Privacy Policy
This Privacy Policy explains how StoryBoo (“StoryBoo”, “we”, “us”, “our”) collects, uses, shares, and protects personal data when you use the StoryBoo mobile application, the website at www.storybooapp.com, and related services (together, the “Service”). It also explains your rights and how to exercise them. Scalebit AB, a limited liability company registered in Sweden (org.nr [ORG.NR]) with its registered office at [REGISTERED ADDRESS] and operating under the name StoryBoo, is the data controller for the personal data described in this policy; contact details are in Section 13. This policy is incorporated into our Terms of Service.
Summary (not a substitute for the full policy): We collect what we need to run StoryBoo — your account details, the stories and characters you create, your subscription status, and basic technical logs. Story prompts and character details are sent to our AI providers to generate text, images, and narration. We don't run ads, we don't use third-party analytics or tracking SDKs, and we never sell your data. Stories you publish to Explore are public. You can export your data and delete your account directly in the app. If you describe your child in a character, please use a first name only — that information is used solely to personalize your stories.
1. Who this Service is for, and children's data
The StoryBoo account holder must be an adult (see our Terms of Service). Children may use the app only through an adult's account and under that adult's supervision. We do not knowingly collect personal data directly from children, and children cannot create accounts. If you believe a child has created an account, contact us and we will delete it.
Information about children that you provide. When you create a character or a story, you may choose to include details about your child — for example a first name, age, gender, or a description of their appearance — so that stories can feature them. Please be aware that:
- you, the parent or guardian, decide what to share, and you can use made-up details instead;
- we recommend using first names only and avoiding identifying details (no surnames, schools, addresses, or similar);
- please avoid descriptions that reveal sensitive characteristics — such as a child's racial or ethnic origin, health, or disability (special categories of data under Art. 9 GDPR); where you include appearance details so a character can be illustrated, we process them solely to generate your story, images, and narration, and never to profile, categorize, or make decisions about any person;
- these details are used solely to generate your stories, images, and narration (which involves processing by our AI providers — see Section 5), and to show your characters and stories back to you in the app;
- we never use them for advertising or marketing, and we never sell them;
- do not publish stories to Explore that identify a real child (see Section 4);
- you can edit or delete characters and stories at any time, and deleting them removes the associated details as described in Section 8.
2. Data we collect
2.1 Data you provide
- Account data — email address, sign-in method (email/password, Google, or Apple), and a display name you choose. Passwords are handled by Firebase Authentication; we never see or store your password. If you sign in with Google or Apple, we receive basic profile data from them (such as your email and name/identifier) as permitted by your settings; Apple lets you hide your real email.
- Profile data — an optional in-app profile picture/avatar selection.
- Content you create — stories (title, description, genre, target age, page text), characters (name, gender, age, appearance description), generated images and audio associated with them, favorites, and likes.
- Onboarding survey (optional) — how you heard about StoryBoo and how often you read to your child. These answers are stored as aggregate counters only (e.g., “+1 for social media”) and are not kept in your user profile.
- Communications — feedback you submit in the app, story reports, appeals, ratings, and any emails you send us.
2.2 Data created when you use the Service
- Usage data — stories created and read, reading progress, language preference, and subscription plan status.
- Moderation data — if your content is reported, removed, or banned, or if you submit a report or appeal, we keep records of those events and decisions (see Section 8 for retention).
- Subscription data — your subscription status, product (monthly/yearly), trial eligibility, renewal and expiry information, and an anonymous RevenueCat app user identifier. We never receive or store your payment card details — payment is handled entirely by Apple or Google.
- Technical data — when your device communicates with our backend, standard technical information is processed and may appear in server logs: IP address, request timestamps, device/app attestation tokens (Firebase App Check, used to block abusive traffic), and error information. We do not use third-party analytics, advertising, or tracking SDKs, and we do not fingerprint your device.
2.3 Data stored only on your device
Some data stays on your device and is not sent to us: cached stories, images, and audio for faster loading and offline reading; app preferences; and locally scheduled notifications (for example the optional free-trial reminder). You can clear this by clearing the app's storage or deleting the app.
3. How we use your data, and the legal bases
We use personal data to:
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | Creating your account; generating stories, images, translations, and narration from your inputs; syncing your library across sessions; operating Explore, favorites, and likes | Performance of a contract (Art. 6(1)(b)) |
| Manage subscriptions | Activating Plus features, tracking credits, processing renewal events from the app stores | Performance of a contract (Art. 6(1)(b)) |
| Keep the platform safe | Content moderation, processing reports and appeals, enforcing strikes and bans, App Check attestation, preventing fraud and abuse | Legitimate interests (Art. 6(1)(f)) — keeping a children's-content platform safe; legal obligation where applicable |
| Improve the Service | Aggregate, non-identifying statistics (e.g., total stories created, onboarding survey counters) | Legitimate interests (Art. 6(1)(f)) |
| Communicate with you | Responding to feedback and support requests, in-app notices about your content (e.g., moderation decisions) | Performance of a contract; legitimate interests |
| Comply with the law | Responding to lawful requests, keeping required records, enforcing our Terms | Legal obligation (Art. 6(1)(c)); legitimate interests |
We do not use your data for advertising, we do not sell or rent personal data, and we do not use your stories, characters, or other content to train AI models (see Section 5 regarding our AI providers).
Automated content-safety filters may flag content for review; meaningful decisions with significant effects (such as account termination) involve human review, and you can appeal moderation decisions in the app.
4. What other users can see
- Private by default. Your stories and characters are private unless you publish a story.
- If you publish a story to Explore, the story (text, images, title, description, genre) and the display name on it become visible to all StoryBoo users. Other users can like, favorite, report, and listen to narrations of it. You can unpublish or delete it at any time; cached copies (such as translations or narration generated while public) may take time to expire.
- Leaderboards and community features may display your display name and activity counts (such as likes received). Your email address is never shown to other users.
Choose a display name that doesn't identify you or your child if you prefer to stay anonymous.
5. Who we share data with (processors and partners)
We share personal data only with the service providers needed to run StoryBoo, under contracts that restrict their use of your data:
| Provider | Role | What they process |
|---|---|---|
| Google Firebase / Google Cloud (Google LLC) | Hosting, authentication, database, file storage, server functions | Account data, content, usage data, logs. Data is primarily stored in Google Cloud's United States region (us-central1). |
| OpenAI (OpenAI, LLC) | AI generation | Story prompts, story text, character details (including any child details you chose to include), and image/narration requests are sent to OpenAI's API to generate text, images, and audio. Per OpenAI's API terms, API data is not used to train their models, and is retained by OpenAI only for limited abuse-monitoring periods. |
| Google Cloud Translation (Google LLC) | Machine translation | Story text submitted for translation into your chosen language. |
| RevenueCat (RevenueCat, Inc.) | Subscription management | Pseudonymous user ID, purchase/entitlement events from Apple/Google. No payment card data. |
| Apple / Google | App distribution and billing | Your purchase is processed by the App Store or Google Play under their own privacy policies. They tell us that you subscribed, not your payment details. |
We may also disclose data where required by law or to protect the rights, safety, or property of our users (especially children), the public, or StoryBoo — for example, reporting content that sexualizes minors to relevant authorities.
We do not share personal data with advertisers, data brokers, or social networks.
6. International transfers
We are based in the EU/EEA, and our infrastructure providers store and process data primarily in the United States. Where personal data is transferred outside the EU/EEA, we rely on safeguards recognized under GDPR — primarily the EU–U.S. Data Privacy Framework (Google, OpenAI, and RevenueCat participate, where certified) and/or the European Commission's Standard Contractual Clauses, together with the providers' technical and organizational security measures. You can contact us (Section 13) for more information about transfer safeguards.
7. Security
We take reasonable technical and organizational measures to protect your data, including encryption in transit (TLS), encryption at rest on our cloud infrastructure, server-side authorization checks on every request (so users can only access their own data), Firebase App Check device attestation, and access controls limiting who can administer production systems. No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authorities as required by law.
8. Retention and deletion
- Account data and content — kept while your account exists. When you delete your account (in the app: Profile → Account settings, or by contacting us), your account record and authentication credentials are deleted immediately, and your stories, characters, generated media, and other associated data are deleted from production systems.
- Individual content — you can delete individual stories and characters at any time; associated stored images/audio are removed.
- Backups — residual copies in backups are overwritten on our normal backup cycle.
- Aggregate statistics — non-identifying counters (e.g., total stories created, survey tallies) are retained indefinitely; they cannot be linked back to you after deletion.
- Moderation and legal records — we may retain records of serious violations, bans, appeals, and related identifiers for as long as needed to enforce our Terms, prevent banned users from returning, and comply with legal obligations, even after account deletion.
- Server logs — routine infrastructure logs (which can include IP addresses) are retained for short periods per our cloud provider's default cycles and then deleted.
- AI providers — content sent to OpenAI for generation is retained by OpenAI only for its limited abuse-monitoring window per its API data-usage policies.
If you simply uninstall the app, your account and data are not deleted — sign back in and delete your account, or contact us.
9. Your rights
Depending on where you live (and in all cases under GDPR if you are in the EU/EEA), you have the right to:
- Access your data — use the in-app data export (Profile → Account settings → Download my data) to get a copy of your account data, stories, and characters in JSON format, or contact us;
- Rectify inaccurate data — most data (display name, characters, stories) can be edited directly in the app;
- Delete your data — use in-app account deletion or contact us (see Section 8 for what is retained);
- Portability — receive data you provided in a structured, machine-readable format (the in-app export);
- Object to or restrict processing based on legitimate interests;
- Withdraw consent where processing is based on consent, without affecting prior processing;
- Complain to a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (IMY, www.imy.se); you may also complain to the authority in your country of residence.
To exercise any right that isn't available in-app, contact us (Section 13). We will respond within the timeframes required by law (under GDPR, normally one month) and may need to verify your identity first. We do not discriminate against you for exercising your rights.
California residents: we do not “sell” or “share” personal information as defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. You may exercise access, deletion, and correction rights as described above.
10. Notifications
The app uses local notifications scheduled on your device (for example, an optional reminder before a free trial ends). These are controlled by your device's notification permission, which you can change anytime in system settings. In-app inbox messages (such as moderation notices) are delivered through your account, not through push tracking. We do not send marketing push notifications.
11. Cookies and website
Our website at www.storybooapp.com is an informational site. It does not set advertising or analytics cookies. Embedded resources (such as web fonts) may be loaded from third-party servers, which receive your IP address as a technical necessity when delivering the resource.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date below shows the current version. For material changes — especially any that would expand how we use children's data, which we do not anticipate — we will give you reasonable advance notice in the app or by email before the change takes effect.
13. Contact us
Scalebit AB — data controller (operating as StoryBoo)
Org.nr: [ORG.NR]
Registered office: [REGISTERED ADDRESS]
Email: support@storybooapp.com
Website: www.storybooapp.com
If you are in the EU/EEA and prefer, you may contact your local supervisory authority; in Sweden this is IMY (www.imy.se).
Last updated: June 13, 2026