1Introduction
CozyTales ("we," "our," or "us") is committed to protecting your privacy and the privacy of your children. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personalized children's story generation service at cozytales.app and related services.
This policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Children's Online Privacy Protection Act (COPPA), and other applicable privacy laws.
2Information We Collect
2.1 Information You Provide Directly
- •Account Information: Email address, password (if not using OAuth), first name, last name
- •Child Profile Information: Child's first name only (no last name), age (2-9 years), gender (optional), interests, favorite values/lessons
- •Pet Information: Pet names and types (optional)
- •Story Preferences: Values to teach, story themes, language preferences
- •Payment Information: Processed securely through Paddle (we do not store credit card numbers)
- •OAuth Profile Data: When using Google or Facebook login, we receive your name, email, and profile ID
- •Parent Quiz Responses: If you complete our optional bedtime-parent quiz, we store your answers and the resulting parenting style archetype
2.2 Information Collected Automatically
- •Usage Data: Stories generated, favorites marked, generation timestamps
- •Device Information: IP address, browser type, device type, operating system
- •Log Data: Access times, pages viewed, errors encountered
- •Session Information: Authentication tokens, session identifiers
2.3 Cookies and Tracking Technologies
We use essential storage required to operate the service, plus first-party analytics cookies for product analytics and session replay so we can understand how the site is used and fix issues. We do not use advertising cookies or cross-site profiling, and we do not sell your data.
- •Essential Cookies: For authentication and session management. Duration: session-only or up to 30 days for "remember me".
- •localStorage: To store authentication tokens and user preferences. Persisted in your browser until you log out or clear browser data.
- •sessionStorage: For temporary data during story creation. Cleared when you close the tab.
If we ever introduce additional tracking or non-essential cookies beyond what is listed here, we will update this policy and obtain your consent before doing so.
3How We Use Your Information
3.1 Primary Uses
- •Generate personalized bedtime stories based on child profiles
- •Manage user accounts and subscriptions
- •Process payments and manage billing
- •Send transactional emails (verification, password resets, receipts)
- •Provide customer support
- •Improve our service and develop new features
- •Understand our user base through aggregate analytics
3.2 Legal Basis for Processing (GDPR)
- •Consent: For marketing communications and non-essential features
- •Performance of Contract: To provide our story generation service
- •Legal Obligations: Tax records, fraud prevention
- •Legitimate Interests: Service improvements, security, analytics
4How We Share Information
4.1 Service Providers
- •Supabase: Database and authentication services
- •Paddle: Payment processing (PCI-compliant)
- •Anthropic: Story text generation via Anthropic's API. We send your child's first name, age, gender, interests, pet name, and sibling first names to generate personalized story content. Anthropic processes this data in the United States and is certified under the EU-US Data Privacy Framework, providing GDPR-compliant transfer protections for EU users. No last names, email addresses, or contact information is ever shared. Anthropic does not retain or use submitted data for model training.
- •OpenAI: We use OpenAI services as part of the story generation, illustration generation, and audio narration. Story content (which contains your child's first name) and minimal child profile data are sent. Illustrations depict environments only, never people. Audio narration is generated using OpenAI's text-to-speech service. OpenAI is US-hosted and certified under the EU-US Data Privacy Framework. Submitted data is not used for model training.
- •Cloudflare R2: Image and audio storage and delivery
- •Resend: Transactional email delivery
- •Vercel: Website hosting, deployment, and cookieless analytics. Vercel Analytics collects aggregate page-view metrics using an anonymized, daily-rotating device hash — no cookies, no persistent identifiers, no cross-site tracking. Vercel is US-hosted and offers GDPR-compliant transfer mechanisms for EU users.
- •Sentry: Error tracking and performance monitoring. When the application encounters an error, technical context (stack traces, browser and device information, anonymized user identifier) is sent to Sentry so we can diagnose issues. Story content, child profile information, and payment data are not sent. Sentry is US-hosted and certified under the EU-US Data Privacy Framework.
4.2 Legal Requirements
We may disclose information if required by law, court order, or government request, or to protect our rights, property, or safety.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, user information may be transferred with appropriate privacy protections.
5Children's Privacy (COPPA Compliance)
CozyTales is designed for parents to create stories for their children. We do not knowingly collect personal information directly from children under 13. Children do not have direct access to our service. All child-related information is provided by parents or guardians.
Under GDPR Article 8, processing personal data of a child requires the consent of the holder of parental responsibility. By creating a child profile in your CozyTales account, you confirm that you are the parent or legal guardian and provide consent for the processing of your child's information for the purpose of generating personalized stories.
- •We collect minimal child information: first name only (no last name), age (2-9), gender (optional), interests, and optional pet/sibling first names
- •To generate personalized stories, your child's first name, age, gender, interests, and pet/sibling first names are sent to our AI providers (Anthropic and OpenAI) as described in Section 4.1. No last names, email addresses, physical addresses, or other contact information is ever shared with AI providers.
- •AI providers process this data solely to generate your story and do not use it for model training or any other purpose
- •No direct communication with children
- •No behavioral advertising targeted at children
- •Parents have full control over their children's profiles and can delete all child data at any time
6Data Retention
- •Active Accounts: Data retained while account is active
- •Inactive Free Accounts: Deleted after 12 months of inactivity
- •After Account Deletion: Personal data deleted within 30 days
- •Aggregate Data: We retain only anonymized aggregate statistics (e.g., total number of users)
- •Temporary Stories: Automatically deleted after 72 hours
7Your Rights and Choices
Your Right to Delete
You have the right to request deletion of your personal data at any time, without providing a reason. This policy explains how we handle deletion requests in compliance with GDPR, CCPA, and other privacy regulations.
To request deletion, simply go to your Account Settings and click "Delete My Account" or email us at hello@cozytales.app.
7.1 GDPR Rights (EU Users)
If you are in the EU/EEA, you have the following rights under the GDPR:
- •Access: Request a copy of your personal data
- •Rectification: Correct inaccurate information
- •Erasure: Request deletion ("right to be forgotten")
- •Portability: Receive your data in a portable format
- •Restriction: Limit processing of your data
- •Object: Opt-out of certain processing
- •Withdraw Consent: Where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal
7.2 CCPA Rights (California Users)
- •Know: What personal information we collect and how it's used
- •Delete: Request deletion of your personal information
- •Opt-Out: We do not sell personal information
- •Non-Discrimination: Equal service regardless of privacy choices
7.3 How to Exercise Your Rights
Email us at hello@cozytales.app or use the account settings in your dashboard. We will respond within 30 days.
8Data Security
We implement appropriate technical and organizational measures to protect your data:
- •Encryption in transit (HTTPS/TLS)
- •Encryption at rest for sensitive data
- •Access controls and authentication
- •Regular security assessments
- •Secure third-party services (SOC 2 compliant where applicable)
In the unlikely event of a personal data breach affecting your information, we will notify the relevant supervisory authority within 72 hours of becoming aware of it (in accordance with GDPR Article 33) and notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).
9International Data Transfers
Your data is primarily processed in the United States. All AI providers (Anthropic and OpenAI) process data in the United States under the EU-US Data Privacy Framework, providing GDPR-compliant protections for EU users. Only the minimal information needed to generate a story (child's first name, age, gender, interests, and pet/sibling first names) is sent to these providers. No account information, email addresses, payment data, or other identifying information is transferred.
If you access our service from outside the US, you consent to the transfer of your data to the US and to third-party processors as described in Section 4.1.
10Do Not Track Signals
CozyTales does not currently respond to Do Not Track browser signals automatically. We use first-party analytics cookies (PostHog) for product analytics and session replay, but we do not engage in cross-site tracking, fingerprinting, or behavioral advertising. You can disable analytics tracking at any time by clearing your cookies for cozytales.app.
11Marketing Communications
With your consent, we may send promotional emails about new features, special offers, or educational content. You can unsubscribe at any time via the link in any marketing email or through your account settings.
12Third-Party Links
Our service may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies before providing personal information.
13Changes to This Privacy Policy
We may update this policy periodically. We will notify you of material changes via email or prominent notice on our website at least 30 days before the changes take effect. Continued use after changes constitutes acceptance.
14Contact Information
For privacy-related questions, concerns, or to exercise your rights, contact us at:
- •Email: hello@cozytales.app
- •Support: hello@cozytales.app
If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection supervisory authority. CozyTales is established in Poland; the Polish supervisory authority is the Urząd Ochrony Danych Osobowych (UODO) — uodo.gov.pl. You may also contact the supervisory authority in your own EU/EEA country of residence.
Last updated: May 12, 2026 • Questions? Contact us