Privacy Policy

Colorful — a coloring book for young children

Last updated 29 August 2026 · Effective 29 August 2026

The short version. Colorful has no accounts, no ads, nothing to buy and no way to reach the open web. A child’s drawings are saved on their own device and are never uploaded to us. We do receive anonymous usage counts and crash reports, through Google Firebase, so we can tell which pages get used and when the app breaks. We never sell or share data with advertisers, and we do not ask children for any personal information.

Who we are

Colorful is made and published by Utsav Patel (“we”, “us”), an independent developer. This policy covers the Colorful iPhone and iPad app and the pages served from colorful-prod.web.app. Questions go to utsavhacker@gmail.com.

What stays on the device

Everything a child makes:

If the device owner uses the share button to save a finished picture to Photos, print it, or send it to someone, that is the device doing it, at their instruction. The picture goes where they send it; it does not come to us.

What we do receive

The app includes two Google Firebase services. Neither one is an advertising service.

Firebase Analytics — anonymous usage

So we can see which worlds and drawing tools children actually use, the app reports these events, and nothing else: the app was opened; a world was opened; a page was opened; a page was finished; a page was started again; a tool was picked; a setting was switched; a world’s artwork could not be downloaded. Each carries only the world or page it refers to — for example seaworld, bugs_3, brush.

Alongside those events, Google’s SDK collects standard, non-identifying context: a randomly generated app-instance identifier, the device model, the iOS and app version, the device language, and an approximate country or region worked out from the network IP address. We never see the IP address itself, and the app-instance identifier is reset if the app is deleted and reinstalled.

Firebase Crashlytics — crash reports

When the app crashes, Crashlytics sends us a report so it can be fixed: where in our code it happened, the device model, the iOS version, how much memory and storage was free, and a randomly generated installation identifier. Crash reports contain no drawings and nothing a child typed, because there is nothing in this app for a child to type.

Serving the artwork

On first launch, and occasionally afterwards to check for new pages, the app requests files from colorful-prod.web.app. Like any web server, Firebase Hosting logs those requests, including the IP address that made them, and Google retains those logs for its own operational and security purposes. We do not use them to build any profile of a user.

What we never collect

Not collectedWhy not
Names, email addresses, phone numbersThere is no account and no form. The app never asks.
The Advertising Identifier (IDFA)There is no advertising in Colorful, so the framework that reads it is not in the app. You will never see an App Tracking Transparency prompt.
Precise locationNever requested, and no location permission is ever asked for.
Contacts, calendar, microphone, cameraNever requested.
Photos on the deviceThe app can add a finished picture to Photos when asked. It has no permission to read the library and cannot see any existing photo.
Drawings and artwork made by a childThey never leave the device.

Tracking, advertising and selling data

We do not track users across apps or websites, and we do not allow anyone else to. There is no advertising SDK in Colorful, no in-app purchase, and no analytics partner other than Google Firebase. Ad-personalisation signals are switched off in our Firebase configuration. We do not sell personal information, and we do not share it for cross-context behavioural advertising — under the CCPA/CPRA or under any other law.

Children

Colorful is made for young children, and it is built so there is nothing for a child to give away: no account, no sign-in, no name to enter, no chat, no comments, no user-to-user contact, no links out to the web, and no advertising. We do not knowingly collect personal information from anyone, of any age.

The anonymous usage and crash information described above is collected to keep the app working and to decide what to draw next. It is not tied to a name or to any identifier that could reasonably be used to recognise a person, and it is never used to advertise to anyone. If you are a parent or guardian and would like the data associated with a device deleted, write to us at utsavhacker@gmail.com and we will do it.

How long it is kept

Analytics events are retained by Google for up to 14 months and then deleted automatically. Crash reports are retained for up to 90 days. Server logs follow Google Cloud’s own retention schedule. Drawings are kept on the device until the child clears the page, the app is deleted, or storage is cleared in the app’s Settings — we hold no copy to delete.

Who else is involved

Google Ireland Limited and Google LLC process analytics, crash reports and hosting on our behalf, under Google’s own terms. Their handling of that data is described in the Google Privacy Policy and the Firebase Privacy and Security notice. Data may be processed on servers in the United States and elsewhere; transfers out of the EEA and UK rely on the European Commission’s Standard Contractual Clauses. Nobody else receives anything.

Your rights

Depending on where you live — the EU and UK under the GDPR, California under the CCPA/CPRA, and comparable laws elsewhere — you may have the right to ask what we hold about you, to have it corrected or deleted, to object to it being processed, or to receive a copy. Because we hold nothing that identifies a person, there is usually nothing to send back; where a request can be acted on, we act on it free of charge and within 30 days. Write to utsavhacker@gmail.com.

Where the GDPR applies, our lawful basis for the analytics and crash information is our legitimate interest in keeping the app working and understanding which pages are worth drawing. You can stop all of it at any time by deleting the app. Exercising any right will never cost you anything or make the app work worse.

Security

Everything the app fetches is fetched over HTTPS. Drawings sit in the app’s own sandbox on the device, protected by iOS. No system is perfect, but there is very little here to lose: we hold no accounts, no passwords and no personal data.

Changes

If this policy changes we will post the new version on this page and move the date at the top. A change that materially affects what is collected will also be described in the app’s release notes on the App Store.

Contact

Utsav Patel · utsavhacker@gmail.com