This Privacy Policy explains how we process personal information when you use the Social Narratives website and iOS app (together, the “Service”). The app creates personalised narratives from information a user provides about a situation and, optionally, a child profile. The Service is intended to be used by a parent, guardian, educator, or other adult authorised to act for a child; it is not designed for children to use independently.
1. At a glance
- The app does not require a user account, email address, password, or social-media login.
- Profiles, stories, settings, and downloaded story images are stored on the device. iCloud sync is enabled by default on first use, but can be turned off in the app’s settings.
- When you request a story, the request is sent to our AWS backend and then to OpenAI’s API to generate the text and, if selected, an illustration. We keep the backend job record for up to seven days so the app can retrieve the result.
- If you allow notifications, Apple provides a device push token. We use it solely to notify the device that a story job has completed or failed.
- We use Apple’s App Store for in-app credit purchases and subscriptions. We do not receive or store your payment-card details.
- You can optionally link a credit wallet to your Apple Account to restore eligible credits and subscriptions. We store a hash of Apple’s stable account identifier, not your Apple Account email address or name.
- If you join the website waiting list, we process your email address and recorded consent to send launch updates. You can unsubscribe at any time.
- We do not sell personal information, use the reviewed app code for targeted advertising, or include third-party advertising or behavioural-analytics SDKs in the app.
- The website uses Google Consent Mode. Google Analytics cookies are set only if you allow analytics through the cookie notice; before that choice, Google may receive limited cookieless consent-mode measurement pings. You can change your choice at any time through Cookie settings in the website footer.
2. Information we process
Information you choose to enter in the app
To create and personalise a story, you enter a situation and may select a child profile. A profile can contain a first name, age, pronouns, optional support needs, and optional avatar-related appearance choices, including skin tone, hair colour and style, eye colour, and glasses. The app sends the selected profile details, its internal identifier, preferred story language, illustration preference, and the situation with a generation request.
Support needs are optional, selected from a fixed list rather than entered as free text. They can include autism, ADHD, anxiety, sensory needs, communication needs, a preference for routines, difficulty with change, or emotional regulation. You can create a story without selecting any support need.
We ask you to enter only the information needed for the story. In particular, please do not include a child’s full address, school identifiers, medical-record numbers, contact details, or detailed medical history in the situation field.
Generated content
We process the generated title, story text, illustration prompt, and, where requested, the generated illustration. The app stores this content with the related situation, selected profile reference, language, favourite/read status, and creation/update timestamps.
Device and service information
The app creates a random installation identifier and request identifiers. These are not an account name, but they are used to associate a story job and its status with the same app installation. We also process job status, read status, timestamps, error messages, and technical information needed to operate the generation service.
Notifications
If you grant notification permission, Apple issues a device push token. The app stores the token locally and registers it with our backend together with the installation identifier, iOS platform, and sandbox/production environment. A completion notification may include the generated story title; notification content may therefore be visible on a device’s lock screen or notification centre depending on the device settings you choose.
Settings and local preferences
The app stores the selected interface/story language, text-to-speech voice and reading speed, iCloud-sync preference, most recently selected profile, illustration preference, and related local app state. The reviewed app code does not collect precise location, contacts, camera roll, microphone recordings, or health data directly from iOS system frameworks.
Credits, purchases, and Apple Account linking
The app creates a random credit-wallet identifier, installation credential, and Support ID to operate your credit balance and help us locate a wallet for support. If you choose to link the wallet to your Apple Account, we verify Apple’s identity token and store only a SHA-256 hash of its stable subject identifier. We do not store the raw Apple subject identifier, Apple Account email address, or name for this purpose.
For credit-pack purchases and subscriptions, we receive and process the App Store transaction identifier, original transaction identifier where applicable, product identifier, purchase time, subscription expiry or renewal time, App Store environment, credit allocation and balance, and refund or revocation status. We verify the signed transaction with Apple and do not store the raw signed transaction. Apple may also send us server notifications about subscription purchases, renewals, refunds, and related events. We keep an operational ledger of credit grants, spending, refunds, account changes, and support adjustments. We do not receive or store your payment-card number or other payment-method details.
Website analytics
Google Consent Mode is enabled on the website. Before you allow analytics cookies, Google Analytics may receive limited cookieless measurement and consent-state pings, such as page information, timestamp, browser/device information, and a consent signal. These pings do not use Google Analytics cookies or a persistent analytics identifier. If you allow analytics, Google Analytics may additionally process pages viewed, interactions, browser and device information, approximate location derived from IP address, and an analytics cookie identifier. We use this only to understand use of the public website. We do not enable Google Signals or advertising-personalisation features.
Waiting list
If you join the waiting list, we process the email address you provide, your consent checkbox response, the submission time, and limited technical submission information supplied by Formspree. We use this only to send Social Narratives launch news and early-access updates.
3. Why we process information and our legal bases
Where the GDPR, UK GDPR, or similar law applies, we process information for the following purposes:
- Providing the Service: creating, delivering, storing, retrieving, printing, sharing, and synchronising stories; operating on a contract or steps taken at your request before entering a contract.
- Optional support needs: where you select one, tailoring the requested story and making the related job result available to your app. Selecting an optional support need and then submitting a story request is your explicit, voluntary request for us to process that selection for this limited purpose. You may remove the selection at any time; where applicable law requires consent for this type of information, we rely on that explicit consent.
- Operating and protecting the Service: preventing duplicate jobs, troubleshooting failures, securing the backend, maintaining logs, and responding to support requests; on our legitimate interests in operating a reliable and secure service.
- Credits, purchases, and subscriptions: operating your credit wallet, verifying and delivering App Store purchases and subscriptions, restoring eligible purchases, preventing fraud and duplicate delivery, handling refunds or revocations, and providing support; on performance of our contract with you and our legitimate interests in preventing fraud and protecting the Service.
- Financial and operational records: retaining records needed for accounting, tax, refund, fraud-prevention, audit, and legal-claim purposes; to meet applicable legal obligations and on our legitimate interests in operating and protecting the Service.
- Notifications: delivering an optional notification that a job has completed or failed; based on your device-level permission and, where required, your consent.
- Website analytics: using analytics cookies and website measurement only after your consent, which you can give, refuse, or withdraw through the cookie notice and Cookie settings.
- Waiting-list updates: sending launch news and early-access updates by email; based on your consent. You can withdraw consent at any time by contacting us or using an unsubscribe option in an update.
- Legal obligations and claims: complying with applicable law and establishing, exercising, or defending legal claims.
An optional support-need selection, such as autism, may be sensitive personal information when connected to a child. You decide whether to select it. Selecting it and then submitting a story request is an affirmative action that authorises our limited processing of that selection to tailor the requested story and operate the short-lived generation job. We do not use it for advertising, to make medical or educational decisions, or to create a server-side child profile. You may remove a selection at any time, and should select one only if you are authorised to provide it and it is helpful for the requested story.
4. How the Service uses information
When a story is requested, the app sends the situation, preferred language, whether an illustration is requested, and—if a profile is selected—the profile’s first name, age, pronouns, selected support needs, internal profile identifier, and optional appearance descriptors to our backend. The backend queues the task, calls OpenAI to generate the story, and, if chosen, calls OpenAI to generate the illustration. Appearance descriptors are used only to help describe the child for an illustration.
The backend stores the request and generated response temporarily so the app can check status, retrieve a completed result, cancel a request, reconcile read status, and retrieve a generated image. It does not maintain a separate server-side child profile. The app then saves the completed story locally. A PDF created for printing or sharing is made in the device’s temporary directory, marked to be excluded from backup, and the app removes stale PDF exports after 24 hours.
5. Where information is stored and how long we keep it
On your device and in iCloud
Profiles, stories, images, and settings are stored in the app’s local SwiftData store. iCloud/CloudKit sync is enabled by default on first use. When enabled, this local app data is synchronised to the user’s private iCloud container associated with the user’s Apple Account. You can turn sync off in Settings. Turning sync off prevents future sync; it does not itself guarantee deletion of information already stored in iCloud. You can delete profiles, stories, or all local app data from the app’s settings. Apple’s own retention and deletion practices apply to data in iCloud.
Our AWS backend
- Story-job records: the record includes the request and generated response. It is stored in Amazon DynamoDB with a configured time-to-live of seven days from creation, after which it is automatically deleted. DynamoDB TTL deletion is asynchronous, so records may remain for a limited period after the seven-day expiry time while AWS completes deletion.
- Generated illustrations: stored in a private Amazon S3 bucket with server-side encryption and a seven-day lifecycle-expiration rule.
- Queue messages: the queue contains a job identifier and has a four-day retention period.
- Service logs: production CloudWatch log groups are configured for 14 days; development logs are configured for seven days. The application redacts story text, prompts, image data, request/response JSON, API keys, tokens, and similar sensitive fields from its structured application logs. Logs can still contain pseudonymous job IDs, installation IDs, route information, timestamps, status, and technical error information.
- Push registrations: the device-registration table contains installation ID, push token, platform, environment, and created/updated/last-seen timestamps. These records do not currently have an automatic expiry period. We delete or replace them when the token is replaced or becomes unusable, and on a verified deletion request or where no longer needed for the notification service.
- Credit wallets and purchase records: we retain the credit-wallet record, App Store transaction and subscription information, and credit ledger while needed to provide the credit system, prevent fraud or duplicate delivery, handle refunds or revocations, provide support, and meet accounting, tax, and legal obligations. If you delete your credit account in the app, we disable the wallet, discard its remaining credits, and remove its Apple-account and Support-ID recovery links. The credit ledger remains only as anonymous operational audit data and can no longer be resolved through those recovery links.
Waiting-list submissions
Formspree retains waiting-list submissions according to the plan and account configuration that applies to our form. We may retain the email and consent record in our support mailbox until you unsubscribe or ask us to delete it, and otherwise for no longer than 12 months after the first public launch notice.
6. Service providers and disclosures
We disclose information only as needed to run the Service, comply with law, or protect rights and safety. The current architecture uses the following providers:
- Amazon Web Services (AWS): API Gateway, Lambda, DynamoDB, SQS, S3, CloudWatch, and Secrets Manager host and operate the generation backend. The configured API endpoints are in AWS US East (N. Virginia).
- OpenAI: receives the generation input and returns the requested story and, if selected, illustration. OpenAI states that API data is not used to train its models by default and that, except for certain features/endpoints, API inputs and outputs may be retained for up to 30 days for service provision and abuse monitoring. See OpenAI’s Enterprise Privacy information.
- Apple: provides iCloud/CloudKit when sync is enabled, Apple Push Notification service (APNs) when notifications are enabled, Sign in with Apple if you choose to link a credit wallet, and App Store purchase, subscription, refund, and transaction-notification services. Apple processes payment details under its own terms and privacy practices.
- Google Analytics: processes optional website analytics only after you allow it through the cookie notice. Google may process analytics information outside your country; see Google’s Privacy Policy for more information.
- Formspree: processes website waiting-list submissions and sends notification emails to us. Formspree hosts its service with AWS in the United States.
- GitHub Pages: hosts the public website and may process limited technical request data needed to deliver it.
We may also disclose information to professional advisers, regulators, law-enforcement bodies, courts, or other third parties when required by law or necessary to protect the Service, our users, or others. We do not sell personal information or disclose it for cross-context behavioural advertising.
7. International transfers
Using the Service may involve processing outside your country, including in the United States through AWS, OpenAI, Formspree when you join the waiting list, and GitHub Pages when you visit the website. Where a transfer of personal information from the EEA, UK, or Switzerland requires a transfer mechanism, we use an applicable adequacy decision, standard contractual clauses, the UK Addendum/IDTA, or another lawful mechanism, together with supplementary safeguards where appropriate.
8. Security
We use technical and organisational measures designed to protect information, including HTTPS endpoints, restricted S3 access, S3 server-side encryption, Secrets Manager for backend credentials, and log-redaction controls. No method of transmission or storage is completely secure. Please protect your device, Apple Account, and any shared PDFs, and avoid including more personal information in a request than is necessary.
9. Your choices and rights
You can manage local profiles and stories in the app, turn iCloud sync on or off, manage notification permission in iOS Settings, and delete local data through the app. You can also delete your credit account through the app; this permanently disables that wallet and discards its remaining credits, and does not cancel an App Store subscription. You can manage or cancel an App Store subscription through your Apple Account settings. Deleting local data does not immediately delete an already-created backend job record; those records expire automatically after the period described above. You can withdraw website-analytics consent at any time through Cookie settings in the website footer, and withdraw waiting-list consent by contacting us or using an unsubscribe option in an update. If you are in the EEA, UK, or another jurisdiction with applicable rights, you may have the right to request access, correction, deletion, restriction, portability, or to object to certain processing; where processing is based on consent, you may withdraw consent at any time without affecting prior processing.
To exercise a right, contact support@socialnarrative.app with the subject line “Privacy request.” Because the Service has no user account, we may need information that helps us identify the relevant installation or request before we can act. We may request reasonable verification and will explain if a request cannot be fully fulfilled because data is no longer available or a legal exception applies. You may also lodge a complaint with the data-protection authority in your habitual residence, place of work, or place of the alleged infringement.
10. Children
Adults are responsible for deciding whether they have authority to enter a child’s information and for using the minimum information necessary. We do not knowingly create accounts for children, because the app does not use accounts. If you believe that information about a child has been submitted without appropriate authority, contact us so that we can assess and address the request.
11. Website data and cookies
The website uses a small local-storage setting to remember your analytics choice. We do not load Google Analytics, use advertising pixels, remarketing, or cross-context behavioural advertising unless you allow analytics.
Your cookie choices
When you first visit the website, you can choose Allow all or Essential only. There are currently no advertising, marketing, or personalisation cookies on the website, so Allow all enables only Google Analytics cookies. Essential only does not load Google Analytics or set Google Analytics cookies or persistent analytics identifiers. You can change your choice at any time through Cookie settings in the website footer.
Essential storage
We store your choice in your browser’s local storage under social-narratives-analytics-consent. This is necessary to remember whether optional analytics may load and is not used to track you across websites. It remains until you change the choice or clear your browser storage.
Optional analytics cookies
Only after you allow analytics, Google Analytics 4 may set the cookies below. We do not enable Google Signals, advertising-personalisation, remarketing, or advertising cookies.
| Cookie | Purpose | Default duration |
|---|---|---|
_ga | Distinguishes visitors for website analytics. | Up to 2 years |
_ga_<container-id> | Persists website analytics session state. | Up to 2 years |
Browser limits may shorten these durations. Google documents its GA4 cookie use and default durations here. Selecting Essential only through Cookie settings prevents Google Analytics from loading on future page visits and removes Google Analytics cookies that are accessible from this website.
The public website is hosted on GitHub Pages. GitHub and supporting internet service providers may process limited technical request data, such as IP address, browser information, requested URL, and time of request, to deliver and secure the website. The Service may link to third-party sites, including Apple, Google, and OpenAI. Their privacy practices are governed by their own notices.
12. Changes to this Policy
We may update this Policy when the Service or legal requirements change. We will post the updated version here and revise the effective date. If a change materially affects how we process information, we will provide additional notice where required by law.
13. Contact
Huszár Balázs e. v.
Harodik u. 60.
8500 Pápa
Hungary
support@socialnarrative.app