. Continuing to use HeyGilli after a change means you accept the updated policy.

11. Contact

Questions, deletion requests, or concerns about a child's information: [email protected].