Privacy Policy

Last updated:

Draft notice: this page was drafted to ship with the marketing site launch and is pending legal review. Substantive changes may follow.

StoryTelly is built by parents, for parents. We collect the minimum data needed to deliver illustrated stories — and we treat your child's name with the care it deserves.

This Privacy Policy explains what we collect and how we use it. For your rights as a data subject — and how to exercise them — see our Privacy Rights page.

1. What we collect

When you create a StoryTelly account, we collect:

  • Email address. For account identification, password recovery, and (with your consent) product updates.
  • Password (hashed). Stored only in salted-bcrypt form. We never see your plaintext password.
  • Stories you generate. Story prompts, narrative text, and illustrations are stored in your account so you can reopen them.
  • Optional account metadata. Display name (if set), subscription tier, two-factor preference.
  • Feedback you send us. If you use “Send us a note”, we store your message, the category you picked, and the app version and platform it was sent from, so we can act on it and (only if you asked us to) reply. The form asks you not to include your child's name or other personal details in the message.

We do not collect: your child's real name when you use the hero name field or mark a character as your child (it stays on your device — see below), your location, your browsing history outside StoryTelly, contacts, or any third-party tracking identifiers. Other names you choose to type into a story are part of your story text and are stored with it.

2. Your child's name

The child name you enter in a story's hero name field — and the name of any saved character you mark as your child — is tokenized client-side before any prompt leaves your device. The server receives only the tokenized form ([CHILD]). The plaintext name is encrypted and stored locally, keyed to your account.

Names entered anywhere else are not tokenized. Another child mentioned in your story text, or a character you have not marked as your child, is part of your story content: it is stored with your story and sent to our AI providers to create it, like the rest of your words. Each story protects one child's name this way. If you would rather a name never reach our servers, use the hero name field for it or leave it out of the story text.

When you read a story, the plaintext name is reinserted client-side. So your child sees their real name on the page; our servers never do.

Logout does not clear locally-stored names (so signing back in on the same device restores them across all your stories). Account deletion does clear them.

3. How we use your data

We use the data above to:

  • Provide the StoryTelly service (generate stories, store them in your account, deliver them across your devices).
  • Send transactional emails (password resets, two-factor codes, email verification).
  • Send optional notification emails — social ones (for example, when a friend sends you a request, comments on a story, mentions you, or shares a new one) and story-update ones (when a story you created finishes or needs another try) — only if you turn them on per category in the app's notification settings. Every such email includes a one-click unsubscribe link, and you can change or turn off these emails any time in the app.
  • Send optional push notifications to a device where you turn them on — for the same events as the notification emails above — only if you enable push in the app and grant your browser's notification permission. Push messages carry only a short title, a short message, and a link back into the app; they never include the content of a story or a child's name. You can turn push off any time in the app's notification settings or in your browser.
  • Provide aggregate, anonymous analytics on site traffic via Cloudflare Web Analytics — cookieless and privacy-first; no individual user is identified.
  • Comply with legal obligations and respond to lawful requests for information.

We do not sell your data, share it with advertisers, or use it to train AI models on your private content.

4. How illustrations are created

Illustration prompts are sent to one of several leading AI image providers (OpenAI, Stability AI, Replicate, Google, fal.ai), depending on the style you choose. Every prompt is screened against OpenAI's moderation API before any image is generated.

Generated images are stored in our object storage (Cloudflare R2) and served to your browser via signed URLs with short expiry. Image-provider companies receive illustration prompts in which a marked child's name has been replaced by a placeholder token; other character names appear in the prompt as written.

5. Voice recordings

The optional “Tell it out loud” feature records short audio clips when you choose to speak — either a story idea or a description of a character you want to save. Each clip is sent to OpenAI for speech-to-text transcription, and the resulting transcript is sent to Anthropic to interpret it into a story setup, or a character description, that you review and confirm before anything is saved or generated. We collect this audio solely to fulfil that request, and for no other purpose.

How the audio is used, and when it is deleted. The recording is used for one thing only: converting your speech into text so we can respond to the request you made. It is deleted immediately after it has been transcribed and we have responded to that request. It is never written to our database, our object storage, or disk; it is never retained, shared, sold, or used to train AI models; and it is never used to identify or recognise a speaker. Only the resulting text is kept. A spoken hero name — or a character's name when you mark that character as your child — is replaced with a private token in the saved text; other spoken names remain part of the text.

Because transcription is performed by our speech-to-text provider, the audio (which may contain a child's spoken name) is processed transiently by that provider before it is deleted. This collection is limited to responding to the user's request and is disclosed here as required.

6. Data retention policy

This is our written data-retention policy. For each category of information we collect, it states the purpose the information is collected for, the business need that justifies keeping it, and the timeframe in which it is deleted. We do not retain any information for longer than is reasonably necessary to fulfil the purpose it was collected for, and we never retain it indefinitely for a purpose it was not collected for.

  • Voice recordings. Purpose: converting speech to text so we can respond to the request you made. Business need: the recording is the input to transcription and has no use once transcribed. Timeframe: deleted immediately after transcription — it is held only transiently in memory and is never written to a database, object storage, or disk.
  • Voice transcripts and their interpreted result. Purpose: producing the story setup or character description you review. Business need: it must survive only long enough for you to review and confirm it. Timeframe: held in memory only and discarded automatically within minutes; nothing is persisted unless you accept it, at which point it becomes ordinary account content below.
  • Account data, stories, characters, and illustrations. Purpose: providing the service and letting you reopen your content. Business need: the content is the service. Timeframe: retained while your account is active, and removed within 30 days of account deletion.
  • Feedback you send us. Purpose: understanding what to fix or build next, and replying when you have asked us to. Business need: a note stops being actionable once it has been read and acted on; we keep it only long enough to spot recurring themes across releases. Timeframe: deleted automatically 12 months after submission, and immediately if you delete your account.
  • Aggregate, anonymized usage statistics. Purpose: understanding service health and usage. Business need: they contain no personal information and cannot be linked back to an individual. Timeframe: may be retained indefinitely in aggregate form.

Backups are retained for 30 days; restoring from backup is reserved for emergency recovery and would never reinstate a deleted account's data beyond that window.

7. Third-party processors

We use a small set of trusted third-party processors to deliver the service. Each processes data only as needed and under contractual confidentiality:

  • Render (US) — application hosting.
  • Neon (Frankfurt, EU) — database hosting for accounts + stories.
  • Cloudflare (US) — DNS, CDN, R2 image storage, and Web Analytics.
  • Resend (US) — transactional email delivery.
  • Web push services — when you enable push notifications, delivery goes through your browser's own push service: Google (Firebase Cloud Messaging, for Chrome, Edge, and Android), Apple (Apple Push Notification service, for Safari and installed iOS web apps), or Mozilla (for Firefox). Which one is used is determined by the browser you enabled push in. These services relay only the push message itself — a short title, a short message, and a link back into the app — never the content of a story or a child's name.
  • OpenAI / Anthropic / Stability / Replicate / Google / fal.ai / ElevenLabs — AI providers for story narrative, character descriptions, illustrations, and audio narration. They receive prompts in which a placeholder token stands in for a marked child's name (the story's hero-name field, or a character marked as your child); other names you include appear in the prompts as written. Two further exceptions:
    • If you use the optional voice feature — to speak a story idea or to describe a character — OpenAI receives the audio clip for transcription and Anthropic receives the transcript, after which the audio is deleted immediately (see “Voice recordings” above).
    • If you use premium AI read-aloud narration, the story text — which may include a child's first name — is sent to the narration provider (OpenAI or ElevenLabs) as transient input to generate speech. The generated audio is streamed to your device and is never stored or logged on our servers. To avoid re-generating the same narration when you re-read a story, your device may keep a copy of the audio on your device only, in encrypted browser storage — it is removed when you delete your account (and whenever you clear your browser's site data), and older clips are evicted automatically as the small space cap fills.
  • Stripe (US) — payment processing (when subscriptions launch). Card details are handled exclusively by Stripe; we do not store them.

9. Security

We follow industry-standard practices to protect your account: HTTPS everywhere, bcrypt-hashed passwords, JWT-based sessions with short expiry, two-factor authentication (optional), CSRF protection on every state-mutating endpoint, and a strict Content Security Policy on the marketing site.

No security system is perfect. If you suspect your account has been accessed without authorization, change your password immediately and email hello@mystorytelly.app.

10. Cookies and similar technologies

The marketing site (mystorytelly.app) uses no cookies. Cloudflare Web Analytics is cookieless by design.

The application (the desktop app today; the web app when it launches at app.mystorytelly.app) uses a single session cookie to keep you signed in. This cookie contains a JWT and is HTTPOnly, Secure, and SameSite=Lax. No third-party cookies, no advertising trackers.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by email at least 30 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the updated Policy. The 2026-08-11 update clarified which names are tokenized — the child name you mark (a story's hero, or a character marked as your child) — and that other names in story text are handled as story content; no practice changed.

12. Contact

Questions about this Policy? Email hello@mystorytelly.app. To exercise your data rights, see /privacy-rights.