Business details required before publication
This document is structurally complete but intentionally remains noindex until the legal entity name, registered address, registration number, NIP, contact email, and effective date are configured.
Effective 2026-08-10
Photo & AI Processing Notice
Reference photos are optional. This direct notice tells the adult account holder exactly what happens before the first photo is accepted.
, trading as Stories
, Poland
Registration:
Tax ID (NIP):
Contact:
1. Notice and controller
Notice version: photo-2026-08-10. The controller is , trading as Stories, at , Poland. Contact: .
This notice supplements our Privacy Policy and Terms of Service.
2. Optional input and data minimization
You can create a complete book without a photograph. If you choose to add references, use 1–3 clear images of the same person and avoid other people, school names, addresses, documents, uniforms with identifying information, or private background details.
The app combines up to three references into one reduced contact sheet for an image request, which controls cost and limits the number of separate image inputs sent to the generation provider.
3. What we do with the photo
We use visible, non-sensitive appearance cues to create a stylized fictional character and keep that character consistent across the book. Earlier generated pages may also be reused as separate continuity references for clothing, palette, recurring environments, and illustration style.
We do not use the photo to identify the person, search for matches, verify identity, build a biometric template, recognize a face, infer sensitive traits, serve advertising, make eligibility decisions, or publish the image.
4. Who receives it
- Stories processes and validates the file in the browser and application service.
- OpenAI receives the prepared reference input with the requested scene to generate the illustration.
- Cloudflare R2 may store a private project copy when server-side project storage is used.
- Supabase stores the versioned adult confirmation and project records, not full card data.
OpenAI states that API content is not used to train its models unless the API customer opts in. Default abuse-monitoring logs may be kept for up to 30 days, and image inputs are scanned for child sexual abuse material. See its current API data controls.
5. Retention and deletion
References remain available only as needed for the active project and requested continuity workflow, until you remove them, withdraw the confirmation, or delete the project/account, subject to limited provider security, safety, legal, and backup cycles. Generated illustrations and PDFs can remain in the project because they are the product you requested.
We minimize operational metrics so they do not contain the photo, story text, prompt, or child name.
6. Required adult confirmation
Before the app accepts a photo, you must affirm all of the following:
- I am at least 18.
- I am the parent or legal guardian, or I otherwise have permission from every identifiable person shown.
- I request that Stories, OpenAI, and necessary storage providers process the optional photo solely for the described book-generation and continuity purpose.
- I understand that I can create the book without a photo and can withdraw this confirmation for future use.
The service records the notice version and acceptance time. It does not ask the child to click or consent.
7. Withdrawal and parent controls
Uncheck the photo authorization in the creator before adding more photos, remove individual photos, delete the project/account, or email . Withdrawal stops future photo-based processing; it does not undo completed generations or processing already lawful before withdrawal.
A parent or guardian may request access to or deletion of child-related content they supplied. We may verify adult identity and authority to protect the child and account.
8. Children must not submit photos
The creator is for adults. A child under 13 must not open an account, use the microphone, upload a photo, or submit personal information directly. If that happens, contact us so we can restrict and delete the information as required. FTC guidance is available on its Children’s Privacy page.
