Privacy Policy
Current data practices, future-feature limits and unresolved privacy gaps, in plain words.
Website draft updated · Version 2026-10-06
1. Who this draft covers
This draft covers Brave Tales’ web and mobile preview. Accounts are intended for adults aged 18 or older acting as parents or legal guardians; children do not have their own account flow. The story audience and child profiles still require a children’s-data assessment. An adult assertion is not verified parental consent.
Brave Tales is a product name, not a confirmed legal controller identity. The operator’s legal name, address, business country and privacy contact remain unconfirmed. The current scope is digital-only. Worldwide wording does not mean every country’s requirements are satisfied.
2. What is collected now and why
Clerk handles adult sign-in information, such as email, account identifiers, authentication factors and session information; using Google sign-in also involves Google. Brave Tales uses the verified account identifier to associate a family account, its creation time and the timestamp of the adult/guardian assertion, to control access to your family bookshelf.
Child profiles store the name you enter, age (not a birth date), pronouns, and optional interests and companion details. These support organising your bookshelf and preparing text previews. Do not enter medical information, school or home addresses, or other sensitive details in optional text fields.
Saved mock text previews store the selected story, title, profile link, a separate copy of child details, personalised page text and artwork descriptions, creation information and a guardian-consent timestamp. Child details may be embedded in the title and story text. These are persisted snapshots, not finished books or live AI output. Editing a profile does not update an existing preview; editing a preview replaces its current stored snapshot and records a new consent timestamp, but is not a guarantee that older copies disappear from backups or logs.
The API records operational request information such as request identifier, method, URL path, response status, timing and errors to operate and troubleshoot the service. Its request logger omits query strings and does not intentionally log profile request bodies; authentication headers and cookies are redacted in configured logs. Hosting and sign-in providers may separately process network, device, IP and diagnostic information. Their full logging and retention practices have not been verified.
3. Current providers and disclosures
Current infrastructure includes Clerk for authentication, Google when chosen for sign-in, and Replit hosting and PostgreSQL database infrastructure for the application and family records. These services process data to provide the account and preview experience. Access is scoped to the authenticated account in the application; infrastructure providers may process records in operating their services.
The reviewed application does not implement advertising trackers, sale of personal data, targeted advertising or customer analytics. This is not a verified statement about every provider’s independent processing or a legal determination of sale/sharing under every law. Processor roles, contracts, subprocessors, access controls and independent uses must be checked before the final notice. Necessary legal disclosures or business transfers, if relevant, require an assessed legal basis and updated information; this draft does not authorise unrestricted sharing.
4. Cookies, device storage and security
Web sign-in uses Clerk session cookies and associated authentication storage. The web signup screen also keeps an adult-assertion flag in browser sessionStorage for that signup flow; it is not verified age or a substitute for the server’s adult confirmation. Native mobile sign-in uses bearer tokens and Clerk’s token cache backed by Expo SecureStore. Family data is also held temporarily in application memory/query caches while you use the screens; caches are cleared on account changes. These mechanisms support authentication and loading your bookshelf, rather than an implemented advertising programme.
A complete provider cookie/storage inventory, durations and strictly-necessary classification are not verified. Browser settings can restrict cookies but may prevent sign-in. Regional cookie consent requirements must be assessed before adding non-essential storage; this preview does not provide a cookie-preference manager.
The API checks authenticated identity and parent ownership before allowing family access. These measures do not guarantee absolute security. Provider encryption, backups, administrative access, incident response and security assurances still require verification. Do not treat this draft as a promise of anonymity, local-only storage or risk-free processing.
5. Children’s data and legal grounds
Parents or guardians supply child information. The adult-confirmation and preview-consent checkboxes record assertions, not verified age, identity or parental authority. Whether verifiable parental consent or other safeguards are required depends on the law and actual service use; the current checkboxes do not establish compliance with COPPA or other children’s-data laws.
Where a legal basis is required, the operator must assess each purpose: providing an adult-requested account may involve contract necessity; essential security may involve legitimate interests subject to a balancing assessment; specific legal duties may require processing; optional processing may require valid, specific consent. None of these grounds is confirmed here for all child data. A contract with an adult does not automatically justify all processing of a child’s information.
Acknowledging this notice or accepting terms is not blanket consent. Where consent is required it must be valid and withdrawable, with appropriate consequences explained. Children’s best interests, minimisation, age-appropriate explanations and any required impact assessment must be addressed before broader availability.
6. Retention and deletion status
Family profiles and saved previews remain stored so they can be reopened. There is no implemented automatic expiry, confirmed retention schedule or self-service account/profile/preview deletion. Signing out does not delete stored data. A new preview does not delete earlier saved previews.
The operator must define purpose-based retention and deletion for accounts, profiles, snapshots, confirmation records, logs and backups, including any lawful recordkeeping needs. Provider retention, backup expiry and deletion propagation are unconfirmed. No fixed deletion period, deletion-on-request capability or removal of all copies is promised by this draft.
7. International processing
Hosting and authentication can involve processing outside your country. Exact data locations, recipient countries, subprocessors and international transfer arrangements have not been confirmed. We do not promise a particular residency location, adequacy decision, contractual safeguards or other transfer mechanism.
Where applicable, the operator must establish a lawful transfer route, assess destination risks and provide the required information and access to safeguards before relying on international processing. Accepting terms does not waive these protections.
8. Your rights and the preview’s limits
Depending on applicable law, adults and children may have rights to access or obtain a copy, correct, delete, restrict or object to processing, portability, withdraw consent, and complain to a regulator. Rights can have lawful exceptions; withdrawing consent does not undo earlier lawful processing. Some US laws provide opt-outs for sale/sharing, targeted advertising or significant profiling, authorised-agent requests, non-discrimination and appeals of denied requests.
You can view and edit child profiles and edit saved previews in the app. Those controls are not a complete legal rights process. There is no working privacy-request channel, self-service deletion, appeal or authorised-agent workflow yet. No request can be submitted through the contact placeholder. The operator must establish accessible channels, proportionate identity/authority verification, response deadlines and escalation before final publication. Do not send identity documents or child details to an unconfirmed address.
EEA/UK users may have GDPR rights and complain to their local data protection authority or the UK ICO; Swiss users can contact the FDPIC. Canadian users may seek access/correction and complain to the OPC or the applicable provincial commissioner, including Quebec’s CAI. US users may contact their state attorney general or privacy regulator; COPPA concerns can be raised with the FTC. Brazil’s ANPD, Australia’s OAIC, New Zealand’s Privacy Commissioner, Japan’s PPC, Korea’s PIPC, Singapore’s PDPC and South Africa’s Information Regulator provide local complaint information. India’s phased framework and China’s supervisory routes need local review. Eligibility and procedures differ; this list is not exhaustive.
Mandatory local rights are not waived by these drafts, account terms, guardian checkboxes or any future refund terms. Worldwide availability requires country-specific assessment; this English draft is not a substitute for required local-language notices.
9. Future features — not collected today
The current scope is digital-only. Photo uploads, live AI personalisation, finished digital books, downloads, payments and subscriptions are not enabled. The current preview does not collect photos, payment details or delivery addresses. Before any new digital feature is enabled, disclosures must identify the selected providers, purposes, legal grounds, consent controls, data use, retention and transfer arrangements. No provider no-training commitment or photo-deletion deadline is verified or promised here.
Any future digital payment service, its data fields, independent uses, countries, contracts and accounting retention must be confirmed before collection. This draft does not activate purchases or resolve existing privacy gaps.
10. Version, changes and contact
Draft version 2026-10-05 describes the processing reviewed on 5 October 2026. Material changes need an updated notice and, where required, advance notice or fresh consent before new uses. It has not been reviewed by qualified legal counsel.
No monitored privacy or support contact is confirmed. This page is not a request form and cannot submit access, deletion, consent-withdrawal or complaint requests. This is an unresolved gap for existing accounts and child data, not only for future purchases. The operator must publish its legal identity, location and a staffed request channel before treating these drafts as a final policy.
11. Website-specific delivery and storage
This website supplement was updated on 6 October 2026 (version 2026-10-06); the shared web/mobile privacy disclosures above retain their 5 October 2026 review version. Clerk is loaded by the website’s shared provider, including on signed-out public and legal pages, not only after you choose to sign in.
The website stylesheet requests Fraunces and Nunito through Google Fonts. Your browser makes external font requests to Google’s stylesheet and font services; these can disclose network information such as your IP address and request metadata. Font files and site assets may be cached by the browser. Their actual cache lifetimes and Google’s independent processing have not been verified. Google Fonts delivery is separate from optional Google account sign-in.
The Cookie Policy explains the website’s authentication storage, signup session flag, temporary application caches, browser controls and inventory limits. It does not establish a lawful basis, classify all provider storage as strictly necessary or resolve the publication blockers described above.