Privacy Policy
Plain-language answers to what we collect, where it lives, how long we keep it, and how it gets deleted.
Storybook Family is a preview product. Orders are $0 test previews — no payment is taken and nothing ships. This page describes what the product actually does; it is a transparency notice, not legal advice.
What we collect
You use Storybook Family without creating an account. There is no sign-up, no password, and no login for children. The only information we hold is what you type or upload while making a book:
- Story details: your child's first name or nickname, age band, pronouns, favorite things, an optional dedication, and an optional description of an everyday moment you want the story to be about.
- Optionally, one photo of your child (JPEG, PNG, or WebP, up to 10 MiB) — and only after you confirm you are the child's parent or legal guardian.
- Optionally, a family cast library: names, short descriptions, and photos of family members, pets, or special items you want painted into books. Each photo upload requires the same explicit confirmation, and you confirm you have the pictured person's permission.
- An email address, only if you create a $0 test order, so you can find the book again later. It is used for order lookup and nothing else.
Where your data lives
Everything runs on Cloudflare's platform: the API is a Cloudflare Worker, records are stored in a Cloudflare D1 database, and photos and generated illustrations are stored in a private Cloudflare R2 bucket. Uploaded photos are resized and re-encoded with Cloudflare Images before storage and are never served from a public URL — every image request is checked against your session, an order lookup you unlocked, or a view-only share link you created.
Share links are optional: if you create one, anyone holding that link can view that book's pages and illustrations (view only) until the link expires — after 30 days, when the book is deleted, or when you turn the link off in the share dialog, whichever comes first.
Sensitive text fields — your child's name, favorite things, dedications, moment descriptions, story text, and order emails — are encrypted at rest with AES-256-GCM field encryption on top of the database's own storage.
AI generation and third-party processing
The story text and illustrations are produced by external AI models reached through a configured relay. When generation runs, your story inputs (favorite things, dedication, moment description) are sent to that provider — but the name you entered in the name field is first replaced with a neutral placeholder and only substituted back into the finished text on our side. If you type the name inside a free-text field (like the moment description), that text is sent as written when the moment is outlined, and redacted again at story time.
If you uploaded a photo, it is sent to the illustration model as a reference only when generation starts, so the pictures can resemble your child. Photo personalization is disabled entirely unless the configured provider's photo terms have been confirmed.
Every generated page passes an automated quality and safety review before you see it. Pages depicting unsafe actions, violence, fear, brands, or stray text are rejected and regenerated.
How long we keep things
- Uploaded photo: deleted within 24 hours after generation ends (success or failure), and no later than 7 days after upload — even if you never generate. You can delete it sooner at any time while the book is editable, and replacing a photo deletes the previous one immediately.
- Books without an order: automatically deleted 30 days after creation, including all images and story text.
- Books with a $0 test order: kept 180 days so you can come back to them, then deleted.
- Family cast characters and their photos: kept 180 days from creation or your last renewal. Renewing is always a click you make on your shelf — nothing extends silently — and deleting a character removes its photo immediately.
- Guest session: a cookie valid for 30 days. Order-lookup access lasts 24 hours per lookup.
A cleanup job runs every hour and permanently removes anything past its deadline: stored files, story records, order records, and — once nothing else references them — the child and household records themselves. Details are on the photo & data deletion page.
Cookies and tracking
The site sets two cookies, both strictly functional: a guest-session cookie (30 days) that ties your drafts to your browser, and an order-access cookie (24 hours) after a successful order lookup. Both are Secure, HttpOnly, and stored server-side only as hashes. There are no advertising, analytics, or tracking scripts in this site. Order lookup includes a Cloudflare Turnstile bot check, which may be switched off during the preview.
Children's privacy
This product is directed at parents and guardians, not at children. See the COPPA notice for how we handle information about your child and the choices you have as a parent.
Contact
A contact page is not available yet. It will be added here when it is. Until then, the deletion timelines above run automatically — you do not need to reach us to have your data removed.