Privacy Policy
Effective: July 13, 2026
This Privacy Policy explains how Dear Storybook ("we," "us," or "our"), operated by Lloyd Luck, collects, uses, and shares information when you use our service at dearstorybook.com ("Service"). Please read it together with our Terms of Service.
1. Information We Collect
Account information
When you create an account, we collect your email address and, if you sign in with Google, your Google profile name and avatar. We also use your email-verification status to determine whether AI generation features are available to your account.
Content you create
To create a book, you provide family memories, names, ages, and other personal details ("story inputs"), and may upload reference photos. This content is stored on our servers and may be processed by our safety and AI-generation providers as described below.
Payment information
When you purchase a creation credit or place a print order, payment is processed by Stripe, Inc. We do not store your full card number, CVV, or other sensitive payment credentials. Stripe may share a billing email and last-four digits for display purposes.
Usage and technical data
We automatically collect device type, browser/app version, IP address, pages visited, and interactions (such as buttons tapped) to help us improve the Service and diagnose errors. This data is collected via Firebase Analytics and Google Analytics. We also record limited generation, quota, cost, security, and fulfillment events needed to prevent abuse and operate the Service.
2. How We Use Your Information
Provide and maintain the Service, including generating AI story text and illustrations based on your inputs.
Run automated text and image safety checks before and after AI generation.
Enforce account-verification, fair-use, request, and spending limits.
Process and fulfill print orders by transmitting the necessary data to our print partner, Lulu.
Send transactional emails (order confirmations, shipping updates) using Firebase Trigger Email.
Authenticate your account and keep it secure.
Improve and debug the Service using aggregated analytics.
Comply with legal obligations.
We do not sell your personal data or use your content to train a Dear Storybook model. Third-party AI providers process content under their own terms and our account settings. We do not promise that all provider processing is zero-retention or excluded from every provider use unless we have verified that commitment for the account and service involved.
Before a reference photo is attached to a page, our server checks its type, size, and pixel count, decodes it, and re-encodes the managed copy as JPEG. This removes embedded metadata, such as EXIF location data, from the managed copy. The temporary original is deleted after a successful attachment. A scheduled cleanup job attempts to delete incomplete or abandoned temporary uploads after their 10-minute reservation expires; failed cleanup may take longer.
3. Third-Party Services
We use the following third-party services to operate Dear Storybook. Each processes your data according to its own privacy policy.
Google Firebase / Google Cloud
Authentication, database, file storage, and analytics
OpenAI
Automated text and image safety screening; story and illustration generation when selected
Google Gemini
Story and illustration generation when selected
Anthropic Claude
Story generation when selected
Stripe, Inc.
Payment processing
Lulu Press, Inc.
Print fulfillment and shipping
Story inputs, revision instructions, page text, art direction, and generated text may be sent to OpenAI for automated safety review. Sanitized reference photos and generated illustrations may also be sent to OpenAI for automated image safety review. Content that passes those checks is sent to the AI provider selected for that generation request: OpenAI, Google Gemini, or Anthropic Claude. These checks are automated and are not a substitute for your review.
Our current Anthropic API organization uses Anthropic's standard retention rather than a zero-data-retention agreement. Anthropic states that API inputs and outputs are generally deleted within 30 days, subject to exceptions for policy enforcement, legal obligations, and separately agreed terms. We have not yet verified zero-retention or equivalent account-level settings and data processing terms for the OpenAI and Gemini projects used by the Service, so you should not assume those providers retain no data.
Your shipping address, order details, and time-limited links to the print files are shared with Lulu solely to quote, produce, and ship your order. Stripe receives the information needed to process your payment and prevent fraud.
4. Data Retention
We generally retain your account information and active book content while your account or book remains active. A book can use the ordinary deletion flow only before checkout begins, while it is in draft or illustration review. For an eligible deletion, we recursively delete its active database records and attempt to delete files stored under that book. We keep a minimal deletion record containing the book identifier, account identifier, prior status, and deletion time for security and audit purposes. File cleanup is best-effort and may take additional time. Our current Cloud Storage configuration keeps deleted file data in a recoverable soft-deleted state for seven days before permanent removal. If the deleted book has an active paid creation credit, we retain a minimal payment ledger showing that the non-refundable credit was forfeited.
After checkout begins, a book cannot be removed through the ordinary book-deletion process. For paid or fulfillment orders, we retain the order's immutable print snapshot, payment and shipping references, print files, and related records as needed to fulfill the order, handle refunds, chargebacks, fraud, accounting, disputes, and legal obligations.
Removing content from Dear Storybook does not immediately remove copies already sent to an AI, payment, or print provider. Those providers apply their own retention periods and legal exceptions. Limited quota, generation-job, security, deletion, and analytics records may also remain after active content is removed. Aggregated or de-identified analytics may be retained longer.
To request account deletion, email us using the address below. We will verify your identity and remove eligible active content, while retaining records that we reasonably need for the purposes listed above.
5. Your Rights
Depending on your location, you may have the right to:
Access the personal data we hold about you.
Correct inaccurate data.
Request deletion of your account and associated data.
Object to or restrict certain types of processing.
Receive a copy of your data in a portable format.
To exercise any of these rights, email us at [email protected]. We will respond within the time required by applicable law and may need to verify your identity first.
6. Children's Privacy (COPPA)
Dear Storybook is a platform for adults to create children's books as gifts or keepsakes. The Service is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has created an account, please contact us at [email protected]. We will take appropriate steps to close the account and remove eligible data, subject to the retention and provider limitations described above.
While books may feature children as subjects, the account holders and purchasers are adults. Photos of minors uploaded by account holders are sanitized and may be sent to OpenAI for automated safety review and to the selected image-generation provider as described above. Account holders must have authority to provide those photos and request this processing.
7. Cookies and Tracking
The web version of our Service uses cookies and similar technologies for authentication and analytics. You can disable cookies in your browser settings, but some features may not work correctly without them.
8. Security
We use safeguards including encrypted connections (TLS), Firebase Security Rules, and access controls to protect your data. Some private images and print files are delivered through time-limited signed links. A person who receives an unexpired signed link may be able to access the linked file, so do not share those links. Current reference upload and read links last about 10 minutes, generated page-preview links last seven days, and print-file links sent to Lulu last seven days. Selecting a saved illustration refreshes its preview link. Link expiration does not itself delete the underlying file. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy at dearstorybook.com and updating the effective date above. Continued use of the Service after changes take effect constitutes your acceptance of the revised policy.
10. Contact Us
If you have questions or concerns about this Privacy Policy, please contact: Lloyd Luck [email protected] dearstorybook.com

privacy