This Privacy Policy explains what information QuilloKit ("we", "us") collects when you use the QuilloKit app and related backend services (the "Service"), how we use it, who we share it with, and the choices you have. QuilloKit is intended for use by adults creating content for children — see our Terms of Service and the in-app Adult Use Notice for details.
1. Information We Collect
Account information
When you create an account, we collect your email address and a securely hashed password (we never store your password in plain text). We also assign your account a credit balance, which we track alongside a record of purchases and credit adjustments.
Story prompts and personalization details
To generate a story, you provide prompts and personalization details — for example, a child's first name, age, interests, a short description, or other details you choose to include so the story feels personal. This information is supplied by you, the adult account holder, never collected directly from a child. See the in-app "Personalization Information" note on the Personalize screen for a short version of this notice.
Photos (if enabled)
QuilloKit does not currently support uploading photos of a child. If we add that capability in the future, any photo will be uploaded by the adult account holder — never directly by a child — and used solely to help personalize that child's own stories, subject to an update of this Policy before the feature ships.
Generated content
We store the stories, illustrations, and narration audio generated through your account (including page text, image files, and audio files) so you can view and re-read them later. This content is stored on our hosting provider's infrastructure (see Section 3) and associated with your account.
Device and usage information
We collect limited technical information needed to operate the Service, such as a device-generated installation identifier (used to attach content created before you signed in to your account once you do), API request logs (timestamps, which endpoint was called, response status), and basic usage counts (e.g., how many stories or regenerations an account has used) for abuse prevention and rate-limiting. We do not currently use third-party analytics or advertising SDKs.
Payment information
If you purchase credits, your payment (card details, billing information) is handled entirely by the app store or payment processor (e.g., Google Play Billing) — we do not receive, process, or store your full payment card details. We only receive confirmation that a purchase occurred, a provider-issued transaction identifier, and the amount, which we use to credit your account and maintain purchase records.
2. How We Use Information
- To create and secure your account, and to let you sign in on multiple devices;
- To generate the stories, images, and narration you request, including sending your prompts to the third-party AI providers listed below;
- To store and display your generated content back to you;
- To process credit purchases and maintain an accurate balance and transaction history;
- To detect, prevent, and respond to fraud, abuse, or violations of our Terms of Service, including reviewing user-submitted content reports (see Section 6);
- To operate, maintain, secure, and improve the Service, including diagnosing technical problems.
We do not sell your personal information, and we do not use your story prompts or personalization details to train our own AI models.
3. Who We Share Information With
We share information only with the service providers ("processors") needed to operate QuilloKit, under their own respective privacy and security terms:
| Provider | Purpose | What they receive |
|---|---|---|
| OpenAI | Generates story text and illustrations | Story prompts, personalization details, and generated text/images |
| Cartesia | Generates narration audio (text-to-speech) | Story page text to be narrated |
| Render | Hosts our backend server, database, and generated file storage | All account and content data described above, at rest |
| Resend | Delivers transactional email (e.g., password reset codes) | Your email address and the email's content |
| Google Play Billing | Processes in-app credit purchases | Payment/billing details (handled entirely by Google, not received by us) |
We may also disclose information if required to by law, legal process, or a good-faith belief that disclosure is necessary to protect the rights, property, or safety of QuilloKit, our users, or the public — including a report of content that may endanger a child.
We do not share your information with third parties for their own marketing purposes.
4. Data Retention
- Account information is retained for as long as your account is active, and for a limited period after deletion as described in Section 5 below (e.g., to comply with legal, tax, or fraud-prevention obligations).
- Generated stories, images, and narration are retained for as long as your account exists, unless you delete a specific story yourself (in which case it is removed from your library and its files are scheduled for deletion) or you delete your account entirely.
- Content moderation / report records (see Section 6) may be retained longer than the underlying story, for as long as reasonably necessary for safety, abuse-prevention, and legal-compliance purposes.
- API/usage logs are retained for a limited operational window before being rotated out, except where retained longer as part of an active abuse investigation.
5. Deleting Your Account
You can delete your account at any time from Settings → Account → Delete Account inside the app. Deleting your account removes your personalization details, stories, characters, generated media, and account credentials from our active systems, subject to the limited retention described in Section 4 (for example, we may retain a minimal record of the deletion itself, or content-report records related to your account, where necessary for legal or safety reasons).
If you don't have the app installed or can't sign in, you can request deletion from any browser at /legal/account-deletion.html - no login required, just the email address on your account. This works the same way as the in-app option and takes effect immediately.
6. Content Reports
If you or another user reports a story as inappropriate, we collect the reported story's content, associated media links, and the account information of the story's creator in order to review the report. Report records are used solely for content-moderation and safety purposes and are retained as described in Section 4.
7. Children's Privacy
QuilloKit does not knowingly collect personal information directly from children. The Service is intended for use by adults; any information used to personalize a child's story (such as a first name or interests) is supplied by an adult account holder who represents that they are authorized to provide it, not collected from the child directly. If we become aware that a child has created an account or submitted personal information directly, we will take reasonable steps to delete it.
8. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. You can exercise most of these rights directly in the app (viewing/editing your stories and characters, or deleting your account); for anything else, contact us using the details below.
9. Security
We use industry-standard measures (such as password hashing and encrypted connections) to help protect your information, but no method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will make reasonable efforts to notify you (e.g., an in-app notice) before they take effect. The "Last updated" date above reflects the most recent revision.
11. Contact
For privacy questions, data requests, or account deletion requests, contact us at privacy@quillokit.com.