Legal

Privacy policy

Last updated: June 16, 2026

Draft policy for MVP readiness. Human legal review is required before public production launch.

This policy explains how the service handles account details, child photo uploads, story inputs, generated books, orders, support requests, and operational logs for personalised children's book creation.

Information we collect

Account and contact details such as name, email address, authentication identifiers, and support messages.

Book inputs such as age band, occasion, theme, story subject, dedication text, character descriptions, selected style, font, and selected language or regional variant.

Optional uploaded photos or reference images when an adult confirms they have permission to use the image for private book generation.

Payment, order, fulfilment, refund, credit, and support records needed to provide the digital proof, hardcover upgrade, customer service, fraud prevention, tax, and accounting workflows.

Operational events such as moderation decisions, generation status, admin actions, webhook processing, email delivery status, and analytics events with sensitive fields redacted.

How we use information

To create, edit, render, and deliver a private digital proof and, after approval, prepare print files for hardcover fulfilment.

To moderate uploads and story inputs, prevent unsafe or infringing requests, troubleshoot failed generation jobs, and support retries.

To process payments, issue receipts, maintain order history, handle approved refunds or credits, and provide customer support.

To protect the platform through rate limiting, audit logs, webhook idempotency, signed private asset links, and admin access controls.

Child photo consent and private assets

Photo upload is optional. The service supports avatar and text-based character descriptions when no photo is provided.

When a child photo is uploaded, the adult uploader must confirm they have permission to use the photo for the private book generation workflow.

Uploaded image bytes are validated, re-encoded to strip metadata such as EXIF/GPS data where possible, and stored in private asset storage.

Private uploads, thumbnails, processed references, generated images, PDFs, and print snapshots are served through expiring signed links instead of public storage paths.

AI providers and generated content

Story and image prompts are constructed from the provided book details and internal safety instructions.

Prompt audit logs store hashed/redacted prompt metadata, model/provider details, and cost information without intentionally storing raw child-photo data or full raw prompts in public-facing records.

Generated books may contain errors or unexpected content. Adults should review the proof before downloading, sharing, or approving it for print.

Retention and deletion

Account privacy controls let signed-in users export account data and request deletion of creative book data, uploaded photos, generated images, editable page text, and page edit history snapshots.

Deletion scrubs creative project, character, and page content while retaining payment, fulfilment, fraud-prevention, tax, support, moderation, and admin audit records where legally or operationally required.

Private assets with expiry dates can be removed by the retention cleanup workflow, and account deletion records count-only analytics events for compliance reconciliation.

Disclosure and processors

Managed providers may process data for authentication, database, private storage, payments, transactional email, analytics, error monitoring, AI generation, moderation, queues, rate limiting, and print fulfilment.

Provider configuration must be completed in the production environment before public launch, and live print submission remains disabled until the print provider is configured and reviewed.

Customer photos and generated likenesses are not used in public examples, reviews, marketing, or training claims without separate explicit opt-in consent.

Contact and requests

Use the contact page or account privacy controls to ask about access, deletion, refunds, support, or safety concerns.

Requests may require account verification before private data, orders, or child-photo related records are disclosed or changed.