ocoboco
Privacy Policy
ocoboco creates personalized, illustrated, interactive stories about a subject you choose — an invented character, yourself, or someone you know. A grown-up describes the subject; our service uses AI to weave a short story that plays in the browser. This policy explains what information we collect, how we use it, who we share it with, and the choices you have — including how we handle information about a child when a story happens to be about one.
1. Who we are & the scope of this policy
ocoboco (“ocoboco,” “we,” “us”) is a service operated by [LEGAL ENTITY NAME / OPERATOR], [ENTITY TYPE & JURISDICTION], located at [BUSINESS ADDRESS]. This policy applies to the ocoboco website, story studio, and story player at ocoboco.co and related subdomains (the “Service”).
United States only. The Service is offered to and intended for users in the United States. It is not directed to, and we do not knowingly onboard, users in the European Union, United Kingdom, or other regions. Do not use the Service if you are outside the United States.
The Service is currently in a limited, invite-only beta. Access is gated by an approved-email list, and features described here may change.
2. The short version
- We collect the grown-up's email (to sign you in) and the brief you write about your story's subject (first name, optional age, interests, and other details you choose to add) so we can generate a story.
- You may optionally upload a photo or drawing as a visual reference; if you do, it is stored and analyzed by an AI vision provider to guide the artwork.
- Stories are generated by third-party AI providers. The brief text is sent to them to create the story, images, and narration.
- We use analytics and error-tracking on the grown-up studio. We deliberately keep third-party tracking scripts away from the story player.
- We do not sell your data, and we do not use personal information for advertising or to build advertising profiles.
- You can delete a story (and the information in it) at any time, and we honor a retention limit for inactive stories.
3. Information we collect
3.1 Account information
When a grown-up creates an account, we collect and store:
- Your email address (used for passwordless “magic-link” sign-in, or provided by Google if you sign in with Google).
- An account identifier, your plan tier, and account role, plus the date you created the account.
- If you were invited via a share link, the referral source of your signup (which shared story led you to us).
We do not collect a name, phone number, or physical address at signup, and we do not collect payment information (the Service has no paid billing in this release — see §12).
3.2 The story brief (information about a child)
To generate a story, you fill in a short brief. You choose how much to provide. Fields include:
- Child's first name (required).
- Age in years (optional; used only to tune vocabulary and pacing).
- Pronouns (optional).
- Interests the child loves, and topics to avoid (optional short lists).
- An optional comfort item, a cameo (the name of a sibling, pet, or friend to include), a setting, a lesson, and a personal dedication message.
Please provide only a first name and keep free-text fields free of sensitive information. Do not include last names, addresses, birthdates, health information, or other sensitive personal details.
3.3 Uploaded reference images (optional)
You may optionally upload an image (a photo or a drawing) as a visual reference for a character. If you do:
- The image is stored in our cloud object storage (Cloudflare R2).
- The image is sent to a third-party AI vision provider (OpenRouter) which analyzes it to produce a written description that guides the generated artwork.
- The analysis produces a written text description only. We do not use the image for facial recognition, to generate a biometric identifier or template, or to identify or authenticate any individual, and we do not sell or share it for advertising.
3.4 Content we generate for you
When we compile a story, we create and store, on your behalf: the story text, illustrated scenes, character portraits, cover art, and audio narration (together, a “story tape”). The child's first name and your dedication are embedded in the finished story tape. We may also retain short character “memory” notes so recurring characters stay consistent across stories.
3.5 Usage, analytics & referral data
- On the grown-up studio, we use PostHog to understand how the studio is used (e.g. when a story is commissioned, and which occasion/length options were chosen). Analytics events are keyed to your account but do not include the child's name or age. Session-replay input masking is enabled, and fields containing a child's name are masked.
- We record a share funnel for shared stories (e.g. link shared, story opened, started, completed) to understand how sharing works, and a referral token so we can credit the story that referred a new signup.
- The child-facing player does not load PostHog or other third-party analytics scripts. It only sends a first-party, anonymous crash report if the player errors (see 3.6).
3.6 Diagnostic & error data
- We use Sentry to capture software errors so we can fix them. In the grown-up studio, an error report may include your account id and email to help us reproduce the problem. Personally-identifying data collection is otherwise disabled.
- If the story player crashes, it sends a first-party error report (error message, technical stack, and page URL) tagged with a temporary, per-page-load anonymous id that is not tied to any account or durable identifier. We forward this to Sentry to diagnose playback problems.
3.7 Technical & device data
Like most websites, our hosting and content-delivery provider (Cloudflare) automatically processes technical data such as IP address, browser type, and request metadata to serve the site, provide security, and prevent abuse.
3.8 Cookies & local storage
Our own application does not set tracking cookies. We use your browser's local storage to remember preferences (such as audio, volume, and theme settings), an onboarding flag, and a referral token. On the grown-up studio, the PostHog analytics SDK may set its own cookies or local-storage entries; we honor your browser's “Do Not Track” signal for analytics.
4. How we use information
- To provide the Service — generate, store, play back, and let you manage and share stories.
- To communicate with you — send the sign-in magic link and a “your story is ready” notification (see §7).
- To operate, secure, and improve — analytics, error diagnosis, abuse prevention, and understanding which features are useful.
- To keep content safe — we apply automated and provider-level safety measures to generated content. These measures are limited and are not a substitute for an adult reviewing a story before sharing it with a child (see the Terms).
- To comply with law and enforce our Terms.
We do not use the child's information, or content about the child, for targeted advertising, and we do not sell or rent personal information.
5. Children's information (our approach)
The Service is a general-audience creative tool for adults; it is not directed to children. You can create stories about invented characters, yourself, or people you know — who may or may not be children. Because a story can be about a child, we take deliberate steps to minimize and protect any information about a child that an adult chooses to provide:
- Adults provide the information. The account holder is an adult who accepts our Terms and attests they have the rights to the content they provide (and, where a story features a child, that they are the child's parent or legal guardian or have that guardian's permission). Children do not create accounts or provide information to us directly.
- Terms accepted up front. When you create your account you accept our Terms and confirm you have the rights to any content you upload. We record this acceptance (who, when, and the policy version).
- Data minimization. We ask for a first name only, an optional coarse age, and short optional details — no last name and no birthdate.
- No behavioral advertising and no sale of personal information.
- Deletion & retention. You can delete a story and the information in it at any time, and we auto-delete inactive stories (see §9).
We do not knowingly collect personal information directly from a child under 13. If you believe a child has provided us information directly, or that a child under 13 has used the Service to create an account, contact us at the address in §12 and we will delete it.
6. AI generation & the providers who receive story information
Stories are generated by artificial intelligence. To create your story, we send the brief text (and any uploaded reference image) to third-party AI providers that generate the words, artwork, and narration. These providers process the information to return generated content to us. We select providers whose terms permit our use, and we do not authorize them to use your content to train their models beyond what is necessary to provide their service to us [CONFIRM PER PROVIDER — COUNSEL].
7. Email
We use Resend to send transactional email: your passwordless sign-in link, and a “your story is ready to play” message that includes the child's first name, the story title, and a private link to play the story. We do not send marketing email in this release.
8. How we share information (subprocessors)
We share information only with service providers (“subprocessors”) who help us run the Service, under contracts that restrict their use of the information. We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer. The subprocessors we use are:
| Provider | Purpose | Information it receives |
|---|---|---|
| Supabase | Accounts & database | Email, account identity, story & brief metadata (child first name, age, brief text) |
| Cloudflare (R2, Pages, network) | Storage, hosting, security | Finished story tapes (incl. child name & dedication), audio, images, uploaded reference images; technical/IP data |
| Fly.io | Application compute | Processes all of the above transiently to run the app |
| Anthropic (Claude) | Story writing (AI) | Brief text: child name, age, interests, avoid list, setting, lesson, dedication |
| OpenRouter | AI model gateway & image analysis | Model prompts; uploaded reference images for visual analysis |
| fal.ai | Image & sound generation (AI) | Text prompts derived from the story and characters |
| ElevenLabs | Narration text-to-speech (AI) | Story text to be narrated |
| Resend | Transactional email | Recipient email, child first name, story title |
| PostHog | Product analytics (studio only) | Account-keyed usage events (no child name/age) |
| Sentry | Error tracking | Error diagnostics; studio errors may include account id/email; player errors are anonymous |
| Optional sign-in (OAuth) | Email/identity, only if you choose Google sign-in | |
| Paddle | Billing (not active in this release) | Would process payment/customer data only if paid billing is turned on later |
9. Public share links, retention & deletion
Share links
A finished story is reachable only through a private link containing an unguessable identifier. We never list, index, or make stories searchable, and shared story pages carry a “no-index” instruction so search engines do not list them. Sharing is off by default: until you choose to share a story, its social preview is not personalized with the child's name. Anyone who has the link can open the story without signing in, so share links only with people you trust. You can revoke a share link at any time, after which it stops opening the story for everyone; note that because content is briefly cached by our content-delivery network, revocation may not be instant.
Retention & deletion
- You can delete any story at any time. Deletion removes the story record and its associated assets (audio, images, and the finished tape) from our storage.
- To minimize how long we hold a child's information, we automatically delete a story and its brief after 12 months of inactivity. “Inactivity” means the story has not been opened, played, or edited in that period — stories you keep using are not deleted. We will notify the account holder by email before an inactive story is removed, so it can be kept or downloaded.
- Account and diagnostic data are retained as needed to operate the Service and meet legal obligations, then deleted or de-identified.
10. Security
We use industry-standard measures to protect information, including encrypted transport, access controls, and reputable infrastructure providers. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. Your choices & rights
- Access & deletion. You can view and delete individual stories in your account at any time. To request deletion of a specific child's information across all of your stories, or deletion of your entire account and all associated data, email us at privacy@ocoboco.co and we will process it. You may also request access to, or correction of, your account information at that address.
- Analytics. We honor “Do Not Track.” You may also use browser controls to limit cookies/local storage on the studio.
- State privacy rights. [FOR COUNSEL — insert applicable US state-law rights (e.g., California/CCPA) disclosures and request mechanism.]
12. Billing
This release of the Service has no paid billing and does not collect payment information. If we introduce paid features later, we will update this policy and provide the required payment and billing disclosures before charging anyone.
13. Changes to this policy
We may update this policy. If we make material changes, we will update the “last updated” date and, where appropriate, notify account holders. Continued use after an update means you accept the revised policy.
14. Contact us
Questions, requests, or concerns about privacy: privacy@ocoboco.co · [LEGAL ENTITY NAME / OPERATOR, BUSINESS ADDRESS].