Privacy Policy

Last Updated: April 9, 2026

1. Introduction & Company Information

Welcome to KidUpStory (kidupstory.com), a children's AI-powered story generation platform operated by Devoffice LLC, a company organized under the laws of the State of Florida, United States of America.

This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website and use our services. Because our platform is designed for families and involves content creation for children, we take the privacy and protection of children's data extremely seriously.

By accessing or using KidUpStory, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the site or use our services.

This Privacy Policy applies to all visitors, users, and others who access or use our services, including parents, guardians, and any authorized adult users who create accounts on behalf of children.

2. Information We Collect

2.1 Information Provided by Parents or Guardians

When a parent or guardian creates an account or uses our services, we may collect:

  • Full name and email address
  • Account credentials (password, stored in encrypted form)
  • Payment and billing information (processed through secure third-party payment processors)
  • Communication preferences

2.2 Children's Information

To create personalized stories, we may collect the following information about children, as provided by a parent or guardian:

  • Child's first name (used to personalize stories)
  • Child's age or age range (used to tailor age-appropriate content)
  • Child's photo (if uploaded by a parent/guardian, used to create personalized story illustrations)
  • Interests and preferences (e.g., favorite animals, hobbies, themes for story personalization)
  • Gender (optional, used for story character representation)

Important: We do not knowingly collect personal information directly from children. All children's data must be provided by a verified parent or guardian.

2.3 Automatically Collected Information

When you access our platform, we may automatically collect:

  • Device information (device type, operating system, browser type)
  • IP address and approximate geographic location
  • Usage data (pages visited, features used, time spent on pages)
  • Referral source (how you found our website)
  • Log data (access times, error logs, diagnostic data)

2.4 User-Generated Content

Stories, illustrations, and other content generated through our platform are stored in association with your account. This includes prompts, story preferences, and the resulting AI-generated stories and images.

3. COPPA Compliance

KidUpStory is committed to full compliance with the Children's Online Privacy Protection Act (COPPA), a United States federal law designed to protect the privacy of children under the age of 13.

3.1 Parental Consent

  • We require verifiable parental consent before collecting, using, or disclosing personal information from or about children under 13 years of age.
  • Only parents or legal guardians may create accounts and provide children's information on our platform.
  • We employ reasonable measures to verify that the person providing consent is the child's parent or legal guardian.

3.2 Limited Collection

  • We collect only the minimum amount of children's personal information necessary to provide our story generation services.
  • We do not condition a child's participation in any activity on the disclosure of more personal information than is reasonably necessary.

3.3 Parental Rights Under COPPA

Parents and guardians have the following rights regarding their child's personal information:

  • Review: You may request to review the personal information we have collected from or about your child.
  • Deletion: You may request that we delete any personal information we have collected from or about your child.
  • Refuse further collection: You may refuse to permit further collection or use of your child's personal information.
  • Consent withdrawal: You may withdraw your consent at any time by contacting us at [email protected].

3.4 No Direct Collection from Children

Our platform does not allow children under 13 to create accounts, submit personal information, or interact with the service directly without a parent or guardian's involvement. If we discover that we have inadvertently collected personal information from a child under 13 without verified parental consent, we will promptly delete such information from our records.

3.5 No Behavioral Advertising to Children

We do not use children's personal information for behavioral or targeted advertising purposes. We do not share children's personal information with third parties for marketing purposes.

3.6 AI Service Providers & Third-Party Data Sharing

Under COPPA, we are required to transparently disclose which third-party service providers receive children's data (under 13). Below is the full list of providers and the data types shared with each:

  • Replicate (Google Nano Banana): AI-powered illustration generation — child's photo (face reference), name, age
  • ElevenLabs / MiniMax: Voice clone creation (optional — if enabled by parent) — voice sample recording, name
  • OpenAI (GPT): Story text generation — child's name, age, story theme (no photo sent)
  • Stripe: Payment processing — parent's payment info only (no child data shared)
  • Lulu (Print-on-Demand): Printed book production & shipping — parent's shipping address only (no child PII shared)

Parents can use the following actions to manage their child's data across these providers:

  • Review: Account → Family Members tab shows all stored data (photo, name, age, interests) for your child.
  • Edit: Use the Family Member edit page to update photo, name, age, and interests.
  • Delete: Deleting a Family Member permanently removes the child's data from our system and from all relevant AI providers (including cloned voices).
  • Withdraw consent: Deleting your child's family member record = withdrawing COPPA consent. For broader withdrawal, contact [email protected].
  • Full data export: Settings → Account → Download Data exports your entire family data in GDPR/COPPA-compliant JSON.

Sharing with the providers above is essential to KidUpStory's core functionality (personalized story generation). Withdrawing consent ends service usage but your parental rights and data deletion remain available at any time.

4. How We Use Information

We use the information we collect for the following purposes:

Service Delivery

  • Generate personalized children's stories
  • Create AI-generated illustrations featuring your child
  • Tailor content to age-appropriate levels
  • Process and fulfill orders

Account Management

  • Create and manage user accounts
  • Process payments and subscriptions
  • Send account-related communications
  • Provide customer support

Platform Improvement

  • Analyze usage patterns to improve services
  • Debug and fix technical issues
  • Develop new features and functionality
  • Conduct research and analytics

Safety & Legal

  • Ensure content safety and appropriateness
  • Prevent fraud and abuse
  • Comply with legal obligations
  • Enforce our Terms of Service

5. AI-Generated Content & Data Processing

KidUpStory uses artificial intelligence technologies to generate personalized stories and illustrations. It is important for you to understand how your data is processed in this context:

5.1 How AI Processes Your Data

  • Children's names, ages, interests, and preferences are used as inputs to our AI models to generate personalized story content.
  • Uploaded photos may be processed by AI image generation models to create illustrated characters that resemble your child within the stories.
  • The AI processing occurs on secure servers, and inputs are not used to train third-party AI models without your explicit consent.

5.2 AI Content Safety

  • All AI-generated content goes through safety filters to ensure age-appropriateness.
  • We implement content moderation measures to prevent the generation of harmful, violent, or inappropriate content.
  • AI-generated stories are reviewed through automated safety systems before delivery.

5.3 Photo Processing

  • Photos uploaded for story illustration purposes are processed solely for generating story artwork.
  • We do not use uploaded photos for facial recognition, biometric profiling, or any purpose beyond story creation.
  • Photos are stored securely and can be deleted at any time upon parental request.
  • We do not sell, license, or distribute uploaded photos to third parties.

5.4 AI Model Training

We do not use your child's personal information, photos, or generated stories to train generalized AI models. Any data used for improving our service is aggregated and anonymized to remove personally identifiable information.

5.5 Voice Samples and Voice Cloning

  • Voice cloning is an entirely optional feature and is used solely to generate a stylized voice model from voice samples you voluntarily upload.
  • We process your uploaded voice sample only to create this voice clone and to narrate your stories; we do not use it for biometric profiling, speaker identification, or identity verification.
  • Your voice data is stored encrypted on secure servers, is not used to train generalized AI models, and is never sold or shared with third parties for marketing purposes.
  • You may delete your voice clones and uploaded samples at any time from your account settings; they are permanently removed within 30 days of your request.
  • You are responsible for uploading only your own voice or the voice of a person from whom you have obtained express written consent; all legal responsibility arising from unauthorized cloning of third parties rests solely with the user.
  • Generated narrations are algorithmic interpretations; we do not guarantee that any output will match a natural human voice or the pronunciation, intonation, or emotional delivery of your uploaded recording.

6. Data Storage & Security

We take the protection of your data seriously and implement industry-standard security measures:

6.1 Security Measures

  • Encryption: All data is encrypted in transit using TLS/SSL protocols and at rest using AES-256 encryption.
  • Access controls: Strict access controls limit who can access personal data within our organization.
  • Secure infrastructure: We use reputable cloud service providers with SOC 2 and ISO 27001 certifications.
  • Regular audits: We conduct regular security assessments and vulnerability testing.
  • Password protection: User passwords are hashed using industry-standard cryptographic algorithms and are never stored in plain text.

6.2 Data Location

Your data is primarily stored on servers located in the United States. If data is transferred or processed in other jurisdictions, we ensure appropriate safeguards are in place as described in the International Data Transfers section below.

6.3 Breach Notification

In the event of a data breach that affects your personal information, we will notify affected users and relevant authorities as required by applicable law, including providing notification within the timeframes mandated by state and federal regulations.

7. Third-Party Services

We may use the following categories of third-party services to operate our platform:

  • Payment processors: To securely process payment transactions. We do not store your full credit card information on our servers.
  • Cloud hosting providers: To host our website and store data securely.
  • AI service providers: To power our story and illustration generation features.
  • Analytics services: To understand how our platform is used and improve user experience.
  • Email service providers: To send transactional and account-related communications.
  • Content delivery networks (CDNs): To deliver content quickly and reliably.

We carefully vet all third-party service providers to ensure they meet our privacy and security standards. Third-party providers are contractually bound to protect your data and use it only for the purposes we specify. We do not sell personal information to third parties.

Children's personal information is shared with third parties only to the extent necessary to provide our services and in compliance with COPPA requirements.

8. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our platform:

Cookie Type Purpose Duration
Essential Required for basic site functionality, authentication, and security Session / 1 year
Functional Remember your preferences, language settings, and customizations Up to 1 year
Analytics Help us understand how visitors use our site to improve the experience Up to 2 years

You can control cookie preferences through your browser settings. Most browsers allow you to block or delete cookies. However, disabling essential cookies may impair the functionality of our platform.

We do not use tracking cookies for children's profiles. Analytics cookies are used only in aggregate and are not linked to individual children's data.

We honor Do Not Track (DNT) browser signals. When we detect a DNT signal, we limit data collection to what is strictly necessary for service delivery.

9. Data Retention & Deletion

9.1 Retention Periods

  • Account data: Retained for as long as your account is active and for a reasonable period thereafter for legal and business purposes.
  • Children's data: Retained only for as long as necessary to provide the services requested and deleted promptly upon parental request or account deletion.
  • Generated stories and illustrations: Stored in your account for your access. Deleted upon account deletion or upon request.
  • Uploaded photos: Retained only as long as needed for story generation and can be deleted at any time by the parent or guardian.
  • Payment records: Retained as required by applicable tax and financial regulations.
  • Server logs: Automatically purged after 90 days.

9.2 Requesting Data Deletion

You may request the deletion of your personal data or your child's personal data at any time by:

  • Using the account deletion feature in your account settings
  • Emailing us at [email protected] with a deletion request

We will process deletion requests within 30 days and confirm completion to you. Some data may be retained in anonymized form for analytics purposes or as required by law.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights regarding your personal information:

Your Rights Under CCPA/CPRA

  • Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You have the right to request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: You have the right to opt out of the sale or sharing of your personal information. Note: We do not sell personal information.
  • Right to Limit Use of Sensitive Personal Information: You may request that we limit the use and disclosure of your sensitive personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To exercise any of these rights, please contact us at [email protected]. We will verify your identity before processing your request and respond within 45 days as required by law.

Categories of personal information collected: Identifiers (name, email), commercial information (purchase history), internet or electronic network activity (usage data), and visual information (uploaded photos).

Sale of personal information: We do not sell and have not sold personal information in the preceding 12 months.

11. International Data Transfers

KidUpStory is operated from the United States. If you are accessing our services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States or other countries where our service providers maintain facilities.

By using our services, you consent to the transfer of your information to the United States and other jurisdictions as described in this Privacy Policy. We ensure that appropriate data protection safeguards are in place when transferring data internationally, including:

  • Standard contractual clauses approved by relevant data protection authorities
  • Data processing agreements with all service providers
  • Compliance with applicable international data transfer frameworks

If you are located in the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data protection laws, you may have additional rights under the General Data Protection Regulation (GDPR) or similar legislation. Please contact us at [email protected] to exercise these rights.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes:

  • We will update the "Last Updated" date at the top of this page.
  • For material changes, we will notify you via email to the address associated with your account or through a prominent notice on our website.
  • For changes affecting children's data practices, we will obtain new verifiable parental consent where required by COPPA.
  • Continued use of our services after the effective date of changes constitutes acceptance of the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy, or if you wish to exercise any of your privacy rights, please contact us:

Devoffice LLC

Florida, United States of America

We aim to respond to all privacy-related inquiries within 30 days. For urgent matters relating to children's privacy, we prioritize responses and aim to address concerns within 48 hours.

This Privacy Policy is effective as of April 9, 2026.

© 2026 Devoffice LLC. All rights reserved.