YOUR FAMILY. YOUR INFORMATION.
Privacy Policy
Effective 10 September 2026. StoryWeaver is a parent-managed family listening service operated by Persica.AI Ltd. This policy covers the iOS app, parent portal, Alexa skill where separately enabled, and support channels.
Who controls your information
Persica.AI Ltd is responsible for StoryWeaver's handling of personal information. For privacy, access, correction, deletion, objection, or account questions, contact StoryWeaver support at support [at] story-book.app.
Information we collect and how
We collect parent account and contact information when an account is created; child profile basics such as name, age in whole years, avatar, and preferences when a parent creates a profile; story ideas, drawings, photos, or other uploads when a parent asks us to create a story; generated story content and media; account and subscription identifiers; purchase and entitlement status; listening activity such as favourites, reactions, downloads, quota use, history, and progress; records of your consent and the policy you accepted; operational diagnostics from use of the service; and information a parent chooses to include in a support request. Sign in with Apple supplies an app-specific account identifier and may supply a parent's name and email, including a private relay email address. We keep a secure record of that connection to manage sign-in and disconnect it when you delete your account. We do not receive payment-card details from Apple.
How we use it
We use this information to authenticate parents, provide age-appropriate family story playback, personalise discovery, generate and moderate custom stories, sync profiles and progress, validate and restore purchases, apply your plan limits and consent choices, prevent fraud and abuse, secure and improve reliability, troubleshoot issues, and respond to support requests. We do not sell personal information, show third-party advertising, or use this information to track people across other companies' apps or websites.
Analytics and diagnostics
We use first-party analytics to understand listening, improve recommendations and the catalogue, and provide support. This includes story and narrator choices, progress, listening duration, and completion. Authorised staff can view listening summaries and information about private stories alongside parent account details, names and email addresses, and child profile names. We also measure overall content popularity.
We record the first authenticated iOS activation for a family and use family-level counts of account creation, listening and subscription status to understand service adoption. These reports do not contain children’s names or profiles. We use Apple’s separate aggregate App Store and Apple Ads reports to measure views, downloads and campaign performance. We do not collect advertising identifiers or add third-party advertising analytics to children’s devices.
The iOS app does not use third-party product analytics or advertising tools, collect an advertising identifier, or track activity across other companies' apps and websites. We use error, performance, and security information to diagnose faults and protect the service. Network delivery and protection services process connection information, including IP addresses, as explained below.
Device security records
To investigate fraud and protect family access, we record parent app and browser installation IDs, generic device or browser names, child connection IDs and parent-chosen labels, first recorded and latest activity times, and first and latest observed IP addresses. These records are associated with the parent account and, for child connections, the selected child profile. We do not use hardware fingerprints or advertising identifiers, or collect a complete history of IP addresses.
Authorised platform administrators with elevated access can search these records, flag them for investigation, and revoke child connections. Sensitive access and management actions are audited. Parent installation records become eligible for removal after 90 days without reported activity; child connection records become eligible one day after expiry. Cleanup runs in batches during device registration, so removal can take longer when the service is inactive. Account deletion removes associated device records. Audit records may be retained for fraud prevention and investigation, with restricted staff access.
Parent or guardian consent
At registration, a parent or legal guardian must take an explicit affirmative action to accept the processing described in this policy, including the processing needed for custom-story creation. If you decline, you cannot use an account. We keep a record of when you consented and the policy you accepted. Existing accounts must give consent again when the policy changes. Without current consent, account and family-content access are unavailable, including listening through CarPlay and offline downloads.
Withdrawal of consent is handled through account deletion. Deleting the account removes the account data described below; limited records needed to complete deletion and verify eligible account recovery are kept only for the stated period.
Children and families
A parent-managed account controls child profiles and purchases. We use a child's age in whole years to provide age-appropriate content and privacy-protective defaults; we do not ask for a full date of birth or require a child's email address. We do not allow children to create independent accounts, sell children's personal information, or use children's data for advertising. Parents can review profiles and request deletion from Parent Zone or by contacting support.
When a parent connects a child’s device, we store the chosen profile, the device label supplied by the parent, connection dates, and a one-way hash of its access credential. The credential on the device is stored in the device-only Keychain. It gives access to that child’s listening experience, not the parent’s sign-in credentials or account controls. Parents can remove a connection in Parent Zone or the web parent portal.
Creating a custom story can involve text and a drawing or photo selected in the app. These inputs are sent to the types of service providers described below to make the requested story, artwork, and narration. We do not automatically include the parent's account email, account credentials, account identifiers, or the child's stored profile name in requests to create stories. Text and pictures can nevertheless contain personal information supplied by the person creating the story. Parents should choose what to submit carefully and review custom stories before sharing them with children.
Service providers and sharing
We share information needed for the feature you use with the following types of service providers. This can include personal information in text or pictures you choose to submit.
Sign-in and payment services. Apple provides Sign in with Apple and App Store purchases, verification, and restores. Payment processors handle web billing where offered. These services receive the account and transaction information needed to manage your sign-in or purchase. We do not receive payment-card details from Apple.
AI story-writing and illustration services. These receive the selected age range, story idea or title, instructions, and, where used, the submitted picture or its description to create and check stories and artwork. Our current family-story service does not use these submissions for model training. Eligible content is excluded from routine retention by this service. Temporary processing and safety exceptions, including review of certain flagged images, can still apply.
AI narration services. These receive story text and voice settings to create audio. Personal information may be included if it is in the story; we do not attach account credentials or profile records. New narration submissions are excluded from model training. This does not delete earlier submissions or mean that content is immediately deleted. The service may retain content to deliver and protect its services after audio has been created.
Playing a catalogue story uses previously prepared audio and artwork. It does not send a new request to AI generation services each time a child listens.
An additional story-writing service is available for optional use but is not used for current family-story creation. If separately enabled, it receives the story prompt and instructions without the raw drawing, account credentials, or unrelated profile records. It retains submissions for 30 days for safety work, with possible extensions for safety or legal reasons.
Service delivery, storage, and security providers. These process account content, media, connection information including IP addresses and request details, and content passing through their services to deliver and protect StoryWeaver. Support services process the information you send when asking for help.
Optional voice-assistant services. Amazon processes Alexa requests and account linking when a parent separately enables Alexa.
We may also disclose information when required by law, to protect a person, or to investigate fraud or abuse. You can contact support for more information about the organisations processing your information.
International processing
We process personal information in the UK and EU. Some service providers process information in other countries, including the United States. Limits on model training or retention do not mean that all processing stays in the UK or EU. Contact support for information about processing locations and the safeguards that apply to transfers of your personal information.
Retention and deletion
Account, child profile, family content, and listening data are retained while the account is active unless a parent deletes content sooner. Records of your consent are kept while the account exists. Support cases are normally retained for up to 24 months after closure, and routine diagnostics for 30 days. Purchase or dispute records may be retained longer when required for tax, accounting, fraud prevention, or legal claims.
Deleting a family story moves it to Recently Deleted and removes it from the library. The parent can restore it for 30 days. After that period, its text, associated creation inputs, and unshared artwork, drawings and audio are permanently removed from the live service. Administrators have the same 30-day recovery period when deleting stories in the story portal. Cleanup is retried if interrupted. Media still used by another story is retained for that story.
In-app account deletion removes the StoryWeaver account, profiles, progress, favourites, generated family stories, private uploads, private media, and consent records. Deletion signs you out and disconnects Sign in with Apple. If we cannot disconnect an older Apple sign-in connection automatically, we provide instructions. Limited records needed to complete deletion and verify eligible account recovery may be retained for up to 90 days. Restoring a purchase after recreating an account requires verification through Apple.
Deletion from the live service does not immediately remove copies in recovery backups. Backup copies are restricted to recovery use and removed as backups expire. Deleted information must not be returned to normal use if a backup is restored. Contact support for retention or deletion questions. Apple subscriptions must be cancelled separately through Apple's subscription settings.
Your choices and rights
Parents can change child profiles, manage Apple subscriptions, restore purchases, delete the account, or ask us for a copy or correction of personal information. Depending on location, a parent may also object to or restrict processing, withdraw consent by requesting account deletion, or complain to the relevant data-protection authority. Withdrawing consent does not affect processing that was lawful before withdrawal.
Security and changes
We use security measures to protect information and restrict access to people who need it to provide the service. No system is completely secure. We will update this policy when our data practices materially change and will show a new effective date; where appropriate, we will also notify parents in the service.
Contact
For privacy or account questions, email StoryWeaver support at support [at] story-book.app.