Privacy Policy
Last updated: April 6, 2026
StoryMaker ("we," "us," or "our") operates the StoryMaker application and website at stories-now.app. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
Account Information
When you create an account, we collect:
- Name
- Email address
- Password (stored as a secure hash, never in plain text)
- Profile picture (if you sign in with Google)
Family Information
When you set up your family, we collect:
- Family name
- Family member names and usernames
- Family member roles (admin, member, child)
Story Content
When you use our service to create stories, we collect:
- Character names, descriptions, traits, and appearance details
- Story themes and preferences
- Generated story text and illustrations
- Age range preferences and art style selections
Usage Information
We automatically collect:
- Session cookies for authentication
- Error logs for debugging and improving the service
2. How We Use Your Information
We use your information to:
- Create and manage your account
- Generate personalized stories and illustrations for your family
- Maintain story continuity across your family's stories
- Provide age-appropriate content based on your preferences
- Send password reset emails when requested
- Improve our service and fix bugs
3. Third-Party Services
We use the following third-party services to operate Story Maker: Supabase (database hosting), Cloudflare R2 (image and audio storage), Stripe (payment processing), PostHog (aggregated usage analytics), Expo (push notifications), and Lulu (print book fulfillment for physical book orders).
Your data may be processed by these services in accordance with their respective privacy policies. The full list of services and what data each receives is shown below:
| Service | Purpose | Data Shared |
|---|---|---|
| Anthropic (Claude) | Story text generation | Character names/traits, themes, story prompts |
| Google Vertex AI (Imagen) | Illustration generation | Image generation prompts (derived from story content) |
| Cloudflare R2 | Image and audio storage | Generated illustrations and audio files |
| Supabase | Database hosting | All account and story data |
| Stripe | Payment processing | Payment details (processed directly by Stripe; we store only subscription status) |
| PostHog | Aggregated usage analytics | Anonymous usage events (no personal data; text masking enabled) |
| Expo | Push notifications | Device push token |
| Lulu | Print book fulfillment | Shipping address and book content (only for physical book orders) |
| Vercel | Application hosting | Request logs, session cookies |
| Sentry | Error monitoring | Error logs and stack traces |
| Resend | Transactional email | Email address (for password reset emails) |
3a. AI-Generated Content
Story Maker uses artificial intelligence services to generate story text and illustrations. Anthropic (Claude) generates story text based on your character and theme selections. Google Vertex AI (Imagen) generates illustrations. Story prompts and character descriptions are sent to these services' APIs. We do not use your stories or characters to train AI models.
4. Children's Privacy (COPPA Compliance)
Story Maker is designed for families. Account holders must be 13 years of age or older. Children under 13 use the app under their parent or guardian's account as family members. We do not knowingly collect personal information directly from children under 13. All data is associated with the parent/guardian's account. Parents can review, modify, or delete their child's data at any time through the app's settings. We comply with the Children's Online Privacy Protection Act (COPPA) and similar international regulations.
Parental Consent
- Only parents or legal guardians may create a StoryMaker account.
- Child profiles are created and managed by the parent/guardian account owner.
- By creating a child profile, the parent or guardian consents to the collection and use of that child's information as described in this policy.
What We Collect from Children
- Username (chosen by the parent)
- Story preferences (age range, art style)
- Story content created using the child's profile
We do not collect email addresses, real names, or other personal information directly from children. Child accounts use a username and password set by the parent.
Parental Rights
Parents and guardians have the right to:
- Review their child's information
- Delete their child's profile and associated data
- Refuse further collection of their child's information
- Request a copy of their child's data
To exercise these rights, contact us at the address listed below.
5. Data Storage & Security
- All data is stored on secure, encrypted servers.
- Passwords are hashed using bcrypt and never stored in plain text.
- All connections use HTTPS/TLS encryption.
- Authentication tokens are signed with secure secrets and expire after 30 days.
While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention & Deletion
Your data is retained as long as your account is active. You can delete your account at any time from the app's Settings. Upon deletion request, all personal data, stories, characters, and associated files are permanently removed after a 7-day grace period. During this period, you can cancel the deletion by signing back in. Print order records are anonymized and retained for financial compliance.
- Password reset tokens expire after 1 hour and are automatically cleared.
7. Cookies & Tracking
StoryMaker uses cookies for authentication and aggregated analytics. We do not use:
- Third-party advertising cookies
- Cross-site tracking
- Session recording or screen capture
We use a secure, HTTP-only session token to keep you logged in. We also use PostHog for aggregated, anonymous usage analytics (e.g., which features are used most). All text on screen is masked before any analytics data is sent, and session recording is disabled.
8. Your Rights
You have the right to:
- Access โ Request a copy of the personal data we hold about you.
- Correction โ Request correction of inaccurate data.
- Deletion โ Request deletion of your account and data.
- Portability โ Request your data in a portable format.
- Objection โ Object to specific processing of your data.
To exercise any of these rights, please contact us using the information below.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the service after changes are posted constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy, your data, or your children's privacy, please contact us at:
- Email: privacy@stories-now.app