Privacy Policy
Last updated: August 4, 2026
1. Overview
Storizee (“we,” “us”) is based in Ottawa, Ontario, Canada, and provides tools to turn photos into illustrated storybooks. This policy describes how we collect, use, share, and protect personal information when you use our website and services (the “Service”). It should be read together with our Terms of Service.
We handle personal information in accordance with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where they apply, provincial privacy laws, as well as other laws that may apply depending on where you live.
Because the Service can feature children’s photographs provided by adults, we take extra care with that data. We do not knowingly collect personal information directly from children under 13 for account registration.
2. Information we collect
- Account data: email address, password (stored hashed), and timestamps such as terms acceptance.
- Content you upload: photos (including of children when you choose to upload them), names and notes about characters, chat messages, story text, prompts, and related metadata.
- Generated content: story pages, illustrations, narration audio, and print-ready files we create for you.
- Character-matching descriptors: when you upload photos, our systems may detect faces and pets and create mathematical representations (often called embeddings or feature vectors) from cropped regions of those photos. We store those descriptors with your account’s characters (and temporarily with pending match proposals) so we can suggest “is this the same person or pet as a character you already have?” Under some privacy laws these descriptors may be treated as biometric or sensitive personal information.
- Usage and technical data: log data, device/browser type, IP address, approximate location derived from IP, pages and product actions (for example sign-in, story creation steps, checkout), and cookies or similar technologies needed for sessions, security, core product features, and product analytics as described in Section 10.
- Purchase data: processed by our payment provider (e.g. Stripe); we receive limited payment metadata (status, amounts, ids), not full card numbers.
- Shipping data: name and address when you order a physical book, shared with print/shipping partners to fulfill the order.
- Communications: messages you send us for support or feedback.
How we use character-matching descriptors. Descriptors are used only to operate character library features for your account: grouping faces and pets across your uploads, proposing matches when you add new photos, and supporting illustration of the characters you choose for a storybook. We do not use them to identify people outside your account, to search other users’ libraries, for law-enforcement identification, for third-party advertising, or to sell biometric data. Photos and descriptors are processed so you can create illustrated storybook characters—not to build a general facial-recognition product. Product analytics and session replay (Section 10) are configured so that uploaded photos, face crops, story illustrations, chat content, and similar on-screen family content are masked or blocked before leaving your browser and are not used for advertising.
3. How we use information
- Provide, personalize, and improve the Service (including AI generation, character matching, quality review, and product analytics).
- Understand how the Service is used (for example funnels, errors, and usability issues) so we can fix bugs and improve flows.
- Authenticate you, prevent abuse and fraud, and secure accounts.
- Process payments, grants of generation credits, and print orders.
- Enable features you choose, such as share links.
- Communicate about the Service (transactional email such as order and account notices; optional product updates where you opt in or as otherwise permitted by law).
- Comply with law and enforce our Terms.
How we justify use (Canada): We collect and use personal information for the purposes described above, with your knowledge and consent where required, or as otherwise permitted by law (for example to fulfill a transaction you requested, protect the Service, or meet legal obligations).
Additional bases (where GDPR/UK GDPR applies): performance of a contract (providing the Service you request); consent (for example certain marketing, non-essential analytics cookies where required, and where required for processing photos you upload of children); legitimate interests (security, fraud prevention, product improvement and limited product analytics where not overridden by your rights); and legal obligation (tax and accounting records).
4. AI processing and model training
We use third-party infrastructure and AI providers to process content you provide and to generate stories, images, and related outputs. Uploaded photos and prompts are sent to those systems solely to create and deliver your storybook and related Service features.
We do not use your family photos, chat prompts, or personal story content to train our own foundation models, and we configure or contract with AI providers, where the product and contracts allow, so that customer content is not used to train their general models. Providers may still process data under their terms and our agreements with them (including temporary processing to return a result). Do not upload content you are not comfortable processing with such services.
Categories of processors may include: cloud hosting and storage; generative AI APIs for text and images; speech/narration providers if enabled; payment processors; print-on-demand and shipping partners; email delivery; product analytics and session replay providers (see Section 10); and error/monitoring tools if enabled. A current list of major subprocessors is available on request at the contact email below.
5. Children’s privacy (COPPA and similar laws)
Storizee is directed at adults. Parents, guardians, and adult gift-givers may create storybooks that feature children. We do not knowingly allow children under 13 to create their own accounts or provide personal information to us directly.
When you upload a child’s photo or name, you represent that you are the parent or legal guardian, or have authority and consent to do so, as described in our Terms. We collect and use that information only as reasonably necessary to create and deliver the storybook and related features you request.
We do not sell children’s personal information. We do not use children’s photos or names for third-party advertising or cross-context behavioral advertising. We do not use children’s photos or story content to train advertising models or to profile children for marketing. Product analytics tools we use are configured to mask or block photos, face crops, illustrations, chat, and story text in session recordings so that those visuals and texts are not sent to the analytics provider in clear form (see Section 10). We do not condition participation on a child providing more personal information than needed for the Service.
Parental rights. A parent or guardian may request to review, correct, or delete personal information we hold about their child in connection with the Service, and may refuse further collection or use (which may limit our ability to provide the Service). Contact us at the email below. If you believe a child under 13 has registered an account, contact us and we will delete the account as required.
6. Sharing
We do not sell your personal information. We share data with:
- Service providers who process data for us (hosting, email, payments, AI generation, print-on-demand/shipping, product analytics/session replay, security/monitoring if enabled), under instructions appropriate to the service.
- People you choose when you enable a share link or allow others to view or purchase a print.
- Authorities when required by law or to protect rights, safety, and security.
- Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate confidentiality and this policy’s spirit.
When you enable sharing, copies can be made and we are not responsible for that. A share link lets anyone who has the link view the digital storybook (and, if you allow it, order a physical print). Viewers or recipients may take screenshots, photos, downloads, or other copies of what they can see or of a printed book they receive. Once you share, we cannot control how third parties use, store, re-share, or further copy that material. You are responsible for deciding whether to enable a share link, who you give it to, and whether others may buy a print. Storizee is not responsible for copies, redistribution, misuse, or further disclosure made by people who access a book through your share settings, or by anyone who receives a physical copy ordered from a share link. You can revoke a share link in the product; that stops new access via that link, but it does not delete copies already made or prints already produced.
7. Retention
We keep data only as long as reasonably needed for the purposes above, unless a longer period is required by law. Typical practices:
- Account and story library: while your account is active so you can re-read, edit, share, and reorder prints, unless you delete content or close the account via Account settings (or by contacting us).
- Uploaded source photos: retained while needed to generate, regenerate, and support your books. You may request earlier deletion of specific photos or your account; we will honor requests within a reasonable time (generally within 30 days), subject to backups and legal holds.
- Character-matching descriptors: retained with the related character or pending match proposal while that content remains in your library so re-uploads can match correctly. They are removed when you delete the character, reject or resolve the proposal, delete the photo (when no longer needed for matching), or delete your account—subject to backups and legal holds as with other account data.
- Generated books, illustrations, and print PDFs: while your account is active for viewing and reprints, or shorter periods if we later introduce automatic archival with notice.
- Order, payment, and tax records: typically up to seven (7) years or as required by accounting and tax law.
- Support communications: as needed to resolve issues and for a reasonable period afterward.
- Pending / abandoned checkouts: may expire on a short schedule (for example about 24 hours) as described in the product.
- Product analytics and session replay: retained only as long as needed for product improvement and debugging, subject to retention settings we configure with our analytics provider (often shorter than account content retention). You may request deletion of analytics-linked personal data via the contact email below where the law and the tools allow.
After account deletion, we may retain limited records (for example payment history or logs) where required for legal compliance, dispute resolution, or security.
8. Security
We use reasonable technical and organizational measures (including encrypted transport (HTTPS/TLS) and hashed passwords). Access to personal data is limited to personnel and processors who need it to operate the Service. No method of transmission or storage is completely secure. If we become aware of a data breach that requires notice under applicable law, we will notify you and regulators as required.
9. Your choices and rights
Depending on your location and the law that applies, you may have rights to:
- Access a copy of personal data we hold about you;
- Correct inaccurate data;
- Delete personal data (subject to legal exceptions);
- Export data in a portable format (where applicable);
- Restrict or object to certain processing;
- Withdraw consent where processing is based on consent (without affecting prior lawful processing);
- Opt out of marketing emails (transactional messages about orders and account security may still be sent);
- Lodge a complaint with a privacy regulator (in Canada, you may contact the Office of the Privacy Commissioner of Canada; in the EEA/UK, your local supervisory authority).
Canada: Subject to limited exceptions under PIPEDA and applicable provincial law, you may request access to personal information we hold about you and challenge its accuracy. We will respond within the timeframes required by law (generally within 30 days under PIPEDA, subject to permitted extensions).
California (CCPA/CPRA) summary: We do not sell personal information or share it for cross-context behavioral advertising in the sense those laws use those terms. California residents may request to know, delete, and correct personal information, and will not be discriminated against for exercising those rights. Sensitive information such as children’s photos and face- or pet-derived character-matching descriptors is used to provide the Service you request (and photos are masked or blocked in session replay as described in Section 10), not for purposes that would require a “limit use of sensitive personal information” opt-out under CPRA for our current product design.
In the product you may update account details where available, revoke share links, and delete your account under Account settings (password confirmation required). Deleting your account removes your stories, chat, photos, characters, and character-matching descriptors; we may retain limited payment and fulfillment records as described in Section 7. To exercise other privacy rights, email us at the contact below. We may need to verify your identity before fulfilling a request. We aim to respond within the timeframes required by applicable law.
10. Cookies, product analytics, and session replay
Essential cookies. We use cookies and similar technologies as needed for authentication, security, session continuity, CSRF protection, and core product function. Disabling essential cookies may break sign-in, checkout, or other features.
Product analytics. We use a third-party product analytics service (currently PostHog) to understand how people use the Service—for example page views, feature usage, conversion steps, and technical errors. Depending on configuration, this may include both browser-side capture and limited server-side events (such as account creation or sign-in). Analytics data may be processed in the United States or other locations where the provider operates.
Session replay. Where enabled, the same provider may record a reconstruction of browser interactions (clicks, navigation, layout) so we can debug problems and improve usability. We configure session replay for privacy by design:
- form inputs (including chat and password fields) are masked;
- on-screen text is masked by default in recordings;
- images, video, and canvas content—including uploaded family photos, character face crops, and story illustrations—are blocked so they appear as empty placeholders in the recording rather than the original media;
- sensitive product regions (for example book preview, character upload, chat, and related panels) are marked so they are not captured in clear form;
- we do not use session replay for third-party advertising or to sell personal information.
Masking and blocking run in your browser so that redacted content is not sent to the analytics provider as visible media or readable text. No system is perfect: residual technical metadata (for example approximate layout size of a blocked image) may still be present. Staff access to analytics and recordings is limited to people who need it to operate and improve the Service.
What analytics is not for. We do not use product analytics or session replay to train our foundation AI models on your family photos or personal story content, and we do not sell analytics data or use children’s photos for cross-context behavioral advertising.
Your controls. You can control cookies through your browser settings and, where available, browser privacy or “do not track” preferences (we treat global privacy controls in line with applicable law). Where local law requires consent before non-essential analytics cookies, we will provide a notice or consent mechanism (or otherwise limit non-essential analytics) as required. You may also contact us at the email below to ask about analytics-related data linked to your account.
We do not currently use third-party advertising pixels or marketing trackers on the Service for cross-site ads. If that changes, we will update this policy and obtain any consent required by law.
11. Storage and international transfers
We operate from Canada. Personal information may be stored or processed in Canada and in other countries where our service providers operate (including the United States and, depending on the provider, elsewhere). Those countries may have different privacy laws than Canada. When we transfer personal information outside Canada, we take steps appropriate to the circumstances so that it continues to receive a comparable level of protection, consistent with PIPEDA and our agreements with providers. Where additional rules apply (for example transfers involving the EEA/UK), we use appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms.
12. Changes
We may update this Privacy Policy. We will revise the “Last updated” date and, when changes are material, provide additional notice (for example in the product or by email) when appropriate. Continued use of the Service after an update means you acknowledge the revised policy, except where applicable law requires a different process.
13. Contact
Storizee is based in Ottawa, Ontario, Canada. Privacy questions, parental requests, or data rights requests: [email protected]. Please include enough detail for us to locate your account (for example the email you registered with).