stori

Privacy

stori is a narrated-story app operated by Frederick James. This notice explains the current app and story service. Updated 17 September 2026.

Information on your device

The first name you optionally enter, preferences, saved stories and downloaded audio are stored on your device. The first-name setting is not included in generation requests. The app creates a random credential in Keychain; a hash of it identifies your credit balance.

Your cloud library

A parent can use Sign in with Apple to recover stories and narration on another device or after reinstalling. We verify Apple’s identity token and retain a hashed account identifier to connect your library and credit identity. We do not request your name or email from Apple. Your device credential authenticates library requests; downloaded stories remain available offline.

Making a story

Before the first generation, a parent or guardian must accept the data-protection notice on this device. The editor can be used before acceptance, but story inputs are not sent for generation until permission is given. When a story is requested, your idea, selected animal, story length, style and voice are sent to our Cloudflare-hosted service. OpenAI processes the story request and generated text to produce the story, narration and cover artwork. Please use imaginary characters and avoid children's real names, addresses, schools or other personal details in story ideas.

Purchases

Apple handles payment. RevenueCat processes purchase records, subscription status, credit transactions and technical app/device information needed to provide purchasing. We do not receive your full payment-card details. The app has no advertising SDK and does not request tracking permission.

Storage and service providers

Our story service stores job requests, generated text and audio to support downloads and retries. For new jobs, guest server copies expire 30 days after creation. Stories saved to a connected cloud library remain until you delete them or the account. The original story idea is removed from our job record after successful writing, or when the job fails. Refunded failed jobs expire after seven days. Existing guest server copies received a 30-day grace period from 17 September 2026; existing signed-in backups were preserved. Cloudflare necessarily processes network information, including IP addresses, to deliver and protect the service. Our application-level request logs and traces are disabled; we do not request device location. OpenAI and RevenueCat also retain information under their service policies. Deleting a generated story removes its available server text, audio and artwork as well as the local story and audio, including without Apple sign-in. Locally downloaded stories remain playable after guest server expiry. Purchase records are managed separately.

Providers: OpenAI, RevenueCat, Cloudflare and Apple.

Parents and your choices

The first story-generation attempt uses a one-time data-protection sheet with an explicit agreement action. We keep the approval date and notice version on your device; withdrawal or an updated notice requires approval again. This records self-declared permission and does not verify parental identity. Paywalls, account connection, outgoing links and audio export have separate birth-year checks for grown-ups. The entered birth year is checked on your device and is not saved or shared. RevenueCat setup waits until a parent enables the grown-up services. You can decline AI processing, withdraw AI permission in Settings, disable story creation, delete generated stories, or manage subscription renewal in your Apple Account. AI-generated stories can make mistakes: a parent should preview them. A narrow offensive-word filter checks generated text before narration; it is not a guarantee that every story is suitable. We do not sell personal information.

Account deletion

Use Settings → Delete account and data, including when using the app without Apple sign-in. Deletion removes the cloud library and account connection, requests deletion of associated RevenueCat customer records, and clears generated downloads and preferences on this device once server deletion has completed. Apple-connected accounts require Apple authentication again so we can revoke the account token; that token is retained only while deletion is pending. Provider outages are retried; the app shows pending status and resumes when reopened. Deletion does not cancel Apple subscription billing; you can manage the subscription from the confirmation screen or delete your account immediately. Other offline devices and exported copies cannot be remotely erased. We keep hashed credential revocation records and deletion receipts for approximately 30 days to reject stale sessions.

Questions and deletion requests

Contact freya@frederickjames.net to ask about access, correction or deletion. Include the support ID shown in Settings so we can locate server data; never send your private device credential. Purchase and transaction records may need to be retained for accounting, fraud prevention or legal obligations. You may also contact your local data-protection authority.