Privacy Policy
Last updated: December 2025
1. Introduction
At The Story House, we are committed to protecting your privacy and the privacy of children whose images you upload. This Privacy Policy explains how we collect, use, store, and protect your personal information and the images you provide.
By using our service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect the following types of information:
Personal Information
- Name: Your name and the child's name for book personalization
- Age: The child's age for age-appropriate content
- Email Address: Used for account management, order updates, and communication
- Account Information: Username, password (hashed), and account preferences
Payment Information
Payment information is collected and processed securely through Stripe, our third-party payment processor. We do not store your full credit card details on our servers. Stripe handles all payment processing in compliance with PCI DSS standards.
Images and Photos
We collect photos and images you upload for the purpose of creating personalized books. These images are stored securely and used only as described in Section 3.
3. How Child Images Are Used
Child images are used exclusively for the following purposes:
- Book Creation: Images are used solely to create your personalized book
- Quality Control: Images may be reviewed to ensure quality and appropriateness
- Customer Support: Images may be accessed by support staff to assist with your order
We do NOT:
- Use images for marketing or advertising purposes
- Share images with third parties except as necessary for service delivery
- Use images to train AI models or machine learning systems
- Retain images longer than necessary (see Data Retention Policy)
4. Data Retention Policy
We retain your information for the following periods:
- Images: All uploaded images are automatically deleted 30 days after your order is finalized or cancelled
- Account Information: Retained while your account is active and for 90 days after account closure
- Order Records: Retained for 7 years for tax and legal compliance purposes
- Payment Information: Handled by Stripe according to their retention policies
You may request earlier deletion of your images or account information by contacting us (see Section 10).
5. Model Training and AI Usage
We do not use your images or your child's images to train AI models, machine learning systems, or any automated processing systems.
While we may use third-party AI services (such as fal.ai's Nano Banana 2) for image processing and book generation, these services are used solely for processing your specific order and do not retain or use your images for training purposes. Our AI service does not require model training and processes images instantly using reference photos only.
6. Third-Party Services
We use the following third-party services that may have access to your information:
- Stripe: Payment processing. See Stripe's Privacy Policy
- Cloudflare R2: Cloud storage for images and files. See Cloudflare's Privacy Policy
- fal.ai: AI image processing for book generation using Nano Banana 2 (Google Gemini 2.5 Flash). See fal.ai's Privacy Policy
- Resend: Email delivery service. See Resend's Privacy Policy
These services are contractually obligated to protect your information and use it only for the purposes we specify.
7. Your Rights
You have the following rights regarding your personal information:
- Access: Request a copy of all personal information we hold about you
- Deletion: Request deletion of your personal information and images (subject to legal retention requirements)
- Correction: Request correction of inaccurate or incomplete information
- Portability: Request your data in a machine-readable format
- Opt-Out: Unsubscribe from marketing communications (account and order emails will still be sent)
To exercise these rights, please contact us using the information in Section 10. We will respond to your request within 30 days.
8. COPPA Compliance
Our service is designed for adults only. Accounts must be created and maintained by individuals who are 18 years of age or older.
While our books feature children, we do not knowingly collect personal information directly from children under 13. All accounts are created by adults (parents, guardians, or authorized individuals) who consent to our Terms of Service and Privacy Policy on behalf of the children featured in the books.
If you believe we have inadvertently collected information from a child under 13, please contact us immediately so we can delete the information.
9. Data Security
We implement industry-standard security measures to protect your information:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of data at rest
- Secure authentication and access controls
- Regular security audits and updates
- Limited access to personal information on a need-to-know basis
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
10. Contact Information
For privacy-related questions, requests, or concerns, please contact us at:
Email: support@thestoryhouse.io
We will respond to all privacy inquiries within 30 days.