Privacy Policy

Effective date: 24 July 2026

Contents

Our Commitments to Your Family

  • Child photos are deleted within 24 hours of avatar acceptance.
  • We never use your child’s photos or data to train AI models.
  • Zero ads, zero ad networks, and zero behavioural tracking of children.
  • You can export or delete your data at any time, from the app.
  • Every story and illustration is AI-generated, and clearly disclosed as such.

1. Introduction

1.1. This Privacy Policy explains how The Dream Management Group FZE LLC, trading as "Once Upon a Me" ("we", "us", "our"), collects, uses, stores, and protects your personal data when you use our platform at onceuponame.io and our mobile application (collectively, "the Service").

1.2. Once Upon a Me is a parent-operated service. Parents and legal guardians create accounts and manage the Service on behalf of their children. Children do not create accounts or interact with the Platform directly.

1.3. We are committed to protecting the privacy of both parents and children. This policy has been designed with particular attention to children's data rights under the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the Children's Online Privacy Protection Act (COPPA), the ICO Age Appropriate Design Code (Children's Code), and the UAE Personal Data Protection Law (PDPL).

1.4. This policy is effective as of 24 July 2026 and applies to all users of the Service worldwide.

1.5. This Service is designed for use by parents and legal guardians. It is not a children's service. Children are the beneficiaries of content created through the Service, not its operators.

2. Data We Collect

2.1. We collect and process the following categories of personal data:

CategoryData CollectedPurpose
Parent account dataEmail address, password (stored as Argon2 hash), display name, push notification tokenAccount creation, authentication, communication
Child profile dataChild's first name, age, gender, interests, unique friend code, chosen narrator voice and accent, optional phonetic spelling of the child's name for narrationPersonalising story content, illustrations, and narration
Learning & play dataAnswers to optional in-story comprehension questions, reading-progress signals, and mini-game and colouring activity (stored against the child's profile)Powering the optional comprehension questions, the parent-facing Journey view, and in-app games; shown to parents, never used for advertising or profiling
Child photographsPhotos uploaded by parent for avatar generationGenerating a personalised character avatar (see Section 4)
Parent / carer appearance & cameo dataOptional self-description (hair, eyes, facial hair) and/or an optional self-uploaded reference photo, plus the resulting cartoon cameo avatarGenerating your personalised cartoon cameo for your household's stories (see Section 4)
Family voice recordings (Add-A-Voice / Record-a-Voice)Optional audio recorded by a parent, grandparent, or carer reading a story aloud, either in the app or, by invitation, in a web browser without an account, uploaded to our content delivery network and stored as a selectable narrator option. For an invited browser recording we also use the device IP address transiently for spam protection only (not stored)Letting a family member's own voice narrate a story for your household (see Section 3)
AI-generated contentCharacter avatars, story text, page illustrations, narration audioDelivering the personalised storybook experience
Payment dataStripe customer ID or RevenueCat subscriber ID (we do not store card numbers or bank details)Processing payments and managing subscriptions
Analytics dataSession events, feature usage, app interactions via PostHog (keyed to internal IDs; no name, email, or IP)Improving service quality and understanding usage patterns
Household dataHousehold membership, intended invitation email, single-use carer invitation tokens (14-day expiry), roles (primary parent / carer), per-child permissions, and likeness-consent permissionsEnabling authorised household access to shared child profiles and stories, and enforcing primary-parent consent controls
Consent recordsTimestamps of terms and privacy acceptance, version acceptedLegal compliance and consent tracking
Access audit logsRecords of data access eventsSecurity monitoring and compliance
Order & delivery dataRecipient name, shipping address, telephone number (collected only at physical-book checkout)Fulfilling and delivering physical book orders via our print partners
Social sign-in identityIf you sign in with Apple or Google: a provider account identifier, your verified email (which may be an Apple private-relay address), and your name on first sign-in. We never receive your social-account password.Creating and securing your account

2.2. We do not collect data directly from children. All data relating to children is provided by their parent or legal guardian.

3. How We Use Data

3.1. We use the data we collect strictly for the following purposes:

  • Parent account data: To create and manage your account, authenticate your identity, send transactional emails (story notifications, password resets, payment confirmations), and deliver push notifications.
  • Child profile data: To personalise story content, tailor illustrations to the child's characteristics, apply content controls, and enable the friend feature.
  • Child photographs: Solely to generate a character avatar. Photos are not used for any other purpose (see Section 4).
  • AI-generated content: To deliver, store, and display your personalised storybooks within the Service, and to generate narration audio for subscriber stories.
  • Family voice recordings (Add-A-Voice / Record-a-Voice): Used only for in-app narration playback when a family voice is selected as the narrator for a story, and made available to members of your household. These recordings are never transcribed, analysed, used for model training, used to create a voiceprint, used to identify anyone, or used for voice cloning.
  • Payment data: To process transactions, manage subscriptions, and provide purchase history.
  • Analytics data: To understand how the Service is used, identify issues, and improve the user experience. Analytics data is keyed to internal pseudonymous identifiers and does not identify individual children.
  • Learning & play data: To power the optional comprehension questions, the parent-facing Journey view, and in-app games (mazes, pairs, colouring). This data stays within the Service, is visible to the parents and carers of the household, and is never used for advertising, profiling, or automated decision-making about the child.
  • Household data: To enable permissioned access within the family unit. Invitations are bound to the intended recipient’s normalised email address. Only a primary parent can grant or revoke AI likeness consent or approve permanent reusable likeness assets. A scoped carer can use only child profiles and likenesses already approved for them.
  • Consent records: To demonstrate that valid consent was obtained for data processing, as required by applicable law.
  • Access audit logs: To detect and investigate unauthorised access attempts and to comply with security monitoring obligations.
  • Order & delivery data: To produce and deliver physical book orders through our print partners, and to send you order and dispatch updates.
  • Safety screening: We screen uploaded photos and the illustrations our AI generates for safety and age-appropriateness before they are used or shown (see Sections 4 and 7).

3.2. We do not sell, rent, license, or trade your personal data or your children's data to any third party, for any purpose, under any circumstances. We do not use children's data for profiling, behavioural advertising, or automated decision-making.

3.3. AI transparency & governance. All stories, illustrations, avatars, and narration are generated by artificial intelligence and are clearly disclosed as AI-generated in the app. We do not use your child’s photographs or personal data to train AI models. We do not make decisions that produce legal or similarly significant effects about you or your child using solely automated means. Generated content is checked for safety before you see it, and any content you report is reviewed by a member of our team.

3.4. Recordings made by invitation (Record-a-Voice). As well as recording in the app, an account holder can invite a relative or carer, such as a grandparent, to narrate a story using a private link. That person records their own voice in their web browser without creating an account. We rely on their own consent, which they give by ticking a clear affirmative box on the recording page (confirming they are 18 or over and that it is their own voice) before any recording begins. From an invited recorder we collect only the audio they record, the display name (and any optional relationship label) the inviting parent chose for the voice and timestamps. To protect the link from spam, we use their device’s network (IP) address only for that rate-limiting check; it is not stored in our database or logs. We do not ask an invited recorder for their name, email, date of birth, or any other contact detail. Their recording is handled, kept, and deleted exactly as an in-app family recording is (see Sections 6 and 8), and it is never used to train AI, to clone the voice, to create a voiceprint, or to identify anyone. Even without an account, an invited recorder has the rights set out in Section 8 (including access, erasure, and withdrawing consent): the inviting parent can remove the recording in the app, and the recorder can ask us to delete it or provide a copy at any time by emailing [email protected]. Recordings may be stored outside the recorder’s country under the safeguards in Section 10.

4. Photo Handling & Deletion

4.1. This section describes how we handle photographs of children. Given the sensitivity of children's images, we have implemented strict safeguards:

Photo Lifecycle

  1. Consent: Before any photo is uploaded, the app asks the parent to confirm, on a dedicated consent screen, that they are the child’s parent or legal guardian and that they consent to the photo being processed by our avatar providers (named on that screen). This consent is recorded with a timestamp.
  2. Upload: Parent uploads photographs through the app. Photos are stored securely on our content delivery network with restricted access.
  3. Processing: The photograph is sent to a photo-analysis service that describes the child’s appearance (currently OpenAI GPT-5-mini, with Anthropic as a backup), and to our avatar-generation providers: xAI Grok Imagine (via fal.ai) as primary, with OpenAI’s gpt-image-1.5 (via fal.ai) as an automatic fallback, to produce a stylised character avatar. Under their API data-usage policies, images submitted through the API are not used to train their models. Before any avatar or story is created, photos are screened for safety: clearly inappropriate images, or images that do not show a child, are rejected. Before the generated cartoon is saved, a separate automated quality check compares it with our house-style reference. The check receives the generated cartoon and the reference, not the original photograph, child’s name, profile, age or account details. It judges art style only and is instructed not to assess identity, ethnicity, age, sex, disability or other personal traits. OpenAI performs this check, with Anthropic as a fallback. A failed version is discarded and is not charged as an avatar creation.
  4. Avatar acceptance: Once the parent accepts the generated avatar, photos enter a 24-hour deletion grace period.
  5. Grace period: During the 24-hour window, the parent may choose to regenerate the avatar, which temporarily reactivates the photos.
  6. Permanent deletion: Once you accept an avatar, the reference photo is marked for deletion and permanently removed from our database and content delivery network within 24 hours by an automated process. If you never accept an avatar, the photo is not placed on this 24-hour timer. Instead, it is removed when you delete the child profile or your account. In the rare event a CDN deletion does not succeed on the first pass, an automated storage sweep removes the orphaned file.

4.2. Parents may request immediate deletion of uploaded photographs at any time by contacting [email protected]. We will process such requests within 24 hours.

4.3. The generated avatar is a stylised illustration rather than a photograph, but it remains personal data when linked to your child’s profile. We do not use it for facial recognition, identity matching, authentication or creation of a biometric template. Avatars are retained as part of the child profile for as long as that profile exists, subject to the deletion terms in Section 6.

4.4. Parent / carer cameo photos. A parent or carer may optionally upload a reference photo of themselves to generate their own stylised cartoon cameo, which can appear alongside the child in your household’s stories. This is never required.

4.4.1. A self-uploaded cameo photo follows the same lifecycle as a child reference photo: it is uploaded to our secure content delivery network, sent only to our avatar-generation providers: xAI Grok Imagine (via fal.ai) as primary and OpenAI’s gpt-image-1.5 (via fal.ai) as a fallback. Once you accept your cameo, the photo is marked for deletion and permanently removed from our database and content delivery network within 24 hours by an automated process. Neither provider uses these photos for model training.

4.4.2. We use your photo only to stylise it into a cartoon likeness. We do not perform facial recognition or use it to identify you. The generated cameo is a stylised illustration and does not constitute a photograph or biometric data. It is retained while your account is active and can be removed at any time from your profile.

5. Third-Party Processors

5.1. We use the following third-party services to operate the Platform. Each processes data only as necessary to provide their specific function:

ServicePurposeData Processed
SupabaseDatabase hostingAll account and content data
Cloudflare (R2)Image CDN and file storageUploaded photos, generated images, story assets, family voice recordings (Add-A-Voice / Record-a-Voice). Stores and serves files only, does not transcribe, analyse, or otherwise process audio, and does not use it to train any model
StripeWeb payment processingPayment tokens, customer ID
RevenueCatMobile in-app purchase managementSubscriber ID, purchase history
PostHogProduct analytics (opt-in in the app; on our website only if you accept analytics cookies)Usage events keyed to internal IDs only, no email, IP, or payment data
Google Analytics 4 & MetricoolAudience measurement on our marketing website (onceuponame.io) only, and only if you accept analytics cookies via our cookie banner; not in the app. Website pages shown inside the app are loaded with these analytics disabledDevice and page-view data collected via first-party analytics cookies on the website; no account, child, or payment data
ResendTransactional email deliveryEmail address, email content
ExpoPush notification deliveryPush token, notification content
Apple (Sign in with Apple)Optional social sign-inOAuth identity token, verified email (may be a private-relay address), provider account ID
Google (Sign-In)Optional social sign-inOAuth identity token, verified email, provider account ID, name (first sign-in)
OpenAIStory planning (primary); photo analysis / visual descriptor + content-safety screen (GPT-5-mini vision, primary); illustration quality/consistency and avatar house-style auditing; avatar generation (gpt-image-1.5, fallback, via fal.ai); automated quality checks on generated narration audio (Whisper)Story planning inputs (child's first name, age, interests, theme and story parameters); child photographs, or a consenting adult member’s own photo where they opt to create a cameo; generated illustrations and cartoon avatars for auditing; generated narration audio for quality checks (API only, not used for training)
AnthropicStory text generation (Claude Sonnet 4.6); photo analysis and visual-audit fallback (Claude Haiku)Child photographs (backup appearance analysis), generated illustrations/cartoon avatars on audit fallback, child name, age, interests and story parameters (API only, not used for training)
Google (Gemini)Story narration (text-to-speech, primary); scene analysis, website chat and gift synopses; optional visual-audit failover only after a separately approved configuration changeStory page text for narration (including the child's first name and any phonetic name spelling you set), your chosen narrator voice and accent; child name, age, interests, theme and story parameters; a generated illustration/cartoon avatar if the approved visual-audit failover is enabled (no original child photographs)
Kie.aiIllustration generation (primary for full-book pages and hero art; fallback for previews); automated story rhythm checks via a proxied text modelText prompts, character descriptions, generated illustrations, and story text for rhythm checks; never photographs
FAL.aiIllustration generation (primary for previews and covers, fallback elsewhere), image upscaling (fallback), processing host for avatar generation and for the xAI narration fallbackText prompts, character descriptions, generated illustrations; brief technical hosting of the uploaded photo (a child’s, or a consenting adult member’s own) during avatar generation; story text during a narration fallback
ProdiaImage upscaling (primary, Real-ESRGAN)Generated illustrations only (never photos)
xAIAvatar generation (primary, Grok Imagine via fal.ai); automatic backup for story narration (text-to-speech) if the primary narration service failsChild photographs, or a consenting adult member’s own photo where they opt to create a cameo (avatar generation only; API only, not used for training); story text for audio only when narration falls back to xAI
InngestWorkflow orchestration for the story-finishing and print pipelineInternal identifiers (story, child, household IDs) and the pipeline data needed for each step, which can include story page text and, for print jobs, the buyer's email address
ProdigiPhysical book printing and fulfilment (one of two print partners)Recipient name, shipping address, phone, buyer email, print-ready PDFs
CloudPrinterPhysical book printing and fulfilment (one of two print partners)Recipient name, shipping address, phone, buyer email, print-ready PDFs
UploadcareLegacy image hosting (no new uploads)Residual older illustration URLs only; no photos, names, or contact data

5.2. We have reviewed each processor's data handling practices and selected providers that offer appropriate safeguards for personal data. Where available, we use API-level access which typically provides stronger data protection guarantees than consumer-level services.

5.3. Our 24-hour source-photo deletion promise describes copies held by Once Upon a Me. AI providers may retain API inputs and outputs for limited abuse, safety or legal purposes under their business terms. OpenAI and Anthropic currently describe a standard maximum period of up to 30 days, subject to limited exceptions and any enhanced zero-retention controls enabled on our account. We do not permit API inputs to be used for model training.

6. Data Retention

6.1. We retain data only for as long as necessary to provide the Service and fulfil the purposes described in this policy:

Data TypeRetention Period
Parent account dataSuspended when deletion is requested; permanently deleted or irreversibly anonymised after the 30-day recovery period, except limited records required for legal, accounting, order-support, fraud, or dispute purposes
Child profile dataRetained for active authorised household members. Data that belongs only to the deleting account is permanently deleted or irreversibly anonymised after the 30-day recovery period. Future use of the deleting member's likeness is stopped.
Child photographs24 hours after avatar acceptance, then permanently deleted. A photo you upload but never turn into an accepted avatar is automatically deleted within about 48 hours of upload
Parent / member cameo photos24 hours after cameo acceptance, then permanently deleted (the cartoon cameo itself is retained while your account is active). A photo never turned into an accepted cameo is automatically deleted within about 48 hours of upload
Family voice recordings (Add-A-Voice / Record-a-Voice)Retained while the completed story exists and the published track is active. A published recording remains with a completed shared-household story after its contributor deletes their account. A draft or unpublished recording belonging only to the deleting account is removed after the 30-day recovery period. A recording is deleted when the story or active track is deleted, or when the household closes. An invitation link expires after 14 days, which stops further recording. These are NOT subject to the 24-hour photo-deletion timer.
Generated stories, illustrations, cover art & narration audioCompleted stories shared with a household remain available to its authorised active members, including likeness and published family narration already embedded in the story. Unfinished drafts and content belonging only to the deleting account are removed after the 30-day recovery period. Household content is removed when the household closes, subject to legal retention requirements.
Character avatars and likeness assetsRetained while the authorised child profile exists. When consent, a friendship, or an account ends, future reuse and access to reusable likeness details and avatar sheets stop immediately. A likeness already embedded in a completed story may remain in that story, subject to applicable erasure and safeguarding rights.
Password reset tokens1 hour, then automatically expired and deleted
Analytics eventsUp to 12 months, then purged
AI quality and cost recordsLinked to internal story, child or household identifiers for up to 12 months, then identifiers and free-form metadata are removed; aggregate provider/model/cost facts may be retained
Payment recordsAs required by applicable tax and accounting regulations
Physical-book order & delivery recordsRetained after delivery for order support, reprints, warranty claims, and tax/accounting record-keeping. The recipient's detailed shipping address, phone number and gift message are removed 180 days after the order is delivered or cancelled, or when your account is deleted, whichever comes first; the town/region/country and the financial record are kept for the statutory accounting period
Print-ready book filesStored under unguessable private links and deleted 90 days after the order is delivered or cancelled, and on account deletion. A later reprint is re-rendered from your story
Illustration quality-review snapshotsCopies of generated illustrations our team reviews to improve automated quality checks are kept for up to 12 months from capture, then deleted, and the related review records are de-identified
Access & security logsUp to 12 months, then automatically purged
Consent recordsRetained for the lifetime of the account for legal compliance

6.2. When you request account deletion, your account enters a 30-day recovery period during which your data is suspended but preserved. A recovery link is emailed to you immediately and opens a confirmation page. Recovery happens only after you expressly confirm it; opening or scanning the link alone does not restore the account. After 30 days, personal data belonging only to the deleting account is permanently anonymised or deleted, except where we must retain limited records for legal, tax, accounting, order-support, fraud, or dispute purposes.

6.3. Where a household still has other active members, its completed stories, illustrations, and published family narration remain available to those members under their existing permissions. The deleting member’s likeness cannot be used for future creation, and reusable likeness details and avatar sheets are no longer accessible. Unfinished drafts and personal uploads belonging only to the deleting account are removed after the recovery period. Shared media is erased when the household closes or the relevant story or track is deleted, subject to any record we must lawfully retain.

6.4. A household creator with remaining members must transfer ownership to another primary parent before deletion can complete. The recipient must accept the transfer. A legacy household with no active primary parent is frozen for governance changes while support verifies ownership; another member is not promoted automatically.

7. Children's Privacy

7.1. This is a parent-operated service designed for adults. It is not directed at children and we do not knowingly collect data directly from children. All child-related data is provided by their parent or legal guardian acting on their behalf.

7.2. Protecting children's privacy is central to how we have designed the Service. The following safeguards are built into the Platform:

  • Parent-operated model: Children do not create accounts, log in, or interact with the Platform. All operations are performed by the parent or legal guardian.
  • Parental consent at the point of collection: Account creation requires an adult (18+) to register with a valid email address and password, and the account holder confirms they are the child's parent or legal guardian. Consent to process a child's data, including the separate, explicit consent required before any child photograph is shared with our AI providers, is captured from that authenticated adult at the point each type of data is collected.
  • No child profiling: We do not create behavioural profiles of children or track their activities. Automated checks may assess whether uploaded or generated content is safe and whether a generated image matches our art style; they assess the content, not the child, and do not make legal or similarly significant decisions about them.
  • No advertising: The Service contains no advertisements, no ad networks, and no marketing content targeted at children.
  • No tracking of children: We do not use tracking cookies, browser fingerprinting, or any tracking SDKs that collect data about children. Our analytics (PostHog) track parent usage patterns only, at an aggregate level.
  • Content controls: Parents can configure per-child content controls including excluded themes, bedtime mode, and preferred values or life lessons.
  • Minimal data collection: We collect only the child data necessary to generate personalised stories: first name, age, gender, and optional interests.
  • Photo deletion: Child photographs are permanently deleted within 24 hours of avatar acceptance, and whenever you delete the child profile or your account (see Section 4).
  • Automated deletion: Reference photos are removed by an automated deletion process backed by an automated storage sweep that reclaims any orphaned file, so deletion does not depend on manual intervention.
  • Tenant isolation: Each household's data is strictly isolated. Parents can only access data belonging to their own household. This isolation is enforced at both the application and database level.
  • Rate-limited access: Authentication endpoints are protected against brute-force attacks to prevent unauthorised access to children's data.
  • Audit trail: Access to children's data is logged for security monitoring purposes.

7.3. Connected families (“Friends”). If you choose to connect your child with another family using a friend code, that family can see your child’s first name, cartoon avatar, and exact age in years (not an age range), and may include your child as a named character in stories they create. This sharing happens only after you enter or accept a friend code. Before an adult rejects a friend request, the Service asks them to confirm. A rejection prevents another request between the same child profiles for 30 days.

7.3.1. You can disconnect at any time. This immediately stops future sharing and removes the disconnected household’s access to profile and reusable likeness details, including avatar sheets. Disconnecting cannot retrieve or delete a likeness already embedded in a completed story the other family has generated. You can contact [email protected] about a legal erasure right or safeguarding concern. Only share friend codes with families you know and trust.

7.3.2. Public story sharing. If an authorised adult creates a public story link, anyone with that link may see the content made available on the share page. The story owner can revoke or replace the link, and disabling external sharing revokes active links. We remove the associated public share asset where technically possible, but cannot remove copies already downloaded or cached outside our control.

7.4. If you believe we have inadvertently collected personal data from a child without proper parental consent, please contact us immediately at [email protected]. We will investigate and delete any such data promptly.

8. Your Rights

8.1. Under the UK GDPR, EU GDPR, UAE PDPL, and applicable data protection laws, you have the following rights regarding your personal data and your child's personal data:

  • Right of access: You may request a copy of all personal data we hold about you and your children.
  • Right to rectification: You may request that we correct any inaccurate or incomplete personal data.
  • Right to erasure: You may request that we delete your personal data and your children's data. You can request deletion of your account and associated personal data at any time from Profile → Delete Account in the app. If you have removed the app, you can instead go at onceuponame.io/delete-account, or by emailing [email protected]. Deletion starts a 30-day recovery window, after which data belonging only to your account is permanently deleted or anonymised. Completed shared-household stories and records we must lawfully retain are handled as described in Section 6. You can still ask us to assess erasure of retained content under applicable law.
  • Right to restrict processing: You may request that we limit how we process your data in certain circumstances.
  • Right to data portability: You may request a copy of your data in a structured, commonly used, machine-readable format.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to object: You may object to processing of your personal data in certain circumstances, including processing for direct marketing purposes.

8.1.1. Data export. You can download a copy of your data yourself at any time from Profile → Download my data in the app, in a structured, machine-readable JSON format. This self-service export covers your account, your child profiles, your stories’ metadata, and roughly the last 90 days of activity events; for a complete copy of everything we hold, contact [email protected].

8.2. To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. In complex cases, we may extend this period by a further 60 days, in which case we will inform you of the extension and the reasons for it.

8.3. You will not be charged a fee for exercising your rights unless your request is manifestly unfounded or excessive.

8.4. If you are a resident of the United Arab Emirates, you have additional rights under the UAE Personal Data Protection Law (PDPL), including the right to access, rectify, and erase your personal data, and the right to object to processing.

9. Cookies & Tracking

9.1. We use a minimal set of cookies and tracking technologies:

  • Authentication cookies: Strictly necessary httpOnly cookies used for session management and keeping you logged in. These cannot be disabled as they are essential for the Service to function.
  • Analytics (PostHog): We use PostHog for product analytics to understand how the Service is used and to identify areas for improvement. In the app, analytics run only if you opt in; on the website, PostHog runs only if you accept analytics cookies in our cookie banner. PostHog collects product-usage events keyed to internal pseudonymous identifiers (no name, email, or IP). No personally identifiable information about children is tracked.
  • Website audience analytics (Google Analytics 4 and Metricool): Our marketing website (onceuponame.io) uses Google Analytics 4 and Metricool to measure page visits and understand how visitors find us. These set first-party analytics cookies on the website only, and only if you accept them in our cookie banner. The app contains no website analytics: its own screens do not run them, and where the app shows pages from our website (for example this policy), it loads them with these analytics disabled. On the website, they receive no account, child, or payment data.

9.2. We do not use:

  • Advertising or marketing cookies
  • Browser fingerprinting
  • Cross-site tracking
  • Social media tracking widgets
  • Any analytics or tracking of children

10. International Transfers

10.1. Our entity is established in the United Arab Emirates (UAE). To deliver the Service, your personal data may be processed in the following locations:

  • United States: Google (Gemini and Google Analytics), Anthropic, OpenAI, Kie.ai, fal.ai, xAI, Prodia, Inngest, PostHog (in-app analytics opt-in only), RevenueCat (mobile purchases), Expo (push notifications), Resend (transactional email), and the identity providers Apple (Sign in with Apple) and Google (sign-in).
  • European Union / United Kingdom: our database is hosted by Supabase on Amazon Web Services in the EU (London, eu-west-2); Cloudflare R2 (CDN) and Stripe operate global edge / EU infrastructure.
  • Print fulfilment: Prodigi and CloudPrinter (selected per order) print and ship, where possible, from facilities in or near the destination country.

10.2. Where we transfer personal data out of the United Kingdom or the EEA to a country without an adequacy decision (including the United States and the UAE), we put appropriate safeguards in place: the UK International Data Transfer Agreement (IDTA) / Addendum and the European Commission’s Standard Contractual Clauses (SCCs), together with a data processing agreement with each processor and data minimisation.

10.3. You may contact us for more information about the specific safeguards applied to international data transfers.

11. Security

11.1. We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using HTTPS/TLS.
  • Password security: Passwords are hashed using Argon2, a memory-hard hashing algorithm that is resistant to brute-force and rainbow-table attacks. We never store passwords in plain text.
  • Password policy: Passwords must meet minimum complexity requirements (8+ characters with mixed case and numbers).
  • Authentication: JWT-based authentication with secure token management ensures only authorised users can access account data.
  • Constant-time authentication: Internal authentication mechanisms use constant-time comparison to prevent timing-based attacks.
  • Rate limiting: Authentication endpoints are protected against brute-force attacks with automatic rate limiting.
  • API security: All API keys and secrets are stored securely as environment variables and are never exposed to client-side code.
  • Access control: Household-based access model ensures parents can only access data belonging to their own household.
  • Upload validation: File uploads are restricted to approved image types (JPEG, PNG, WebP, HEIC) with a 10MB size limit.
  • Access & security-event logging: Access to personal data and security events (such as failed log-in attempts) are logged to detect and investigate anomalies. These logs are kept for a limited period (up to 12 months), are used only to protect the security and integrity of the Service on the basis of our legitimate interests, and are never used for advertising or to profile children. Email and IP addresses in these logs are stored in pseudonymised (hashed) form.
  • Automated deletion: An automated cleanup process runs regularly (at least hourly) to ensure photos are deleted within the 24-hour window described in Section 4.
  • Breach notification: If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will inform affected users without undue delay where the breach is likely to result in a high risk.

11.2. While we take all reasonable precautions, no method of transmission or storage is completely secure. If you become aware of any security concern or vulnerability affecting your account or the Service, please contact us immediately at [email protected].

12. Regional Provisions

12.1. Which data-protection laws apply. Because we serve families in several countries, more than one data-protection law can apply to our processing at the same time. In particular:

  • EU GDPR: for users in the European Economic Area, because we offer our Service to them (Article 3(2)).
  • UK GDPR and the Data Protection Act 2018: for users in the United Kingdom, on the same basis (Article 3(2)).
  • US COPPA and applicable US state privacy laws (for example California's CCPA/CPRA and state children's design codes): for users and child beneficiaries in the United States.
  • The UAE Personal Data Protection Law (PDPL): as the law of the country where we are established.

12.2. Where more than one of these applies, we apply the protection that is most favourable to you. Our choice of the law of England and Wales in our Terms (Section 16 of the Terms) governs our contract with you; it does not change which data-protection laws apply, and it does not remove any data-protection right you have under the laws listed above. You can find how to reach our EU and UK representatives, and how to complain to a supervisory authority, in the region-specific sections below and in the Contact section (Section 14), which lists our Article 27 representatives.

12a. United Kingdom & European Union

12a.1. If you are located in the United Kingdom or the European Union, the UK GDPR and/or EU GDPR applies to our processing of your personal data.

12a.2. Our legal basis for processing your personal data is consent (provided at account creation) and legitimate interests (to operate and improve the Service). Where we rely on legitimate interests, we have assessed that our interests do not override your fundamental rights and freedoms.

12a.3. We have designed the Service with the principles of the ICO Age Appropriate Design Code (Children's Code) in mind, including data minimisation, high privacy defaults, and transparency appropriate to the age of the children who benefit from the Service.

12a.4. You have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO). In the European Union, this is your local Data Protection Authority.

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

12b. United States

12b.1. COPPA: We do not knowingly collect personal information directly from children under 13 years of age. All child data is provided by a verified parent or legal guardian who has created an account and consented to the processing of their child's data.

12b.2. California (CCPA/CPRA): If you are a California resident, you have the right to know what personal information we collect, the right to request deletion of your personal information, and the right to opt out of the sale of personal information. We do not sell personal information.

12b.3. We do not discriminate against users who exercise their privacy rights.

12c. United Arab Emirates

12c.1. The UAE Personal Data Protection Law (PDPL) applies to our processing of your personal data. Children's data is classified as sensitive personal data under the PDPL and is afforded additional protections.

12c.2. Consent from the authenticated adult account holder is collected and documented at the point of account creation and child profile creation. Separate, explicit consent to share a child's photograph with our AI providers is captured when the photograph is added, in accordance with the PDPL's requirements for processing sensitive personal data.

12c.3. You have the right to lodge complaints with the UAE Data Office or the relevant free zone authority regarding our handling of your personal data.

13. Changes to This Policy

13.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

13.2. For minor changes, we will update the effective date at the top of this page. For material changes that significantly affect how we handle your data or your children's data, we will:

  • Notify you by email at the address associated with your account
  • Display a prominent notice within the Service
  • Where required, seek your renewed consent before continuing to process data under the new terms

13.3. We encourage you to review this policy periodically. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

13.4. Business transfers. If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, or in the event of insolvency, personal data may be transferred to a successor or affiliate. Any successor will be bound by commitments at least as protective of your data as those in this Privacy Policy, and we will notify you (by email or in-app notice) of any such change and of any choices you may have.

14. Contact

14.1. The Dream Management Group FZE LLC, trading as Once Upon a Me, is the data controller responsible for your personal data. If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

The Dream Management Group FZE LLC

Trading as Once Upon a Me

BC-890780, 26th Floor, Amber Gem Tower

Ajman, P.O BOX: 4848, United Arab Emirates

Privacy enquiries & data-rights requests: [email protected]

Concerns about a child’s data: [email protected] (please mark “Child Data” in the subject line)

General support: [email protected]

Website: onceuponame.io

Representative (Article 27 EU GDPR & UK GDPR): We value your privacy and your rights as a data subject and have therefore appointed Prighter Group, with its local partners, as our privacy representative and your point of contact for the following regions: the United Kingdom (UK) and the European Union (EU). Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative Prighter, or make use of your data-subject rights, please visit app.prighter.com/portal/once-upon-a-me.

EU representative: iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria. Prighter is the controller’s representative under Article 27 of the EU GDPR.

UK representative: Prighter Ltd, 20 Mortlake Mortlake High Street, London, SW14 8JN, United Kingdom. Prighter is the controller’s representative under Article 27 of the UK GDPR.

GDPR Certification: Art 27 representation by Prighter

powered by Prighter

UK-GDPR Certification: Art 27 representation by Prighter

powered by Prighter

14.2. If you are not satisfied with our response to your data protection concern, you have the right to lodge a complaint with a supervisory authority:

United Kingdom

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

European Union

Your local Data Protection Authority

United Arab Emirates

UAE Data Office or relevant free zone authority