How Genesis handles information
Draft of September 4, 2026
Genesis (“we”, “us”) is a storybook maker for children, operated by its author, Blaise. This notice explains what information the app creates, where it is kept, who else ever sees any of it, and how a parent can delete it. It is written to meet the Children's Online Privacy Protection Act (COPPA) and its rule at 16 CFR Part 312, and the Kids Category rules of the app stores we intend to publish in.
1.Children use this app, and we designed for that
Genesis is directed to children under 13 (and to the adults who read with them). We therefore treat everyone who uses it as a child for privacy purposes and collect as little as the app can run on. There is no photo upload, no chat, no comments, no public sharing, and no advertising.
2.What information the app creates, and where it lives
Kept only on your device (browser storage for this site: localStorage, IndexedDB and the Cache API). We have no copy and no access:
- The creator profile: a first name or nickname, an age band, hair/skin/color/interest choices, and the portrait painted from those choices.
- Every saved story: title, text, pictures, coloring pages, the choices that made it, and the date saved.
- The Story Book cover design, badges, Word Lab progress, and which recent nights a story was read.
- Cached read-aloud audio clips of story text.
- A five-minute “grown-up check passed” marker (session storage) after the parental gate.
Sent to a service provider only to perform the task, then not kept by us:
- To write a story — the words entered (first name, character word, companion, virtue, an optional adjustment note) and the age band go to Anthropic (Claude API). Before sending, the app strips control characters, caps length, and removes email addresses, phone numbers and street addresses.
- To paint a page — the page's scene description, the character description, and the character sheet image go to Replicate (Flux image models).
- To read aloud, when enabled — the page's text goes to ElevenLabs. When not enabled, the device's built-in speech is used and nothing is sent.
- To fix a reported page — the story and your note go to Anthropic; the title, page number and note are also written to our hosting provider's runtime log (Vercel) so the problem can be fixed.
Each provider processes these inputs under its own API terms. We do not sell any information, and we do not use it for advertising or profiling.
Not collected: photographs or video of anyone; precise location; contact lists; persistent identifiers for advertising or analytics. The app contains no third-party analytics, advertising or social SDK. Our hosting provider keeps ordinary web-server logs (IP address, request path, timestamp) for its standard period for security and operation.
3.Accounts and parental consent
Without an account, nothing identifies a child or a family to us, and nothing persists beyond the device. A parent may create an account with a parent email address: a sign-in link is sent to that address by our email provider (Resend); the address is used to derive an account id and is not stored on our servers. Once signed in, the Story Book — the creator profile and the saved stories with their pictures — is stored under that account id with our hosting provider (Vercel) so it can be restored on another device, and the parent can delete all of it from the account page. We will obtain verifiable parental consent before any personal information from a child is stored on our servers, by a method permitted under 16 CFR §312.5(b).This notice will be updated and re-dated when the consent method is chosen.
4.Parents' rights: review, delete, refuse
Because all information is on your device today, you can review it in the app and delete it yourself, completely:
- Remove one story from the Story Book with the × beside its chapter.
- Remove everything — creator, stories, cover, badges, cached audio — by clearing this site's data in your browser (steps at For parents).
When accounts are enabled, a parent will be able to review the account's data, delete the account and all of its content, and refuse further collection, from within the app and by writing to us; we will verify that the request comes from the parent before acting on it (§312.6).
5.Retention
We keep personal information only as long as reasonably necessary for the purpose it was collected for, and then delete it. Today: on-device data stays until you delete it; provider API inputs are governed by each provider's retention terms; fix-report log lines follow our host's standard log retention. When accounts are enabled: account data is deleted on request and within a stated period after an account is closed.
6.Security
All traffic between the app and our servers, and between our servers and providers, is encrypted in transit (HTTPS). Every request the app makes is validated before any provider is called; malformed or over-long input is cleaned or refused. Provider API keys live only on our servers, never in the app.
7.Outside links and purchases
Genesis shows a “for grown-ups” check (hold to continue, then a spelled-out arithmetic question) before any link that leaves the app and, when enabled, before any purchase or account action. The only outside link planned today is to a print shop for a hardcover Story Book (Shopify), which has its own privacy policy. Payments are not open yet; when they open, a purchase is completed on Stripe's own hosted page — Stripe receives the grown-up's payment details and we receive only an opaque account id and the plan bought, never a card number.
8.Changes
When this notice changes materially — in particular when accounts, sync or payments are enabled — we will re-date it, and where the change involves new collection from children, obtain fresh parental consent before it applies.
9.Contact
Questions or requests: hello@genesisstorybook.com.
This is a draft written to describe the software honestly; it has not been reviewed by a lawyer and is not legal advice. The plain-English companion is For parents; the terms of use are at Terms.