Privacy & Child Safety
Plain-English answers about your child’s photos and data — in clear terms, not legal ones. For the full legal detail, read our Privacy Policy.
Where your child’s photo goes
If you add a photo, here is exactly what happens to it — including every moment it briefly leaves Australia.
- Step 1
You add a photo (optional)
A reference photo is only needed for social and emotion books. Phonics readers never need one.
- Step 2
Safety-screened before it is stored
Every upload is checked by OpenAI’s moderation service in the United States before we store it. This is the first time the photo crosses the border.
- Step 3
Stored encrypted in Australia
The photo is encrypted at rest in Australian data centres — Supabase Sydney for the database and Supabase Storage (Sydney) for files. EXIF metadata is stripped on upload.
- Step 4
Sent overseas at the moment of generation
To make an illustration the photo goes to two named United States providers: Anthropic (Claude) reads it for appearance analysis, then the image provider — OpenAI, or Google Gemini as a fallback — draws from it. Your child’s name is never sent; their age and pronouns are.
- Step 5
The illustration returns to Australia
Only the generated illustration comes back. It is stored alongside the rest of your child’s data in Australia.
- Step 6
What the providers’ published terms say
We use each provider on its paid API tier, whose published terms state that data sent through the API is not used to train their models. We rely on those published terms; we cannot independently inspect their systems.
What we store, and where
Stored in Australia
Profiles, photos and books are stored in Australian data centres — Supabase Sydney (database) and Supabase Storage Sydney (files).
Encrypted at rest
Photos are encrypted at rest through the storage provider, and sensitive credentials are additionally encrypted with AES-256-GCM.
Metadata stripped
EXIF data — GPS location, device details and timestamps — is automatically removed from every upload. Stripping happens in the storage layer itself, so no upload path can skip it.
First names only
We collect a child’s first name only, and it is never sent to any AI provider — a placeholder goes in its place and the real name is re-inserted on our own servers.
Who processes data overseas — and what they keep
To screen uploads and to generate stories and illustrations, some data is sent to named AI providers in the United States. These transfers are transient, and we use these providers on their paid API tiers, whose published terms state that data sent through the API is not used to train their models. We rely on those published terms; we cannot independently inspect their systems.
| Provider | Location | What it receives |
|---|---|---|
| Anthropic (Claude) | United States | The story-text request (age, pronouns, level, topic — no photo, and the name replaced with a placeholder), and, for illustrated books, the reference photo for appearance analysis. |
| OpenAI | United States | Every uploaded photo, to safety-screen it before we store it; and the reference photo, to generate illustrations that resemble your child (our primary illustration provider). |
| Google (Gemini) | United States | The reference photo, to generate illustrations that resemble your child. Used as a fallback when the primary provider is unavailable. |
No reference photo is sent with story-text requests, and the child’s name is never sent to any AI provider — it is replaced with a placeholder before the request leaves our servers and re-inserted afterwards. Their age and pronouns are sent.
Is a photo required?
A photo is optional, and personalisation still works without one — we build the book around your child’s name, age and interests.
- Phonics readers never need a photo. Choose your child’s interests and reading level, and you’re ready to go.
- Social and emotion books use a reference photo so the child sees their own likeness in the illustrations. If you’d rather not add one, you can still create phonics readers.
Uploading a photo safely
A few simple choices keep an uploaded photo safe and easy to work with.
Do
- Use a clear, recent photo of only the child whose consent you have.
- Choose a plain background with the child’s face clearly visible.
- Upload good, even lighting so the likeness is easy to match.
Avoid
- School uniforms, name badges, or anything showing the child’s school.
- Home addresses, street signs, or other location clues in the background.
- Other children in the frame.
- A child’s face in an interest-reference image — those should show the interest only.
Deleting your child’s data
You can delete a child’s profile and its photo at any time from your account. When you do, the profile is removed from view immediately and enters a short grace period in case it was deleted by mistake. After 7 days, a background job permanently erases the profile and its photos. Permanent erasure cannot be undone.
Who needs to consent
Before a child’s photo is uploaded, the right person must consent. What that looks like depends on who you are.
Parents & carers
You confirm you are the child’s parent or legal guardian and consent to creating personalised resources for them.
Schools & educators
Obtain parent or carer consent before uploading a student’s photo, and collect first names only. You manage consent for the students in your account.
Therapists & clinicians
Obtain client or guardian consent in line with your professional obligations. You remain responsible for your clients’ personal information.
This page is a plain-English summary. For the full legal detail, including your rights under the Australian Privacy Principles, read our Privacy Policy. Questions? Contact us.