Skip to content
Storyo
Stories For parents Support Coming soon

Privacy policy

Last updated: September 30, 2026

Storyo ("we", "the app") is built by Eric Kunz. This policy explains what information we collect when you use the app, how we use it, who we share it with, how long we keep it, and the choices you have. The app is designed for parents to read personalized stories with their children. We treat your family's data with care and only collect what we need to make the app work.

If you have any questions, write to ericjkunz@gmail.com.

Who this policy is for

Storyo is intended to be set up and operated by a parent or legal guardian. We assume the adult creates the account, takes the photo, and manages the subscription. The app is not directed at children to collect their personal information. The personalization features use photos provided by the parent — they do not enroll the child as an account holder.

Information we collect

We collect different categories of information for different purposes.

1. Account information

  • An anonymous account identifier created automatically the first time you open the app, so your subscription and stories can be tied to you across sessions.
  • Sign in with Apple is required to finish setting up the app. We ask Apple for no name and no email address — only the Apple-supplied user identifier, which becomes the identity your account is linked to. We therefore never learn your name or your email address (real or Hide My Email relay) unless you write to us yourself. This identifier is your information as the parent — we ask for nothing equivalent about your child.

2. Information you provide

  • A first name for each child profile you add. This is used in the story text. The name never leaves your device — stories are assembled on your iPhone or iPad, so we never receive it.
  • A main photo of each child you add, and optionally up to three additional photos of the same child. The photos are used to render that child into the AI-generated illustrations.
  • An optional dedication line for a child's dedication page (for example, "With love from Grandma"). Like the name, this stays on your device and is never sent to us.

3. Story personalization data

  • Photos, in transit: when you personalize a story, your child's photo — together with any additional photos, the child's character drawing, and the book's original illustration — is sent securely over HTTPS to our backend, which forwards it to Google's Gemini image-generation service to produce the personalized page art. We send no name and no account identifier to Google alongside it.
  • We do not retain your photos. Our servers hold the photo in memory only for as long as the request takes, and write only the generated artwork. We do not create, derive, or store a facial template, faceprint, face embedding, or any other biometric measurement of your child, and we do not run face recognition or face matching of any kind. Google processes the photo to generate the image and, under its API terms for paid services, does not use it to improve its products; it logs requests for a limited period solely to detect abuse.
  • Character drawing ("Meet {name}"): the single canonical drawing of your child in our house style. It is stored on your device and in our cloud storage, tied to your account, and is sent as a reference on later pages so your child looks consistent from book to book. It is a drawing, not a photograph.
  • Generated artwork: the personalized story pages we create are stored in our cloud storage (Google Cloud / Firebase) tied to your account identifier. Only you can read them. We keep them so a story you have already personalized reopens instantly, for free, and offline.
  • Personalization record: which books have been personalized for which child profile, used to enforce the monthly book quota and to avoid charging you a quota slot twice for the same story. This record uses a randomly generated child identifier, never the child's name.
  • Picture reports: if you report a generated picture, we receive the book, the page number, your account identifier, the child identifier, and any short note you choose to add.

4. Subscription information

  • Apple App Store transactions. Apple processes your payment. We never see your credit card or full Apple ID.
  • A subscription status record from our subscription provider (RevenueCat), including the product purchased, trial state, expiration date, and whether the subscription will renew. This is linked to your account identifier and contains no information about your child.

5. App usage information

  • Funnel analytics. We log non-personally-identifying events such as "completed onboarding", "opened book", "started subscription", together with book identifiers, page numbers, counts and timings. These help us understand which parts of the app work and which don't. No event ever carries a child's name, photo, or free text.
  • We do not collect advertising identifiers (IDFA, IDFV), location, or contacts. We do not enable Google Signals or any cross-app advertising feature, and there is no advertising in the app.

6. Diagnostics

  • Crash and error reports may be collected to fix bugs. They are configured not to collect personal data such as your IP address, and they contain no information about your child. They are associated with your account identifier so we can connect a crash to a support request.

Your devices and iCloud

The data Storyo keeps on your device — children, photos, character drawings, personalized pages, dedications, reading progress and favourites — is stored in the app's local database. If you are signed in to iCloud, that database is automatically mirrored to your own private iCloud account, so your library follows you to your other Apple devices. That copy belongs to you: it lives in your private iCloud database and we cannot read it. Apple's privacy policy governs it. You can stop this mirroring by turning iCloud off for Storyo in your device's iCloud settings.

How we use the information

We use the information solely to:

  1. Run the app (sign-in, subscription enforcement, content delivery).
  2. Personalize the stories you ask us to personalize.
  3. Investigate pictures you report to us.
  4. Improve the app via aggregated analytics (event counts, funnel conversion rates).
  5. Communicate with you about your account or the service if needed.

We do not sell your data, we do not use it for advertising, and we do not use your photos to train AI models.

Who we share the information with

We use these third-party service providers to operate the app. They each have their own privacy policies that govern how they handle your data.

Service What we share Why
Apple Sign in with Apple identifier, App Store transaction records Authentication, subscription processing
Google Firebase / Cloud Account identifier, generated artwork, character drawings, subscription state, analytics events Hosting, authentication, storage, functions
Google Gemini Child photos (in transit only), the character drawing, the book's original illustration, and the scene prompt AI image generation
RevenueCat Account identifier, App Store receipt Subscription management
Sentry Crash and performance reports, account identifier Diagnostics

Your consent to this sharing. By adding a child's photo and asking us to personalize a story, you consent, as that child's parent or legal guardian, to our sending the photo to Google's Gemini service for the sole purpose of drawing the illustration you requested, and to our storing the resulting artwork with Google Cloud so you can read it again. That transfer is integral to the service — the illustration cannot be made without it. Our subscription provider (RevenueCat) receives only your account identifier and your App Store receipt, never anything about your child. If you do not want your child's photo processed this way, do not add a photo; the app cannot personalize stories without one.

We do not share personal information with any other third parties for marketing, advertising, or any unrelated purpose.

Children's privacy and COPPA

Storyo is intended for parents to use with their children, and is listed in the App Store's Kids category. We do not knowingly collect personal information from children under 13 except for content the parent provides on the child's behalf — a first name (which stays on your device) and one or more photos — for the sole purpose of personalizing the stories.

  • A parent creates the account. Signing in with Apple is required to finish setting up the app, so the account holder is an adult with an Apple ID. Personalizing a story additionally requires a subscription bought with an adult payment method. Purchases and destructive actions such as deleting a child or your account sit behind an adult-only hold-to-confirm gate.
  • The photos are used only to draw the illustrations. We do not keep them, and we do not create or store a facial template, faceprint, or any other biometric measurement of your child.
  • The first name is never transmitted. It is shown only inside the stories on your own devices.
  • We do not contact children, do not show them advertising of any kind, and do not let them communicate with anyone through the app.
  • Parents can delete a child profile or the entire account at any time (see Your choices and rights), and can refuse to permit further collection by deleting the child's photos or the account.

If you believe a child has provided us with personal information without parental consent, please contact us at ericjkunz@gmail.com and we will delete the data.

Data retention

We keep children's information only as long as is reasonably necessary for the purpose it was collected for, and never indefinitely.

What Why we keep it How long
Child photos (main and additional) Nothing — we have no need to retain them Not retained by us. Held in memory for the length of the generation request only. Google logs the request for a limited period for abuse detection under its own terms
Character drawing So your child looks consistent across books, and so redrawing doesn't cost you money Until you delete that child or your account
Generated story pages So a personalized story reopens instantly, free, and offline Until you delete that child or your account
Account record, subscription and quota state To run your subscription and enforce the monthly allowance Until you delete your account
Picture reports To investigate a picture you told us about Until the report is resolved, and for 12 months afterwards, then deleted
Analytics events Aggregate product measurement For no longer than 14 months, the longest period Google Analytics keeps this kind of data, then deleted automatically
Crash and performance reports To fix the bug For no longer than 90 days, then deleted automatically
Data on your device and in your iCloud It's your library Until you delete the child, delete your account, or remove the app

Your choices and rights

You can:

  • Delete a single child profile in the app: long-press the child's photo and choose Delete, then pass the adult check and confirm. This removes that child, their photos and their stories from your device and from your iCloud. Copies of that child's generated artwork remain in our cloud storage until you delete your account; if you want them removed sooner, email us and we will delete them.
  • Delete your entire account in Settings → Delete account. This removes your account record, your generated artwork and character drawings, your subscription record on our side, your authentication identity, and everything Storyo stores on your device. Your App Store subscription is not automatically cancelled — you must manage that separately at Settings → Apple ID → Subscriptions.
  • Manage or cancel your subscription at Settings → Apple ID → Subscriptions on your device.
  • Request a copy or correction of your data, or the deletion of analytics or diagnostic records that in-app deletion does not reach, by writing to ericjkunz@gmail.com. We will respond within a reasonable time, and within one month where the law requires it.

If you are in the EU, UK, or California, you have additional statutory rights under the GDPR, UK GDPR, and CCPA (the right to access, rectify, delete, restrict, and port your data, and to withdraw consent and lodge a complaint with your supervisory authority). Where we process a child's photo, we do so on the basis of your explicit consent as the holder of parental responsibility, and you may withdraw that consent at any time by deleting the child profile or your account. To exercise any of these rights, write to ericjkunz@gmail.com.

Security

We use industry-standard security measures: encrypted connections (HTTPS) for data in transit, access controls so users can only read their own data, server-side rules that prevent any client from writing to our database or storage directly, device attestation (App Check) on every backend endpoint, and least-privilege configuration of our cloud services. No system is perfectly secure — we will notify you if we ever become aware of a material breach affecting your data, as required by applicable law.

International data transfers

Our backend functions run on Google Cloud in the United States (us-central1), and our database and storage are hosted in the United States as well (Firestore in the nam5 multi-region, Cloud Storage alongside it). Google's Gemini service may process requests on infrastructure outside your country. Where data is transferred out of the European Economic Area or the United Kingdom, the transfer relies on the Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum) incorporated into our data-processing agreement with Google. By using the app you understand that your data may be processed in jurisdictions different from your own.

Changes to this policy

We may update this policy from time to time. If we make material changes we will update the "Last updated" date at the top and, where appropriate, notify you in the app. The current version will always be available at https://storyo.app/privacy.

Contact

Eric Kunz ericjkunz@gmail.com

Storyo
For parents Privacy policy Terms of service Support

Made by Eric Kunz at High Line Labs.