Privacy Policy
Last updated:
Draft notice: this page was drafted to ship with the marketing site launch and is pending legal review. Substantive changes may follow.
Contents
StoryTelly is built by parents, for parents. We collect the minimum data needed to deliver illustrated stories — and we treat your child's name with the care it deserves.
This Privacy Policy explains what we collect and how we use it. For your rights as a data subject — and how to exercise them — see our Privacy Rights page.
1. What we collect
When you create a StoryTelly account, we collect:
- Email address. For account identification, password recovery, and (with your consent) product updates.
- Password (hashed). Stored only in salted-bcrypt form. We never see your plaintext password.
- Stories you generate. Story prompts, narrative text, and illustrations are stored in your account so you can reopen them.
- Optional account metadata. Display name (if set), subscription tier, two-factor preference.
- Feedback you send us. If you use “Send us a note”, we store your message, the category you picked, and the app version and platform it was sent from, so we can act on it and (only if you asked us to) reply. The form asks you not to include your child's name or other personal details in the message.
We do not collect: your child's real name when you use the hero name field or mark a character as your child (it stays on your device — see below), your location, your browsing history outside StoryTelly, contacts, or any third-party tracking identifiers. Other names you choose to type into a story are part of your story text and are stored with it.
2. Your child's name
The child name you enter in a story's hero name field — and the name of any saved character you mark as your child — is tokenized client-side before any prompt leaves your device. The server receives only the tokenized form ([CHILD]). The plaintext name is encrypted and stored locally, keyed to your account.
Names entered anywhere else are not tokenized. Another child mentioned in your story text, or a character you have not marked as your child, is part of your story content: it is stored with your story and sent to our AI providers to create it, like the rest of your words. Each story protects one child's name this way. If you would rather a name never reach our servers, use the hero name field for it or leave it out of the story text.
When you read a story, the plaintext name is reinserted client-side. So your child sees their real name on the page; our servers never do.
Logout does not clear locally-stored names (so signing back in on the same device restores them across all your stories). Account deletion does clear them.
3. How we use your data
We use the data above to:
- Provide the StoryTelly service (generate stories, store them in your account, deliver them across your devices).
- Send transactional emails (password resets, two-factor codes, email verification).
- Send optional notification emails — social ones (for example, when a friend sends you a request, comments on a story, mentions you, or shares a new one) and story-update ones (when a story you created finishes or needs another try) — only if you turn them on per category in the app's notification settings. Every such email includes a one-click unsubscribe link, and you can change or turn off these emails any time in the app.
- Send optional push notifications to a device where you turn them on — for the same events as the notification emails above — only if you enable push in the app and grant your browser's notification permission. Push messages carry only a short title, a short message, and a link back into the app; they never include the content of a story or a child's name. You can turn push off any time in the app's notification settings or in your browser.
- Provide aggregate, anonymous analytics on site traffic via Cloudflare Web Analytics — cookieless and privacy-first; no individual user is identified.
- Comply with legal obligations and respond to lawful requests for information.
We do not sell your data, share it with advertisers, or use it to train AI models on your private content.
4. How illustrations are created
Illustration prompts are sent to one of several leading AI image providers (OpenAI, Stability AI, Replicate, Google, fal.ai), depending on the style you choose. Every prompt is screened against OpenAI's moderation API before any image is generated.
Generated images are stored in our object storage (Cloudflare R2) and served to your browser via signed URLs with short expiry. Image-provider companies receive illustration prompts in which a marked child's name has been replaced by a placeholder token; other character names appear in the prompt as written.
5. Voice recordings
The optional “Tell it out loud” feature records short audio clips when you choose to speak — either a story idea or a description of a character you want to save. Each clip is sent to OpenAI for speech-to-text transcription, and the resulting transcript is sent to Anthropic to interpret it into a story setup, or a character description, that you review and confirm before anything is saved or generated. We collect this audio solely to fulfil that request, and for no other purpose.
How the audio is used, and when it is deleted. The recording is used for one thing only: converting your speech into text so we can respond to the request you made. It is deleted immediately after it has been transcribed and we have responded to that request. It is never written to our database, our object storage, or disk; it is never retained, shared, sold, or used to train AI models; and it is never used to identify or recognise a speaker. Only the resulting text is kept. A spoken hero name — or a character's name when you mark that character as your child — is replaced with a private token in the saved text; other spoken names remain part of the text.
Because transcription is performed by our speech-to-text provider, the audio (which may contain a child's spoken name) is processed transiently by that provider before it is deleted. This collection is limited to responding to the user's request and is disclosed here as required.
6. Data retention policy
This is our written data-retention policy. For each category of information we collect, it states the purpose the information is collected for, the business need that justifies keeping it, and the timeframe in which it is deleted. We do not retain any information for longer than is reasonably necessary to fulfil the purpose it was collected for, and we never retain it indefinitely for a purpose it was not collected for.
- Voice recordings. Purpose: converting speech to text so we can respond to the request you made. Business need: the recording is the input to transcription and has no use once transcribed. Timeframe: deleted immediately after transcription — it is held only transiently in memory and is never written to a database, object storage, or disk.
- Voice transcripts and their interpreted result. Purpose: producing the story setup or character description you review. Business need: it must survive only long enough for you to review and confirm it. Timeframe: held in memory only and discarded automatically within minutes; nothing is persisted unless you accept it, at which point it becomes ordinary account content below.
- Account data, stories, characters, and illustrations. Purpose: providing the service and letting you reopen your content. Business need: the content is the service. Timeframe: retained while your account is active, and removed within 30 days of account deletion.
- Feedback you send us. Purpose: understanding what to fix or build next, and replying when you have asked us to. Business need: a note stops being actionable once it has been read and acted on; we keep it only long enough to spot recurring themes across releases. Timeframe: deleted automatically 12 months after submission, and immediately if you delete your account.
- Aggregate, anonymized usage statistics. Purpose: understanding service health and usage. Business need: they contain no personal information and cannot be linked back to an individual. Timeframe: may be retained indefinitely in aggregate form.
Backups are retained for 30 days; restoring from backup is reserved for emergency recovery and would never reinstate a deleted account's data beyond that window.
8. Friend invite links
If you use the optional friends feature, you may generate an invite link to connect with another adult without them searching for your handle. The social features are for adults only; invite links never involve or expose any child's information.
- The link contains a single random code. We store only a one-way cryptographic hash of that code, never the code itself, so the link cannot be reconstructed from our records.
- Each link is single-use, expires automatically after 72 hours, and can be revoked by you at any time. Used, expired, and revoked links are purged.
- Anyone who opens the link — before signing in — is shown your public profile identity (handle, display name, and avatar) so they know who invited them. This preview is available to any holder of the link even if your profile visibility is set to friends-only; sharing the link is what authorizes it. Redeeming the link creates a pending friend request that you still choose to accept.
9. Security
We follow industry-standard practices to protect your account: HTTPS everywhere, bcrypt-hashed passwords, JWT-based sessions with short expiry, two-factor authentication (optional), CSRF protection on every state-mutating endpoint, and a strict Content Security Policy on the marketing site.
No security system is perfect. If you suspect your account has been accessed without authorization, change your password immediately and email hello@mystorytelly.app.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email at least 30 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the updated Policy. The 2026-08-11 update clarified which names are tokenized — the child name you mark (a story's hero, or a character marked as your child) — and that other names in story text are handled as story content; no practice changed.
12. Contact
Questions about this Policy? Email hello@mystorytelly.app. To exercise your data rights, see /privacy-rights.