For parents

Privacy policy

Plain-language answers about what StorySprout collects, where it lives, and who can see it. If anything below is unclear, drop us a note — we read every message.

What we collect about your child

Only what you choose to share — and only enough for the app to work. If you tell us your child's first name and age range, we store them so the library knows which stories belong to which child. Otherwise the stories just attach to your account.

We save every story your child writes and the AI responses they received. That's what powers the library, the reread, and the bedtime-story output. We do not collect school names, home addresses, photos, birthdates, contact lists, or anything else about your family.

Your parent account

Your email address is your identifier. When you join the beta from the landing page or the exit-intent form, your email is stored in our beta_signups table along with the referral source and the landing-page A/B variant you saw. That's it — name is optional, and we never ask for a password during the beta.

Once you're signed in, your child's stories and writing sessions are scoped to your user id. No one else can reach them, and they never appear in any public listing. We use one cookie, hero_variant, to remember which landing-page version you saw so the analytics stay consistent.

Payment data

StorySprout is in open beta, so we're not collecting payments today. When paid plans launch, they will run through Stripe Connect — our platform integration ships with PCI-compliant handling on Stripe's side, so your card data never touches StorySprout's servers. We will only ever store the last four digits, brand, and expiry month for display, and Stripe holds the actual card details.

Story retention

Your child's stories are scoped to your signed-in account and live as long as your account does. You can request deletion at any time — email us from the address tied to your account and we'll remove any story you no longer want there. A one-click delete button is on the way.

Stories are not used to train external models. Our AI uses them only to generate the next response during an active session and to render the bedtime-story output you ask for.

Third-party services

StorySprout runs on a small set of trusted vendors. Here is who handles what.

OpenAI generates the co-writer replies and the bedtime stories. Requests go through a server-side proxy and OpenAI's API policy states that API inputs and outputs are not used to train OpenAI models. Neon hosts our Postgres database. Render hosts the application. Cloudflare R2 stores static assets through our CDN proxy. Mixpanel receives aggregate event analytics — page views, signup events, library views — and no story text.

Contact

Privacy questions, story-deletion requests, account changes, anything else — write to privacy@storysprout.app from the email tied to your account and we'll get back to you, usually within a couple of days.

Last updated: August 2026