HelloBlink App - Privacy Policy
Privacy Policy
HelloBlink
Version: 1.16
Effective Date: [EFFECTIVE_DATE]
Last Reviewed: 1 September 2026
Table of Contents
- About This Policy and Who We Are
- Scope of This Policy
- Special Notice: Children's Privacy and COPPA Compliance
- Information We Collect
- How We Collect Information
- How We Use Information
- AI-Powered Features and Voice Processing
- Device Connectivity: Bluetooth and Wi-Fi
- In-App Purchases and Billing
- How We Share Information
- Third-Party Service Providers
- Data Retention and Deletion
- Data Security
- International Data Transfers
- Cookies, Local Storage, and Device Identifiers
- App Permissions
- Your Rights and Choices
- Parental Rights and Controls
- California Residents (CCPA/CPRA)
- Google Play Data Safety and Apple Privacy Labels
- Push Notifications
- Analytics and Crash Reporting
- Licensed Content (Disney Edition)
- Links to Third-Party Services
- Changes to This Privacy Policy
- Operators and Privacy Contact
1. About This Policy and Who We Are
Buffalo Games LLC and its subsidiary Ceaco Inc. (collectively, the “Company,” “we,” “us,” or “our”) operate the HelloBlink mobile application ecosystem (the "App" or "Service"), which includes the HelloBlink consumer mobile application for iOS and Android, the Hello Blink Sticker Maker Magic hardware companion ("AI Printer"), associated cloud backend services, and the connected Bluetooth thermal sticker and tattoo printers.
This Privacy Policy describes what information we collect when you and your child use the HelloBlink Service, how we use and protect that information, and the rights and choices available to you as a parent or guardian. It has been designed to comply with the Children's Online Privacy Protection Act ("COPPA") and the FTC's implementing regulations (including its amendments to the Rule), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), Google Play Families Policy, and Apple App Store child safety and privacy requirements.
This Privacy Policy should be read in conjunction with our Terms of Use.
By downloading, installing, or using the HelloBlink App or connected hardware, the parent or guardian of the child using the Service acknowledges the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Service and uninstall the App.
2. Scope of This Policy
This Privacy Policy applies to:
- The HelloBlink mobile application for iOS (version 14 and above) and Android (version 8.0 and above);
- The HelloBlink Sticker Maker Magic device and its cloud connectivity features;
- The HelloBlink Bluetooth thermal sticker printers and tattoo printers;
- All associated backend APIs, cloud services, and content delivery systems operated by The Company
- Any communications between you and The Company related to the Service (e.g., support requests).
This Policy does not apply to:
- Third-party websites, services, or applications that may be referenced or linked from the App;
- Apple App Store or Google Play Store, whose own privacy policies govern their respective platforms;
- Disney or other licensed content providers, whose separate privacy practices govern their own platforms.
3. Special Notice: Children's Privacy and COPPA Compliance
3.1 Intended Audience
HelloBlink is designed for children eight (8) years of age and older, used under the active supervision and with the express consent of a parent or legal guardian.
3.2 COPPA Notice to Parents
The Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. §§ 6501–6508, and the Federal Trade Commission's implementing regulations (16 C.F.R. Part 312) require that operators of websites and online services directed to children under 13 obtain verifiable parental consent before collecting personal information from children.
- HelloBlink does not create named accounts for children. When a child uses the AI voice-to-sticker feature, we process limited personal information consisting of the child’s voice recording, a text prompt derived from the recording, the generated image, and associated persistent device, job, safety, and processing information. This information is not directly associated with the child’s name, email address, or parent account.
- Not Publicly Available. The Service does not enable children to post or otherwise make their personal information publicly available.
- Age verification occurs on-device. The App presents an age-gate screen at first launch. The user enters their birth year; verification is performed locally on the device against the current date. No date of birth or birth year is transmitted to any server. Children who do not meet the minimum age requirement are directed to a dead-end screen with no bypass path.
- Parent/guardian controls all account functions. A parent or guardian is required to complete account setup, authorize purchases, and manage all account-level settings. These parent-facing flows are protected by a math-based gate and a personal PIN or biometric credential, ensuring children cannot access or alter them.
- Voice data is deleted within 60 seconds. When a child uses the AI Sticker Maker feature, voice audio captured by the AI Printer device is transmitted to our servers solely to generate a sticker image. Voice recordings are deleted no later than 60 seconds after speech-to-text processing is completed, text prompts are retained for no more than 30 days for safety and quality-review purposes, and generated images are deleted after delivery to the device.
- No targeted advertising. No information collected through the HelloBlink Service — from children or parents — is used for targeted advertising, behavioral profiling, or sale to third-party data brokers.
- No conditioning of services on excess data collection. The Company does not condition a child's use of any feature on the collection of personal information beyond what is reasonably necessary to provide that feature.
3.3 Parental Consent
Creating a parent account does not by itself constitute verifiable parental consent for collection of a child’s personal information. Before the AI voice-to-sticker feature is enabled, we provide the parent with a direct notice and obtain verifiable parental consent through the process described below. The feature remains disabled unless and until consent is received.
3.4 Verifiable Parental Consent for the AI Printer ("Email Plus")
Before a child may use the AI Sticker Maker (AI Printer) voice feature, The Company obtains verifiable parental consent using the "email plus" method recognized under the FTC’s COPPA Rule. This consent is separate from, and in addition to, the general parent account setup described above, and applies specifically to enabling the AI Printer’s voice-to-sticker feature. The process works as follows:
- Before the AI Printer can be used, the HelloBlink App collects the email address of a parent or guardian.
- We send the parent a direct notice by email describing the child personal information collected through the AI Printer, how that information is used, the service providers that process it, applicable retention and deletion periods, and safety and quality controls, including any potential review by authorized Company personnel. The notice explains that the feature will remain disabled unless the parent affirmatively consents and provides a link to this Privacy Policy. The parent provides consent by following a link in the email to a webpage where they can affirmatively indicate consent.
- We then send the parent a follow-up email confirming that consent was received and providing instructions for next steps within the App. This email also explains that consent may be revoked at any time and describes how the parent can revoke it.
- The parent’s email address is processed transiently to authenticate the parent and deliver OTP, consent, acknowledgment, and related transactional communications. The raw email address is not retained in the Company’s parent-account database. A consent link may temporarily contain an encrypted representation of the email address until the link is used or expires. When the parent completes the consent process, our systems use that information to send the acknowledgment and then discard it. Our email-delivery provider may retain limited delivery, security, and suppression records in accordance with its contractual obligations and retention practices. We retain a pseudonymous identifier derived from the email address for account linkage and consent-record purposes.
- The Company retains documentation of verified parental consent for seven (7) years following receipt of an account deletion request, for recordkeeping and compliance purposes.
3.5 COPPA Operator Role
The Company acts as the data controller and operator with respect to any information collected through the HelloBlink Service. For the purposes of COPPA compliance, the legal obligations for applicable consent models, age verification practices, policies, filings, and regulator interactions rest with Us as the operator of the Service.
Compliance with the COPPA Rule
The Company has reviewed and intends to comply with the current COPPA Rule, including its requirements concerning notice and verifiable parental consent, limitations on the collection and use of children’s personal information, data retention and deletion, information security, and parental rights. The Company’s specific practices are described throughout this Privacy Policy.
4. Information We Collect
HelloBlink's architecture is built around a principle of data minimization by design. The following categories describe all information collected across both the child-facing and parent-facing layers of the Service.
4.1 Information Collected from Children
HelloBlink does not create named child accounts. When the AI voice-to-sticker feature is used, we process limited child personal information consisting of voice audio, a derived text prompt, the generated image, and associated persistent device, job, safety, and processing information:
|
Data Element |
Description |
Storage |
|---|---|---|
|
Pseudonymous Device Identifier |
A randomly generated, non-reversible identifier assigned to the device installation. It is not tied to any name, email address, account, or hardware identifier. |
Stored on the device and transmitted with service requests for device authentication, job routing, security, and operational support. It is not used for advertising or to identify or contact a particular child. |
|
Print Telemetry (anonymous) |
On successful print completion via Bluetooth, the App sends an anonymous event containing: print type (sticker or tattoo) and creation source (gallery, drawing, photo, or AI). No image content, device hardware identity, child identity, or location is included. |
Stored server-side in aggregate analytics tables only. |
|
Local Preferences |
Language selection, paper-type selection, saved drawings, and favorited stickers are stored locally on the device using platform-standard storage (SharedPreferences on Android, NSUserDefaults on iOS). |
Never transmitted to our servers. |
|
App State and Error Information |
Technical information required for app functionality (e.g., print progress state, Bluetooth connection status). |
Processed in-memory; not logged or transmitted in a form that identifies any child. |
4.2 Information Collected from Parents and Guardians
|
Data Element |
Description |
Retention |
|---|---|---|
|
Email Hash (Account) |
A pseudonymous identifier derived from the parent’s email address is retained for account linkage and restoration. The raw email address is processed transiently as described in Section 3.4 and is not stored in the parent-account database. |
Retained for the life of the parent account. Deleted upon account deletion request. |
|
Encrypted consent-link information: |
An encrypted representation of the parent’s email address may be included in the consent link so that, when the link is used, our systems can send the consent acknowledgment. The information is not stored in the parent-account database. |
Retained until the consent link is used or expires after |
|
[INSERT PERIOD], then deleted or rendered unusable. |
||
|
Parent JWT (session token) |
A short-lived JSON Web Token issued upon successful OTP verification, valid for one (1) hour. Used to authenticate purchase and restore flows. |
Held in device memory only; not stored persistently. |
|
Parent PIN |
A 4- or 6-digit PIN chosen by the parent to gate purchases and settings. |
Stored exclusively in the device's platform secure storage (iOS Keychain / Android Keystore). Never transmitted to or stored on any server. |
|
Pack Entitlements |
A record of content packs purchased or unlocked by the parent account, linked to the email hash. |
Retained to support purchase restore. Deleted upon account deletion. |
|
Newsletter Email Hash (opt-in only) |
If a parent voluntarily opts into the HelloBlink newsletter, a one-way cryptographic hash of their email address is stored in HelloBlink's database to record the opt-in status and support unsubscribe requests. The raw email address is forwarded to our email-delivery provider for actual newsletter delivery and is not retained in HelloBlink's own database. The email hash retained by Us cannot be used to send emails directly; it is used solely to manage the opt-in/opt- out record. |
Retained until the parent unsubscribes or deletes their account. Deleted upon account deletion request. |
|
Survey Responses |
Occasional voluntary surveys presented to parents contain no device ID or identity linkage. Responses are stored in aggregate form only. |
Retained in anonymous aggregate form indefinitely or until the survey is archived. |
4.3 Biometric Authentication Data (Device-Level Only)
Where a parent chooses to confirm a purchase or unlock the Parent Zone using their device's fingerprint or facial recognition feature (e.g., Apple Face ID/Touch ID or Android biometric unlock) instead of the parent PIN, that biometric authentication is performed entirely by the device's operating system and secure hardware enclave. We do not collect, receive, view, transmit, or store any fingerprint, facial geometry, voiceprint, or other biometric identifier. Our systems receive only a yes/no confirmation from the device's operating system that the on-device biometric check succeeded; no biometric template or raw biometric data ever leaves the parent's device or reaches our servers.
4.4 Information Collected from the AI Printer Device
The AI Printer is a standalone hardware device. It is not linked to or associated with a parent account. The AI Printer operates independently and communicates with our cloud pipeline using device-specific credentials only.
|
Data Element |
Description |
Retention |
|---|---|---|
|
Voice Audio (transient) |
Audio captured by the AI Printer microphone when a user activates the voice-to-sticker feature.Uploaded to our cloud pipeline for speech-to-text processing only. |
Purged from cloud storage automatically within 60 seconds of STT processing completion. Never written to any database. |
|
AI- Generated Prompt (limited retention) |
A text prompt derived from the speech-to-text transcription and refined for image generation.Retained for a short period solely to allow our operations team to review the quality of generated sticker output and calibrate the AI pipeline. |
Retained formaximum of 30 daysafter pipeline completion, then automatically purged. Not linked to any child or parent identity. |
|
AI- Generated Image (transient) |
The sticker image generated from the refined prompt. |
Delivered to the AI Printer device via our secure device-messaging service and then purged. Not retained beyond delivery. |
|
Device Heartbeat |
Periodic connectivity signals sent by the AI Printer to confirm it is online (timestamp of last seen). |
Retained for up to seven years after collection, unless a longer period is reasonably necessary to investigate fraud, security incidents, legal claims, or comply with law. |
|
Moderation Log Entry |
When a voice prompt is processed, an anonymized safety classification result (outcome: passed, flagged, or rejected; job ID; timestamp; category classification only) is logged for compliance audit purposes. No voice content, transcribed text, or prompt text is retained in the moderation log. |
Retained per our audit log retention policy (90 days for compliance-sensitive events). |
4.5 Technical and Operational Information
|
Data Element |
Description |
Retention |
|---|---|---|
|
Structured Application Logs |
Server-side logs for API request/response monitoring, error detection, and performance analysis. All log configurations are reviewed to ensure no PII appears in any log line before shipping to production. |
Retained per our infrastructure monitoring policy. |
|
Code Redemption Attempt Events |
Records of attempts to redeem unlock codes (success, failure, error type). No child PII is present in any row. Used for analytics and abuse detection. |
Retained in analytics tables. |
|
COPPA Audit Logs |
Dedicated compliance-sensitive event logs (audio purge confirmations, OTP lifecycle events, newsletter opt-in/opt-out events). |
Retained for 90 days in a dedicated audit workspace. |
5. How We Collect Information
We collect information through the following means:
5.1 Direct Input from Parents
- Email address entered during account setup or restoration. The address is processed transiently to authenticate the parent and deliver related transactional communications but is not stored in the Company’s parent-account database. See Section 3.4.
- Email address entered at newsletter opt-in (raw email forwarded to email-delivery service for delivery; email hash retained by The Company to record opt-in status).
- PIN entry (processed locally on-device only; never transmitted).
- Wi-Fi credentials for AI Printer setup (transmitted exclusively over Bluetooth to the printer; never sent to our cloud).
- Survey responses submitted voluntarily.
5.2 Automatic Collection by the App
- Pseudonymous Device Identifier generated on first installation.
- Anonymous print telemetry events on successful Bluetooth print completion.
- Language and preference settings stored locally.
- AI Printer heartbeat signals (device-to-cloud, not linked to any parent or child account).
5.3 Voice Input via AI Printer Hardware
- Voice audio captured by the AI Printer device microphone when the child activates the voice-to-sticker feature. Audio is transmitted from the device to our secure cloud pipeline over an encrypted connection. Audio is never captured or accessed by the mobile app.
5.4 Platform Stores (Apple / Google)
- In-app purchase receipt data is processed between your device, Apple or Google, and our backend solely for the purpose of verifying and granting purchased content entitlements. We do not receive your payment card or billing details.
5.5 Camera and Photo Library
- If a child or parent uses the photo-import feature to create a sticker from an image, the image is processed entirely on-device. Photo data is not uploaded to our servers. Photos converted to black-and-white thermal format for printing remain on-device only.
6. How We Use Information
We use the information described in Section 4 for the following purposes:
|
Purpose |
Information Used |
|---|---|
|
Providing the Service — enabling sticker creation, gallery browsing, printing, and content unlocking |
Pseudonymous Device Identifier; local preferences |
|
Processing and verifying in-app purchases and content entitlements |
Email hash; IAP receipt (via Apple/Google); pack grants |
|
Enabling account restoration across devices |
Email hash; pack entitlement records |
|
Operating the AI voice-to-sticker pipeline |
Voice audio (purged within 60 seconds of STT); AI prompt (retained for maximum of 30 days for quality review only); AI image (transient) |
|
Delivering content to the AI Printer via cloud messaging |
AI-generated sticker BMP; delivery via our secure device-messaging service |
|
AI pipeline quality calibration and output review |
AI-generated prompt text (retained for maximum of 30 days; not linked to any identity) |
|
Enforcing content safety on AI-generated stickers |
Moderation log (anonymized) |
|
Anonymous analytics and product improvement |
Anonymous print telemetry; anonymous code redemption events; anonymous survey aggregates |
|
Purpose |
Information Used |
|
Security, fraud prevention, and abuse detection |
Device ID (rate limiting); code redemption attempt events |
|
Maintaining service reliability and troubleshooting |
Structured application logs (PII-free) |
|
Newsletter communications (where parent opts in) |
Email hash stored for opt-in record; raw email forwarded to email-delivery service for delivery; not retained by us |
|
Compliance with legal obligations |
COPPA audit logs; admin audit trail |
|
Customer support |
Information you provide in support requests |
We do not use any information collected through HelloBlink for:
- Training external AI models;
- Advertising targeting or behavioral profiling;
- Sale or transfer to third-party data brokers;
- Any purpose unrelated to the operation of the HelloBlink Service.
7. AI-Powered Features and Voice Processing
7.1 Overview of the Sticker Maker Magic (AI Printer) Feature
The HelloBlink Sticker Maker Magic is an optional hardware accessory ("AI Printer") that enables a child to speak a wish or description aloud, causing the AI Printer to generate and print a custom sticker automatically. This feature is set up by a parent within the Parent Zone of the mobile app.
7.2 The AI Processing Pipeline
When a child activates the AI Sticker Maker, the following processing occurs:
- Voice Capture: The AI Printer device's microphone captures a voice recording (up to 15 seconds). The recording is transmitted from the device to our secure cloud API over an encrypted connection.
- Speech-to-Text (STT): Our self-hosted speech recognition system (operated entirely within our own private cloud infrastructure) converts the audio to text. If transcription confidence is below an acceptable threshold, the job is rejected and the child is notified via the device's LED indicator to try again.
- Prompt Refinement: The transcription is processed by an automated prompt-engineering stage to produce a structured, child-appropriate image description. This stage is designed to produce age-appropriate output by construction.
- Safety Filtering: All prompts are evaluated by our self-hosted AI safety system before image generation proceeds. Prompts that contain references to violence, adult content, copyright-protected characters, or other prohibited categories are automatically rejected. An operator-maintained copyright and content blocklist provides an additional layer of filtering.
- Image Generation: Approved prompts are submitted to our self-hosted image generation system (running on dedicated infrastructure within our own private cloud environment). No third-party commercial AI image generation API is used in production.
- Post-Processing: Background removal and thermal image conversion are applied to prepare the image for printing.
- Delivery: The final sticker image is delivered to the AI Printer via our secure device-messaging service and the sticker is printed. The image file is then purged.
7.3 Data Minimization and Retention in AI Processing
- Voice audio is deleted from cloud storage no later than 60 seconds after speech-to-text processing is completed. It is not written to the parent-account database and is not used for advertising, profiling, or AI-model training.
- AI text prompts are retained for a maximum of 30 days after pipeline completion solely for safety, quality, and operational review, which may include review by authorized Company personnel; the prompts are not linked to any child or parent identity and are automatically and permanently deleted when the retention period expires..
- AI-generated images are delivered to the device and then purged. They are not retained beyond delivery.
- A moderation log entry is created for each job, containing: an anonymous job ID, the processing outcome (passed, flagged, or rejected), a content category classification (not the prompt text), and a timestamp. The moderation log contains no voice content, transcribed speech, or prompt text.
7.4 STT Failures, Timeouts, and Retry Retention
Whenever the AI Sticker Maker cannot successfully process a voice request — whether because the recording was empty, too long, or too large; because our backend failed and needed to retry; or because speech-to-text could not produce a confident result — it is designed to still show a response and leave no processing incomplete. The following retention rules apply regardless of outcome:
- Rejected recordings (empty, over-length, or over-size): These are rejected immediately at ingestion and are never stored or forwarded to the speech-to-text pipeline.
- Automatic retry attempts: If a backend or processing failure occurs, the system automatically retries once. The original audio is retained only for the duration of that retry and is purged on the same 60-second timeline described in Section 7.3, regardless of whether the retry succeeds.
- Low-confidence or unrecognized speech, and technical failures: Voice audio is purged within 60 seconds of processing completing, exactly as it is for successful requests. No audio, transcript, or derived text is retained for a failed, timed-out, or rejected attempt.
- Device-shown fallback messages: The on-device messages shown when a request cannot be completed (e.g., light effect that signals “we couldn’t quite hear that, please try again”) are fixed, pre-written strings. They are never generated from, or contain, anything the child said, and are not stored or logged.
- Error and outcome logging: A moderation/processing log entry (see Section 4.1) records only the anonymous job ID, timestamp, and outcome category (e.g., rejected, retried, failed, or timed out) for monitoring purposes. Recordings are limited to 15 seconds and the device receives progress updates throughout, but neither the recording length telemetry nor the error logs contain voice content, transcribed text, or any information that identifies a child.
7.5 AI Safety and Content Moderation
We take the safety of child-accessible AI-generated content seriously. All sticker imagery generated by the Service is subject to:
- Automated safety classification before generation proceeds, using a self-hosted multi-category safety model.
- Copyright and content blocklisting maintained and regularly updated by our operations team.
- Child-appropriateness standards applied at the prompt-construction stage to constrain output style and subject matter.
We reserve the right to reject, filter, or block any voice input or AI-generated output that our systems or human reviewers determine may produce inappropriate content. We cannot guarantee that all AI-generated content will perfectly reflect a child's intended request, as AI generation is inherently non-deterministic.
7.6 AI Content Disclaimer
AI-generated stickers are created by automated systems and may not precisely match the child's spoken description. Generated content is subject to the limitations of speech recognition accuracy, AI image generation, and automated safety filtering. We are not responsible for the specific form of any AI-generated sticker image, provided it passes our content safety checks.
7.7 No Third-Party AI API Dependency in Production
All AI processing components (speech-to-text, safety filtering, image generation) are deployed on infrastructure owned and operated by The Company within a private network environment. Voice audio and AI prompts are not transmitted to third-party commercial AI API services in the production environment.
8. Device Connectivity: Bluetooth and Wi-Fi
8.1 Bluetooth
The HelloBlink App uses Bluetooth to set up and communicate with the HelloBlink printers and the AI Printer device.
Bluetooth communication occurs locally between your mobile device and the printer. Print job data (sticker images generated on-device) is not transmitted to our cloud servers when printing via Bluetooth; ordinary Bluetooth print data remains local. Print telemetry (anonymous type and source only) is separately transmitted to our API to support operational analytics.
8.2 Wi-Fi Provisioning for the AI Printer
To enable the AI Printer's cloud connectivity, a parent must enter their Wi-Fi network SSID and password in the HelloBlink App's Parent Zone. Wi-Fi credentials pass directly from the App to the AI Printer and are not received or stored by Company servers. Once provisioned, the AI Printer uses the credentials to connect directly to your local Wi-Fi network.
8.3 IoT Cloud Connectivity (AI Printer)
The AI Printer sends voice audio and operational connectivity information to Company systems and receives generated images and status messages.
9. In-App Purchases and Billing
9.1 In-App Purchases (Content Packs)
HelloBlink offers one-time content pack purchases processed through the native billing systems of Apple (App Store / StoreKit) and Google (Google Play Billing). All payment processing is handled entirely by Apple or Google. We do not collect, process, or store your payment card number, bank details, or any payment credentials.
When a purchase is completed, Apple or Google sends a receipt to our backend for verification. We verify the receipt to grant the purchased content entitlement to your parent account. The receipt data is not retained beyond the verification process.
9.2 Purchase Restore
Purchased content packs can be restored on a new or replacement device. Restoration is processed by authenticating your parent account via email OTP, which allows our backend to reconcile your entitlements against the stored pack grant records. Cross-platform restore (e.g., from iOS to Android) is supported through the parent account layer.
A family device cap (configurable, default 3–5 devices) applies per parent account. Exceeding this cap will prevent additional devices from being associated.
10. How We Share Information
The Company does not sell, rent, trade, or otherwise transfer personal information to third parties for commercial purposes. We share information only in the following limited circumstances:
10.1 Service Providers
We share limited information with third-party service providers who assist us in operating the HelloBlink Service. These providers act as data processors on our behalf and are contractually bound to use data only for the purposes we specify, to implement appropriate security measures, and to comply with applicable privacy laws. See Section 11 for a description of our service providers.
10.2 Platform Billing Partners (Apple and Google)
In-app purchase verification requires sharing IAP receipt data with Apple's App Store Server API and Google's Play Developer API. This exchange is governed by Apple's and Google's respective terms of service and privacy policies.
10.3 Email Delivery Provider
The Company uses an email-delivery provider for two distinct email functions:
- OTP and transactional-email delivery: A parent’s email address is provided to our email-delivery provider to send one-time passcodes, consent notices, consent acknowledgments, and related transactional communications. The Company does not store the raw address in its parent-account database. The provider may retain limited operational records as described in Section 3.4.
- Newsletter delivery (opt-in only): If a parent opts into the HelloBlink newsletter, their raw email address is forwarded to our email-delivery provider to perform the actual email delivery. We do not retain the raw email address after forwarding. A one-way cryptographic hash of the email is retained in HelloBlink's database solely to record the parent's opt-in status and support unsubscribe requests. This hash cannot be used to send emails directly. Our email-delivery provider may retain limited delivery, security, suppression, and unsubscribe records in accordance with its contractual obligations and retention practices. You may unsubscribe at any time (see Section 17.5).
10.4 Legal Requirements and Safety
We may disclose information to government authorities, regulators, or law enforcement agencies where required by law, valid legal process (e.g., court order or subpoena), or where we reasonably believe disclosure is necessary to: protect the safety of a child or any person, enforce our Terms of Use, or protect the rights and interests of The Company.
10.5 Business Transfers
In the event of a merger, acquisition, reorganization, asset sale, or similar corporate transaction involving The Company, information held by us may be transferred as part of that transaction, subject to the acquirer's commitment to honor the privacy protections described in this Policy (or provide notice and choice if material changes are proposed).
10.6 Aggregated or Anonymized Data
We may share aggregate, anonymized statistics (e.g., "X stickers were printed this month") with business partners, licensors (such as Disney), investors, or the public. Such information cannot be used to identify any individual user or child.
11. Third-Party Service Providers
The following third-party service providers are engaged in the operation of the HelloBlink Service:
|
Provider |
Purpose |
Information Processed |
Role and Restrictions |
|---|---|---|---|
|
Microsoft Azure |
Hosting and operating cloud-based portions of the HelloBlink Service, including parent-account and consent functions, the AI voice-to-sticker feature, device communications, content delivery, security, logging, and service support. |
Depending on the feature used, Azure may process a parent’s email address transiently; encrypted consent-link information; pseudonymous email-derived identifiers; consent records; content entitlements; child voice audio; derived text prompts; generated images; pseudonymous device and job identifiers; safety and moderation results; and limited operational logs and telemetry. |
Azure processes this information as a contracted service provider solely on the Company’s behalf and for the purposes described in this Privacy Policy. Azure is not permitted to use the information for advertising, behavioral profiling, independent product development, or training artificial-intelligence models. Retention is governed by the schedules described in Section 12. |
|
Apple Inc. |
In-app purchase receipt verification |
IAP receipt token; parent pack grant |
Governed by Apple's terms; no child data involved |
|
Google LLC |
In-app purchase receipt verification |
IAP receipt token; parent pack grant |
Governed by Google's terms; no child data involved |
|
Mailchimp |
OTP email delivery for parent account setup; newsletter delivery (where parent opts in) |
Raw email used for OTP delivery and newsletter delivery; raw email not retained by The Company after forwarding. Email hash retained by The Company for newsletter opt-in record |
Parent may unsubscribe at any time; raw email data in Mailchimp governed by Mailchimp's privacy policy |
12. Data Retention and Deletion
12.1 Retention Schedule
|
Data Category |
Retention Period |
Basis |
|---|---|---|
|
Voice audio (AI pipeline input) |
Voice audio is deleted from cloud storage no later than 60 seconds after speech-to-text processing is completed. |
Providing the requested feature; data minimization. |
|
Rejected, retried, or failed voice audio (STT failures/timeouts) |
Rejected recordings are never stored. Retried and failed/timed-out recordings are purged within 60 seconds, the same as successful requests; only an anonymized outcome log entry (no audio or text) is retained. |
Data minimization; consistent handling regardless of processing outcome |
|
Verified parental consent records (AI Printer "email plus") |
Retained for seven (7) years following receipt of an account deletion request. The retained consent record contains the pseudonymous email identifier, consent date and time, consent method, and version of the applicable privacy notice. It does not contain the raw email address. |
documenting consent, responding to legal or regulatory inquiries, and maintaining compliance records |
|
AI-generated image |
Purged after delivery to device |
Data minimization |
|
AI text prompt |
Retained for maximum of 30 days after pipeline completion, then automatically purged |
AI quality calibration; not linked to any identity |
|
Parent email raw address (OTP) |
Processed transiently for authentication and transactional communications; not stored in the parent-account database. An encrypted representation may remain in the consent link until the link is used or expires after [PERIOD]. |
Data minimization |
|
Parent email hash (account linkage) |
Life of parent account |
Necessary for account linkage and restore |
|
Newsletter email hash (opt-in only) |
Until parent unsubscribes or deletes account |
Recording opt-in status; supporting unsubscribe |
|
Parent pack entitlement records |
Life of parent account |
Necessary for purchase restore |
|
Anonymous print telemetry |
Retained for seven (7) years after collection |
Anonymous; no personal data |
|
Anonymous code redemption events |
Retained for seven (7) years after collection |
Anonymous; no personal data |
|
Survey responses (anonymous) |
Retained for seven (7) years after collection |
Anonymous; no personal data |
|
COPPA compliance audit logs |
90 days |
Legal compliance |
|
Admin audit trail |
Retained for seven (7) years after collection |
Legal compliance and security |
|
Database backups (production) |
35 days (point-in-time restore) |
Business continuity |
|
Application logs |
Per infrastructure monitoring policy |
Operational necessity |
12.2 Account Deletion
Parents may delete their HelloBlink account at any time from the Parent Zone > Settings menu within the App. Account deletion:
- Requires PIN confirmation;
- Permanently deletes the parent account record and all associated pack entitlements;
- Purges the account email hash and newsletter email hash from our systems;
- Is irreversible. A confirmation modal with clear warning is displayed before execution.
Following account deletion, content packs previously unlocked on the device through a QR code redemption remain accessible locally on that device (as they are stored in local device storage), but cannot be restored on a new device. Purchased content entitlements are permanently removed and cannot be recovered.
13. Data Security
We maintain a written information-security program and use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information we process. These safeguards include encryption, access controls, authentication measures, monitoring and testing, personnel controls, incident-response procedures, and service-provider oversight. No method of electronic transmission or storage is completely secure.
14. International Data Transfers
The Company’s cloud infrastructure is hosted in the United States. If you are located outside the United States, information you provide (including any parent-account data) will be transferred to and processed in the United States, which may have different data protection laws than your country of residence. By using the HelloBlink Service, you acknowledge and consent to this transfer.
15. Cookies, Local Storage, and Device Identifiers
15.1 Mobile Application
The HelloBlink mobile app does not use web cookies. The App stores certain preferences, saved content, and parental-control information locally on the device. The parent PIN is maintained using the device platform’s protected storage. This locally stored information is not transmitted to Company servers except as otherwise expressly described in this Policy. Pseudonymous Device Identifier
The App generates a random persistent device identifier upon installation. The identifier is not directly associated with a name, email address, or named account. It is used only for duplicate-redemption prevention, rate limiting, security, and other disclosed internal operations. It is not used for advertising, cross-service tracking, or behavioral profiling.
15.2 Admin Panel (Web)
The HelloBlink administrative operations panel, accessible only to authorized Company staff, may use session cookies and related web storage technologies. This panel is not accessible to consumers or children.
15.3 Do Not Track (DNT) Signals
Some web browsers include a "Do Not Track" (DNT) signal that a user can enable to indicate a preference that websites not track online activity. HelloBlink does not track users across third-party websites or services and does not use information for cross-context behavioral advertising. The App therefore does not respond to browser-based Do Not Track signals.
16. App Permissions
The HelloBlink App requests the following device permissions. All permissions are requested at the time they are needed, with an explanation of their purpose, and can be managed through your device's operating system settings:
|
Permission |
Platform |
Purpose |
Required? |
|---|---|---|---|
|
Bluetooth / Bluetooth Low Energy |
iOS,Androi d |
Discovering and communicating with the HelloBlink thermal printer and AI Sticker Maker device |
Required for printing and AI Printer setup; app remains functional for non-printing features without this permission |
|
Camera |
iOS,Androi d |
Scanning QR codes on physical product packaging to unlock content; capturing photos to convert to stickers |
Required for QR unlock and photo-to-sticker features |
|
Photo Library / Media Access |
iOS,Androi d |
Importing existing photos from the device gallery to convert to stickers |
Required for gallery import feature |
|
Push Notifications |
iOS,Androi d |
Sending service-related alerts to parents (e.g., connectivity issues with the AI Printer, where applicable) |
Optional; app functions without notifications enabled |
|
Internet Access |
Android |
Standard network access for API communication |
Required |
|
Location (if required by OS for Bluetooth) |
Android |
Some Android versions require location permission for Bluetooth scanning; no location data is collected or used by HelloBlink |
Required by Android OS for Bluetooth on affected versions |
We do not request or use microphone permissions on the mobile app. Voice capture for the AI Sticker Maker is handled entirely by the AI Printer hardware device and is not routed through the mobile app.
17. Your Rights and Choices
17.1 Access and Correction
You may request access to the personal information (email hash, newsletter opt-in status, pack entitlements) we hold about your parent account at any time by contacting us at customerservice@buffalogames.com. To verify your identity, we will ask you to authenticate via the parent account OTP process.
Please note that because the email hash is a one-way cryptographic transformation, we cannot recover or display your original email address — only confirm that an account linked to a given email exists.
17.2 Deletion
You may delete your parent account and associated data through the App (Parent Zone > Settings > Delete Account) or by contacting us at customerservice@buffalogames.com. See Section 12.2 for details of what is deleted and what remains on-device.
17.3 Data Portability
You may request a copy of the data we hold about your parent account in a structured, machine-readable format by contacting customerservice@buffalogames.com.
17.4 Requesting Early Deletion of AI Prompts
The AI-generated text prompts associated with sticker generation are retained for a maximum of 30 days for internal quality calibration (see Section 7.3). Prompts are not linked to any parent or child identity. If you wish to request early deletion of prompts associated with a specific generation session, contact customerservice@buffalogames.com with the approximate date and time of the session. We will make reasonable efforts to identify and delete the relevant prompt data within our retention window.
17.5 Newsletter Unsubscribe
If you have opted into the HelloBlink newsletter, you may unsubscribe at any time by:
- Clicking the unsubscribe link in any newsletter email (processed by email-delivery service); or
- Contacting us at customerservice@buffalogames.com with the subject line "Newsletter Unsubscribe."
Upon unsubscribe, we will delete the newsletter email hash from our database and instruct our email-delivery service to remove you from the mailing list. Unsubscribe requests are processed typically within 10 business days.
17.6 Push Notifications
You can disable push notifications from HelloBlink at any time through your device's notification settings.
17.7 App Permissions
You can revoke any app permission (Bluetooth, camera, photo library, notifications) through your device's operating system settings at any time. Revoking required permissions will disable the corresponding features.
18. Parental Rights and Controls
As the parent or legal guardian, you have the following specific rights regarding your child's use of HelloBlink:
18.1 Review
HelloBlink does not create named accounts for children. However, when a child uses the AI voice-to-sticker feature, we process limited personal information consisting of voice audio, a derived text prompt, the generated image, and associated device, job, safety, and processing information, as described in this Policy. This information is not directly associated with the child’s name, email address, or parent account. A parent may contact us to review the types of information collected and our processing practices.
18.2 Deletion of Child Information
Voice audio and generated images are automatically deleted according to the retention periods described in Section 12. Text prompts and related processing records may be retained for limited periods. A parent may request early deletion of retained information associated with a particular generation session by providing the approximate date and time of the session and any other reasonably available information that may help us identify the applicable records. Because HelloBlink does not create named child accounts, we may be unable to identify a particular record without sufficient session information.
Deleting the parent account will delete the parent-account information described in Section 12.2. A parent may separately withdraw consent for future use of the AI voice-to-sticker feature as described in Section 18.3.
18.3 Consent Withdrawal
A parent may withdraw consent for the AI voice-to-sticker feature at any time through [INSERT IN-APP PATH] or by contacting us. Upon withdrawal, the feature will be disabled and we will cease further collection of the child’s voice information. We will delete retained child personal information associated with the request, subject to limited legal, security, backup, and recordkeeping exceptions. Withdrawal of consent does not require deletion of the parent account unless the parent chooses to delete it.
18.4 Parental Controls Within the App
The App provides the following in-app parental controls:
- PIN gate: All purchase, account, and settings functions are protected by your parent PIN.
- Math gate: The Parent Zone (where all account and device management occurs) requires solving an adult-appropriate math problem to enter.
- Purchase gating: No purchase can be initiated without PIN or biometric confirmation.
18.5 Contacting Us About Child Privacy
Parents with questions or concerns about how HelloBlink handles their child's privacy, or who wish to exercise any right described in this section, should contact us at customerservice@buffalogames.com or the postal address in Section 26.
19. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"), provides you with specific rights regarding your personal information.
19.1 Categories of Personal Information Collected
We collect limited personal information from California residents, including information relating to parents or guardians and, when the AI voice-to-sticker feature is used, limited information relating to children. Depending on how the Service is used, the categories may include:
- Identifiers: pseudonymous email-derived identifiers, persistent device identifiers, and job identifiers.
- Commercial information: records of content packs purchased or unlocked by a parent.
- Internet or other electronic activity information: print events, code-redemption events, AI-processing events, and application or security logs.
- Audio and user-provided information: transient voice recordings and text prompts derived from those recordings.
- Inferences: We do not create profiles or inferences about a child or parent for advertising or behavioral-profiling purposes.
The child-related information is not directly associated with the child’s name, email address, or a named child account.
We do not collect Social Security numbers, financial account numbers, precise geolocation data, racial or ethnic origin, health information, or biometric identifiers.
19.2 Purposes for Collection
Personal information is collected for the purposes described in Section 6. We do not use or disclose it for any secondary, unrelated purpose.
19.3 Sale or Sharing of Personal Information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising purposes.
19.4 Universal Opt-Out Mechanisms (Global Privacy Control)
The Company honors Global Privacy Control (GPC) and other legally recognized universal opt-out preference signals as opt-out-of-sale/sharing preference signals under the CCPA/CPRA, to the extent such signals are transmitted through a browser or platform used to interact with our Service. Because HelloBlink does not sell or share personal information for cross-context behavioral advertising, honoring a universal opt-out signal does not change any current data practice; it is treated as confirmation that no such sale or sharing should occur for that browser or device. If our practices change in the future such that a universal opt-out signal would have a practical effect, we will process the signal in accordance with then-applicable law and update this Policy accordingly.
19.5 Sensitive Personal Information
We do not collect "sensitive personal information" as defined by CCPA/CPRA (e.g., Social Security numbers, financial information, precise geolocation, racial or ethnic origin, health information, contents of communications).
19.6 Your CCPA/CPRA Rights
You have the right to:
- Know what personal information we have collected about you, its categories, purposes, and third parties with whom it is shared;
- Access the specific personal information we have collected about you;
- Delete personal information we hold about you (subject to applicable exceptions);
- Correct inaccurate personal information;
- Opt-out of the sale or sharing of personal information (though we do not sell or share as defined above);
- Limit use of sensitive personal information (not applicable; we do not collect such information);
- Non-discrimination: We will not discriminate against you for exercising any of these rights.
19.7 Submitting a CCPA Request
To submit a request to know, access, delete, or correct your personal information, contact us at customerservice@buffalogames.com with subject line "CCPA Privacy Request." We will verify your identity before processing the request. We aim to respond within 45 days (extendable to 90 days with notice).
Alternatively you can contact us at Toll-Free Telephone: (855)-895-4290 or atPrivacy Request Form: [INSERT URL]
Authorized Agents: You may designate an authorized agent to submit a CCPA request on your behalf. We will require written proof of the agent's authorization and may verify your identity directly.
20. Google Play Data Safety and Apple Privacy Labels
- We maintain privacy disclosures in the Apple App Store and Google Play Store in accordance with their respective requirements. Those disclosures are reviewed and updated separately to reflect the data practices applicable to the mobile App.
21. Push Notifications
The App may send push notifications to parents for service-related purposes, where applicable and depending on enabled features. Push notifications are delivered via Apple Push Notification Service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android.
We do not use push notification services for advertising or marketing purposes. You may disable push notifications at any time through your device's notification settings; this does not affect core App functionality.
22. Analytics and Crash Reporting
22.1 Anonymous Analytics
The Company collects anonymous, aggregate analytics data to understand how the HelloBlink Service is used and to improve the product. Analytics data includes:
- Anonymous print event counts (by type and source);
- Anonymous code redemption outcome distributions;
- AI generation request and outcome counts.
All analytics exports are reviewed to confirm they contain no row-level child data, no device identities, and no personal information before being used by operations teams.
22.2 Crash Reporting
Structured application logs are used for error detection, performance monitoring, and service reliability. Log configurations are reviewed before production deployment to ensure no PII appears in any log line.
The Service does not use third-party crash analytics SDKs (such as Firebase Crashlytics or Sentry) within the consumer mobile app in a manner that would transmit personal information. Where such tooling is evaluated in future, this Privacy Policy will be updated.
23. Licensed Content (Disney Edition)
The HelloBlink Disney Edition includes co-branded content and hardware. Access to licensed content may be validated using product or device information within Company systems. This validation does not require disclosure of a child’s name, contact information, voice recording, prompt, or generated image to Disney.
23.1 Data Sharing with Disney and Other Licensors
Certain HelloBlink products include content licensed from Disney or other licensors. We do not provide licensors with children’s personal information, parent-account information, email-derived identifiers, purchase histories, or device identifiers. We may provide licensors with aggregate or deidentified usage statistics that cannot reasonably identify a child, parent, account, or device.
Licensors’ privacy policies apply only when you interact separately with services they operate.
Disney-licensed content is not provided, transmitted, or managed by The Walt Disney Company or its affiliates through this App. The Walt Disney Company's privacy policies govern interactions with Disney's own platforms and are separate from this Policy.
24. Links to Third-Party Services
The HelloBlink App may include links to third-party resources such as the App Store, Google Play Store, or support pages. These links are provided for convenience only. The Company does not control, and is not responsible for, the privacy practices of any third-party website or service. We encourage you to review the privacy policies of any third-party service before providing personal information.
25. Changes to This Privacy Policy
The Company may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. Material changes will be communicated to parents through:
- A prominent in-app notice;
- An updated "Effective Date" at the top of this Policy.
For changes that materially affect how we process children's data or introduce a new use of personal information (though our architecture is designed to prevent such a change), we will provide advance notice and, where required by applicable law, obtain fresh parental consent before implementing the change. This commitment is consistent with the FTC's amended COPPA Rule's requirement for separate consent for material new uses of children's personal information.
We encourage you to review this Policy periodically. Your continued use of the Service after the effective date of any updated Policy constitutes your acceptance of the changes.
26. Operators and Privacy Contact
The operators of the HelloBlink Service are Buffalo Games LLC and Ceaco Inc. Buffalo Games LLC serves as the designated contact for questions and parental requests concerning children’s privacy:
Buffalo Games LLC Attn: Privacy Team
220 James E. Casey Drive Buffalo, NY 14206
Email: customerservice@buffalogames.com Telephone: (855) 895-4290 Privacy Request Form: [INSERT URL]
We aim to respond to all privacy inquiries within 30 days.
General Support:
- Choosing a selection results in a full page refresh.
- Opens in a new window.