Toldbook Privacy Policy
DRAFT for review: not yet published. Written from what the app does as of 2026-10-03. Items in [brackets] need filling in. Have a lawyer review it before launch, especially the children's-privacy sections (COPPA) and any state laws (for example California's CCPA/CPRA). Keep it in sync with
docs/security/DATA_RETENTION.mdand the code.
Effective date: [date] Who we are: [Company legal name] ("Toldbook", "we", "us"), [mailing address]. Questions: [privacy contact email].
Toldbook helps families record spoken stories about their children through the year and turn them into a printed book. This policy explains what we collect, why, who helps us, and the choices you have. In short: your family's stories belong to your family. We use them only to run Toldbook and make your books. We never sell them, never use them for advertising, and never let anyone train AI on them.
Who uses Toldbook
Toldbook is for adults: parents and the family members and friends they invite. Children don't have accounts and don't use the app. A parent or guardian creates a child's journal and decides who can join it.
Toldbook is available in the United States.
What we collect
From you, when you use Toldbook:
- Your account: your name as you'd like it shown (for example "Mom" or "Grandma Jo"), and the email address that Sign in with Apple shares with us. That may be a private relay address if you choose "Hide My Email". We never see your Apple password.
- Your relationship to the child (for example "Dad" or "Nana"), so the book can say who told each story and prompts can fit you.
About the child, from the parent or guardian (and from family they invite):
- The child's first name, optional nickname, and optional birthday. The birthday is used only to suggest age-appropriate prompts.
- The child's people, if you add them: names and how they're related (for example "Theo, brother" or "Biscuit, dog").
- Little facts, if you add them: interests, activities, favorites, dislikes, places. We use them to personalize prompts and to spell names and places correctly.
The stories themselves:
- Voice recordings of the stories you tell. Before upload, the app evens out the volume. The recording isn't otherwise changed.
- Transcripts and story text: the words of each recording, any edits you make, titles and chapters.
- Photos you add to a story. Before a photo leaves your phone, the app removes its hidden details, including location (GPS), camera and date information.
- Who's in a story: names you tag.
- Follow-up questions: if automatic write-ups are on, we may suggest one question after a story so you can add more, and keep it as a prompt for you until you answer or dismiss it.
When you order a book or copies:
- The shipping name and address, and what you ordered. During our beta, books are free and we don't collect payment details. When we start charging, payments will be handled by [payment provider]; we won't see or store your full card number.
We don't collect: your contacts, your location, advertising identifiers, or browsing activity. Toldbook has no ads and no third-party analytics or tracking.
How we use it
- To run Toldbook: save your stories, share them with the family members you invite, show this week's prompt, and send the weekly reminder you chose. The reminder is scheduled on your phone.
- To write up stories, if the journal's owner has turned this on (see below).
- To make and ship the books you order.
- To keep Toldbook secure, fix problems, and respond to you.
We don't sell or rent personal information, and we don't share it for advertising.
Automatic write-ups (AI)
The journal's owner decides whether stories are written up automatically. It's off unless the owner turns it on, and they can turn it off at any time in the Family tab. Family members who join are told when they join.
When it's on:
- The recording is sent to OpenAI to be turned into text.
- The transcript, along with the child's first name, the names of family and the child's people, and places you've added (so names come out spelled correctly), is sent to Anthropic (Claude) for light tidying. Filler words and false starts are removed, and your own words are kept. Anthropic also suggests a title, a chapter, who's in the story, and one follow-up question.
- Both companies process this only to provide the write-up to us. They don't use it to train their AI. [Confirm the zero-data-retention status for each provider before publishing. If it isn't granted: "They may keep it for up to 30 days to detect abuse, then delete it."]
- You can always see the original transcript, restore it, or change any word.
When it's off: your phone transcribes the recording itself using Apple's on-device speech recognition, and nothing is sent to an AI provider.
Who else handles your information
We use a small number of service providers, only to run Toldbook:
| Provider | What for | What they receive |
|---|---|---|
| Supabase | Database, file storage, sign-in, and our server functions | Everything stored in Toldbook, kept in private storage (region: [Supabase project region]) |
| Apple | Sign in with Apple; on-device speech recognition when write-ups are off | Sign-in only; on-device transcription stays on your phone |
| OpenAI | Transcription, only if write-ups are on | The recording |
| Anthropic | Light tidying and suggestions, only if write-ups are on | The transcript plus the names and places described above |
| RPI Print ([confirm legal name]) | Printing and shipping books | The book's pages (stories, photos, QR codes) and the shipping address |
We may also disclose information if the law requires it, to protect someone's safety, or as part of a merger or sale of the business. In that last case this policy would continue to apply to your data, and we would tell you first.
Sharing within your family
What you record is visible to the people who are members of that child's journal: the owner, and anyone the owner invites with a code. Owners decide whether each person can add stories or only listen. QR codes printed in the book link to the recordings, so anyone holding a printed book can listen to its stories. [Describe the QR access rules once the short-link service is built.]
Children's privacy
Toldbook collects information about children (their name, birthday, photos, and stories told about them) from their parents or guardians, not from children. The parent or guardian who creates a child's journal controls it:
- They choose who can see and add stories.
- They can review everything about their child in the app at any time, and export it (Account → Export My Stories).
- They can correct or delete any story, photo or detail, or delete the child's whole journal, and with it every story, recording and photo.
If you believe a child has given us information directly, contact us at [privacy contact email] and we'll delete it.
How long we keep it
We keep your family's stories for as long as your account or the child's journal exists, because they are the source of your books. Book files are deleted 90 days after a book ships. Shipping addresses are removed from orders 1 year after delivery. Recordings on your phone are deleted once they're safely uploaded. Backups roll off within 7 days of a deletion. Details: [link to the published retention policy].
Your choices and rights
- See and export your stories, recordings and photos: Account → Export My Stories.
- Correct anything: edit a story's words, title, chapter, photo or people at any time.
- Delete a story, a photo, a child's journal, or your whole account in the app: Account → Delete Account. When you delete your account, you choose for each shared journal whether to hand it to another family member or delete it, and whether your own stories stay.
- Turn off automatic write-ups (owners), or the weekly reminder.
- Depending on where you live, you may have other rights, such as asking what we hold about you. Contact [privacy contact email] and we'll respond within [30] days. We won't treat you differently for using your rights.
Security
- Private storage: stories, recordings and photos are stored privately and are only ever shown through short-lived links.
- Access rules: these are enforced on our servers for every request, not just in the app, and we test them regularly.
- Encryption: data is encrypted in transit.
- Sign-in: handled by Apple.
No system is perfectly secure. If we ever learn of a breach affecting your information, we'll notify you as the law requires.
Changes
If we change this policy in a way that matters, we'll tell you in the app before the change takes effect. The date at the top shows the latest version.
Contact
[Company legal name], [mailing address], [privacy contact email].