Staris Kids — Consent & Eligibility Policy
Version: 1.0 · Effective date: 27 August 2026 · Controlling language: English. We also publish this policy in Portuguese, Japanese, French, and Spanish; where the law of your place of residence entitles you to rely on the version in your own language, that version prevails for you to the extent of any inconsistency.
The on-screen consent copy in §5–§7 is shown in-app at the relevant step.
1. What this policy covers
This policy sets out who may use Staris Kids and the consents the adult Account Holder gives before a Child's information or a photo is used:
- Eligibility & the adult/parent gate (§2–§4) — the account holder must be an adult parent or guardian.
- Parental consent for a Child's information (§5).
- Biometric/photo consent to analyze a photo into a cartoon (§6).
- Photo & likeness rights you confirm for every photo you upload (§7).
Defined terms (You / Account Holder = the adult (18+) parent or legal guardian, the sole user class; Child = a minor in Your care; Uploaded Photo; Biometric Data = facial-characteristic analysis used only to make a cartoon; Generated Content; Service; Subprocessor) carry the same meaning as in the Terms of Use.
Operator: Clever Labs Pty Ltd (ACN 700 956 010), Australia. Contact:
support@cleverlabs.com.au.
2. Who may use Staris Kids
Staris Kids is a children's app that only an adult can hold an account for. It is listed in the Apple App Store Kids Category and takes part in Google Play's Designed for Families programme, so both stores treat children as an intended audience and both programmes' rules for children's apps bind us — including in later versions of the App. What that does not change is who the account belongs to: Staris Kids is a tool for a parent or legal guardian to create AI-generated illustrated stories for the children in their care, and it is not designed for children to sign up for or operate on their own.
- You / the Account Holder must be 18 or older and the parent or legal guardian of any Child who experiences content through your account.
- A Child is not provided with an account, a sign-in path, or any means of submitting information to us directly, and should not create or independently operate an account — a Child experiences content through your supervised, authenticated account.
- There is no separate class of child user. The adult account holder is the sole user and the data subject for account information.
3. The adult / parent gate at signup
At account creation, the Service presents an explicit gate the Account Holder must complete before any account exists:
- an affirmative attestation — "I am 18 or older and the parent or legal guardian of the child(ren) who will use this app" — actively confirmed (not pre-ticked); and
- acceptance of the Terms of Use and Privacy Policy, recorded with the version accepted and a timestamp.
This gate applies to all sign-in paths and is enforced at account creation. Both are recorded on the account with the version accepted and a timestamp. We use an adult/parent attestation (not an "I am over 13" checkbox) because the account holder must be an adult.
The gate establishes who the Account Holder is. It is not the consent for a Child's information — that is given separately, at the point of collection, under §5. The age-range selector shown during setup is a content-appropriateness setting, not an age gate.
4. Who provides a Child's information, and what covers it
Three points carry this, under our launch-market laws (Australia, Brazil, Canada/Québec, Japan). It is worth being precise about what each one does — and what it does not do:
- A parent supplies the data about their own child. That is the substance. Our launch markets treat personal information collected online from children as the trigger for consent. Here, an adult chooses what (if anything) to add about a Child through an adult-attested account — the safer, ordinary case. Nothing is collected from a Child. Where a Child's information is collected, the consent that covers it is the one the parent gives at the point of collection under §5.
- The attestation in §3 establishes who the Account Holder is. It is not itself that consent. It records that the person opening the account is an adult and the parent or legal guardian. That is a statement of identity and eligibility, not permission for any particular processing, and we do not treat it as one.
- A payment card is an additional signal, never a basis. The Service can be used on a free tier, so account creation does not require a purchase, and no feature is unlocked by proving a card. Where the Account Holder does purchase a subscription, the payment card and the app store's per-charge receipt (Apple / Google Play) are a further indication that an adult is in control — bank-verified identity and a per-transaction audit trail. We do not rely on it to establish consent, and a parent who never purchases anything stands in exactly the same position.
We do not collect or store government identification for verification; if a fallback verification method is ever added, any identification would be deleted immediately after verification and never retained.
5. Parental consent for a Child's information
What we collect about a Child, and why (data minimization — only what a story needs, and only what You choose to add):
| We collect | Why | Notes |
|---|---|---|
| A nickname (we recommend not a full legal name) | Personalize a story | You choose whether to add one |
| An age range | Keep content age-appropriate | Not a birthdate |
| Interests / preferences | Tailor stories | Optional |
| An Uploaded Photo of the Child (optional) | Create a cartoon character likeness | Raw photo never stored (see §6); requires the biometric consent in §6 |
| Memory Story photos (optional, up to 8 per Memory story) | Understand a real event — the occasion, who is present, the kind of place, the objects and context — so the story can be about it | A different use from the row above: no facial analysis, no likeness, no character. Uploaded, read once, then deleted automatically within seconds (see §6b) |
| The Generated Content made for the Child | The product | Stories, characters, illustrations, library, progress |
What we never collect about a Child: precise geolocation, contacts, a Child's real name (unless You add one), advertising identifiers, or anything for behavioral profiling. We serve no advertising, do no cross-app tracking, and never sell a Child's information. The Child's information is used only to provide and personalize the Service, keep content safe, and meet legal/security obligations — never for advertising or to train AI models.
When we ask — beside the field itself, as its own tick-box. The Child's name or nickname is the only identifying information we store about a Child, so the consent notice sits directly under that field on the setup screen. The consent is a separate checkbox that starts unticked; it is never pre-ticked, and it is never inferred from You typing in the field. Filling in a form is behaviour, not agreement — consent must be an unambiguous act of its own, and a Child's-data consent must stand out rather than be a by-product of ordinary use. A Child's photo is handled separately and later, under §6.
We store the name only if the box is ticked. Leave it unticked — or choose "Not now" — and no name is stored and no consent record is written. If You have typed a name without ticking, we say so on screen before You continue, so nothing is lost silently. The age range is still kept either way: it is strictly necessary to keep content age-appropriate, and is the content-appropriateness setting described in §3, not identifying information about a Child.
Refusing does not cost You the Service. You keep full use of Staris Kids; stories are simply not personalized to a named child. We do not require a Child's name or nickname, because the Service does not need it — stories are generated without one. We only ever require information the Service actually needs, and consent is in any case only valid if it is freely given.
On-screen consent copy (shown under the name field, before any name is stored):
Your permission
We use your child's name or nickname only to make and personalize their stories. No ads. No sale of your information. No use of their name for advertising.
Change or delete it any time in Settings.
[ ] I am the parent or legal guardian of this child, and I consent to Staris using their name or nickname to personalize their Staris Kids experience.The Privacy Policy explains how we use it. You can leave this unticked and still use Staris Kids — stories just won't use your child's name.
(shown only if a name has been typed and the box is not ticked) Tick the box to use this name — without it we won't save it, and stories won't use their name.
The record we keep: the account identifier; the policy version consented to; the timestamp; and the adult/parent attestation from §3 (its version and timestamp) that establishes who gave it. All held on the account's own profile record. The record is written only when the box was ticked and a name is actually stored — a consent record with nothing behind it would be meaningless, and stored information with no record is what this section exists to prevent. Withdrawal is by deleting the Child's information or the account, and takes effect on deletion. A material change to what we collect or how we use it triggers fresh consent at the new version.
Interests and the age range are the Account Holder's own content settings, disclosed under Privacy Policy §3(b); they are not identifying and are not gated by this consent.
Because the Account Holder supplies this information themselves through an adult-attested account, this consent is the parent's own act — there is no separate child-facing collection to verify.
6. Biometric / photo consent (analyzing a photo into a cartoon)
Two photo uses — this section is about the first one only. The App uses photographs in two distinct ways: (1) a Character Photo, analysed for a person's appearance to draw a cartoon character — that is this section; and (2) Memory Story photos, analysed to understand a real event so a story can be written about it — that is §6b. They differ in what is analysed, what consent applies, and whether the photo is stored. Nothing in this section should be read as a statement about §6b, and vice versa.
This is a separate, specific consent, shown at or before the first photo upload — its own notice, not a checkbox in "I accept the Terms" — because analyzing facial characteristics can be treated as processing sensitive personal information requiring explicit, separate consent (Australia's Privacy Act/APPs; Brazil's LGPD Art. 11; Canada's PIPEDA/Québec Law 25; Japan's APPI).
What we derive, and the only thing we do with it. When You upload a photo, OpenAI analyzes facial characteristics only to draw a stylized cartoon likeness. We treat this as Biometric Data. It is never used to identify or verify a person, perform one-to-one/one-to-many matching, build or query a face/identity database, be sold/leased/traded/profited from, or train AI models.
Retention & destruction — Character Photos. The raw Uploaded Photo is never written to storage — held in memory, EXIF/geolocation stripped, sent to OpenAI in a single generation flow, and discarded immediately after the cartoon is generated — within minutes, never beyond 24 hours.
A written description derived from the analysis IS kept, and we state that plainly rather than imply it is discarded. It is a short set of words describing that person's facial and appearance characteristics — not the photograph. We treat it as biometric information wherever applicable law requires us to do so. It exists so a character drawn today still looks like itself in a story generated later, and it is kept in two contexts with different lifetimes: with the character (the life of the character — deleted when You delete the character, withdraw this consent, or delete Your account) and frozen inside stories already generated (the life of that story — deleted when You delete that story or Your account). It is never used to identify anyone, and it cannot be used to create a new character or restore a deleted one. The derived cartoon portrait is likewise retained (life of the character/account, or until you delete it or withdraw consent; outer bound 3 years of last account interaction).
We do not hold a Zero Data Retention arrangement with OpenAI, and we do not claim one. Under OpenAI's API terms the transmitted image may be retained for up to 30 days for service operation and abuse monitoring and is then deleted; OpenAI does not train on it. It may be kept longer only where the law requires it, or where OpenAI's automated safety checks flag content for review — we disclose this rather than overstate. Full schedule and destruction triggers: Data Retention & Deletion Policy §4.
International transfer. The analysis happens at OpenAI in the United States, on Your explicit, specific consent (below), safeguarded by our data-processing agreement with OpenAI (no training; retention limited to OpenAI's published up to 30 days for service operation and abuse monitoring, longer only where the law requires it or where automated safety checks flag content for review; no Zero Data Retention arrangement) and by the fact that we never store the raw photo (see Privacy Policy §8–§9).
Withdrawal. Revocable anytime in Settings. Withdrawal stops further photo→feature-extraction and deletes the derived cartoon portrait, the associated character, and the appearance description held with it. It does not reach the description already frozen into stories You have generated — that stays with those stories so their illustrations remain coherent, and is removed when You delete those stories or Your account. Withdrawing it does not remove Memory Story photos, which are not processed under this consent — see §6b for how to remove those. Stories already generated may remain available, with the illustrations they were made with — remove those by deleting the stories individually or the account (see §8).
On-screen consent copy (its own screen, before any photo is analyzed):
Making a cartoon from a photo — your permission
To turn a photo into a cartoon character, our AI briefly analyzes the facial features in the photo you add. In some places this is called biometric information, so we ask separately and explain it clearly.
- What we do: analyze the facial features only to draw a cartoon likeness and keep that character looking the same in later stories.
- What we never do: never identify or recognize anyone, never match faces, never build a face database, and never sell it.
- What we keep: we never save the original photo. We do keep a short written description of facial and appearance characteristics — so your character still looks like itself in later stories. It stays with the character, and a copy stays inside stories you've already made. Withdrawing removes the first; deleting those stories removes the second.
- Sent to the United States: the analysis is done by our AI provider, OpenAI, in the United States — so agreeing also allows the photo to be sent there for this purpose. OpenAI does not use it to train its AI, and may keep it for up to 30 days to run the service and check for misuse before deleting it.
- You can change your mind: withdraw anytime in Settings — that deletes the cartoon portrait, the character, and the appearance description held with it. Deleting that character, or your account, removes them too.
- One person only: you confirm this photo is of one person — you, or a child or other person you are the parent, legal guardian, or legally authorized representative of. Staris checks the photo on your device and refuses one where it detects more than one face, though automated detection cannot promise to spot every face in every image (see §7).
By tapping "I consent — analyze this photo to make a cartoon," you give your specific, informed consent for Staris Kids and its AI provider (OpenAI) to analyze the facial characteristics of the single person shown in the photo you upload — either you, or a person for whom you are the parent, legal guardian, or legally authorized representative — for the sole purpose of generating and maintaining a cartoon likeness, to keep a written description of that appearance for as long as the character exists and inside stories already made with it — and in any case no longer than three years after your last interaction with Staris Kids — and for the photo to be sent to OpenAI in the United States for that purpose.
[ I consent — analyze this photo to make a cartoon ][ Not now ]
The record we keep: the account identifier; consent event (biometric — photo → facial-characteristic analysis, recorded separately from ToS and parental-data consent); policy version; timestamp; scope — carried by the notice version, which pins the exact wording you were shown: analysing the Uploaded Photo to create the cartoon likeness, maintaining that likeness across stories, the appearance description kept with the character and frozen into stories already generated, the provider it is sent to, and the retention and destruction terms; request context (IP, user agent); withdrawal timestamp + confirmation of portrait/character deletion. Held as a dedicated photo-consent record, separate from the account profile. Electronic/checkbox consent is a valid, logged form; a material change triggers re-consent.
7. Photo & likeness rights you confirm
For every Uploaded Photo of a person, You represent and warrant that (this is made binding by Terms of Use §6(a) and backs the §17 indemnity):
- Parent/guardian of any Child depicted — and authorized to use that Child's image to create a cartoon likeness.
- Consent of any other identifiable person — for any other identifiable person (adult or child) in the photo, You have their consent (or, for another child, that child's parent/guardian's consent).
- All rights, no infringement — You hold all rights and authority, and using the image infringes no copyright, trademark, privacy, publicity, moral, or other right.
- The duty to obtain consent is Yours — You are solely responsible for the notices/consents; we rely on Your attestation and cannot verify it.
You must not upload a photo of anyone You are not authorized to use. If a person believes their likeness was used without authorization, they (or You) can contact support@cleverlabs.com.au; we will review and can remove the character and any derived portrait (copyright-specific complaints follow the Copyright & Takedown Policy).
Character Photos show one person. A Character Photo must show the one person the character is being made from. Before the photo is processed the App checks it on Your device and refuses it where it detects more than one face, where it detects no face for a human character, or where the check cannot run at all. There is no option to continue past a refusal — You choose a different photo. Automated detection cannot promise to find every face in every image, so this reduces the risk rather than eliminating it. The check runs entirely on Your device, counts faces only, and nothing about it leaves the device or is recorded: no image, no face data, and no result beyond what is shown to You on screen. This rule is for Character Photos only. Memory Story photos may show several people — they are never put through facial-characteristic analysis (§6b), and the rights warranties above continue to apply to everyone recognisable in them.
On-screen confirmation copy (shown before we process a photo):
Before you add photos
You can only add photos you're allowed to use. By adding a photo, you confirm that:
- you are the parent or legal guardian of any child shown in it;
- you have the permission of anyone else who can be recognized in it (or, for another child, that child's parent/guardian); and
- you have all the rights to use the photo, and using it breaks no one's copyright, privacy, or publicity rights.
You're responsible for getting those permissions — we rely on your word here. If someone raises a concern about a photo you added, you agree to stand behind it as described in the Terms of Use (§6 and §17).
The raw Uploaded Photo is not part of this record (it is never stored); we keep only proof of the confirmation (the account identifier, policy version, timestamp, IP address and user agent).
6b. Memory Story photos (analyzing photos of a real event into a story)
A Memory story is a story about something that actually happened. To write one, You may attach up to eight photographs of the event. This is optional — Memory stories can be created from Your written description alone, and the rest of the Service does not involve photos.
What is analysed, and what is not. The photographs are read once, together, by OpenAI (GPT-4o mini vision) to produce a short written description of the memory: what the occasion was, who appears in the pictures, the kind of place it seems to be, and the objects, details and order of events. That description is what the story is drafted from. We instruct the model not to attempt precise geolocation and not to name a city or country without a clear visual cue. We do not perform facial recognition or biometric identification on these photographs. Understanding a photograph necessarily involves the AI system processing the people visible in it — that is how it knows who was at the party — but we do not derive facial geometry, do not create a biometric identifier or template, do not build or match a likeness, and do not create a character from them. They therefore do not produce Biometric Data, and the §6 biometric consent does not extend to them — a separate act, in a separate place, for a separate purpose.
The straight answers.
| Question | Answer |
|---|---|
| Sent to OpenAI? | Yes — read once via a time-limited private link, for that single analysis. No training; up to 30 days' abuse-monitoring retention, then deletion (longer only where the law requires it, or where automated safety checks flag content for review); no Zero Data Retention arrangement. |
| Stored? | Briefly. Unlike a Character Photo, these must be written to a private, non-public area of our storage in Australia (Sydney), scoped to Your account and reachable only by signed expiring link, because OpenAI reads them from a link. |
| Only held temporarily? | Yes — the duration of one request, normally seconds. They are deleted the moment the analysis returns; a draft is rebuilt from the written description, never from the pictures. |
| Identifying metadata removed? | Yes — the image is resized and re-encoded on Your device before upload, so the original EXIF, including GPS coordinates, capture time and device identifiers, is not carried. |
| What is generated? | Story text only. Illustrations are drawn from the story text and Your characters' existing cartoon portraits — not from these photographs. The photograph is never shown in the App or printed into a story. |
| Deleted after generation? | Yes, automatically — as soon as the analysis returns, on the failure path as well as the success path. Saved drafts hold no photographs, so cancelling, discarding a draft or finishing a story leaves nothing behind. |
What we rely on, stated exactly. There is no separate consent screen for Memory Story photos, and we do not claim one. The basis is Your own deliberate act as the adult Account Holder: You choose Memory mode, You choose which pictures to attach, and this policy and the Privacy Policy §3(c).2 tell You beforehand what happens to them. The rights warranties in §6 — that You are the parent or guardian of any child shown, that You have the permission of anyone else recognisable, and that You have all rights to use the image — apply equally to every Memory Story photo, as stated in Terms of Use §6(a). You confirm those rights on screen before adding the photographs, exactly as set out in §7; that confirmation is a warranty about whose photographs they are, not a consent to processing, and it does not gate the feature — a Memory story can always be written from Your description alone.
Choice and withdrawal. You can create Memory stories without attaching photographs, and You can remove a photograph before generating. After generating there is nothing left to withdraw: the photographs are already deleted. If an upload is interrupted, an automatic sweep removes anything left behind, and deleting Your account purges the area regardless.
8. Your ongoing controls — review, correct, delete, withdraw
As the parent, You keep full control anytime, in the App: review all information associated with the Child; correct a nickname, age range, interests, or character; delete an individual item or the entire account; and withdraw consent, which halts further processing and triggers deletion of the relevant data, including any biometric-derived portrait and its character (see the Data Retention & Deletion Policy). Stories already generated keep the illustrations they were made with — delete those stories individually, or delete the account, to remove them too. We honor these whether or not a law compels them. To exercise a right You cannot complete in-app, contact support@cleverlabs.com.au; we verify through the account holder.
9. Monitoring for direct child use
If we learn a child is using the Service directly (rather than through a supervising adult), or has created an account without a parent, we will delete that account and its personal data. We act promptly on any signal that reaches us — a support contact, a report, registration information, or content we review in the course of moderation — and the Service is designed so that only an adult can create and hold an account — there is no child sign-up and no child sign-in path (§2).
10. Jurisdictional scope (markets)
One set of consents + one published destruction schedule + a no-sale commitment satisfies every market:
- United States (COPPA; Illinois BIPA) — personal information actively provided about a Child — profile details, photographs and the inputs used to create content — is supplied through the adult-controlled account, not collected from the Child. The App also generates limited operational and engagement data during use, tied to the account rather than to a Child's profile and used only to operate, secure, personalize, support and improve the Service (see Privacy Policy §3(f) and §11): there is no Child account and no Child sign-in path, and every point where a Child's information can be added sits behind a grown-up check. The §6 biometric consent is the written release Illinois requires before any facial characteristics are analysed, and the Data Retention & Deletion Policy is the publicly available retention schedule and destruction guidelines that Act also requires. We never sell, lease, trade or otherwise profit from biometric information, and never disclose it without Your consent. Neither the adult attestation in §3 nor a payment card is treated as verifiable parental consent — see §4.
- Australia (Privacy Act / APPs; the Children's Online Privacy Code once it is registered) — biometric/facial data is sensitive information requiring consent before collection; the Operator is Australia-based (a primary driver).
- Brazil (LGPD) — facial data is sensitive personal data (Art. 11) requiring specific, highlighted consent, and children's data requires parental consent + best-interest handling; the strongest sensitive-data basis of the four.
- Canada (PIPEDA / Québec Law 25) and Japan (APPI) — each requires informed, purpose-limited consent, and parental consent for a young child, which these flows provide.
- Other markets — New Zealand (Privacy Act 2020), Singapore (PDPA and its children's-data guidelines, which treat a child's data to a higher protection standard), Taiwan (PDPA — consent via the legal representative), Hong Kong (PDPO — consent from a "relevant person"), and the Spanish-speaking Latin American markets where the Service is offered (for example Mexico, Colombia, Chile, and Argentina — each requiring the legal representative's authorization for a child's data, with facial data treated as sensitive in several). The same design — express parental consent, minimization, and a published destruction schedule — is the basis in each.
11. Retention & changes
We keep a Child's information only as long as needed and per the Data Retention & Deletion Policy (no indefinite retention; Character Photos never retained, Memory Story photos deleted automatically within seconds of upload — see §6b). On withdrawal we stop the relevant future processing and delete the active data that withdrawal covers; on account deletion we purge the Child's personal data and instruct our Subprocessors to do the same. Both are subject to the specifically disclosed retention of limited appearance information already incorporated into stories You have already generated (§6 — it goes when those stories or the account go), and to minimal records the law requires (the consent record; tax/billing records). We may update this policy; for material changes we change the version/effective date and give notice, and a material change to a consent's scope triggers fresh consent.