← Beyond Stories

Privacy Policy

Effective August 1, 2026

1. Introduction

Beyond Stories ("Beyond Stories", "we", "us") is an illustrated, narrated story app made for young children and set up by a parent or guardian. This policy explains what we collect, why, and who we share it with. It covers the website at beyondstories-production.up.railway.app, the browser app at /play/, and the iOS and Android apps.

The short version. The account belongs to an adult. The child never types anything — there is no text box anywhere in the app — so nothing a child writes can ever be collected or sent to an AI provider. We run no advertising and no third-party analytics.

2. Who is responsible

The data controller is the operator of Beyond Stories. For any privacy question or request, email beyondstories@ziembaapps.com.

3. What we collect

4. What we deliberately do not collect

5. How we use it

To run the app: to generate and store stories, to keep saved stories available, to apply star balances and free claims, to process purchases, to prevent abuse of free grants, to answer support requests, and to keep the service secure and working. We do not sell personal information, and we do not use it for advertising or profiling.

6. AI processing

Story text, illustrations, narration audio and songs are generated by third-party AI providers. What we send them is: the chosen world description written by us, the sequence of pictures tapped so far, and the story lines already generated. Nothing typed by a user is ever included, because nothing can be typed. Generated output is filtered against a safety charter before it is shown or read aloud, and is then stored with the saved story on our databases.

7. Legal bases (EEA/UK)

Where the GDPR applies we rely on: performance of a contract (providing the app the adult signed up for); legitimate interests (security, prevention of free-grant abuse, keeping the service reliable); consent, given by the parent or guardian on the child's behalf, where required for processing relating to a child; and legal obligation (tax and accounting records for purchases).

8. Service providers

We share data only with providers needed to operate the app, each under contract and only for that purpose: Google Firebase (sign-in), our cloud hosting provider, MongoDB (our database), OpenRouter and the AI models it routes to (story text), fal.ai (illustrations), OpenAI (narration audio), ElevenLabs (songs), Amazon S3 (storing images and audio), Stripe (web payments), and RevenueCat with the App Store and Google Play (mobile purchases).

9. International transfers

Data may be processed outside your country, including in the United States, where our infrastructure and providers operate. We take steps intended to protect it in line with applicable law.

10. Retention and deletion

Saved stories expire automatically after about 90 days without use. Account, star balance and purchase records are kept while the account exists. An adult can delete the account from inside the app at any time; doing so removes the stories, the star balance, the purchase claims, and the sign-in itself, and releases the device so a genuine future reinstall can receive free stars again. We may keep minimal purchase records where tax or accounting law requires it.

11. Children's privacy

Beyond Stories is intended for young children, used with an account set up and controlled by a parent or guardian. We do not knowingly collect personal information directly from a child: the app collects no free text, no name and no birthday, and every purchase or outbound link sits behind a gate a young child cannot pass. If you believe a child has provided us personal information, email us and we will delete it. A parent or guardian may request access to, or deletion of, any information associated with their account at the address below.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of personal data, and to data portability or withdrawal of consent. Email us to exercise any of these. You may also complain to your local data protection authority.

13. Security

We use encrypted transport (HTTPS), authenticated APIs, and access controls, and every request to our servers is verified against a signed sign-in token. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

14. Changes

We may update this policy. The revised version will appear on this page with a new effective date, and material changes will be signalled in the app where practical.

15. Contact

beyondstories@ziembaapps.com