Business details required before publication
This document is structurally complete but intentionally remains noindex until the legal entity name, registered address, registration number, NIP, contact email, and effective date are configured.
Effective 2026-08-10
Privacy Policy
This US-facing notice explains how our Poland-based business handles personal information when an adult creates an AI-assisted personalized children’s storybook. It also preserves GDPR rights that may apply because we operate from Poland.
, trading as Stories
, Poland
Registration:
Tax ID (NIP):
Contact:
1. Scope and controller
, trading as Stories, is the controller of personal information handled through the website, adult account, story creator, project library, billing records, and order coordination. Address: , Poland. Privacy contact: .
Stripe, Google, an email or social sign-in provider, and some delivery providers may act as separate controllers for their own fraud, account, legal, or network purposes. Their notices apply to that independent processing.
2. Notice at collection — categories and sources
| Category | Examples | Source |
|---|---|---|
| Identifiers and account data | Name, email, provider account ID, avatar, login and consent timestamps | You and the sign-in provider |
| Story and project content | Story idea, text, optional first name or age range, language, style, prompts, edits, generated illustrations, proof, PDF | You and requested generation |
| Optional child-related content | Appearance description and 1–3 reference photos supplied by an authorized adult | You |
| Commercial information | Selected plan, credits, transactions, refunds, entitlements, print and shipment status | You, Stripe, Stories, Lulu |
| Delivery and support | Recipient, postal address, shipping option, tracking, support messages, defect photographs | You, Lulu, carriers |
| Technical and security | IP address, timestamps, browser/device information, rate-limit, authentication, fraud, and error records | Your device and our systems |
| AI operational metadata | Provider/model, request status, token or image usage, latency, estimated cost, and non-sensitive error code | Our systems and AI provider |
| Optional analytics | Product step, device-size class, outcome, and non-sensitive checkout cancellation reason | Your browser only after your choice |
We do not request a child’s exact birth date, school, contact details, government identifier, or precise location. Please do not include those details in a story.
3. Why we use information
- provide the adult account, save and edit projects, perform requested text and image generation, maintain visual continuity, prepare PDFs and proofs, and deliver support;
- process payments, grant book or credit entitlements, prevent duplicate grants, respond to refunds and chargebacks, and keep accounting records;
- quote, authorize, produce, ship, track, replace, or refund a personalized physical book;
- secure accounts, moderate dangerous or unlawful use, enforce limits, diagnose failures, and protect people and the service;
- comply with tax, accounting, consumer, child-safety, sanctions, and lawful-request obligations;
- measure product reliability using minimized first-party analytics only after the requested choice.
Where GDPR applies, these purposes rely on contract, legal obligation, legitimate interests balanced against your rights, and consent where required. Optional photograph processing also requires the versioned adult confirmation described in our Photo & AI Processing Notice.
4. Children, COPPA, and adult-supplied content
Stories is an adult-directed service. We do not knowingly permit a child under 13 to create an account or submit information directly. An adult may choose to provide limited child-related content to create a book, but must confirm that the adult is 18+ and has parental, guardian, or other lawful authority.
If we learn that information was submitted directly by a child under 13 without appropriate adult involvement, we will restrict processing and delete it as required. A parent or guardian can contact us to review or delete child-related content they provided and prevent further use. The FTC explains that covered services must minimize retention and give parents access and deletion controls in its COPPA guidance.
5. Reference photos and sensitive information
Reference photos are optional and are used to carry visible, non-sensitive appearance cues—such as hair, face shape, skin tone, and visible accessories—into a stylized fictional character. We do not use them for face recognition, identity verification, biometric identification, authentication, emotion analysis, or inference of health, religion, ethnicity, sexual orientation, or other sensitive traits.
Before processing a photo, we record an adult’s confirmation of age, authority, and requested AI processing. Withdrawing that confirmation stops new photo-based requests and clears the photos stored in the current browser project. It cannot remove visual traits already incorporated into an illustration, and providers may complete legally permitted security-log deletion cycles.
6. Microphone dictation
The “tell it out loud” feature uses the speech-recognition capability supplied by your browser or operating system. Stories receives the resulting text transcript and does not intentionally upload or retain a raw audio recording. The browser, operating system, or speech provider may process audio under its own settings and notice. You can type instead and can deny microphone permission.
7. Service providers and disclosures
We disclose only the information reasonably needed for the selected function to these categories:
- Supabase — adult authentication, database, access controls, and account infrastructure;
- OpenAI — requested story and illustration generation, including optional reference images and earlier illustrations used for continuity;
- Cloudflare R2 — private project, image, proof, and PDF storage where server storage is used;
- Stripe — hosted checkout, payment methods, fraud controls, transaction, refund, and dispute records; we do not receive full card numbers;
- Google, Meta, or email infrastructure — only the sign-in option you choose;
- Lulu and delivery partners — final print files, recipient and address, production instructions, shipping option, tracking, and defect resolution;
- security vendors, professional advisers, authorities, and a buyer of the business where legally permitted and appropriately safeguarded.
OpenAI states that API data is not used to train its models unless the API customer opts in. Its default abuse-monitoring logs may contain prompts, responses, images, or files and are generally retained for up to 30 days, subject to safety and legal exceptions. Image inputs are also scanned for child sexual abuse material. See OpenAI’s API data controls.
8. No sale, targeted advertising, or unrelated training
We do not sell personal information for money, share it for cross-context behavioral advertising, or use story text or child-related photographs for targeted advertising. We do not use customer content to train our own general-purpose model. We do not knowingly sell or share personal information of consumers under 16.
Because we do not conduct those activities, there is currently no sale/share opt-out signal to process. If this practice changes, we will provide advance notice and the legally required controls before the change.
9. Retention and deletion
- Account and active project content: while the account or saved project remains active and as needed to deliver requested books, unless deleted sooner.
- Optional source photos: only while needed for the selected project and generation workflow, until you remove them, withdraw the photo confirmation, or delete the project/account, subject to provider security and backup cycles.
- Generated illustrations and PDFs: while the project remains saved so you can edit, download, reprint, or obtain support.
- AI request operational metadata without story or photo content: up to 90 days, then deleted or aggregated.
- Optional first-party product analytics: up to 13 months, then deleted or aggregated.
- Payment, tax, accounting, fulfillment, complaint, refund, and fraud records: for the period required by applicable law and reasonably needed to establish or defend claims.
Deletion from active systems can be followed by a limited rolling backup cycle. We may preserve specific information when required by law, for child safety, fraud prevention, dispute handling, or a litigation hold. De-identified information may be retained when it cannot reasonably identify a person.
To delete an account or specific project, follow our Data Deletion Instructions.
10. US state privacy rights
Subject to applicable state law, you may request confirmation or access, the categories and specific pieces collected, sources, purposes, and recipient categories; correction; deletion; portability; restriction of certain sensitive-data uses; opt-out of covered sale, sharing, targeted advertising, or qualifying profiling; and an appeal if a request is denied. We do not discriminate against a consumer for exercising a privacy right.
Send a request or appeal to with “US Privacy Request” in the subject. We will verify the requesting adult and may verify parental authority before disclosing or deleting child-related content. An authorized agent may act where state law permits; we may request proof of authority and direct identity confirmation. California residents can review the California Attorney General’s CCPA rights overview.
11. International processing and GDPR rights
We operate from Poland and use providers in the United States and other countries. Where GDPR or UK GDPR applies, transfers use an adequacy decision, standard contractual clauses, or another lawful safeguard where required.
You may also have rights to access, correct, erase, restrict, port, or object; withdraw consent; and complain to a supervisory authority, including Poland’s UODO. Withdrawing consent does not make earlier lawful processing unlawful.
13. Security and incidents
Measures include encrypted transport, OAuth or magic-link authentication, row-level database controls, restricted private storage, signed upload links, content and file validation, rate and queue limits, Stripe-hosted card entry, webhook signatures, idempotent fulfillment, and minimized operational logging. No system is perfectly secure.
If you believe an account, child-related project, or photograph was exposed, contact promptly. We will investigate and provide legally required notifications.
14. Changes and contact
We may update this notice to reflect service, provider, or legal changes. The effective date identifies the current version; material changes will be communicated where required.
Privacy questions, rights, parent/guardian requests, or appeals: . Postal address: , , Poland.
