Privacy policy
Effective September 12, 2026. This describes how Story Creator works. It is not a substitute for a lawyer's advice.
Story Creator is a writing app for families. Parents (or guardians) sign in with Google. Kids can write under a parent-created profile, including a family code and PIN that does not use the child’s email.
We designed this for children about 7–13 with a parent in the loop. If you are a parent in the United States, this notice is meant to help you understand COPPA-style consent: you agree to this policy when you create an account and when you add a child profile.
Who this is for
Google sign-in is for parents and caregivers. We do not ask children to create a Google account. A child signs in only with a family code and PIN that you issue from the Dashboard.
What we collect
- Parent: name, email, and profile image from Google; stories you write; payment records from Stripe (we do not store full card numbers).
- Child profile: the name and reading level you choose; stories they write; a family code; a hashed PIN (we cannot read the PIN back); daily AI-use counts.
- Stories and pictures: story text, optional genre, safety flags, and generated illustrations stored as image files.
- Technical: session cookies so you stay signed in; basic server logs (for example, errors).
We do not require a child’s email, phone number, home address, school, or photo. Please do not put those in stories.
How we use it
- Run the app: save stories, show them to your family, export PDFs.
- Send story text to xAI so a model can suggest the next paragraph or draw illustrations you unlock.
- Process one-time payments with Stripe when you buy an export.
- Moderate content with automated word lists and parent review tools.
- Fix bugs and keep the service running.
We do not sell personal information. We do not show third-party ads.
Who else sees data (processors)
- Google — parent sign-in.
- xAI — story text (and illustration prompts) to generate writing help and pictures. Do not include real last names, addresses, or school names in stories.
- Stripe — checkout; parent email may be sent so Stripe can send a receipt.
- Cloudflare R2 — story illustration files.
- Railway — hosting the website and the database.
Cookies
We use a session cookie (NextAuth) so you do not have to sign in on every click. We do not use advertising cookies.
Parents’ choices
You can open, edit, or delete your family’s stories. You can remove a child profile from the Dashboard (that deletes that profile’s login). You can sign out. To delete the parent Google account’s data on Story Creator, email us and we will help.
Contact: [email protected].
How long we keep it
We keep account and story data until you delete it or close the account, unless we must keep a record of a payment. Generated images stay with the story until the story or account is removed.
Security
Child PINs are stored hashed. Payments go through Stripe. No method is perfect; please use a parent Google account you control and do not share family codes in public.
Changes
If this policy changes in a material way, we will update the date at the top of this page.
See also Terms of use and For parents.