We protect your child's data
We collect only what's needed, handle it only with parental consent, and delete it on request.
1. Principles We Keep
StoryLoom is designed to follow child-privacy principles (COPPA & GDPR-K). A child's data is handled only with parental consent, and only to the minimum extent the Service requires. We never use children's data for advertising or marketing.
2. What We Collect — the Bare Minimum
We collect only a parent's email (to operate the parent account) and, optionally, a child's first name or nickname (to personalize stories). We do not ask for or collect anything else — no birth dates, no location, no contact details for the child.
3. How We Handle Children's Data
Information about a child is collected and used only with a parent's consent. Children use the Service solely through a profile under a parent's account, and there is no feature that lets a child enter or publicly share personal information on their own.
4. Why We Use It
Collected data is used only to personalize stories (showing the child's name), save reading history and badges, operate accounts, and respond to support requests. Once the purpose is fulfilled, the data is no longer retained.
5. How Long We Keep It
Data is kept only while the account exists. When a parent requests account deletion, we delete the data without delay, except where retention is required by law. Some records — like favorites and reading progress — are stored only on the device (browser) and can be cleared by the parent at any time.
6. No Third-Party Sharing · Processing Notice
We never sell or share children's data with third parties. However, to create narration and illustrations, story text may be sent to and processed by a voice-generation service (ElevenLabs) and an image-generation API. For the photo-avatar feature, a child's photo is sent to the image-generation API only after a parent's explicit consent. We explain any such processing to parents and obtain consent before the feature is used.
7. Children's Photos (Avatar Feature)
A child's photo is processed only with a parent's explicit consent and only to draw the story hero (avatar). The photo is downscaled and stripped of location data on the device, used once for generation, never stored on our servers, and discarded from memory right after. The finished avatar is kept only on the parent's device (browser) and can be deleted anytime with the Delete button in the parent area. Generation uses an external AI processor (Google Gemini), which is not permitted to retain the photo.
8. Parents' Rights
Parents may at any time request access to, correction of, deletion of, or a halt to the processing of their child's data. Requests are accepted via the Support page or email, handled without delay, and the outcome is reported back.
9. Sign-in, Payments and Overseas Services
When you sign in we receive the parent's email (and nickname, for Kakao or Google sign-in) to manage the account and subscription. StoryLoom never receives or stores card numbers — the payment provider handles payment details directly. To run the service we rely on the following overseas providers, so information may be transferred to and stored abroad (mainly the United States): Lemon Squeezy (payments and tax; email and payment records), Vercel (hosting; access logs), Upstash (subscription status; email and plan), Google (Google sign-in; drawing the child's avatar — the photo is discarded right after), and Resend (sign-in emails; email address). If you delete your account, subscription records are destroyed after the legally required retention period (5 years for e-commerce transaction records). You may choose not to sign up if you do not want these transfers, but paid features then cannot be used.
10. Contact
For privacy questions or requests, contact the privacy officer at StoryLoom via email: hello@storyloom.app.
Effective date: 2026-09-26 (draft) — this policy may be updated after legal review before official launch.