Privacy Policy

Last updated: [DATE]

Storytime Buddies ("we," "us," "our") is operated by [LEGAL ENTITY NAME, e.g. company name and registration number], of [REGISTERED ADDRESS]. This policy explains what information we collect, why we collect it, and the choices you have. We have written it in plain English because parents deserve to understand it without a law degree.

The short version

We collect as little as possible. A parent's email address to run the account. A child's first name and age, entered by the parent, to personalise stories and set reading level. The stories created. Payment is handled entirely by our payment provider; we never see card numbers. We do not show ads, we do not sell data, and children never create accounts or enter personal information themselves.

Who provides information

Only adults. Accounts are created and managed by a parent or legal guardian aged 18 or over. Children cannot sign up, cannot enter contact details, and cannot communicate with other users, because the product contains no chat, messaging, sharing, or comment features.

What we collect

From the parent: email address, password (stored in encrypted form by our authentication provider), subscription plan and billing status, and any correspondence you send us.

About each child, entered by the parent: first name, age, a chosen avatar, and a reading-level setting derived from age. We deliberately do not collect surnames, birthdates, photographs, locations, school details, or contact information for children.

Created in the app: the stories generated for each child profile, the choices made to create them (character, place, story event), reading progress (number of stories completed, characters unlocked), and, for older reading levels only, an optional short story idea typed by the child. Typed ideas are used once to generate the story and are not displayed back, published, or used for any other purpose.

Automatically: basic technical information needed to run a secure website, such as IP address, browser type, and login timestamps, held by our hosting and authentication providers ([Supabase / HOSTING PROVIDER]). We use [NO ANALYTICS / the following analytics: ANALYTICS TOOL, configured without advertising features].

What we do NOT collect

No advertising identifiers. No behavioural advertising profiles. No precise location. No microphone audio: the read-aloud voice is generated on your own device by your browser and no recording or audio data is sent to us. No data is ever sold or rented to anyone.

How we use information

To run the service: creating stories, remembering progress and unlocked characters, enforcing daily story limits, and managing subscriptions. To keep the service safe and secure. To respond when you contact us. To send essential service emails such as receipts, renewal notices, and password resets. We send marketing email only if you opt in, and you can opt out at any time.

AI processing

Stories are written by an artificial intelligence model provided by Anthropic. When a story is created, we send the chosen character, place, story event, reading level, and (where used) the typed story idea to Anthropic's API to generate the story text. We do not send the child's name, age, or any account information to the AI provider. Anthropic processes API inputs under its commercial terms and does not use our API data to train its models. See the AI Content Disclosure for more.

Payments

Subscriptions are processed by Lemon Squeezy, our merchant of record. Lemon Squeezy collects and processes your payment details under its own privacy policy and handles applicable sales taxes. We receive confirmation of your subscription status, never your card details.

Where data lives and how long we keep it

Account data and stories are stored with [Supabase, hosted in REGION]. We keep your data while your account is active. If you delete a child profile, that child's stories and progress are deleted [immediately / within X days]. If you close your account, all account data is deleted within [X days], except minimal records we must keep for tax and legal compliance. Free-plan stories that are not saved to a shelf are automatically deleted after [X days].

Your rights

Depending on where you live (including under UK and EU GDPR and applicable laws of [JURISDICTION]), you may have rights to access, correct, delete, restrict, or port your data, and to object to processing. You can exercise most of these directly in the parent dashboard: view and delete any child profile, any story, or your whole account. For anything else, email [PRIVACY EMAIL]. You also have the right to complain to your data protection authority.

Security

We use encrypted connections (HTTPS) throughout, encrypted password storage, row-level database security so each family's data is isolated, and server-side controls so that account limits and child data cannot be accessed from the browser of another user. No internet service can promise perfect security, but we have designed this one to hold as little sensitive data as possible, which is the best protection of all.

Changes

If we make material changes to this policy, we will email account holders and post the new version with a new date at least [14] days before it takes effect.

Contact

[LEGAL ENTITY NAME], [ADDRESS], [PRIVACY EMAIL].