Welcome! At Bedtime Stories, we keep things simple when it comes to your family's privacy. This policy explains exactly what we need to create magical, personalized bedtime stories for your child.
The simple truth:To personalize a story we use the details you enter for each child profile — a first name or nickname (with an optional phonetic spelling so the narrator says it correctly), the child's gender, and an age range (3-4, 5-6, 7-8, or 9-12 years) for age-appropriate content. You decide what to enter, you can use a nickname instead of a real name, and you can edit or delete a profile at any time.
Bedtime Storiesis a sole proprietorship registered with the Dutch Chamber of Commerce. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), we are the data controller for personal data processed through the Service.
You can reach us about any data-protection matter — including access, correction, deletion, portability, restriction, or objection requests — at [email protected]. We respond to verified requests within 30 days. We are below the GDPR threshold for appointing a Data Protection Officer; the business owner handles all privacy queries directly.
For Your Account:
For Your Child Profiles & Stories:
Like any website, we automatically collect some technical information to keep things running smoothly:
Here's exactly what we do with your information:
AI Processing Note:Story text is generated using Anthropic Claude for creating personalized narratives. To personalize a story, the story details you enter in the creation wizard — including your child's first name, age range, and any custom instructions — are sent to Anthropic (story text) and Google (illustrations) solely to generate that story; we never send your email address, account details, or voice recordings to these providers. Story images are created through Google's Gemini image model using only story-related prompts. Text-to-speech conversion is handled by ElevenLabs for catalog voices and Mistral AI for custom voice cloning. We log AI requests through Helicone for observability and validate the inputs you provide before a story is generated. Our backend services running on Hetzner European servers coordinate these AI services and store the final content in Supabase. We ensure all AI partners maintain strict data protection standards.
Bot Protection: We use Cloudflare for DNS and Turnstile captcha protection to protect against automated abuse and ensure platform security. Turnstile processes technical information (IP address, browser signals, TLS fingerprint) to distinguish humans from bots. This data is processed by Cloudflare Inc. (US) under their privacy policy. Turnstile does not use traditional cookies and collects minimal data solely for security purposes.
Analytics & Cookies: We use PostHog (European data region) for analytics and product improvement. PostHog uses cookies and local storage to track user sessions, feature usage, and platform performance. You can manage your cookie preferences and opt out of analytics tracking at any time. PostHog data is processed under their privacy policy with GDPR-compliant safeguards. For more details, see our Cookie Policy.
Error Monitoring: We use Sentry to detect and fix technical issues. Sentry does not use cookies and we have disabled personal data collection.
Email Communications: Transactional emails (account confirmations, password resets, story-ready notifications) and the welcome series for new accounts are sent via Resend. Every marketing message includes a one-click unsubscribe link, and you can also turn marketing emails off in your account settings at any time.
Under GDPR Article 6 (and Article 9 for special-category data) we rely on the following lawful bases:
Our service is designed exclusively for parents and guardians. Children under 13 should not create accounts or provide personal information directly. Only parents or legal guardians should sign up and use this service on behalf of their children.
No Direct Collection from Children: We do not knowingly collect personal information directly from children under 13. All child-related information (names, gender, age ranges) is provided by parents through their adult accounts.
Parental Consent & Control:By creating an account and providing your child's information, you (as the parent/guardian) are giving consent for us to use that information to create personalized stories. You maintain complete control and can review, modify, or delete your child's data at any time.
We comply with children's privacy regulations including:
If we discover we have received personal information directly from a child without proper parental consent, we will delete it immediately.
Here's the simple truth:We use the names, gender, and age ranges from your child profiles, plus the choices you make in the story wizard, to create personalized stories. That's it!
You can optionally record your own voice to narrate bedtime stories. This feature uses AI voice cloning technology provided by Mistral AI (France, EU). Here is exactly how your voice data is handled:
We (Bedtime Stories) are the Data Controller for your voice data. Our AI voice technology partner acts as our Data Processor, processing your voice data solely on our instructions under a Data Processing Agreement. Our AI partner does not use your voice data for their own purposes.
Voice data is biometric data under GDPR Article 9. We process it based on your explicit consent (GDPR Article 9(2)(a)), which you provide before recording by checking the consent box. You can withdraw consent at any time by deleting your voice from your dashboard or deleting your account.
We have opted out of allowing our AI voice partner to use your voice data for model training. Your voice recordings and clones are used exclusively for generating story narration within our service.
Your data is stored primarily on European servers through Supabase's European data region, ensuring GDPR compliance and strong data protection standards. This includes our database, object storage, and authentication systems.
We implement enterprise-grade security measures including encryption, access controls, and regular security audits. For detailed technical security information, please see our comprehensive Security Policy.
We work with trusted partners who maintain strict data protection standards:
All partners maintain GDPR-equivalent protection standards through data processing agreements and appropriate safeguards.
Most of your personal data stays in the European Economic Area (Supabase Frankfurt, Hetzner Germany, PostHog EU, and Mistral AI in France for custom voice cloning). However, some processors are based outside the EEA — primarily in the United States — including:
Where personal data leaves the EEA, we rely on one or more of the following safeguards under Chapter V of the GDPR:
A copy of the relevant transfer mechanism for any specific processor is available on request at [email protected].
We do not sell, rent, or trade your personal information. We may share limited data only in these circumstances:
You can delete your stories or entire account anytime directly from your account settings. When you delete data, it's removed from our systems within 30 days. No need to contact us - you're in complete control!
To exercise any of these rights, email [email protected]. We may ask for proof of identity to prevent unauthorised disclosure. We respond within 30 days.
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or service features. When we make material changes:
Have privacy questions or concerns? I'm here to help!
Email Me
Contact Form
Visit our contact pageRelated: Security Policy | Cookie Policy
This policy is effective as of the date listed above and applies to all users of Bedtime Stories.