At LittleReaders, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
Account Information
When you create an account, we collect your email address (for authentication and communications), name (if provided through Google OAuth), and profile picture (if provided through Google OAuth).
Important: How We Handle Your Photos
- When you upload a photo to create a character, we do not permanently store the original photo.
- The photo is sent to our AI image processing service (fal.ai) to generate a stylized character illustration.
- Finished illustrations are kept for reuse. Original photos are kept privately only while needed for drafts, open payments, or active generation.
- Original uploaded photos are stored privately to prepare character drafts and fulfill paid books. Unpurchased drafts expire after 48 hours. Inputs required by open payments or active generation are retained until no longer needed. Originals are then deleted; failed deletion operations are retried.
Payment Information
Payment processing is handled by Stripe. We do not store your credit card numbers, CVV, or other sensitive payment details on our servers.
Generated Content
We store the content you create: AI-generated character illustrations, generated story text and translations, story page illustrations, and your customization settings.
2. How We Use Your Information
We use the information we collect to:
Legal Bases for Processing (GDPR Article 6)
Providing the service: account management, generating your stories and illustrations, processing purchases and refunds, customer support.
Processing photos you upload to create character illustrations, and information about children you choose to provide. You can withdraw consent at any time by deleting the content or your account.
Retaining transaction and tax records for statutory periods, responding to lawful requests from authorities.
Fraud and abuse prevention, service security, error monitoring, and improving the service through aggregated, privacy-preserving analytics.
Please do not include sensitive personal data (such as health, religious, or other special-category information) in free-text fields like story themes or special elements. These fields are intended for creative story details only.
3. Information Sharing with Third Parties
Uploaded photos and text descriptions are sent for character generation after payment. Original photos are temporarily stored privately by LittleReaders until no longer needed for the order. Processing is governed by fal.ai's API terms, which state that submitted content is not used to train or develop their products or services.
Story parameters (theme, character names, language) for narrative generation. Routed under OpenRouter's data policy: prompt content is not stored unless we opt in to logging (we do not), and the upstream model providers we route to state that API inputs are not used to train their models.
Email address and transaction details for secure payment handling.
Generated content (illustrations, story text) stored securely in the US.
If you order a printed book, Peecho B.V. (Netherlands) acts as the seller of record: it receives your name, shipping address, and payment through its own checkout, and fetches the print file from us. Peecho's own privacy policy applies to print orders.
Hosts the website and processes requests (including IP addresses) to serve and secure the application.
Managed database hosting for account data, generated story text, and transaction records.
Runs background jobs such as story generation and PDF rendering on our behalf.
Sends transactional emails (account, order, and story notifications) to your email address.
Collects error reports and diagnostic data when something breaks, so we can fix it. Error replays are captured only when an error occurs, with text and media masked.
If you sign in with Google, Google shares your email, name, and profile picture with us under its own privacy policy.
We do not sell your personal information to third parties.
Your Data Is Never Used to Train AI Models
Neither we nor the AI providers we work with use your photos, your children's information, or your story content to train AI models. Your uploads and your generated books are used solely to create your stories, under provider terms that commit to exactly that.
4. Children's Information
How We Handle Children's Data
- LittleReaders is designed to be used by adults (18+) to create stories for children.
- We collect information about children (names, ages, photos) that is provided by adults (parents, guardians).
- We do not collect information directly from children.
- The adult who creates an account has full control over the children's data and can delete it at any time.
If you believe a child has provided us with personal information directly without parental consent, please contact us immediately at support@littlereaders.ai.
5. Data Retention
6. Data Security
We implement appropriate technical and organizational measures to protect your information:
7. Your Rights and Choices
All Users
GDPR and UK GDPR Rights (EU, EEA and UK Users)
If you are in the EEA or the United Kingdom, you have additional rights under the GDPR (or the UK GDPR):
You can delete your account yourself at any time from your Account page (Danger Zone → Delete Account). Deletion is immediate: your stories, characters and personal details are removed, and your sign-in is revoked. Payment ledger records we are legally required to keep are retained in anonymized form for the statutory period. For any other request, contact us at support@littlereaders.ai. We respond within 30 days.
You also have the right to lodge a complaint with a data protection supervisory authority. Our lead authority is the Croatian Personal Data Protection Agency (AZOP), azop.hr. You may also complain to the supervisory authority of your own EU member state, or, in the United Kingdom, to the Information Commissioner's Office (ICO), ico.org.uk.
8. International Data Transfers
Some of the providers listed above process data in the United States. Where personal data leaves the EEA or the UK, we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework (including its UK Extension) for providers certified under it, and on Standard Contractual Clauses (with the UK Addendum where applicable) otherwise, together with technical measures such as encryption in transit and at rest. You can contact us for details of the safeguard applying to a specific provider.
9. Cookies and Tracking
We use only cookies that are strictly necessary to run the service: session and authentication cookies (so you stay signed in) and a language preference cookie. We do not use advertising or marketing cookies, and we do not track you across other websites. Because we set no non-essential cookies, we do not show a cookie consent banner: there is nothing to consent to.
For usage statistics we use Vercel Web Analytics, which is cookieless and does not identify individual visitors. Error monitoring (Sentry) activates only when something goes wrong, with text and media masked in any error replay.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on our website.
11. Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Data controller: Jubiflow d.o.o., Supilova ulica 7, 10000 Zagreb, Croatia
OIB 50187059236 · MB 05849110 · MBS 081540714 (Trgovački sud u Zagrebu) · Full company details