Privacy Policy

Last updated: 23 September 2026

Stories That Remember ("we", "us", "our") makes personalised children's stories from the details you share with us about your child. This policy explains what we collect, why, and what rights you and your family have over it.

The short version: you (the parent, guardian, or family member) are our customer and account holder. Your child is who the story is about. Everything about your child is entered by you, stored under your account, and can be edited or deleted by you at any time. Nobody else can see it, apart from the limited cases explained in Section 7 (keeping children safe) and when we prepare a printed keepsake you've ordered.

1. Who we are

Stories That Remember is a UK-based service.
Stories That Remember, 9 White Court, WF4 1TB.
[Company registration number to be added, if trading as a limited company.]

For privacy questions or to exercise your rights, contact us at privacy@storiesthatremember.com.

2. What we collect

CategoryWhat
Account detailsYour email address and password (password is hashed by our authentication provider — we never see it in plain text). Confirmation that you are 18 or over.
Child profile detailsName, age, and your relationship to the child; free-text answers you give during the story questionnaire (memories, obsessions, upcoming excitements, personality, and physical description including hair, eyes, ethnicity, and build).
Story contentThe stories generated for your family, and short structured notes ("story references") kept so future stories can build on earlier ones.
Anything else you choose to shareParents sometimes mention sensitive real-world context (e.g. a hard week at school) to help the story reflect what's going on. See Section 6.
Keepsake ordersFor printed books: the story, any dedication you write, the appearance details you confirm for each illustrated character, the recipient's name and postal address, and any delivery note.
Chat assistant messagesIf you use the chat assistant on our Contact page, the messages you type, the replies, and a scrambled (one-way hashed) version of your IP address, used to limit how many messages can be sent. We never store your actual IP address. Please don't share personal details about your child there.
Safety recordsIf a story is held back by our safety checks: the story, the request that produced it, and why it was flagged. For a serious safety concern only, also the relevant answers you gave in the questionnaire. See Section 7.
Payment detailsHandled directly by our payment processor (Stripe) — we do not store your card details ourselves. [Payments not yet live.]

3. Why we collect it, and our lawful basis

4. Who we share it with

We use a small number of specialist providers to run the service. None of them may use your family's data for their own purposes.

ProviderWhat they processLocation
AnthropicConversation transcripts, questionnaire answers and story requests, to generate and safety-check story text; and messages sent to our website chat assistantUnited States
SupabaseAccount and database hostingFrankfurt, Germany (EU)
VercelWebsite and serverless function hostingWashington, D.C., USA
Neolemon (operated by Sachin Kamath)Character appearance descriptions and first names (no photos), to create keepsake illustrationsPortugal (EU)
StripePayment details (planned, not yet live)[TBC]
Lulu Press, Inc.The finished book, recipient name and postal address, to print and deliver keepsakesUnited States (Durham, North Carolina)
ResendYour email address, to send account emails such as sign-up confirmationIreland (EU)
Google Workspace (Google Ireland Limited)Emails you send us, and our repliesIreland (EU); may also be processed in the United States

We use Anthropic's Claude API to generate story content. Under Anthropic's commercial API terms, data sent through the API is not used to train Anthropic's general models — you can read Anthropic's current terms at anthropic.com/legal.

Where a provider is based outside the UK/EEA — this currently includes Anthropic, Vercel and Lulu, all US-based, and Google may also process email data in the US, while Supabase hosts your data in Frankfurt, Germany (EU) — we rely on appropriate safeguards such as Standard Contractual Clauses. [Data Processing Agreements with each provider are being finalised — see internal action log.]

We never sell your family's data, and we don't share it for advertising.

5. How long we keep it

We keep as little as we can, for as short a time as we can. Here's how that works:

Safety records. Routine safety flags are kept for 90 days. Where an account is reviewed for a safeguarding concern, the relevant information is kept for up to 12 months if no further action is needed, or up to 6 years if the account is closed for serious misuse or the matter is reported to an authority (longer only if an authority asks us to). While a review is ongoing, we can't delete the account on request until the review is complete.

6. Sensitive information

Some questions — like your child's ethnicity — help us describe them accurately in the story and, if you order a keepsake, in its illustrations. This is optional. You don't have to share it, and leaving it out won't stop you creating a story.

Parents also sometimes mention something difficult going on for their child — a hard day, a big change at home, something unkind that happened. We understand this is offered in good faith, as context. Our system is specifically instructed to take only the general emotional shape of anything sensitive you share (for example, "going through a big change") and never to reproduce the specific words, incident details, or other people involved — either in the story, or in what we keep afterwards.

Please only share what you're comfortable with. Sensitive information is never required to create a story.

7. Keeping children safe

Every story is checked by an automated safety system before you see it. If something is held back, we keep a record of what was flagged and why, including the story and the request that produced it, and it may be reviewed by our Designated Safeguarding Lead. Only where the concern is serious (for example, anything sexual involving a child) do we also keep the relevant answers you gave in the questionnaire, which we otherwise never store. Apart from that, someone at Stories That Remember only reads your questionnaire answers or stories when preparing a printed keepsake you've ordered, or when you ask us to help.

If we have a serious concern that a child may be at risk, we may share relevant information with the police, the National Crime Agency, children's social care or other appropriate authorities. The law allows us to do this, and in some cases not to tell you first, where telling you could put a child at risk or harm an investigation. Our Safeguarding Statement explains more.

8. Children's data — an important distinction

Your child is who this service is about, but they are not our customer and do not use the questionnaire, sign up, or manage any settings themselves — you do, as the account holder. This is a deliberate design choice, and it shapes how this policy applies: your child's information is provided, viewed, and controlled entirely through your account.

If your child is old enough to want to exercise their own data protection rights directly with us in future, we'll have a process for that — for now, please contact us and we'll help.

9. Your rights

Under UK GDPR, you can ask us to:

Some of these rights have limits. For example, we may not be able to delete information we need to keep for child safety, or share it with you where that could put a child at risk or harm an investigation.

To do any of these, contact us using the details in Section 1. You can also complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at any time.

10. Security

Access to your data is protected by row-level security at the database layer, meaning your account's data is only ever returned to your own authenticated session — not just filtered by the app, but enforced by the database itself. All traffic to the site is encrypted (HTTPS). Passwords are hashed, never stored in plain text.

A small number of named people at Stories That Remember can access account data where it's needed to prepare a keepsake you've ordered, review a safety flag, or help when you ask us to.

11. Cookies

See our separate Cookies Policy for details on the (very few) things we store in your browser.

12. Changes to this policy

If we make material changes, we'll update the date at the top of this page and, where appropriate, let account holders know directly.

13. Contact

privacy@storiesthatremember.com

Safeguarding concerns: safeguarding@storiesthatremember.com