Privacy Policy
Last updated: 7/13/2025
Introduction
This Privacy Policy describes how we collect, use, and protect your information when you use our AI-powered bedtime story generation service. We are committed to protecting your privacy and the privacy of children who use our service.
Information We Collect
Personal Information
- Name and email address when you create an account
- Billing information when you subscribe to our service
- Profile information and preferences you provide
- Communication data when you contact us for support
Usage Data
- Stories you generate and character information you provide
- Usage patterns and feature interactions
- Subscription and billing history
- Technical logs and error reports
Technical Data
- IP address, browser type, and device information
- Cookies and similar tracking technologies
- Analytics data to improve our service
How We Use Your Information
- To provide and maintain our bedtime story generation service
- To process payments and manage subscriptions
- To send you technical notices and support messages
- To improve our services and develop new features
- To ensure content safety and age-appropriateness
- To comply with legal obligations and protect our rights
- To provide customer support and respond to inquiries
Third-Party Services
Google Authentication
We use Google OAuth for secure account creation and login. Google may collect and process data according to their privacy policy.
AI Content Generation
We use OpenAI's services to generate story content. Story prompts and generated content may be processed by OpenAI according to their privacy policy and terms of service.
Analytics
We use Vercel Analytics to understand how our service is used and to improve user experience. This helps us optimize our platform performance.
Payment Processing
Payment information is processed securely through Stripe, our payment processor. We do not store your complete payment card information on our servers.
Stripe may collect and process payment data according to their privacy policy. They provide secure, PCI-compliant payment processing.
Children's Privacy
Our service is designed for children's content, but we do not knowingly collect personal information from children under 13 without parental consent. Parents and guardians are responsible for supervising their children's use of our service.
If you are a parent or guardian and believe your child has provided personal information without your consent, please contact us immediately and we will delete such information.
We practice data minimization when it comes to children's data, collecting only what is necessary to provide our service.
Cookies and Tracking
We use cookies and similar technologies to provide and improve our service. You can control cookie settings through your browser.
Types of Cookies
- Essential Cookies: Required for the service to function properly, including authentication and security
- Analytics Cookies: Help us understand how users interact with our service to improve it
- Functional Cookies: Remember your preferences and settings for a better user experience
Data Retention
We retain your information only as long as necessary to provide our service and comply with legal obligations:
- Account information is retained while your account is active and for a reasonable period after deletion
- Payment records are retained as required by law and for accounting purposes
- Usage data is typically retained for analytical purposes in aggregated, anonymized form
- Generated stories are retained while your account is active, unless you delete them
Your Rights
Under applicable privacy laws (including GDPR), you have the following rights:
- Right to Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data under certain circumstances
- Right to Data Portability: Request your data in a structured, machine-readable format
- Right to Restriction: Request restriction of processing under certain circumstances
- Right to Object: Object to processing based on legitimate interests
Information Sharing
We do not sell, trade, or otherwise transfer your personal information to third parties except as described below:
We may share information in the following circumstances:
- With service providers who assist in operating our platform (under strict confidentiality agreements)
- When required by law or to protect our rights and safety
- In connection with a business transaction (merger, acquisition, etc.)
- With your explicit consent for specific purposes
International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place when transferring data internationally, including adequacy decisions and standard contractual clauses.
Data Security
We implement appropriate technical and organizational security measures to protect your personal information:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication requirements
- Secure coding practices and vulnerability management
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and, where appropriate, by sending you an email notification.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@bedtimestori.com
Data Protection Officer: dpo@bedtimestori.com
EU Supervisory Authority: Contact your local data protection authority for GDPR-related concerns