HeyGilli is operated as an independent project, not a company. Throughout this policy, "we," "us," and "HeyGilli" refer to that project, reachable at hello@heygilli.com.
Only a parent or guardian creates a HeyGilli account and signs in. A child never signs in to anything, is never asked to enter information, and is never shown a way to leave their own screen without the parent's PIN. Everything in this policy about "you" refers to the parent.
HeyGilli offers two ways to start a household, and what is collected differs between them.
| Sign-in method | What is collected |
|---|---|
| Continue with Google |
Your Google account's basic profile only (name, email address,
profile photo — the standard openid, email,
and profile scopes). HeyGilli does not ask for access to
your YouTube account: sign-in tells us which household you are, and
nothing more.
|
| Set up without Google |
A random identifier generated on your device (for example
trial-3c994baf52eab4ec…). No name, email, or Google
account is collected. This identifier is stored only on your device
and sent to our server to find your household on later visits.
|
You create this; your child does not enter any of it themselves.
HeyGilli never reads your YouTube account. Channels reach your household in one of three ways, all initiated by you:
Watch history is opt-in, every single time, and is never stored as a list. If you tick the history option during an import, we read the exported "watch-history.json" only long enough to compute a small aggregate — total videos, the date range, a per-hour-of-day pattern, and the channels most and least watched — and then discard the underlying list of individual videos entirely. We do not retain a video-by-video watch history for any child, on our servers or otherwise.
We do not use your or your child's information to build advertising profiles, and we do not run any advertising or third-party analytics or tracking SDKs of any kind in the app.
We do not sell personal information, and we do not share it with anyone for their own marketing purposes. Information passes through the following service providers, strictly to run the app:
| Provider | What it handles |
|---|---|
| Google (Sign-In) | Authenticates the parent, and nothing else. No access to your YouTube account is requested. |
| Amazon Web Services — Bedrock | The AI model that screens videos and drafts Gilli's questions. It sees video metadata and transcripts, not your account identity. |
| Amazon Web Services — Polly | Converts Gilli's scripted lines to speech audio. |
| Amazon Web Services — DynamoDB | Stores household, child, and session records described above. |
| Render & Vercel | Host the server and the app itself. Standard web server logs (IP address, timestamp, requested address) are generated at this layer, as with any web service. |
We may disclose information if required to by law, or to protect the safety of a child, ourselves, or others — this is a standard reservation, not something we expect to need.
Google API Services User Data Policy. HeyGilli's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Your YouTube subscription data is used only to run the features described in this policy — never for advertising, never to train general-purpose AI or machine-learning models, and never read by a person except where the law requires it.
HeyGilli is built around the requirement that a child never creates an account, never signs in, and never provides information directly — every child profile is created and configured by a parent, and every consent to connect a Google account or upload an export is given by that parent. We do not knowingly collect personal information directly from a child.
If you believe a child has provided us with personal information other than through a parent's own account setup, contact us at hello@heygilli.com and we will investigate and delete it.
We keep household and child records for as long as the account exists, so the app can keep working the way you left it. Some things you can remove yourself right now inside the app:
Full account deletion is not yet self-serve. HeyGilli does not currently have an in-app "delete my account" button. To request deletion of a household, a child's profile, or your connected Google token, email hello@heygilli.com from the address associated with the account (or describe the household so we can locate it) and we will delete the underlying records. We aim to complete this within 30 days of a verified request.
You can also revoke HeyGilli's access to your Google account at any time, independently of us, from myaccount.google.com/permissions . This immediately stops the app from being able to read your subscriptions; existing app data is removed only once we act on a deletion request as above.
Data is transmitted over encrypted connections (HTTPS/TLS). This project is at an early, actively developed stage — as with any software at this stage, our security practices continue to evolve, and we do not claim a specific certification or guarantee against every possible failure. We ask that you use a household-specific Google account and PIN you don't reuse for anything sensitive elsewhere.
Our infrastructure runs on servers located in the United States (AWS
us-east-1). If you use HeyGilli from outside the United
States, your information is transferred to and processed there.
If this policy changes in a way that meaningfully affects what we collect or how we use it, we will update the date at the top of this page. Continuing to use HeyGilli after a change means you accept the updated policy.
Questions, deletion requests, or concerns about a child's information: hello@heygilli.com.