Privacy Policy
Last updated: September 2026
This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with the Story Gliders parent portal and related services (the“Services”). We are committed to privacy by design and to complying with the privacy laws of the regions we serve, including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec’s Law 25, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Australia’s Privacy Act 1988 and Australian Privacy Principles (APPs), and U.S. children’s privacy rules (including COPPA).
1. Who we are
The Services are provided by Story Gliders Inc. (“we”, “us”, or “our”). We are responsible for the personal information we process via the parent portal. Our full contact details, including our postal address, are provided at the end of this policy.
As in our Terms of Use, a parent profile is the profile of the parent or legal guardian who owns and manages the account, and a user is a child that parent has added to the account to use the reading features. Users do not have accounts of their own.
2. What information we collect
- Parent account information: name, email address, authentication identifiers, preferences, and settings.
- Child user information: nickname or first name, avatar/character choices, reading preferences, and progress indicators. We encourage parents to avoid entering full legal names. Names are encrypted at rest using AES-256-GCM with a per-row random initialisation vector and authentication tag. Real names are decrypted server-side only when they need to be returned to the authenticated parent for display, and a separate per-child privacy alias is used in their place for any AI prompts (see Section 9 for details).
- Accessibility reading supports: a parent can turn on optional Dyslexia and ADHD/Focus reading supports for a child. These simply unlock reading helpers that adapt how stories are shown and read aloud (extra spacing between letters and words, a light line that dims the text around the line being read aloud, an easy-read font, a slower read-aloud voice, and an optional colour or bold cue for tricky words), which the child then switches on or off as they read. Because turning a support on can reveal information about a child’s health or learning needs, some privacy laws (including Quebec’s Law 25 and the EU’s GDPR) treat this as sensitive, special-category health-related information. These supports are off by default; we record them only with a parent’s explicit consent, use them solely to adapt how stories are shown and read aloud (never for profiling, advertising, or AI training), and a parent can turn them off at any time.
- Usage and activity: interactions with stories, reading sessions, quiz results, comprehension, and word practice history.
- Audio/voice data: when your child uses speech features (such as read-aloud practice or pronunciation feedback), their voice is captured by the device microphone and streamed to our speech-processing provider for real-time analysis. We do not store, save, or retain any audio recordings of your child’s voice. Audio is processed transiently — once the service returns results (such as word accuracy scores or recognised text), the audio data is discarded immediately. Only derived, non-audio results are kept (for example, pronunciation accuracy scores and word-level error classifications). See Section 12 for full details on how our speech provider handles data.
- AI-generated content: to create personalised stories, illustrations, and reading activities, we send limited information about the child user (such as approximate age, interests, and character/place descriptions) to our AI content-generation providers. A child’s name and chosen character names are never sent to an AI provider. Before any prompt reaches the AI content generator, those names are replaced with privacy aliases (fictional stand-in names). The AI-generated story text is then re-tokenised so that the stored version contains only opaque entity tokens, and real names are inserted back only within your authenticated session. Free-text you write yourself is sent as entered (see Section 9b). For text-to-speech and pronunciation assessment, the child’s first name may appear in text sent to our speech-processing provider so that stories are read aloud naturally and reading accuracy can be assessed correctly. The provider does not retain this data after processing (see Section 12a). See Sections 9 and 12 for full details.
- Avatar customisation (optional): a parent can turn on optional avatar customisation for a child (off by default). If enabled, the generic appearance choices you select — such as hair style and colour, eye colour, skin tone, and outfit — are saved to the child’s profile and included in the image prompt sent to our image-generation provider so the artwork can resemble your child. Because a skin-tone selection can indicate racial or ethnic characteristics, some privacy laws treat it as sensitive personal information. You can turn avatar customisation off at any time, which deletes the saved appearance settings and any generated avatars.
- Technical data: device and browser type, OS, language, and time zone for core functionality. We do not use analytics trackers. In our own application database and audit logs, IP addresses are stored only as one-way hashes — for security auditing and rate limiting — never in plaintext and never for profiling (see Section 9d); our hosting and bot-protection providers process IP addresses in their standard short-lived request logs (see Sections 12h and 12i).
- Support communications: messages and contact details when you reach out to us.
- Waitlist and early-access sign-ups: if you join a waitlist while we are invite-only, we collect your first name, email address, and country (the tutor waitlist collects only your email, plus a short note if you choose to tell us what you would like from Story Gliders), along with the page you signed up from. We use these only to tell you when a place opens and to send you launch and availability updates, which you can unsubscribe from at any time. These details are encrypted at rest, and you can ask us to delete them at any time (see Section 14).
3. How we use information
- Provide, maintain, and improve the Services and personalise content for your child’s learning.
- Enable speech features (e.g., recognition, pronunciation feedback, and text-to-speech), using transient audio processing only.
- Generate personalised stories, characters, illustrations, and reading activities through AI services.
- Monitor service reliability and prevent abuse; we do not build behavioural profiles.
- Communicate with parents about features, updates, and support (you can manage preferences).
- Comply with legal obligations and enforce our terms and policies.
4. Our grounds for processing
We process personal information on the following grounds:
- Performance of a contract: to provide the Services you request.
- Legitimate interests: to improve and secure the Services in a manner that respects privacy.
- Consent: for optional features where required.
- Legal obligation: to meet compliance and regulatory requirements.
5. Children’s privacy
Story Gliders is designed for families with parental oversight. A parent or legal guardian must add and manage every child as a user. Children do not create accounts or provide information directly to us without parental involvement.
- Data minimisation: we collect only what is needed to deliver the reading experience. We encourage nicknames rather than full legal names and do not require a child’s date of birth (age is optional and approximate). Names are pseudonymised and encrypted at rest (see Section 9).
- No voice storage: audio from a child’s microphone is streamed for real-time processing and never recorded, saved, or persisted by Story Gliders. Only non-audio derivatives (e.g. pronunciation accuracy scores) are retained.
- No advertising or tracking: we do not serve ads, use analytics trackers, or build behavioural profiles of children.
- Name isolation from AI content generation: when generating stories, illustrations, quizzes, and other AI content, your child’s real name and chosen character names are replaced with temporary privacy aliases before any data reaches our AI content-generation providers. After generation, aliases are converted to opaque entity tokens for storage, and real names are re-inserted only within your authenticated session. Free-text you write yourself is sent as entered — see Section 9b.
- Story content and place names: story place names entered by parents are fictional story settings created for entertainment purposes. We recommend using invented, imaginative names (such as “Crystal Caves” or “Moonberry Island”) rather than real addresses, cities, or locations. Story content is stored with character names replaced by anonymous tokens — real child names and character names are never stored in plain text within story content.
- Names in speech services: for text-to-speech (reading stories aloud) and pronunciation assessment (evaluating how a child reads), your child’s first name may appear in text sent to our speech-processing provider. This is necessary so the story is read aloud with the child’s name and so pronunciation scoring can match against the actual text being read. The provider does not retain this data after processing and does not use it for model training (see Section 12a).
- No model training: child data is not used to train AI models. Our AI providers process requests under API terms that prohibit using customer data for model training.
- Parental controls: parents can view, edit, and delete a child’s profile and all associated data (stories, characters, places, reading history, and assessment results) at any time through the parent portal. You can also refuse to permit any further collection or use of your child’s information by revoking your consent at any time: revoking consent cancels your subscription and permanently deletes your child’s data as described in Section 8, because the Services cannot be used for a child without it.
- No over-collection: we do not condition a child’s participation in any activity on the child disclosing more personal information than is reasonably necessary to participate in that activity.
- COPPA (U.S.): for children under 13 in the United States, we obtain verifiable parental consent before collecting any personal information from a child. At signup the account holder confirms in writing that they are the parent or legal guardian (with an authenticated email address); verifiable parental consent is then completed through a credit/debit-card verification when the parent starts a subscription. Child information is not collected until that card-based verification is in place, in compliance with the Children’s Online Privacy Protection Act.
- Age-appropriate design: we apply data-protection-by-design principles for child users, including data minimisation, no profiling, and clear transparency.
6. Sharing and disclosure
- Access by our staff: within Story Gliders, access to personal information is limited to authorised staff who need it to operate and support the Services. That access requires two-factor authentication, and every access to child user data is recorded in the audit log described in Section 9d and monitored for anomalies.
- Service providers: we use trusted processors to enable core features. A full list of our sub-processors appears in Section 12 below. They process data only under our instructions and appropriate safeguards.
- Parent-invited educators: you may have a tutor, teacher, or speech-language pathologist view your child’s reading progress, phonics levels, and practice activities. While tutor invitations are in early access they are arranged with our team at your request, and no sharing begins until you approve that specific tutor for that specific child in your parent dashboard \u2014 your approval is recorded as your consent. The educator sees your child under a privacy alias unless you separately choose to share their name, can only access data for the specific child you approve, and you can revoke access at any time from your account settings.
- Legal and safety: we may disclose information to comply with law, protect users, or respond to lawful requests.
- Business transfers: if we undergo a merger, acquisition, or asset sale, your information may transfer as part of that transaction, subject to this policy.
- No sales of personal information: we do not sell or “share” personal information for cross-context behavioural advertising as defined by CCPA/CPRA.
7. International transfers
Story Gliders Inc. is a Canadian company, and the Services are offered in Canada, the United States and Australia. Some of the providers described in Section 12 process personal information outside your own country:
- United States: our AI content-generation providers, our authentication and database host (US East region), our application hosting and serverless compute, and our payment processor.
- Speech processing: our speech-processing provider handles audio and reference text in the data-centre region configured for our account. Audio is never stored there or by us (see Section 8).
- European Union: our transactional email provider is based in France.
- Worldwide network: our bot-protection checks run at the network location nearest to you, which may be inside or outside your country. Only a one-time challenge response and your IP address are involved (see Section 12i).
When personal information is processed in another country, it is subject to that country’s laws and may be accessible to its courts, law-enforcement and national-security authorities under those laws. Several of our providers are headquartered in the United States, so United States law may reach data they hold regardless of where it is stored.
Our safeguards do not depend on location. Every provider that handles personal information is bound by a written data processing agreement with confidentiality, security and deletion obligations and, for our AI providers, a prohibition on using our data to train models (see Section 12j). Data is encrypted in transit and at rest, child profile fields are encrypted before they reach our database host (see Section 12e), names are replaced with privacy aliases before any prompt reaches an AI content-generation provider (see Section 9b), and voice audio is discarded as soon as results are returned (see Section 8).
Quebec residents: the personal information described in this policy may be communicated outside Quebec, principally to the United States, for the purposes described in Section 3. Australian residents: the overseas recipients of your information are located in the countries listed above; the safeguards described here are the reasonable steps we take so that they handle it consistently with the Australian Privacy Principles.
8. Data retention
We retain personal information only as long as necessary to provide the Services. Specific retention practices:
- Voice/audio: never stored. Audio is processed in real time and discarded immediately. No recordings exist on our servers or in the app after processing.
- Spoken-answer transcripts: when a child speaks an answer, the text transcript (not the audio) is stored encrypted at rest so we can score comprehension and show progress. We retain it for the life of the child’s profile and delete it when the profile is deleted (or by the 24-month dormancy sweep described below), so progress stays continuous while the profile is in use.
- Pronunciation scores: word-level and phoneme-level accuracy results are kept in two places. (a) On the device in the browser’s local storage, for fast on-device progress views and offline access. (b) On our servers as part of the child’s profile, so progress is preserved across devices and after a browser cache clear. The server-stored paragraph text and story title used as reference for an assessment are encrypted at rest. We retain server-side assessment results for the life of the child’s profile and delete them when the profile is deleted (see below); the local-storage copy is pruned to a rolling window of the most recent attempts.
- Child users and content: stories, characters, places, and reading history are retained while the profile is in use, and are never kept indefinitely. When a parent removes a child user, all associated data is permanently removed. In addition, a profile that has not been used for 24 months is automatically and permanently deleted — we email the parent twice beforehand (about 30 days and 7 days in advance), and opening a story or doing any reading or practice activity in the profile cancels the deletion.
- AI-generated content: stories and images generated by AI services are stored as part of the child’s profile. Story text is stored with opaque entity tokens instead of real names (see Section 9b), so the stored content is not directly identifiable. We do not keep a separate copy of the assembled prompts sent to AI providers; the profile details used to build them (such as interests and character descriptions) remain stored in your account, encrypted, as described in Section 2.
- Parent account information: your name, email, and settings are retained for the life of your account and deleted when you delete it. If you have an active subscription, deletion completes at the end of the current billing period, and you can cancel the deletion until then.
- Parental-consent records: kept to demonstrate we obtained verifiable parental consent, as the law requires. These are pseudonymised (no names or contact details) and retained for up to 5 years, then deleted.
- Security and audit logs: pseudonymised access and anomaly records we keep to detect and investigate abuse. Access logs are retained for up to 5 years and security alerts for up to 2 years, then deleted.
- Usage and metering: counts used to enforce plan limits, rate-limit, and prevent abuse. Rate-limiting keys hold operational data (with IP addresses only as one-way hashes) for the length of the limit window — typically about one hour, and up to about 30 days for monthly speech-usage caps; metering logs are kept for 90 days; spend counters for up to 2 years; then deleted.
- Backups: encrypted database backups kept for disaster recovery expire within about 7 days (our hosting provider’s point-in-time-recovery window), after which deleted data ages out of backups too.
- Cancellation feedback: when you close your account we ask — optionally — why you are leaving. If you answer, we keep the reason you chose and any comment you write, so we can understand why families leave and improve. Answering is never a condition of closing your account, and skipping it changes nothing.
This is the one record described here that we cannot later find, show you, or delete on request, and we want to be plain about why. We store it with no link to you, your account, or your child — deliberately, so that it survives the deletion of your account and cannot be traced back to you. The same missing link is what stops us locating it afterwards. It is kept indefinitely, as aggregate feedback about why people leave.Because of that, before storing a comment we automatically strip out email addresses and phone numbers, and we encrypt what remains. Those checks are pattern-based and cannot catch a name typed into a sentence, which is why we ask you — in the form itself — not to include names or other personal details. Anything you do write there is the one thing on this page that a later deletion request cannot reach. - Waitlist sign-ups: while we are invite-only, we keep your waitlist details so we can notify you when a place opens. Once an entry has served its purpose — you have been sent an invite, declined, or converted into an account — it is automatically and permanently deleted 24 months later. You can also ask us to remove your details at any time and we will delete them.
Parents may request deletion of a child user’s profile and associated data at any time through the parent portal or by contacting us.
Deletion removes your profile content and your child’s personal information. As set out above, we keep a small number of pseudonymised security and consent records (which contain no names or contact details) for a limited, defined period to meet our security and legal record-keeping obligations. Beyond those, the only thing we keep indefinitely is cancellation feedback you choose to write — stored unlinked, stripped of contact details, and asked for with a request not to include personal information. We do not otherwise retain a child’s personal information indefinitely.
9. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, environment isolation, and least-privilege practices. No method of transmission or storage is 100% secure, but we continuously improve our controls. For a comprehensive overview of our security programme, including infrastructure, secure development, incident response, and responsible disclosure, see our Security page.
9a. Encryption of names and the AI privacy alias
To protect the identities of children, characters, and other entities, we apply a layered approach:
- Encryption at rest: child names, family or household names, interests, gender, character and place details, story titles and content, spoken transcripts, and per-word reading-assessment records are stored AES-256-GCM-encrypted (authenticated encryption with a 256-bit key) in the same row that holds the rest of the profile. Each value carries its own random initialisation vector and authentication tag, so an attacker with database access cannot read the values without the encryption key, which is held separately in the application environment.
- Privacy alias for AI: a separate per-child privacy alias (a natural-sounding fictional name, e.g. “Bramble”) is generated once at profile creation and stored in its own column. The alias is the only name string that ever leaves our servers for AI content generation; the real encrypted name is never sent to AI providers.
- Hashed email lookups: for account uniqueness and invitation matching, we compare a one-way keyed hash (HMAC-SHA-256) of the normalised email address rather than the plaintext, so emails are matched without being exposed in query parameters. Names themselves are protected by the AES-256-GCM encryption described above rather than hashing.
- Decryption only on demand: real names are decrypted server-side only when they need to be returned to an authenticated parent or tutor for display in the app. Names appear only as encrypted ciphertext in log output and are never included in error reports. Personalised story titles shown in reading history may contain a first name and are cached in your browser’s local storage for offline progress views; this on-device cache is cleared automatically when you sign out (see Section 11b).
9b. AI name isolation (three-stage tokenisation)
When generating stories, illustrations, quizzes, and other content through our AI content-generation providers, we use a three-stage privacy pipeline so that a child’s name and chosen character names are not shared with any AI provider:
- Aliasing: before any prompt is sent to the AI, all real names are replaced with temporary privacy aliases — natural-sounding fictional names (e.g. “Bramble”, “Pippin”) that allow the AI to generate coherent prose without knowing the child’s identity.
- Tokenisation: after the AI returns the generated text, privacy aliases are replaced with opaque entity tokens (e.g. “{{child:abc123}}”). These tokens carry no personal information and are what we store in the database.
- Resolution: entity tokens are resolved back to the real display names only within your authenticated session — in your browser, or server-side for an authorised parent or tutor request — using data already available to that session. This means the stored story text itself contains no real names.
Exception — speech services: for text-to-speech and pronunciation assessment, the resolved story text (including the child’s first name) is sent to our speech-processing provider. This is functionally necessary so the story can be read aloud with the correct name and so pronunciation scoring works against the actual text the child is reading. The provider processes this data transiently and does not retain it (see Section 12a).
Free-text you enter: the aliasing above covers a child’s name and the character names they choose. Free-text you write yourself — such as place descriptions, story problems, quests, or notes — is sent to the AI as you typed it, and our spoken-comprehension feature transcribes what a child says aloud. We cannot reliably detect other people’s real names entered into free-text or spoken aloud, so please avoid including the real names of children or others in those fields (see our Terms of Use, Acceptable Use).
9c. Right to erasure
When a parent removes a child user or requests account erasure, we permanently delete the encrypted profile rows (including the encrypted real name and the privacy alias) along with any associated entity tokens. Because story text contains only opaque tokens (not real names), deletion of the profile renders any residual tokens unresolvable.
9d. Internal audit logging
Access to child user data is recorded in an internal audit log used for security monitoring and abuse prevention. Actor and resource identifiers are pseudonymised (HMAC-SHA-256), client IP addresses are stored only as SHA-256 hashes (never in plaintext), and any free-text metadata is encrypted at rest using AES-256-GCM. We do not use these logs for profiling or analytics. Audit log records are retained for up to 5 years to support security investigations and regulatory compliance.
9e. Data incidents
If we learn of a security incident affecting personal information, we will investigate promptly, contain it, and notify affected parents without undue delay — and the relevant privacy regulators where the incident creates a real risk of significant harm, as required under Quebec’s Law 25, PIPEDA, Australia’s Notifiable Data Breaches scheme, and applicable US state law. We keep an internal register of incidents, including those that did not meet the notification threshold. The Security page describes how we work to prevent incidents in the first place.
10. Your rights
The Services are offered in Canada, the United States, and Australia. They are not directed to or offered in the European Economic Area or the United Kingdom; where this policy mentions European frameworks such as the GDPR, it does so as comparative context, not because we offer the Services there.
- California (CCPA/CPRA): rights to know/access, correct, delete, and opt out of certain data uses; right to limit use of sensitive personal information where applicable; non-discrimination for exercising rights.
- Canada (PIPEDA and Quebec’s Law 25): rights to access and challenge accuracy, and to withdraw consent subject to legal/contractual restrictions and reasonable notice; for Quebec residents, additional rights to data portability and to be informed of automated processing.
- Australia (APPs): rights to access and correction; complaints may be submitted to us and, if unresolved, to the Office of the Australian Information Commissioner.
To exercise rights, see “Contact us” below. We may need to verify your identity and relationship to any child user before responding. Authorised agent requests (e.g., under CCPA/CPRA) are supported where applicable.
Who has handled your information. An access request response includes the names of the service providers that have processed your or your child’s information and the country each processes it in, alongside the functional descriptions in Section 12.
One limit, stated plainly. Access and deletion requests reach everything we hold about you except the optional cancellation feedback described in Section 8. We store that with no link to you on purpose, so that it cannot be traced back to you after your account is gone — which also means we have no way to identify it as yours in order to return or erase it. If you would rather leave nothing behind, simply skip the question when you close your account.
Response times. Once we have verified your identity and relationship to any child user, we respond to requests within the following timeframes:
- CCPA / CPRA: 45 days, extendable by an additional 45 days where reasonably necessary.
- PIPEDA / Quebec Law 25: 30 days.
- Australian Privacy Principles: within a reasonable period, typically 30 days.
We aim to acknowledge receipt of every request within 5 business days.
11. Cookies and local device storage
11a. Cookies
We use first-party cookies and similar browser storage to operate the Services — for example: keeping you securely signed in, remembering your sign-up and checkout progress, protecting our public forms against bots, verifying sign-ins, gating early access while we are invite-only, speeding up the loading of your family’s data (access control is always enforced against your authenticated session on the server, never by a cookie alone), and remembering a referral code you arrived with so any discount applies. If we introduce cookies for materially new purposes (such as analytics), we will update this policy and put any required consent mechanism in place before doing so.
11b. Local device storage
Some data is stored locally on your device using browser storage (localStorage) to provide a faster experience and keep progress data available offline. This includes reading preferences, pronunciation scores, and practice word history. Some of this data — in particular pronunciation and paragraph-level reading assessments— is also synchronised to our servers so that progress is preserved across devices and survives a browser cache clear. See Section 8 for retention details. You can clear the on-device copy at any time through your browser settings, and you can request deletion of the server-side copy from your account.
12. Third-party services
We use a small number of specialist providers to power core features. We describe each one by the job it does for us rather than by company name. You can ask us for the current named list at any time (Section 14), and we include it in every access request response (Section 10). For each provider: what it does, what data it receives, how long it keeps it, and how long we do.
12a. Speech processing
Purpose: speech-to-text (real-time word tracking while a child reads aloud), pronunciation assessment (accuracy, fluency, completeness, and prosody scoring), and text-to-speech (reading stories aloud to the child).
- Provider: an enterprise cloud speech service operated by a large US-headquartered technology company, processing in the data-centre region configured for our account (see Section 7).
- Data sent: audio from the device microphone (streamed in real time), and reference text for pronunciation comparison and speech synthesis. Reference text is the story content being read or spoken, which may include the child’s first name.
- Data returned: recognised words, accuracy scores, phoneme-level feedback, and synthesised speech audio.
- Storage by the provider: under our agreement with the provider, audio submitted for recognition or assessment is not retained after processing and is not used to train or improve the provider’s models. The provider offers an optional human-review programme for improving its models; we have not enabled it.
- Our retention: we discard audio immediately after receiving results. Only numerical scores and text are kept.
12b. Story and comprehension generation
Purpose: generating personalised stories, narrative content, and reading-comprehension questions, and evaluating a child’s written or spoken answers.
- Provider: a large-language-model API service operated by a US artificial-intelligence company, processing in the United States. If this service is unavailable, the provider described in Section 12c generates the story instead, under the same data rules.
- Data sent: approximate age, interests, character descriptions, place descriptions, reading level, and story context. Real names are never included in prompts sent to the provider. All names are replaced with temporary privacy aliases before any data reaches the provider (see Section 9b). No audio is sent. The character and place details you provide — including any appearance choices and free text you write — are sent to the provider as you enter them, so please avoid including a real person’s name or sensitive personal information in those fields (see Section 9b).
- Data returned: generated story text, comprehension questions, answer evaluations, and related narrative content.
- Storage by the provider: under our agreement, data submitted through the API is not used to train the provider’s models. The provider may retain API inputs and outputs for up to 30 days for trust and safety purposes, after which they are deleted.
- Our retention: generated stories are saved as part of the child’s profile. The prompts used to generate them are not stored by us after the request completes.
12c. Illustrations, character suggestions and content moderation
Purpose: generating illustrations and avatar images, character suggestions, and content-safety moderation of the text you and your child enter; also the fallback for story generation described in Section 12b.
- Provider: a second US artificial-intelligence API service (image generation, text moderation and language models), processing in the United States.
- Data sent: approximate age, interests, character descriptions, place descriptions, reading level, and story context. Real names are never included in prompts sent to the provider. All names are replaced with temporary privacy aliases before any data reaches the provider (see Section 9b). No audio is sent. If you enable avatar customisation for a child (off by default), the generic appearance choices you select — such as hair style and colour, eye colour, skin tone, and outfit — are included in the image prompt so the artwork can resemble your child. You can turn this off at any time, which also deletes the saved appearance settings and any generated avatars.
- Data returned: generated images, character suggestions, moderation results, and related content.
- Storage by the provider: under our agreement, data submitted through the API is not used to train the provider’s models. API inputs and outputs may be retained for up to 30 days for trust and safety monitoring, after which they are deleted.
- Our retention: generated images and content are saved as part of the child’s profile. The prompts used to generate them are not stored by us after the request completes.
12d. Voice transcription and spoken responses
When your child uses voice features (such as reading aloud or spoken comprehension answers), their speech is converted to text. These transcripts are used for pronunciation scoring (by our speech-processing provider) and comprehension evaluation (by our AI content-generation providers). Please be aware:
- Transcripts may contain names: if your child speaks their own name, a friend’s name, or other personal information while answering a question or reading aloud, that information will appear in the transcript. Transcripts sent to our AI providers for comprehension evaluation do not include any child user data (such as the child’s name or age), but the transcript itself may contain whatever the child says.
- Speech assessment reference text: for pronunciation assessment, the story text being read (including the child’s first name if it appears in the story) is sent to our speech-processing provider as reference text. This is necessary for accurate phoneme-level scoring. The provider processes this data transiently and does not retain it after the assessment is complete.
- No audio retention: neither Story Gliders nor our providers store any audio recordings. Only derived text transcripts and numerical scores are retained.
12e. Authentication and database hosting
Purpose: identity and authentication for parent accounts, and managed PostgreSQL hosting for our application database.
- Provider: a managed authentication and PostgreSQL hosting service; our project is hosted in the provider’s US East region.
- Data sent: parent email, hashed password, session tokens, and the encrypted profile, story, and progress rows that make up the application database. Child PII (names, interests, etc.) is encrypted server-side with AES-256-GCM before it ever reaches the provider.
- Data returned: authentication results, session cookies, and database query results.
- Storage by the provider: data is stored in the region above under a written data processing agreement (see Section 12j).
- Our retention: account and profile data are retained while the parent account exists; removal of a child user or deletion of the account removes the corresponding rows.
12f. Payment processing
Purpose: processing subscription payments (the card payment also serves as verifiable parental consent).
- Provider: a PCI DSS Level 1 certified payment processor headquartered in the United States.
- Data sent: parent email and an internal family identifier. Card details are entered by the parent directly into the processor’s hosted checkout and never pass through our servers. No child user data is sent to the processor.
- Data returned: customer and subscription identifiers, payment status, and webhook events confirming charges.
- Storage by the provider: handled under the processor’s data processing agreement (see Section 12j).
- Our retention: we retain the processor’s customer and subscription identifiers as long as the account is active so that billing and cancellations work; we do not store full card numbers.
12g. Transactional email
Purpose: sending transactional emails such as welcome messages, weekly progress summaries, password resets, and account notifications.
- Provider: an email delivery service headquartered in France (European Union).
- Data sent: parent email address, parent name, and template parameters needed to render the message (for example, a child’s first name in a weekly progress email).
- Data returned: delivery status and message identifiers.
- Storage by the provider: handled under the provider’s data processing agreement (see Section 12j).
- Our retention: we do not store the email body once it has been sent; only the sent/delivered status is logged.
12h. Hosting and serverless compute
Purpose: hosting the parent portal, running our serverless API functions, scheduled jobs, and platform logs.
- Provider: a US cloud application-hosting platform; our serverless functions run in the United States.
- Data sent: any data processed by our application as part of normal request handling (e.g., parent session cookies, encrypted profile data on its way to or from the database). We do not write names, emails, transcripts of child speech, or decrypted profile data to application logs: log identifiers are internal account IDs (pseudonymised for external-provider error reports), IP addresses appear only as one-way hashes, and audit records are pseudonymised as described in Section 9d.
- Data returned: hosting infrastructure does not return data to us beyond the standard request/response cycle.
- Storage by the provider: handled under the provider’s data processing agreement (see Section 12j).
- Our retention: platform logs are retained on a short rolling window per the provider’s defaults; we do not write child PII into logs.
12i. Bot protection and other technical services
- Bot protection: a privacy-preserving bot-protection check used on our public sign-in, sign-up, password-reset, tutor and partner sign-in, and waitlist forms to block automated abuse. Data sent: a one-time challenge response and the requester’s IP address (used to score the challenge). No child user data, names, or content are sent. The check is designed not to be used for cross-site tracking or advertising.
- Dictionary lookups: a public dictionary API used to look up child-friendly word definitions in the reader. Data sent (from our servers): the single English word a child taps — no names, profile data, or other personal information.
- Web fonts: when generating a downloadable PDF report or data export, our server fetches a web font from a public web-font service. This request comes from our server and contains no personal data.
12j. Provider agreements and named register
Every provider that handles personal information is bound by a written data processing agreement covering confidentiality, security, deletion on termination and, for our AI providers, a prohibition on using our data to train models. We keep a register of each provider’s name, role, processing country and the agreement in force, review it at least annually, and provide it on request (Section 14). Other than parent-initiated educator sharing described in Section 6 and the providers described in this section, we do not share child data with anyone. Some providers (such as our bot-protection service) receive only limited technical data, such as an IP address, and never receive child names, content, or profile data.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version and revise the “Last updated” date. For material changes, we will provide additional notice (e.g., via the parent portal).
14. Contact us
If you have questions, concerns, or requests about this Privacy Policy or our data practices, please contact our privacy team at contact@storygliders.com. You may also contact the relevant regulator in your region — in Canada, the Office of the Privacy Commissioner of Canada (or the Commission d’accès à l’information du Québec for Quebec residents); in Australia, the Office of the Australian Information Commissioner (OAIC); and in California, the California Privacy Protection Agency.
Story Gliders Inc., 430 Wickstead Avenue, North Bay, Ontario P1A 3H1, Canada. Telephone: +1 647-269-3625.
Privacy Officer: questions or complaints about how we handle personal information may be directed to our Privacy Officer at contact@storygliders.com.