Privacy Policy
Effective date: 24 July 2026
Contents
Our Commitments to Your Family
- Child photos are deleted within 24 hours of avatar acceptance.
- We never use your child’s photos or data to train AI models.
- Zero ads, zero ad networks, and zero behavioural tracking of children.
- You can export or delete your data at any time, from the app.
- Every story and illustration is AI-generated, and clearly disclosed as such.
1. Introduction
1.1. This Privacy Policy explains how The Dream Management Group FZE LLC, trading as "Once Upon a Me" ("we", "us", "our"), collects, uses, stores, and protects your personal data when you use our platform at onceuponame.io and our mobile application (collectively, "the Service").
1.2. Once Upon a Me is a parent-operated service. Parents and legal guardians create accounts and manage the Service on behalf of their children. Children do not create accounts or interact with the Platform directly.
1.3. We are committed to protecting the privacy of both parents and children. This policy has been designed with particular attention to children's data rights under the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the Children's Online Privacy Protection Act (COPPA), the ICO Age Appropriate Design Code (Children's Code), and the UAE Personal Data Protection Law (PDPL).
1.4. This policy is effective as of 24 July 2026 and applies to all users of the Service worldwide.
1.5. This Service is designed for use by parents and legal guardians. It is not a children's service. Children are the beneficiaries of content created through the Service, not its operators.
2. Data We Collect
2.1. We collect and process the following categories of personal data:
| Category | Data Collected | Purpose |
|---|---|---|
| Parent account data | Email address, password (stored as Argon2 hash), display name, push notification token | Account creation, authentication, communication |
| Child profile data | Child's first name, age, gender, interests, unique friend code, chosen narrator voice and accent, optional phonetic spelling of the child's name for narration | Personalising story content, illustrations, and narration |
| Learning & play data | Answers to optional in-story comprehension questions, reading-progress signals, and mini-game and colouring activity (stored against the child's profile) | Powering the optional comprehension questions, the parent-facing Journey view, and in-app games; shown to parents, never used for advertising or profiling |
| Child photographs | Photos uploaded by parent for avatar generation | Generating a personalised character avatar (see Section 4) |
| Parent / carer appearance & cameo data | Optional self-description (hair, eyes, facial hair) and/or an optional self-uploaded reference photo, plus the resulting cartoon cameo avatar | Generating your personalised cartoon cameo for your household's stories (see Section 4) |
| Family voice recordings (Add-A-Voice / Record-a-Voice) | Optional audio recorded by a parent, grandparent, or carer reading a story aloud, either in the app or, by invitation, in a web browser without an account, uploaded to our content delivery network and stored as a selectable narrator option. For an invited browser recording we also use the device IP address transiently for spam protection only (not stored) | Letting a family member's own voice narrate a story for your household (see Section 3) |
| AI-generated content | Character avatars, story text, page illustrations, narration audio | Delivering the personalised storybook experience |
| Payment data | Stripe customer ID or RevenueCat subscriber ID (we do not store card numbers or bank details) | Processing payments and managing subscriptions |
| Analytics data | Session events, feature usage, app interactions via PostHog (keyed to internal IDs; no name, email, or IP) | Improving service quality and understanding usage patterns |
| Household data | Household membership, intended invitation email, single-use carer invitation tokens (14-day expiry), roles (primary parent / carer), per-child permissions, and likeness-consent permissions | Enabling authorised household access to shared child profiles and stories, and enforcing primary-parent consent controls |
| Consent records | Timestamps of terms and privacy acceptance, version accepted | Legal compliance and consent tracking |
| Access audit logs | Records of data access events | Security monitoring and compliance |
| Order & delivery data | Recipient name, shipping address, telephone number (collected only at physical-book checkout) | Fulfilling and delivering physical book orders via our print partners |
| Social sign-in identity | If you sign in with Apple or Google: a provider account identifier, your verified email (which may be an Apple private-relay address), and your name on first sign-in. We never receive your social-account password. | Creating and securing your account |
2.2. We do not collect data directly from children. All data relating to children is provided by their parent or legal guardian.
3. How We Use Data
3.1. We use the data we collect strictly for the following purposes:
- Parent account data: To create and manage your account, authenticate your identity, send transactional emails (story notifications, password resets, payment confirmations), and deliver push notifications.
- Child profile data: To personalise story content, tailor illustrations to the child's characteristics, apply content controls, and enable the friend feature.
- Child photographs: Solely to generate a character avatar. Photos are not used for any other purpose (see Section 4).
- AI-generated content: To deliver, store, and display your personalised storybooks within the Service, and to generate narration audio for subscriber stories.
- Family voice recordings (Add-A-Voice / Record-a-Voice): Used only for in-app narration playback when a family voice is selected as the narrator for a story, and made available to members of your household. These recordings are never transcribed, analysed, used for model training, used to create a voiceprint, used to identify anyone, or used for voice cloning.
- Payment data: To process transactions, manage subscriptions, and provide purchase history.
- Analytics data: To understand how the Service is used, identify issues, and improve the user experience. Analytics data is keyed to internal pseudonymous identifiers and does not identify individual children.
- Learning & play data: To power the optional comprehension questions, the parent-facing Journey view, and in-app games (mazes, pairs, colouring). This data stays within the Service, is visible to the parents and carers of the household, and is never used for advertising, profiling, or automated decision-making about the child.
- Household data: To enable permissioned access within the family unit. Invitations are bound to the intended recipient’s normalised email address. Only a primary parent can grant or revoke AI likeness consent or approve permanent reusable likeness assets. A scoped carer can use only child profiles and likenesses already approved for them.
- Consent records: To demonstrate that valid consent was obtained for data processing, as required by applicable law.
- Access audit logs: To detect and investigate unauthorised access attempts and to comply with security monitoring obligations.
- Order & delivery data: To produce and deliver physical book orders through our print partners, and to send you order and dispatch updates.
- Safety screening: We screen uploaded photos and the illustrations our AI generates for safety and age-appropriateness before they are used or shown (see Sections 4 and 7).
3.2. We do not sell, rent, license, or trade your personal data or your children's data to any third party, for any purpose, under any circumstances. We do not use children's data for profiling, behavioural advertising, or automated decision-making.
3.3. AI transparency & governance. All stories, illustrations, avatars, and narration are generated by artificial intelligence and are clearly disclosed as AI-generated in the app. We do not use your child’s photographs or personal data to train AI models. We do not make decisions that produce legal or similarly significant effects about you or your child using solely automated means. Generated content is checked for safety before you see it, and any content you report is reviewed by a member of our team.
3.4. Recordings made by invitation (Record-a-Voice). As well as recording in the app, an account holder can invite a relative or carer, such as a grandparent, to narrate a story using a private link. That person records their own voice in their web browser without creating an account. We rely on their own consent, which they give by ticking a clear affirmative box on the recording page (confirming they are 18 or over and that it is their own voice) before any recording begins. From an invited recorder we collect only the audio they record, the display name (and any optional relationship label) the inviting parent chose for the voice and timestamps. To protect the link from spam, we use their device’s network (IP) address only for that rate-limiting check; it is not stored in our database or logs. We do not ask an invited recorder for their name, email, date of birth, or any other contact detail. Their recording is handled, kept, and deleted exactly as an in-app family recording is (see Sections 6 and 8), and it is never used to train AI, to clone the voice, to create a voiceprint, or to identify anyone. Even without an account, an invited recorder has the rights set out in Section 8 (including access, erasure, and withdrawing consent): the inviting parent can remove the recording in the app, and the recorder can ask us to delete it or provide a copy at any time by emailing [email protected]. Recordings may be stored outside the recorder’s country under the safeguards in Section 10.
4. Photo Handling & Deletion
4.1. This section describes how we handle photographs of children. Given the sensitivity of children's images, we have implemented strict safeguards:
Photo Lifecycle
- Consent: Before any photo is uploaded, the app asks the parent to confirm, on a dedicated consent screen, that they are the child’s parent or legal guardian and that they consent to the photo being processed by our avatar providers (named on that screen). This consent is recorded with a timestamp.
- Upload: Parent uploads photographs through the app. Photos are stored securely on our content delivery network with restricted access.
- Processing: The photograph is sent to a photo-analysis service that describes the child’s appearance (currently OpenAI GPT-5-mini, with Anthropic as a backup), and to our avatar-generation providers: xAI Grok Imagine (via fal.ai) as primary, with OpenAI’s gpt-image-1.5 (via fal.ai) as an automatic fallback, to produce a stylised character avatar. Under their API data-usage policies, images submitted through the API are not used to train their models. Before any avatar or story is created, photos are screened for safety: clearly inappropriate images, or images that do not show a child, are rejected. Before the generated cartoon is saved, a separate automated quality check compares it with our house-style reference. The check receives the generated cartoon and the reference, not the original photograph, child’s name, profile, age or account details. It judges art style only and is instructed not to assess identity, ethnicity, age, sex, disability or other personal traits. OpenAI performs this check, with Anthropic as a fallback. A failed version is discarded and is not charged as an avatar creation.
- Avatar acceptance: Once the parent accepts the generated avatar, photos enter a 24-hour deletion grace period.
- Grace period: During the 24-hour window, the parent may choose to regenerate the avatar, which temporarily reactivates the photos.
- Permanent deletion: Once you accept an avatar, the reference photo is marked for deletion and permanently removed from our database and content delivery network within 24 hours by an automated process. If you never accept an avatar, the photo is not placed on this 24-hour timer. Instead, it is removed when you delete the child profile or your account. In the rare event a CDN deletion does not succeed on the first pass, an automated storage sweep removes the orphaned file.
4.2. Parents may request immediate deletion of uploaded photographs at any time by contacting [email protected]. We will process such requests within 24 hours.
4.3. The generated avatar is a stylised illustration rather than a photograph, but it remains personal data when linked to your child’s profile. We do not use it for facial recognition, identity matching, authentication or creation of a biometric template. Avatars are retained as part of the child profile for as long as that profile exists, subject to the deletion terms in Section 6.
4.4. Parent / carer cameo photos. A parent or carer may optionally upload a reference photo of themselves to generate their own stylised cartoon cameo, which can appear alongside the child in your household’s stories. This is never required.
4.4.1. A self-uploaded cameo photo follows the same lifecycle as a child reference photo: it is uploaded to our secure content delivery network, sent only to our avatar-generation providers: xAI Grok Imagine (via fal.ai) as primary and OpenAI’s gpt-image-1.5 (via fal.ai) as a fallback. Once you accept your cameo, the photo is marked for deletion and permanently removed from our database and content delivery network within 24 hours by an automated process. Neither provider uses these photos for model training.
4.4.2. We use your photo only to stylise it into a cartoon likeness. We do not perform facial recognition or use it to identify you. The generated cameo is a stylised illustration and does not constitute a photograph or biometric data. It is retained while your account is active and can be removed at any time from your profile.
5. Third-Party Processors
5.1. We use the following third-party services to operate the Platform. Each processes data only as necessary to provide their specific function:
| Service | Purpose | Data Processed |
|---|---|---|
| Supabase | Database hosting | All account and content data |
| Cloudflare (R2) | Image CDN and file storage | Uploaded photos, generated images, story assets, family voice recordings (Add-A-Voice / Record-a-Voice). Stores and serves files only, does not transcribe, analyse, or otherwise process audio, and does not use it to train any model |
| Stripe | Web payment processing | Payment tokens, customer ID |
| RevenueCat | Mobile in-app purchase management | Subscriber ID, purchase history |
| PostHog | Product analytics (opt-in in the app; on our website only if you accept analytics cookies) | Usage events keyed to internal IDs only, no email, IP, or payment data |
| Google Analytics 4 & Metricool | Audience measurement on our marketing website (onceuponame.io) only, and only if you accept analytics cookies via our cookie banner; not in the app. Website pages shown inside the app are loaded with these analytics disabled | Device and page-view data collected via first-party analytics cookies on the website; no account, child, or payment data |
| Resend | Transactional email delivery | Email address, email content |
| Expo | Push notification delivery | Push token, notification content |
| Apple (Sign in with Apple) | Optional social sign-in | OAuth identity token, verified email (may be a private-relay address), provider account ID |
| Google (Sign-In) | Optional social sign-in | OAuth identity token, verified email, provider account ID, name (first sign-in) |
| OpenAI | Story planning (primary); photo analysis / visual descriptor + content-safety screen (GPT-5-mini vision, primary); illustration quality/consistency and avatar house-style auditing; avatar generation (gpt-image-1.5, fallback, via fal.ai); automated quality checks on generated narration audio (Whisper) | Story planning inputs (child's first name, age, interests, theme and story parameters); child photographs, or a consenting adult member’s own photo where they opt to create a cameo; generated illustrations and cartoon avatars for auditing; generated narration audio for quality checks (API only, not used for training) |
| Anthropic | Story text generation (Claude Sonnet 4.6); photo analysis and visual-audit fallback (Claude Haiku) | Child photographs (backup appearance analysis), generated illustrations/cartoon avatars on audit fallback, child name, age, interests and story parameters (API only, not used for training) |
| Google (Gemini) | Story narration (text-to-speech, primary); scene analysis, website chat and gift synopses; optional visual-audit failover only after a separately approved configuration change | Story page text for narration (including the child's first name and any phonetic name spelling you set), your chosen narrator voice and accent; child name, age, interests, theme and story parameters; a generated illustration/cartoon avatar if the approved visual-audit failover is enabled (no original child photographs) |
| Kie.ai | Illustration generation (primary for full-book pages and hero art; fallback for previews); automated story rhythm checks via a proxied text model | Text prompts, character descriptions, generated illustrations, and story text for rhythm checks; never photographs |
| FAL.ai | Illustration generation (primary for previews and covers, fallback elsewhere), image upscaling (fallback), processing host for avatar generation and for the xAI narration fallback | Text prompts, character descriptions, generated illustrations; brief technical hosting of the uploaded photo (a child’s, or a consenting adult member’s own) during avatar generation; story text during a narration fallback |
| Prodia | Image upscaling (primary, Real-ESRGAN) | Generated illustrations only (never photos) |
| xAI | Avatar generation (primary, Grok Imagine via fal.ai); automatic backup for story narration (text-to-speech) if the primary narration service fails | Child photographs, or a consenting adult member’s own photo where they opt to create a cameo (avatar generation only; API only, not used for training); story text for audio only when narration falls back to xAI |
| Inngest | Workflow orchestration for the story-finishing and print pipeline | Internal identifiers (story, child, household IDs) and the pipeline data needed for each step, which can include story page text and, for print jobs, the buyer's email address |
| Prodigi | Physical book printing and fulfilment (one of two print partners) | Recipient name, shipping address, phone, buyer email, print-ready PDFs |
| CloudPrinter | Physical book printing and fulfilment (one of two print partners) | Recipient name, shipping address, phone, buyer email, print-ready PDFs |
| Uploadcare | Legacy image hosting (no new uploads) | Residual older illustration URLs only; no photos, names, or contact data |
5.2. We have reviewed each processor's data handling practices and selected providers that offer appropriate safeguards for personal data. Where available, we use API-level access which typically provides stronger data protection guarantees than consumer-level services.
5.3. Our 24-hour source-photo deletion promise describes copies held by Once Upon a Me. AI providers may retain API inputs and outputs for limited abuse, safety or legal purposes under their business terms. OpenAI and Anthropic currently describe a standard maximum period of up to 30 days, subject to limited exceptions and any enhanced zero-retention controls enabled on our account. We do not permit API inputs to be used for model training.
6. Data Retention
6.1. We retain data only for as long as necessary to provide the Service and fulfil the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Parent account data | Suspended when deletion is requested; permanently deleted or irreversibly anonymised after the 30-day recovery period, except limited records required for legal, accounting, order-support, fraud, or dispute purposes |
| Child profile data | Retained for active authorised household members. Data that belongs only to the deleting account is permanently deleted or irreversibly anonymised after the 30-day recovery period. Future use of the deleting member's likeness is stopped. |
| Child photographs | 24 hours after avatar acceptance, then permanently deleted. A photo you upload but never turn into an accepted avatar is automatically deleted within about 48 hours of upload |
| Parent / member cameo photos | 24 hours after cameo acceptance, then permanently deleted (the cartoon cameo itself is retained while your account is active). A photo never turned into an accepted cameo is automatically deleted within about 48 hours of upload |
| Family voice recordings (Add-A-Voice / Record-a-Voice) | Retained while the completed story exists and the published track is active. A published recording remains with a completed shared-household story after its contributor deletes their account. A draft or unpublished recording belonging only to the deleting account is removed after the 30-day recovery period. A recording is deleted when the story or active track is deleted, or when the household closes. An invitation link expires after 14 days, which stops further recording. These are NOT subject to the 24-hour photo-deletion timer. |
| Generated stories, illustrations, cover art & narration audio | Completed stories shared with a household remain available to its authorised active members, including likeness and published family narration already embedded in the story. Unfinished drafts and content belonging only to the deleting account are removed after the 30-day recovery period. Household content is removed when the household closes, subject to legal retention requirements. |
| Character avatars and likeness assets | Retained while the authorised child profile exists. When consent, a friendship, or an account ends, future reuse and access to reusable likeness details and avatar sheets stop immediately. A likeness already embedded in a completed story may remain in that story, subject to applicable erasure and safeguarding rights. |
| Password reset tokens | 1 hour, then automatically expired and deleted |
| Analytics events | Up to 12 months, then purged |
| AI quality and cost records | Linked to internal story, child or household identifiers for up to 12 months, then identifiers and free-form metadata are removed; aggregate provider/model/cost facts may be retained |
| Payment records | As required by applicable tax and accounting regulations |
| Physical-book order & delivery records | Retained after delivery for order support, reprints, warranty claims, and tax/accounting record-keeping. The recipient's detailed shipping address, phone number and gift message are removed 180 days after the order is delivered or cancelled, or when your account is deleted, whichever comes first; the town/region/country and the financial record are kept for the statutory accounting period |
| Print-ready book files | Stored under unguessable private links and deleted 90 days after the order is delivered or cancelled, and on account deletion. A later reprint is re-rendered from your story |
| Illustration quality-review snapshots | Copies of generated illustrations our team reviews to improve automated quality checks are kept for up to 12 months from capture, then deleted, and the related review records are de-identified |
| Access & security logs | Up to 12 months, then automatically purged |
| Consent records | Retained for the lifetime of the account for legal compliance |
6.2. When you request account deletion, your account enters a 30-day recovery period during which your data is suspended but preserved. A recovery link is emailed to you immediately and opens a confirmation page. Recovery happens only after you expressly confirm it; opening or scanning the link alone does not restore the account. After 30 days, personal data belonging only to the deleting account is permanently anonymised or deleted, except where we must retain limited records for legal, tax, accounting, order-support, fraud, or dispute purposes.
6.3. Where a household still has other active members, its completed stories, illustrations, and published family narration remain available to those members under their existing permissions. The deleting member’s likeness cannot be used for future creation, and reusable likeness details and avatar sheets are no longer accessible. Unfinished drafts and personal uploads belonging only to the deleting account are removed after the recovery period. Shared media is erased when the household closes or the relevant story or track is deleted, subject to any record we must lawfully retain.
6.4. A household creator with remaining members must transfer ownership to another primary parent before deletion can complete. The recipient must accept the transfer. A legacy household with no active primary parent is frozen for governance changes while support verifies ownership; another member is not promoted automatically.
7. Children's Privacy
7.1. This is a parent-operated service designed for adults. It is not directed at children and we do not knowingly collect data directly from children. All child-related data is provided by their parent or legal guardian acting on their behalf.
7.2. Protecting children's privacy is central to how we have designed the Service. The following safeguards are built into the Platform:
- Parent-operated model: Children do not create accounts, log in, or interact with the Platform. All operations are performed by the parent or legal guardian.
- Parental consent at the point of collection: Account creation requires an adult (18+) to register with a valid email address and password, and the account holder confirms they are the child's parent or legal guardian. Consent to process a child's data, including the separate, explicit consent required before any child photograph is shared with our AI providers, is captured from that authenticated adult at the point each type of data is collected.
- No child profiling: We do not create behavioural profiles of children or track their activities. Automated checks may assess whether uploaded or generated content is safe and whether a generated image matches our art style; they assess the content, not the child, and do not make legal or similarly significant decisions about them.
- No advertising: The Service contains no advertisements, no ad networks, and no marketing content targeted at children.
- No tracking of children: We do not use tracking cookies, browser fingerprinting, or any tracking SDKs that collect data about children. Our analytics (PostHog) track parent usage patterns only, at an aggregate level.
- Content controls: Parents can configure per-child content controls including excluded themes, bedtime mode, and preferred values or life lessons.
- Minimal data collection: We collect only the child data necessary to generate personalised stories: first name, age, gender, and optional interests.
- Photo deletion: Child photographs are permanently deleted within 24 hours of avatar acceptance, and whenever you delete the child profile or your account (see Section 4).
- Automated deletion: Reference photos are removed by an automated deletion process backed by an automated storage sweep that reclaims any orphaned file, so deletion does not depend on manual intervention.
- Tenant isolation: Each household's data is strictly isolated. Parents can only access data belonging to their own household. This isolation is enforced at both the application and database level.
- Rate-limited access: Authentication endpoints are protected against brute-force attacks to prevent unauthorised access to children's data.
- Audit trail: Access to children's data is logged for security monitoring purposes.
7.3. Connected families (“Friends”). If you choose to connect your child with another family using a friend code, that family can see your child’s first name, cartoon avatar, and exact age in years (not an age range), and may include your child as a named character in stories they create. This sharing happens only after you enter or accept a friend code. Before an adult rejects a friend request, the Service asks them to confirm. A rejection prevents another request between the same child profiles for 30 days.
7.3.1. You can disconnect at any time. This immediately stops future sharing and removes the disconnected household’s access to profile and reusable likeness details, including avatar sheets. Disconnecting cannot retrieve or delete a likeness already embedded in a completed story the other family has generated. You can contact [email protected] about a legal erasure right or safeguarding concern. Only share friend codes with families you know and trust.
7.3.2. Public story sharing. If an authorised adult creates a public story link, anyone with that link may see the content made available on the share page. The story owner can revoke or replace the link, and disabling external sharing revokes active links. We remove the associated public share asset where technically possible, but cannot remove copies already downloaded or cached outside our control.
7.4. If you believe we have inadvertently collected personal data from a child without proper parental consent, please contact us immediately at [email protected]. We will investigate and delete any such data promptly.
8. Your Rights
8.1. Under the UK GDPR, EU GDPR, UAE PDPL, and applicable data protection laws, you have the following rights regarding your personal data and your child's personal data:
- Right of access: You may request a copy of all personal data we hold about you and your children.
- Right to rectification: You may request that we correct any inaccurate or incomplete personal data.
- Right to erasure: You may request that we delete your personal data and your children's data. You can request deletion of your account and associated personal data at any time from Profile → Delete Account in the app. If you have removed the app, you can instead go at onceuponame.io/delete-account, or by emailing [email protected]. Deletion starts a 30-day recovery window, after which data belonging only to your account is permanently deleted or anonymised. Completed shared-household stories and records we must lawfully retain are handled as described in Section 6. You can still ask us to assess erasure of retained content under applicable law.
- Right to restrict processing: You may request that we limit how we process your data in certain circumstances.
- Right to data portability: You may request a copy of your data in a structured, commonly used, machine-readable format.
- Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to object: You may object to processing of your personal data in certain circumstances, including processing for direct marketing purposes.
8.1.1. Data export. You can download a copy of your data yourself at any time from Profile → Download my data in the app, in a structured, machine-readable JSON format. This self-service export covers your account, your child profiles, your stories’ metadata, and roughly the last 90 days of activity events; for a complete copy of everything we hold, contact [email protected].
8.2. To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. In complex cases, we may extend this period by a further 60 days, in which case we will inform you of the extension and the reasons for it.
8.3. You will not be charged a fee for exercising your rights unless your request is manifestly unfounded or excessive.
8.4. If you are a resident of the United Arab Emirates, you have additional rights under the UAE Personal Data Protection Law (PDPL), including the right to access, rectify, and erase your personal data, and the right to object to processing.
10. International Transfers
10.1. Our entity is established in the United Arab Emirates (UAE). To deliver the Service, your personal data may be processed in the following locations:
- United States: Google (Gemini and Google Analytics), Anthropic, OpenAI, Kie.ai, fal.ai, xAI, Prodia, Inngest, PostHog (in-app analytics opt-in only), RevenueCat (mobile purchases), Expo (push notifications), Resend (transactional email), and the identity providers Apple (Sign in with Apple) and Google (sign-in).
- European Union / United Kingdom: our database is hosted by Supabase on Amazon Web Services in the EU (London, eu-west-2); Cloudflare R2 (CDN) and Stripe operate global edge / EU infrastructure.
- Print fulfilment: Prodigi and CloudPrinter (selected per order) print and ship, where possible, from facilities in or near the destination country.
10.2. Where we transfer personal data out of the United Kingdom or the EEA to a country without an adequacy decision (including the United States and the UAE), we put appropriate safeguards in place: the UK International Data Transfer Agreement (IDTA) / Addendum and the European Commission’s Standard Contractual Clauses (SCCs), together with a data processing agreement with each processor and data minimisation.
10.3. You may contact us for more information about the specific safeguards applied to international data transfers.
11. Security
11.1. We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using HTTPS/TLS.
- Password security: Passwords are hashed using Argon2, a memory-hard hashing algorithm that is resistant to brute-force and rainbow-table attacks. We never store passwords in plain text.
- Password policy: Passwords must meet minimum complexity requirements (8+ characters with mixed case and numbers).
- Authentication: JWT-based authentication with secure token management ensures only authorised users can access account data.
- Constant-time authentication: Internal authentication mechanisms use constant-time comparison to prevent timing-based attacks.
- Rate limiting: Authentication endpoints are protected against brute-force attacks with automatic rate limiting.
- API security: All API keys and secrets are stored securely as environment variables and are never exposed to client-side code.
- Access control: Household-based access model ensures parents can only access data belonging to their own household.
- Upload validation: File uploads are restricted to approved image types (JPEG, PNG, WebP, HEIC) with a 10MB size limit.
- Access & security-event logging: Access to personal data and security events (such as failed log-in attempts) are logged to detect and investigate anomalies. These logs are kept for a limited period (up to 12 months), are used only to protect the security and integrity of the Service on the basis of our legitimate interests, and are never used for advertising or to profile children. Email and IP addresses in these logs are stored in pseudonymised (hashed) form.
- Automated deletion: An automated cleanup process runs regularly (at least hourly) to ensure photos are deleted within the 24-hour window described in Section 4.
- Breach notification: If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will inform affected users without undue delay where the breach is likely to result in a high risk.
11.2. While we take all reasonable precautions, no method of transmission or storage is completely secure. If you become aware of any security concern or vulnerability affecting your account or the Service, please contact us immediately at [email protected].
12. Regional Provisions
12.1. Which data-protection laws apply. Because we serve families in several countries, more than one data-protection law can apply to our processing at the same time. In particular:
- EU GDPR: for users in the European Economic Area, because we offer our Service to them (Article 3(2)).
- UK GDPR and the Data Protection Act 2018: for users in the United Kingdom, on the same basis (Article 3(2)).
- US COPPA and applicable US state privacy laws (for example California's CCPA/CPRA and state children's design codes): for users and child beneficiaries in the United States.
- The UAE Personal Data Protection Law (PDPL): as the law of the country where we are established.
12.2. Where more than one of these applies, we apply the protection that is most favourable to you. Our choice of the law of England and Wales in our Terms (Section 16 of the Terms) governs our contract with you; it does not change which data-protection laws apply, and it does not remove any data-protection right you have under the laws listed above. You can find how to reach our EU and UK representatives, and how to complain to a supervisory authority, in the region-specific sections below and in the Contact section (Section 14), which lists our Article 27 representatives.
12a. United Kingdom & European Union
12a.1. If you are located in the United Kingdom or the European Union, the UK GDPR and/or EU GDPR applies to our processing of your personal data.
12a.2. Our legal basis for processing your personal data is consent (provided at account creation) and legitimate interests (to operate and improve the Service). Where we rely on legitimate interests, we have assessed that our interests do not override your fundamental rights and freedoms.
12a.3. We have designed the Service with the principles of the ICO Age Appropriate Design Code (Children's Code) in mind, including data minimisation, high privacy defaults, and transparency appropriate to the age of the children who benefit from the Service.
12a.4. You have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO). In the European Union, this is your local Data Protection Authority.
12b. United States
12b.1. COPPA: We do not knowingly collect personal information directly from children under 13 years of age. All child data is provided by a verified parent or legal guardian who has created an account and consented to the processing of their child's data.
12b.2. California (CCPA/CPRA): If you are a California resident, you have the right to know what personal information we collect, the right to request deletion of your personal information, and the right to opt out of the sale of personal information. We do not sell personal information.
12b.3. We do not discriminate against users who exercise their privacy rights.
12c. United Arab Emirates
12c.1. The UAE Personal Data Protection Law (PDPL) applies to our processing of your personal data. Children's data is classified as sensitive personal data under the PDPL and is afforded additional protections.
12c.2. Consent from the authenticated adult account holder is collected and documented at the point of account creation and child profile creation. Separate, explicit consent to share a child's photograph with our AI providers is captured when the photograph is added, in accordance with the PDPL's requirements for processing sensitive personal data.
12c.3. You have the right to lodge complaints with the UAE Data Office or the relevant free zone authority regarding our handling of your personal data.
13. Changes to This Policy
13.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
13.2. For minor changes, we will update the effective date at the top of this page. For material changes that significantly affect how we handle your data or your children's data, we will:
- Notify you by email at the address associated with your account
- Display a prominent notice within the Service
- Where required, seek your renewed consent before continuing to process data under the new terms
13.3. We encourage you to review this policy periodically. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
13.4. Business transfers. If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, or in the event of insolvency, personal data may be transferred to a successor or affiliate. Any successor will be bound by commitments at least as protective of your data as those in this Privacy Policy, and we will notify you (by email or in-app notice) of any such change and of any choices you may have.
14. Contact
14.1. The Dream Management Group FZE LLC, trading as Once Upon a Me, is the data controller responsible for your personal data. If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
The Dream Management Group FZE LLC
Trading as Once Upon a Me
BC-890780, 26th Floor, Amber Gem Tower
Ajman, P.O BOX: 4848, United Arab Emirates
Privacy enquiries & data-rights requests: [email protected]
Concerns about a child’s data: [email protected] (please mark “Child Data” in the subject line)
General support: [email protected]
Website: onceuponame.io
Representative (Article 27 EU GDPR & UK GDPR): We value your privacy and your rights as a data subject and have therefore appointed Prighter Group, with its local partners, as our privacy representative and your point of contact for the following regions: the United Kingdom (UK) and the European Union (EU). Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative Prighter, or make use of your data-subject rights, please visit app.prighter.com/portal/once-upon-a-me.
EU representative: iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria. Prighter is the controller’s representative under Article 27 of the EU GDPR.
UK representative: Prighter Ltd, 20 Mortlake Mortlake High Street, London, SW14 8JN, United Kingdom. Prighter is the controller’s representative under Article 27 of the UK GDPR.
14.2. If you are not satisfied with our response to your data protection concern, you have the right to lodge a complaint with a supervisory authority:
European Union
Your local Data Protection Authority
United Arab Emirates
UAE Data Office or relevant free zone authority