Privacy & data processing
Last updated July 30, 2026
Heirloom Stories turns the details you share into a one-of-a-kind illustrated story, read aloud in a loved one’s voice. Making that story requires handling some deeply personal things, a child’s name, a photo, your voice. This page is our privacy policy and data-processing notice in one. It explains exactly what we collect, why the law lets us process it, what touches it, how long we keep it, who we share it with, and the rights you have. It is written to match what the product actually does, and it forms part of our Terms of Service.
The three promises everything else follows from
- We collect the minimum needed to make your story, and nothing speculatively.
- We never sell your personal data, and never use recordings, photos, children’s details, or story content for advertising or to train AI models. Meta receives only the limited site and purchase events described below.
- The most sensitive things are deleted first. The photo and the raw voice recording are removed automatically as soon as their single job is done, on the schedule set out below.
What we collect, and why
- Story details: the child’s first name, age, interests, optional personal touches, and how you’d like the story told. Used only to write and illustrate the story.
- A photo of the child (optional): only if you share one, used solely so the illustrations resemble them.
- Voice recordings: a minute or two of your reading, used solely to teach the narration your voice; and an optional short clip of how you say the child’s name.
- Email addresses: yours (for receipts and your story link) and the recipient’s (used once, only to deliver the story you send, never for marketing).
- Payment details: handled entirely by Stripe; we never see or store card numbers. We keep the purchase record (what was bought, when, for which story) for receipts, refunds, and our legal bookkeeping obligations.
- Account details (optional): if you choose to sign in, our sign-in provider Clerk stores your account email so your stories can appear on your shelf.
- Agreement records: when you tick the consent box, complete a purchase, or spend a keepsake credit, we record the moment it happened, which versions of the Terms and this page it covered, and the network address and browser the agreement came from. This is both of our proof of what was agreed, and it is used for nothing else.
- Technical basics: like any website, our hosting provider processes IP addresses and request logs to serve pages and defend against abuse.
- Advertising measurement: Meta Pixel records page visits across the site and, after Stripe confirms a payment, a Purchase event containing the amount and currency. Private link addresses are scrubbed before any event is sent. Meta also receives ordinary browser and network details such as your IP address, browser type, and its pixel identifiers, and may set or read cookies. For purchase attribution we may send a one-way hash of the buyer’s email address. We never send Meta payment-card details, plain email addresses, story content, recordings, photos, or children’s details.
Why we're allowed to process it (legal bases)
If you’re in the UK, EU, or another place with a GDPR-style law, this is the legal basis we rely on for each kind of processing:
- Performing our contract with you: story details, email addresses, purchase records, and delivery: we can’t make and send your story without them.
- Your explicit consent: the photo and the voice recording. Voice data can qualify as biometric information in some places, so we don’t touch it until you actively tick the consent box in the create flow, and you can withdraw that consent at any time by asking us to delete the story and everything attached to it. Withdrawing consent doesn’t undo processing that already happened, but it stops everything from that moment on.
- Legitimate interests: the technical basics (security logs and abuse prevention), the child-safety review we run on every story, and measuring whether our advertising leads to visits and completed purchases. We scrub private link addresses from Meta events and exclude story activity and content.
- Legal obligation: keeping purchase and tax records for as long as bookkeeping law requires.
Meta Pixel and advertising measurement
Meta Pixel runs across the site and sends a PageView event when a page opens. Before any event is sent, we scrub the page address: private story links, recipient links, and admin pages report only their bare section name (for example, /story), and query strings, including Stripe’s Checkout Session ID, are never included. We send the Purchase event only after our server has retrieved the Checkout Session from Stripe and verified that it is paid; its value is the amount Stripe actually collected, in the payment currency. To keep purchase counts accurate when browsers block tracking, our server may also report the same purchase to Meta directly, carrying the amount, the currency, and a one-way hash of the buyer’s email address for attribution , never the address itself. Both reports share an identifier so Meta counts them once. Meta’s automatic button and page metadata collection is disabled.
Meta never receives story content, recordings, photos, children’s details, or the private tokens that open a story , only that a page in a section was viewed. Meta processes the events and identifiers under its own data policy to measure and attribute advertising. Browser tracking protection or an ad blocker may prevent the pixel from running without affecting your purchase or story.
How each piece is processed
- The photois looked at once to write a short illustrator’s description of the child and to paint page one, then deleted from storage automatically as soon as the pictures are painted. It is never used to train anything and never shared beyond the illustration step.
- Your voice recordingis sent to our narration partner to create a private, story-specific voice. Unless you tick “keep my recording,” the raw recording is deleted as soon as the voice is taught. The keep option is capped at 30 days and never inherits a permanent story’s lifetime. The taught voice itself is deleted after the story is sent, and swept automatically within 7 days regardless. Your voice is never available to any other customer and is never added to any shared voice library.
- Story details are sent to our writing partner to compose the story and to review it for child-safety, and to our illustration partner as scene descriptions.
- Story links you send are private, signed, and expire after 90 days unless the keepsake includes a permanent link. Anyone with the link can view the story, so share it with care. The creator can revoke every previously sent link.
How long we keep things
The retention schedule, in one place:
| Data | Kept for |
|---|---|
| Photo of the child | Deleted automatically the moment the illustrations are painted |
| Photos of other featured characters | Deleted automatically the moment the illustrations are painted |
| Raw voice recording | Deleted when the voice is taught, unless kept for up to 30 days |
| The taught (cloned) voice | Deleted after the story is sent; swept automatically within 7 days regardless |
| Story pages, pictures, and narration | Kept while the story link is live, 90 days from the story's creation or last delivery, or for the life of a permanent keepsake, then removed automatically |
| Story details (name, age, interests) | Kept with the story; deleted when the story is deleted |
| Recipient's email address | Used to send the story, retained only in the delivery record |
| Purchase records | Kept as long as bookkeeping and tax law requires; contains no story content |
| Agreement records | Kept with the story or purchase they belong to, as proof of what was agreed |
| Account email (optional sign-in) | Kept until you delete your account |
| Meta Pixel events and identifiers | Controlled by Meta under its data policy and the retention settings for our Meta business account |
You can shorten any of this at any time by asking us to delete a story, see “Your rights” below.
Subprocessors
These service providers and measurement partners process the specific pieces of data shown below for the listed purpose:
| Provider | Purpose | What it processes |
|---|---|---|
| Vercel | Hosting and file storage | The app itself; stored story pages, pictures, and narration |
| Anthropic (Claude) | Writing the story and child-safety review | Story details; the photo (once, to describe the child for the illustrator) |
| ElevenLabs | Teaching and reading in your voice | Your voice recording; the story text it reads aloud |
| Replicate | Painting and animating the pictures | Scene descriptions; the photo (once, for page one's likeness) |
| Stripe | Payments | Payment details and billing email (we never see card numbers) |
| Resend | Email delivery | Sender and recipient email addresses; the story link |
| Clerk | Optional sign-in | Your account email, if you create an account |
| Inngest | Reliably running story generation | Internal story identifiers only, no personal content |
| Meta | Advertising measurement and purchase attribution | Page visits with private link addresses scrubbed; confirmed purchase amount and currency; hashed buyer email for purchase attribution; browser, network, cookie, and pixel identifiers, no story or child data |
We don’t sell your data, and no story content, recording, photo, or child detail is used to train AI models or sent to Meta. If we ever add or change a provider or measurement partner, we’ll update this table before it touches your data.
Where your data lives
Our services and the providers above operate primarily in the United States, so your data is processed there. If you use Heirloom Stories from the UK, EU, or elsewhere, that means an international transfer. We rely on recognized safeguards for those transfers , our providers operate under standard contractual clauses and, where applicable, the EU–US Data Privacy Framework, so your data keeps equivalent protection wherever it’s processed.
How we protect it
- Everything is encrypted in transit, and stored files are encrypted at rest by our hosting provider.
- Story links are signed, so a link can’t be guessed or forged, only shared.
- The most sensitive items, photo and raw recording, are deleted automatically by the pipeline itself, not by a manual process that could be forgotten.
- Access to production data is limited to what operating the service requires.
- No system is invulnerable. If a breach ever affects your personal data, we will notify you and the relevant authorities as the law requires, promptly and plainly.
Children's privacy
Stories are made for children by the adults who love them. All information about a child is provided by you, the adult creating the story, and is used only to make that story. We never collect information from children directly, our creation tools are for adults only, and we deliberately ask for as little as possible, a first name, an age, and the things that make them light up. We do not knowingly collect personal information from anyone under 13 (or the equivalent age where you live); if you believe a child has submitted information to us directly, write to us and we will delete it.
Your rights
Wherever you live, we extend the same rights to everyone, and you never need a lawyer to use them, an email is enough:
- Access & portability: ask what we hold about you and receive a copy in a usable format.
- Correction: ask us to fix anything inaccurate.
- Deletion: ask us to delete a story and everything attached to it (recordings, photos, details, the taught voice) at any time. A purchased keepsake also carries a permanent-delete control on its private creator page for immediate erasure; a story that was never purchased erases itself, recordings and photos included, within 7 days. The only thing we keep afterward is the purchase record bookkeeping law requires.
- Withdraw consent: for the photo or voice processing, at any time, without affecting anything else.
- Object or restrict: object to processing based on legitimate interests, and we’ll stop unless the law requires otherwise.
- No sale or story profiling: we do not sell personal information, use story content or sensitive family data to target advertising, or make automated decisions about you that have legal effects. Meta Pixel’s limited site and purchase measurement may be treated as advertising “sharing” under some privacy laws; you may object or ask us to restrict it by contacting us below.
- Complain: if you’re unhappy with our answer, you can complain to your local data-protection authority. We’d appreciate the chance to fix it first.
We will never treat you differently for exercising any of these rights. To protect your data, we may ask you to verify that a request really comes from you (for example, from the email address on the story).
Your choices while creating
- Skip the photo entirely, a few written words work too.
- Read the story yourself instead of teaching your voice.
- Choose whether your raw recording is kept or deleted the moment the voice is taught.
- Delete a purchased keepsake directly from its private creator page, or ask us at any time. An unfinished story tidies itself away, recordings and photos included, within 7 days.
Changes to this page
If our data handling changes, this page changes first, the date at the top always reflects the current practice. For changes that matter (a new subprocessor, a new use of data, a longer retention period), we’ll tell you by email or a notice on the site before the change takes effect. We will never retroactively apply a broader policy to data you’ve already given us.
Questions
Write to us at support@heirloomstories.ai. A person reads it. That address reaches the people responsible for data protection at Heirloom Stories.