STORYCRAFT KIDS
Privacy
About this draft
This development document describes the current implementation of Storycraft Kids. It does not replace the policy currently linked from the app. Before publication: confirm the controller’s legal name, tax identifier, professional address, privacy contact, effective date, applicable legal bases, international transfer safeguards and retention periods.
Website and app
This website has no contact form, accounts, advertising or analytics scripts. Hosting infrastructure processes technical request information. The mobile app separately uses Firebase for accounts and data, OpenAI for generated content, RevenueCat for purchase management and Amplitude for analytics. The app’s analytics fields and retention settings require review before this policy is finalised.
Photos and characters
Photo-based character creation is behind a parental gate. The app sends a compressed photo to our backend and an AI image service. The original photo is not stored in Firebase Storage or Firestore by this flow; temporary backend files are removed after processing. The generated clay-style image is stored in Firebase Storage and currently has a public URL. This is not a promise that the AI provider retains no input data.
Stories, purchases and deletion
Stories, characters and credit records are associated with an account in Firebase. Purchases are handled through the app stores and RevenueCat. Account deletion triggers cleanup of user records and stored files. Exact coverage, operational logs, backups and provider retention must be verified before stating deletion deadlines.
Children and parental involvement
Storycraft Kids is designed for family use. The app includes parental gates for selected actions; a gate alone must not be described as verified legal consent. The final policy must specify the applicable age rules and parental authorisation process. Parents should avoid supplying photos or personal details without the necessary permission.
Your privacy requests
Controller and privacy contact: PENDING. Before production, provide a working channel for access, correction, deletion and other applicable requests, together with the relevant supervisory authority information. Until migration, use the contact information in the policy linked from the released app.
Provider information
Provider processing must be checked against the current service configuration and agreements. Review notes and official source links are maintained with this website’s documentation. This draft does not claim certification or full legal compliance.