Once Upon A Hero
Legal

Privacy Policy

Effective July 21, 2026. Version 2026-07-21-v1. This policy explains what personal data Once Upon A Hero collects when you create a personalized book, how we use it, who we share it with, and — most importantly — how we handle your child's photo.

Our promise: A photo is optional — you can simply describe how your child looks instead. If you do upload one, it is used only to create their book, is never used to train AI models, and is permanently deleted within 30 days.

1. Who we are

Once Upon A Hero (“we”, “us”) creates AI-personalized children’s storybooks and comic books, delivered as digital PDFs and printed via global print-on-demand partners. For questions about this policy or your data, contact us at /contact or email privacy@onceuponahero.com.

2. Data we collect

We collect only what we need to make and ship your book:

  • Account data — email, and (optionally) a display name.
  • Hero details — the child’s first name, age, pronouns, and preferred language. We deliberately do not ask for last name, date of birth, or address of the child.
  • Reference photo (optional) — one photo you may upload of the child so we can illustrate a stylised likeness. If you prefer not to upload a photo, you can instead give us a short description (skin tone, hair, eyes, build, glasses) and we illustrate an original character from that.
  • Appearance details (optional) — if you describe your hero, you may optionally tell us the heritage or background whose features we should draw. It is never required, it is stored only with that one order, it is never used for advertising, profiling or analytics, and it is deleted with the rest of your order data.
  • Order & shipping information — recipient name, shipping address (for printed books only), gift note, and order history.
  • Payment metadata — Stripe handles all payments. We never receive or store card numbers; we retain only a Stripe reference, the last-four digits, and the amount, currency, and status of the transaction.
  • Support messages — anything you send us via the contact form, and any email correspondence.
  • Analytics events — anonymised page views and product events via PostHog, so we can improve the site. No third-party ad tracking.
  • Cookies — a small number of strictly necessary cookies for sign-in and cart state (see §10).

3. How we use it

  • Generate the personalised story text. The prompts we send to the language model include only the child’s first name, age, pronouns, chosen theme, and art-style — never their photo, email, or shipping address.
  • Generate the character sheet and page illustrations. The uploaded photo is sent to the image-generation model only for the character-sheet step; we never send the photo back to text-based LLMs.
  • Human-in-the-loop moderation and quality-check before printing.
  • Fulfil printed orders through print-on-demand partners (Lulu, Gelato) and their shipping carriers.
  • Send transactional emails: order confirmation, character-preview approval notices and reminders, shipping and tracking updates.
  • Prevent fraud and abuse (Cloudflare Turnstile on public forms).
  • Comply with tax, accounting, and legal obligations.

4. Photo policy

Uploading a photo is optional — if you describe your hero instead, we never receive or store a photo at all. When you do upload one, it is the single most sensitive thing you give us, and it is treated as such:

  • Consent required. You confirm at upload that you are the child’s parent or legal guardian, or that you have their guardian’s permission.
  • Private storage. Stored in a private, encrypted bucket that is not publicly listable; access is granted only via short-lived signed URLs (typically ≤15 minutes) to the specific job that needs it.
  • EXIF stripped on upload, so no GPS coordinates, camera serials, or timestamps travel with the file.
  • Never used to train AI models. Our image-model providers are configured with training opt-out; we do not use uploaded photos to fine-tune or train any model, ours or theirs.
  • Never shown on the printed book — the printer only ever sees the finished illustrated pages, never the raw photo.
  • Auto-deleted within 30 days by a daily job. You can also delete it earlier at any time from your account page.

5. Who we share data with

We do not sell personal data. We share the minimum necessary with the following processors:

  • Stripe — payments.
  • Lulu / Gelato — print-on-demand and shipping (they receive the finished PDF and the shipping address; never the raw photo).
  • Shipping carriers — chosen by our POD partners for delivery.
  • Resend — transactional email delivery.
  • PostHog — product analytics.
  • Cloudflare — Turnstile bot protection and CDN.
  • Supabase / Lovable Cloud — database, storage, authentication, and hosting.
  • AI model providers — story text and illustrations. All are contracted with training opt-out on the data we send.

We may also disclose data if required by law or to protect rights, property, or safety.

6. How long we keep it

  • Uploaded photo: ≤ 30 days from upload.
  • Order records & invoices: up to 7 years (tax and accounting obligations).
  • Finished book files (PDF): kept in your account so you can re-download the digital edition. Deleted on account closure.
  • Account & profile: until you delete the account (see §8).
  • Analytics events: 12 months, aggregated afterwards.

7. Children’s privacy

Our books are made for children, but our service is intended for adults 18+ (parents, guardians, gift-givers). We do not knowingly create accounts for or market to children under 13. In the U.S. this policy is designed to be consistent with COPPA; in the EU/UK with the GDPR’s guidance on children’s data. If you believe a child has created an account without a guardian, contact us and we will delete it.

8. Your rights

Wherever you are, you can:

  • Access & export your data — one-click from your Account page.
  • Correct any inaccurate profile or order data.
  • Delete your account — this anonymises order records we’re legally required to keep and removes everything else, including any remaining photo files.
  • Object to or withdraw consent for optional processing (e.g. analytics).
  • Lodge a complaint with your local data-protection authority (EEA/UK) or your state Attorney General (US).

EEA/UK (GDPR). Legal bases: performance of contract (making your book), consent (photo processing, marketing emails), legitimate interests (fraud prevention, product analytics), and legal obligation (accounting).

California (CCPA/CPRA). We do not sell or “share” personal information for cross-context behavioural advertising. You have the right to know, delete, correct, and to non-discrimination for exercising these rights.

9. Security

Encryption in transit (TLS 1.2+) and at rest. Row-Level Security in the database so one customer’s data is not readable by another. Webhook signature verification on every payment and print callback. Least-privilege access for staff. No system is perfect; if we ever detect a breach affecting your data, we will notify you within the timeframes required by applicable law.

10. Cookies & analytics

We use strictly-necessary cookies for sign-in and cart state, and a first-party analytics cookie (PostHog) to understand how the site is used. No third-party advertising cookies. See our Cookie Policy for details.

11. International transfers

Our processors operate globally. Where personal data is transferred outside the EEA/UK, we rely on the European Commission’s Standard Contractual Clauses (or equivalents) with our sub-processors.

12. Changes to this policy

We may update this policy from time to time. Material changes will be announced by email or an in-app notice at least 14 days before they take effect. The “Effective” date at the top of this page always reflects the current version.

13. Contact us

Privacy questions: privacy@onceuponahero.com. General support: /contact.