StoryKinder

Privacy Policy

Version 2026-08-05-v1 · Effective date: [to be set on adoption]

Draft — not yet in force. This policy is under attorney review and does not take effect until an effective date is set above. It describes how StoryKinder is actually built, and we publish it now so parents can read it before we ask for anything.

This policy also serves as StoryKinder’s COPPA online notice of information practices. It is written to be read by a parent, not only by a lawyer.

1. Who we are

StoryKinder is operated by TradePals LLC, a Texas limited liability company. TradePals LLC is the sole operator collecting or maintaining personal information through StoryKinder. No other operator collects personal information through the service.

TradePals LLC
Privacy and legal: legal@storykinder.com
Everything else: support@storykinder.com
[STREET ADDRESS], San Antonio, TX [ZIP] · [PHONE]

2. Who uses StoryKinder, and who holds the account

StoryKinder publishes interactive choose-your-path stories for children roughly ages 9 to 12. Because our audience includes children under 13, we designed the service so that the account holder is always a parent or legal guardian, and children never create accounts of their own.

  • A parent creates and controls the account, and is the only person who signs in.
  • A parent creates one or more child profiles inside that account so each child’s reading is kept separate.
  • Children do not register, do not sign in, do not enter personal information, and do not communicate with anyone through StoryKinder.
  • There are no message features, no comments, no user-generated content, no friend lists, no leaderboards, and no public profiles.

Throughout this policy, “you” means the parent account holder.

3. Information we collect

3.1 From the parent

WhatHow collectedWhy
Email addressYou provide it at registrationAccount creation, sign-in, service and billing notices, parental notices
Authentication identifierProvided by you, or by Google if you use Google sign-inTo sign you in
Payment informationEntered directly with our payment processorTo bill your subscription
Support correspondenceYou send itTo answer you

We never see or store full payment card numbers. Card details go directly to Stripe. We retain only what Stripe returns to us: a customer reference, subscription status, and the last four digits and brand of the card.

3.2 About a child

We deliberately collect as little as possible about children. For each child profile, the parent supplies:

  • A display name or nickname — we ask that this not be the child’s full name
  • An avatar selected from images we provide
  • Optionally, an age band (not a birth date)

We do not collect from children, and do not permit children to enter: full name, home address, email address, phone number, geolocation, photographs, audio, video, biometric identifiers, government identifiers, or persistent identifiers used for advertising.

3.3 Generated as a child reads

When a child reads, our servers record reading activity linked to that child profile. This is a persistent identifier under COPPA, so we treat it as the child’s personal information:

  • Which book was opened, and when
  • Which story ending was reached, and whether the book was finished
  • Which vocabulary words were tapped for a definition
  • Reading progress, streaks, and achievements earned

We use this only to run the service: to resume a story where the child left off, to build the child’s reading journal, to show you their progress, to pay our authors, and to fix problems and understand how the service is used in aggregate. We do not use it to build advertising or marketing profiles.

3.4 Technical information

Our hosting and infrastructure providers process IP addresses, browser type, and request logs as a normal part of delivering and securing the service. On pages children use, this information is used only for support for internal operations — delivery, security, fraud prevention, and error diagnosis — and is not used to profile or track children across sites or over time.

4. What we do not do

We think this list matters more than the one above.

  • No advertising. StoryKinder shows no ads of any kind, and we do not run behavioral or contextual advertising to children or to you.
  • No third-party trackers on children’s pages. We do not embed Google Analytics, Meta pixels, advertising SDKs, or similar tools on any page a child uses. A Content Security Policy blocks third-party requests on those routes.
  • No sale of personal information. We do not sell, rent, or trade personal information, and we do not share it for cross-context behavioral advertising.
  • No disclosure of children’s personal information to third parties except to the service providers described below and the narrow legal circumstances in section 6.

Because we do not disclose children’s personal information to third parties for their own purposes, we do not seek — and you are not asked to give — the separate parental consent for third-party disclosure described in the COPPA Rule. If that ever changes, we will obtain that separate consent first.

5. Service providers

We use a small number of vendors to run StoryKinder. Each processes information only on our instructions, only to provide its service to us, and is contractually barred from using it for its own purposes.

ProviderRoleChildren’s personal information?
SupabaseDatabase, authentication, file storageYes — child profiles and reading activity are stored here
VercelApplication hosting and deliveryTransiently, in request handling and logs
StripePayment processing for subscriptionsNo — parent billing information only
ResendTransactional email to parentsNo — parent email only

6. When we may disclose information

We may disclose personal information when we reasonably believe it is necessary to comply with law or valid legal process; to enforce our terms; to protect the rights, safety, or property of a child, a user, the public, or us; or in connection with a merger, acquisition, or sale of assets — in which case children’s personal information would remain subject to this policy or to a successor policy no less protective, and we would notify you before it became subject to a different policy.

7. Parental consent

Before we collect personal information from a child, we send you a direct notice and obtain your verifiable consent.

We use the monetary-transaction method: because a paid subscription requires a payment card transaction that Stripe confirms to you by receipt at the account holder’s email address, that transaction serves as verifiable parental consent. We record the consent method, the version of this policy in force, the scope consented to, and the date and time.

Consent is not permission to collect more than we described. If we ever want to collect, use, or disclose a child’s personal information in a materially different way, we will send you a new direct notice and obtain your consent again before doing so.

8. Your rights as a parent

From the Parent Dashboard in your account — protected by re-authentication or a PIN so that a child cannot reach it — you can at any time:

  • Review all personal information we hold about each child
  • Export it in a portable format
  • Correct a child profile
  • Delete a child profile and everything associated with it
  • Refuse further collection by deleting the profile or closing the account
  • Withdraw consent, which stops further collection and deletes the child’s personal information

Deletion is permanent and cascades to reading activity, journal entries, and achievements. It cannot be undone. We complete deletion within 30 days, including in backups, subject to the schedule in our Retention and Deletion Policy.

Withdrawing consent for a child means that child can no longer use StoryKinder. It does not by itself cancel your subscription; you can do that separately in account settings.

You may also reach us at legal@storykinder.com or the address in section 1 to exercise any of these rights.

9. How long we keep information

We keep children’s personal information only as long as reasonably necessary for the purposes described in section 3, and never indefinitely. Our full Data Retention and Deletion Policy — including the purpose for each category, the business need for keeping it, and the deletion timeframe — forms part of this notice.

10. Security

We maintain a written children’s personal information security program with safeguards appropriate to the sensitivity of the information we collect and to our size and operations. It is summarized at our security page. No system is perfectly secure, but data minimization is our primary control: the less we hold about a child, the less there is to lose.

11. Where information is processed

StoryKinder is operated from the United States and information is processed there.

12. Changes to this policy

If we change this policy in a way that materially affects how we treat children’s personal information, we will notify you by email and, where the law requires, obtain your consent again before applying the change. Each version carries a version identifier, and we record which version you consented to.

13. Contact and complaints

Questions or complaints: legal@storykinder.com, or write to us at the address in section 1. You may also contact the Federal Trade Commission at ftc.gov.