Privacy Policy
Policy version 2026-06-25 · Effective date: [Counsel to set]
DRAFT SCAFFOLD — must be reviewed and finalized by counsel before launch, including children’s-privacy (COPPA, and GDPR-K if applicable). The summaries reflect how StoryKinder is built; counsel converts them to binding policy language.
Who we are & scope
StoryKinder is an interactive reading service intended for children. The account holder is always a parent or guardian; children read under child profiles within that account and never create accounts or sign in.
[Counsel] Legal entity name, address, and contact; jurisdictions covered.
Our approach to children's data
We practice data minimization. A child profile holds only a nickname, a preset avatar, and an optional age range — never a real name, email, photo, audio, birthday, or location. We collect reading activity (books read, endings found, words learned) to save progress and show growth.
Information we collect
From the parent/account holder: email address and authentication, and — if subscribing — payment details processed by our payment provider (we never store card numbers).
From or about a child (via the parent-created profile): nickname, preset avatar, optional age range, and reading activity tied to an internal profile id (not personally identifying).
[Counsel] Confirm the complete data inventory and categories.
How we use information
To operate the service: authenticate the parent, save reading progress, personalize the reading journal, show literacy growth to the parent, and process subscriptions. We do not use children’s data for advertising, profiling, or any purpose beyond providing the service.
Verifiable parental consent
Before any child-data collection we obtain verifiable parental consent — either through the parent’s subscription payment or an on-screen direct notice the parent affirmatively accepts. We record the policy version consented to, and a parent can withdraw consent at any time (which immediately halts further collection).
[Counsel] Confirm the consent methods satisfy the applicable VPC standard.
No selling, no ads, no third-party trackers
We never sell or rent personal information and never share a child’s information with third parties for their own purposes. Children’s screens run no advertising and no third-party analytics or tracking technologies (enforced technically by our content-security policy).
Service providers (sub-processors)
We use vetted providers strictly to run the service — currently our cloud database/hosting provider and our payment processor. They act on our instructions and may not use the data for their own purposes.
[Counsel] List sub-processors (e.g., Supabase, Stripe, Vercel) + DPAs.
Cookies & essential technology
We use only strictly functional cookies — to keep a parent signed in and to remember which child profile is active. No advertising or cross-site-tracking cookies are used.
Data retention
We keep reading activity only as long as needed to provide the service, then prune it on a defined schedule. Account or profile data is removed when a parent deletes it (see your rights below).
[Counsel] State the exact retention period(s) to match the operational window.
Parental rights & controls
From the PIN-protected Parent dashboard, a parent can, for each child: review what data exists, export it (JSON), delete the profile and all of its data, and revoke consent. A parent can also delete the entire account and all associated data.
[Counsel] Add the formal rights notice + how to make a verifiable request.
Security
We protect data with access controls, row-level security, encryption in transit, and least-privilege server access.
[Counsel] Reference the written information-security program.
Changes to this policy
If we make material changes we will update the policy version and ask parents to review and re-consent before continuing data collection.
Contact
Privacy questions or requests: privacy@storykinder.com.
[Counsel] Add the COPPA operator contact (name, address, phone) required for the notice.
