Welcome! At Bedtime Stories, we keep things simple when it comes to your family's privacy. This policy explains exactly what we need to create magical, personalized bedtime stories for your child.
The simple truth: To personalize a story we use the details you enter for each child profile — a first name or nickname (with an optional phonetic spelling so the narrator says it correctly), the child's gender, and an age range (3-4, 5-6, 7-8, or 9-12 years) for age-appropriate content. You decide what to enter, you can use a nickname instead of a real name, and you can edit or delete a profile at any time.
Bedtime Stories is a sole proprietorship registered with the Dutch Chamber of Commerce. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), we are the data controller for personal data processed through the Service.
You can reach us about any data-protection matter — including access, correction, deletion, portability, restriction, or objection requests — at hello@bedtime-stories.fun. We respond to verified requests within 30 days. We are below the GDPR threshold for appointing a Data Protection Officer; the business owner handles all privacy queries directly.
For Your Account:
For Your Child Profiles & Stories:
Like any website, we automatically collect some technical information to keep things running smoothly:
Here's exactly what we do with your information:
AI Processing Note: Story text is generated using Anthropic Claude for creating personalized narratives. To personalize a story, the story details you enter in the creation wizard — including your child's first name, age range, and any custom instructions — are sent to Anthropic (story text) and Google (illustrations) solely to generate that story; we never send your email address, account details, or voice recordings to these providers. Story images are created through Google's Gemini image model using only story-related prompts. Text-to-speech conversion is handled by ElevenLabs for catalog voices and by Fish Audio (Hanabi AI Inc., United States) for custom voice cloning. We log AI requests through Helicone for observability and validate the inputs you provide before a story is generated. Our backend services running on Hetzner European servers coordinate these AI services and store the final content in Supabase. Every AI processor we use is named in this policy, along with the country it operates from.
Bot Protection: We use Cloudflare for DNS and Turnstile captcha protection to protect against automated abuse and ensure platform security. Turnstile processes technical information (IP address, browser signals, TLS fingerprint) to distinguish humans from bots. This data is processed by Cloudflare Inc. (US) under their privacy policy. Turnstile does not use traditional cookies and collects minimal data solely for security purposes.
Analytics & Cookies: We use PostHog (European data region) for analytics and product improvement. PostHog uses cookies and local storage to track user sessions, feature usage, and platform performance. You can manage your cookie preferences and opt out of analytics tracking at any time. PostHog data is processed under their privacy policy with GDPR-compliant safeguards. For more details, see our Cookie Policy.
Error Monitoring: We use Sentry to detect and fix technical issues. Sentry does not use cookies and we have disabled personal data collection.
Email Communications: Transactional emails (account confirmations, password resets, story-ready notifications) and the welcome series for new accounts are sent via Resend. Every marketing message includes a one-click unsubscribe link, and you can also turn marketing emails off in your account settings at any time.
Under GDPR Article 6 (and Article 9 for special-category data) we rely on the following lawful bases:
Our service is designed exclusively for parents and guardians. Children under 13 should not create accounts or provide personal information directly. Only parents or legal guardians should sign up and use this service on behalf of their children.
No Direct Collection from Children: We do not knowingly collect personal information directly from children under 13. All child-related information (names, gender, age ranges) is provided by parents through their adult accounts.
Parental Consent & Control: By creating an account and providing your child's information, you (as the parent/guardian) are giving consent for us to use that information to create personalized stories. You maintain complete control and can review, modify, or delete your child's data at any time.
How we handle children's data across the regions we serve:
If we discover we have received personal information directly from a child without proper parental consent, we will delete it immediately.
Here's the simple truth: We use the names, gender, and age ranges from your child profiles, plus the choices you make in the story wizard, to create personalized stories. That's it!
You can optionally record your own voice to narrate bedtime stories. The voice clone is created by Fish Audio (Hanabi AI Inc.), a company based in the United States. Fish Audio's terms allow it to use the audio you submit to train its own AI models. Here is exactly how your voice data is handled:
We (Bedtime Stories) are the Data Controller for your voice data. Fish Audio is our processor: we send it your recording, it creates and hosts the voice clone, and we call it to narrate your stories. We do not hold a signed Data Processing Agreement with Fish Audio, and its terms let it use submitted content to train its models. That is why we ask for your explicit consent before you record, and why this section spells out what Fish Audio may do.
Voice data is biometric data under GDPR Article 9. We process it based on your explicit consent (GDPR Article 9(2)(a)), which you provide before recording by checking the consent box. Sending the recording to Fish Audio also takes it outside the EEA, and we rely on your explicit consent for that transfer too (Article 49(1)(a)). Fish Audio's own privacy policy states that it relies on standard data protection clauses adopted by the European Commission. You can withdraw consent at any time by deleting your voice from your dashboard or deleting your account.
Fish Audio's terms state that content submitted to its service may be used to develop, train, or enhance the AI models behind its products. The terms draw no distinction between free and paid accounts, and Fish Audio offers no opt-out. We tell you this before you record so the choice is yours. If you would rather your voice was not used this way, do not create a custom voice. The catalog voices need no recording from you and are not affected.
Your account, child profiles, stories, and media files are stored on European servers through Supabase's European data region, which covers our database, object storage, and authentication. Custom voice cloning is the one exception. Those recordings go to Fish Audio in the United States; everything else stays in the EEA.
We implement enterprise-grade security measures including encryption, access controls, and regular security audits. For detailed technical security information, please see our comprehensive Security Policy.
We work with trusted partners who maintain strict data protection standards:
Where a partner processes personal data outside the EEA, the safeguard we rely on is set out in the next section.
Most of your personal data stays in the European Economic Area (Supabase Frankfurt, Hetzner Germany, PostHog EU). Some processors are based outside the EEA, primarily in the United States:
Where personal data leaves the EEA, we rely on one or more of the following safeguards under Chapter V of the GDPR:
For custom voice cloning we rely on your explicit consent (Article 49(1)(a)), given through the consent box before you record. We have no separate agreement with Fish Audio; its own privacy policy states that it relies on standard data protection clauses adopted by the European Commission.
Ask us which safeguard applies to a specific processor and we will tell you, and send a copy of any transfer document we hold, at hello@bedtime-stories.fun.
We do not sell, rent, or trade your personal information. We may share limited data only in these circumstances:
You can delete your stories or entire account anytime directly from your account settings. When you delete data, it's removed from our systems within 30 days. No need to contact us - you're in complete control!
To exercise any of these rights, email hello@bedtime-stories.fun. We may ask for proof of identity to prevent unauthorised disclosure. We respond within 30 days.
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or service features. When we make material changes:
Have privacy questions or concerns? I'm here to help!
Email Me
hello@bedtime-stories.fun
Contact Form
Visit our contact pageRelated: Security Policy | Cookie Policy
This policy is effective as of the date listed above and applies to all users of Bedtime Stories.