Staris Kids — Privacy Policy
Version: 1.0 · Effective date: 27 August 2026 · Controlling language: English. We also publish this policy in Portuguese, Japanese, French, and Spanish; where the law of your place of residence entitles you to rely on the version in your own language, that version prevails for you to the extent of any inconsistency (see §14).
The short version (plain language for parents)
- Staris Kids is for children — the account is for grown-ups. You must be 18+ and the parent or legal guardian to create an account. Children use the app only through your account and your supervision.
- You are in control of your child's information. You decide what to add, and you can view, correct, or delete it — or your whole account — at any time.
- There are two different photo uses, and they are handled differently. (1) A Character Photo — used to turn a real person into a cartoon character — is never saved: it is held only in memory, turned into a cartoon, then discarded. What we do keep is the cartoon portrait and a short written description of facial and appearance characteristics, so the character still looks like itself in stories you make later (see §8). (2) Memory Story photos — the pictures you add to a Memory story so it can be written about something that really happened — are uploaded, read once, and then deleted automatically, normally within seconds. They have to reach our storage because our AI provider reads them from there, but they are erased as soon as that single reading is done; a saved draft never contains them, and they are never shown in the App or printed into a story. Identifying metadata (such as EXIF geolocation) is removed from both kinds of photo before they leave your device or our servers, and both are processed by our AI provider OpenAI under terms that do not permit training on them. If a photo shows someone other than you or your child, you need their permission (or their parent's) before you add it — that responsibility is yours and we rely on your word. Full detail in §3(c).
- We do not sell your data, show your child ads, or track your child across other apps. The one time your Content leaves your account is when you choose to share a story — see §3(g).
- We use AI to create stories and illustrations — Anthropic's Claude writes the story text, and OpenAI creates the illustrations and turns a photo into a cartoon. Your prompts and photos are processed by these providers to generate content; we use both under terms that do not permit them to train their models on our data.
- Full detail is below. Questions:
support@cleverlabs.com.au.
1. Who we are
Staris Kids (the "App" or "Service") is provided by Clever Labs Pty Ltd (ACN 700 956 010) ("Staris," "we," "us"), a company incorporated in Australia. We are the data controller for the information described here. Contact: support@cleverlabs.com.au.
This policy explains what we collect, why, who we share it with, how long we keep it, and the choices and rights you have. It applies to the Staris Kids apps for iOS and Android and related services.
2. Who can use Staris Kids
Staris Kids is made for children to enjoy, and built so that only an adult can hold the account. It is listed in the App Store Kids Category and takes part in Google Play's Designed for Families programme. The account holder must be 18 or older and confirm they are the parent or legal guardian. We provide no child account and no child sign-in path, and children should not create or independently operate a Staris Kids account. A child may experience content through an adult-controlled account and under that adult's supervision, and the information about a child that we hold — profile details, photographs, and the inputs used to create content — reaches us because the adult account holder chose to add it. Using the App also generates limited operational and engagement data, which is tied to the account rather than to a child's profile (see §3(f) and §11). See our Consent & Eligibility Policy.
3. Information we collect
We practice data minimization — we collect only what the App needs.
a. Account & identity
- Email address and authentication credentials, securely processed through our authentication provider (Supabase — see §6). We do not store a readable copy of your password.
b. Child profile you provide (you choose what to add)
- A child's nickname (we recommend not using a full legal name), an age range for content-appropriateness, interests, and content preferences. This information is provided by you, the adult, to tailor stories.
c. Photos you upload
The App uses photographs in two separate ways. They are not the same processing, they do not carry the same risk, and they are not retained the same way. Whenever this policy says something about photos, check which of the two it is talking about.
Photographs often show other people. A photo you add may show your Child, another family member, a friend, or someone in the background. Whichever of the two uses it is for, you are responsible for having the authority or the consent to give us that photograph — for your own Child as their parent or guardian, and for anyone else recognizable in it, from that person or their parent or guardian. We rely on your confirmation and cannot verify it ourselves. See Terms of Use §6(a) and the Consent & Eligibility Policy §7.
c.1 Character Photos — a photo turned into a cartoon character
- To create a character from a real person, you may upload a photo of your child, a family member, or another person you are authorized to depict.
- The photo is analysed for that person's appearance — including facial characteristics — in order to draw a cartoon likeness of them. Because of that, it needs the separate biometric consent described in §8 and in the Consent & Eligibility Policy, and the App will not process it until you have given that consent.
- We never save the original Character Photo. It is processed only transiently in memory and discarded immediately — it is never written to our storage or databases. We strip identifying metadata (such as EXIF geolocation) before processing. It is transmitted to our AI provider (OpenAI) solely to create the cartoon; OpenAI does not use it to train its models. Under OpenAI's API terms it may be retained for up to 30 days for service operation and abuse monitoring and is then deleted — longer only where the law requires it, or where OpenAI's automated safety checks flag content for review. We do not hold a Zero Data Retention arrangement with OpenAI, and we do not claim one. What we do retain is the derived cartoon portrait, and a limited written description of facial and appearance characteristics used to keep that character visually consistent across stories. See §8 and the Data Retention & Deletion Policy.
c.2 Memory Story photos — photos that tell us what really happened
- When you create a Memory story, you may add up to eight photographs of a real event so the story can be written about that event rather than an invented one. This is a different feature from creating a character, and it is optional — you can create stories without it.
- What we do with them. They are analysed once, together, to understand what the occasion was, who is in the pictures, the kind of place it appears to be, and the objects, details and order of events that make the memory recognisable. The analysis produces a short written description — for example "a birthday at a sandy beach, three children, a blue kite" — and that description is what shapes the story we draft for you. We instruct the model not to attempt precise geolocation and not to guess an exact city or country where there is no clear visual cue.
- We do not perform facial recognition or biometric identification on Memory Story photos. Understanding a photograph necessarily involves the AI system processing the people visible in it — that is how it knows a birthday had three children at it — but that processing is used only to describe the occasion in words. It is not used to derive facial geometry, to create a biometric identifier or template, to build a likeness of anyone, to recognise or match a person, or to create a character. That is what §c.1 is for, and it is a separate step with its own consent.
- Are they sent to OpenAI? Yes. The analysis is performed by OpenAI (GPT-4o mini vision), which is given a time-limited private link to read the photograph for that one analysis. OpenAI does not use it to train its models. Under OpenAI's API terms it may be retained for up to 30 days for service operation and abuse monitoring and is then deleted — longer only where the law requires it, or where OpenAI's automated safety checks flag content for review.
- Are they stored? Briefly — and this is the one difference from a Character Photo. A Character Photo never reaches our storage at all. A Memory Story photo has to, because OpenAI reads it from a link rather than from the message we send. It is written to a private, non-public area of our storage tied to your account, in Australia (Sydney,
ap-southeast-2), reachable only through a signed, expiring link — there is no public address for it. It is then deleted as soon as the single analysis above returns. In normal use it exists on our servers for a matter of seconds. - Is identifying metadata removed? Yes. Before a Memory Story photo leaves your device it is resized and re-encoded into a new image file, which does not carry the original's EXIF data — including GPS coordinates, capture timestamp and device identifiers. What we receive and store is the re-encoded picture only.
- What is generated from them. They contribute to the written story text only. They are not used to draw the illustrations — illustrations are generated from the story text and from your characters' existing cartoon portraits. A Memory Story photo is never displayed in the App, never printed into a story page, and never shown to anyone else.
- Are they deleted after the story is generated? Yes — automatically, and we do not wait for the story to finish. Deletion runs the moment the analysis returns, whether or not the rest of the story succeeds — if generation fails, the photos are removed anyway and a retry sends fresh copies from your device. Your saved draft holds no photographs, so there is nothing left to clean up when you finish a story, discard a draft, or cancel part-way. If an upload is interrupted before the analysis can run, an automatic sweep removes anything left behind, and deleting your account purges the whole area regardless. See §12 and the Data Retention & Deletion Policy.
d. Content you create (user content)
- Stories, characters, and AI-generated illustrations, and your library, favorites, and reading progress.
- Story worlds you build — the settings, characters, and story worlds you create yourself.
- Your favourites, and your world and series progress — what you have unlocked, saved, or progressed through, and where each character stands in a world you are following.
e. Purchases & subscription
- Subscription status, plan, and purchase records, processed through the app store you purchased from (Apple or Google Play) and our billing provider RevenueCat. We do not receive or store your full payment-card number.
f. Device & technical data, and product telemetry
- Basic technical data needed to operate, secure, and troubleshoot the App, and crash diagnostics (see §6). No analytics SDK ships in the App — there is no third-party analytics or advertising software in it.
- A persistent identifier, and the only one. Crash reports carry a Firebase installation identifier — an identifier that persists on the device — generated when anyone, adult or child, uses the App. We use it for one set of purposes only: diagnosing crashes, protecting the security and integrity of the App, and keeping it working. It is never used to contact a specific individual, and there is no way for us to do so: we hold no record connecting an installation identifier to a person. It is never used for advertising, never used to build a profile of you or your child, and never combined with information from other companies. There is no advertising identifier, no ad-conversion software, and no App Tracking Transparency prompt, because there is nothing to authorize.
- Usage telemetry we generate as you use the App — how worlds and stories are used and engaged with, your reading activity, and operational records of generated-content jobs still in progress. This is first-party operational/product data held in our own Australian database, kept for a limited retention window and purged when you delete your account (see §12 and the Data Retention & Deletion Policy).
g. When someone opens a story shared with them
- If an Account Holder shares a story and the person they send it to opens the link on the web, we do not ask that person for any information, and they do not need an account. Our hosting provider keeps the ordinary technical records a web request produces — such as the network address and browser type — for a limited period, to keep the service running and secure.
- We do not set advertising or analytics cookies on that page, we run no third-party scripts on it, and we do not build a profile of anyone who opens a shared link. We count how many times a link was opened, as a plain total, so the Account Holder who shared it can see it; that count identifies no one. If a short note was added when the story was shared, it is stored with the link and removed when the link is.
What we never collect: we do not collect precise geolocation, contacts, or a child's real name (unless you choose to add one); we do not sell personal information; we do not serve third-party or behavioral advertising; and we do not track you or your child across other companies' apps or websites.
4. How we use information
- To provide the App — create and store your characters, stories, and illustrations, and personalize content for the chosen age range.
- Safety & moderation — automated filtering screens story text (submitted and generated) to keep content age-appropriate (see §7).
- Billing — manage subscriptions, credits, and purchases.
- Support, security, and legal — respond to you, protect the Service against abuse, and comply with law.
We do not use your content or your child's information for advertising, and we do not allow our AI providers to use it to train AI models (see §6).
5. Why we process your information — and consent
We process your information to provide the App you sign up for, to keep content safe, and to meet legal obligations (such as child-safety and tax/consumer records). We rely on your consent for the information you choose to add about your Child, and for photo/biometric processing. You give each of these by an affirmative action in the App before the information is collected or processed — for your Child's information, on the setup screen where you add it; for a photo, on its own screen before the photograph is processed — and you may withdraw any of them at any time. Facial-characteristic data from a photo is sensitive information we process only on your consent (see §8).
Automated decision-making. We do not make decisions that produce legal or similarly significant effects about you or your Child based solely on automated processing. Tailoring story content to a chosen age range is a content-appropriateness setting you control — it is not a solely-automated decision with legal or significant effect, and it does not profile a child for advertising.
6. Subprocessors, third parties, cookies & tracking
Running the App requires a small set of trusted service providers ("subprocessors") that process information on our behalf and under our instructions. The service providers we currently use to process personal information for the App are listed below. We do not sell your information — or your child's — to anyone, and no subprocessor may use it for its own advertising or to build advertising or identity profiles.
| Subprocessor | Purpose | Data received | Location | Key safeguard |
|---|---|---|---|---|
| OpenAI | Illustrations, Character-Photo→cartoon analysis (GPT-4o vision + gpt-image-1), Memory Story photo analysis (GPT-4o mini vision), content moderation | Story/character inputs; the Character Photo transiently, in-flight only; and the Memory Story photos you add, read once via a time-limited private link | United States | Data-processing agreement; no training on our data; up to 30 days' abuse-monitoring retention then deletion (longer only where the law requires it, or where automated safety checks flag content for review); no Zero Data Retention arrangement; Character Photo never written to our storage, Memory Story photos written and then deleted once read (§3(c).2) |
| Anthropic (Claude) | Story text | Text prompts + child-profile/story inputs (text only — no photo) | United States | Data-processing agreement; no training on our data; up to 30 days' retention then deletion, longer only where the law requires it or where content is flagged for safety review; no Zero Data Retention arrangement; no advertising use |
| Apple | App distribution + payments (iOS) | Account-level purchase records; payment handled by Apple | Apple global infrastructure | Merchant of record under Apple's own terms; we never receive your full card number |
| Google Play | App distribution + payments (Android) | Account-level purchase records; payment handled by Google | Google global infrastructure | Payments processed under Google Play's own terms; we never receive your full card number |
| RevenueCat | Subscriptions & entitlements | Purchase/entitlement records (not your card number) | United States | Bound to process only to manage entitlements |
| Firebase Crashlytics (Google) | Crash diagnostics only | Crash reports and the device/diagnostic data attached to them | Google global infrastructure | No analytics SDK ships in the App — Firebase Analytics is not included, so there is no advertising identifier, no ad-conversion API, and no ATT prompt; crash data is used to fix crashes and for nothing else |
| Supabase | Secure cloud storage + account infrastructure; also serves the illustrations on a shared-story page and receives reports sent from it | Account, child profile, characters, stories, derived cartoon portraits; and, for a shared-story page, the visitor's network address and request details when their browser loads an illustration or sends a report | Australia — Sydney, ap-southeast-2 |
Encryption in transit; access controls; region disclosed for transfer analysis |
| Vercel | Website hosting, including the unlisted shared-story pages | Ordinary web-request records for visitors to our website — network address, browser type and related technical details | Global edge network; page rendering currently in the United States | Data-processing terms; short operational log retention; no advertising or analytics use |
Two flows send a photograph to a subprocessor, and only to OpenAI: creating a character from a Character Photo (transiently — the photo is never written to our storage), and creating a Memory story from Memory Story photos (read by OpenAI through a time-limited private link; these ones do briefly reach our storage and are deleted once read — see §3(c).2). Only the first analyses facial characteristics. No subprocessor may use facial data for identification, verification, one-to-one matching, or to build an identity database (see §8). We require each provider to protect information consistently with this policy and applicable law. This list may change as the Service evolves; for material changes we will update this policy and, where required, give notice.
On-device storage, cookies & tracking (minimal by design). We are not an advertising product, so our use of on-device storage and identifiers is minimal:
- No advertising cookies, no IDFA, and no App Tracking Transparency (ATT) prompt — we do not use the advertising identifier or track you or your child across other companies' apps or websites, so there is nothing to authorize.
- We use only essential first-party technical data — authentication tokens held in your device's secure storage (iOS Keychain / Android Keystore-encrypted storage), a local settings store, and basic session data — to run, secure, and troubleshoot the App.
- Crash diagnostics via Firebase Crashlytics — a crash report, and the diagnostic data attached to it, sent when the App fails so we can fix it. There is no analytics SDK in the App. Crash data is not used to build a profile of you or your Child, is never a basis for advertising, and is never combined with data from other companies; we use no advertising, retargeting, social-media, or data-broker SDKs. Measuring how the App is used is first-party only and stays in our own database (§3(f)).
7. Content safety & moderation
We apply automated filtering to story text — both what is submitted and what the AI generates — to block sexual content, sexual or exploitative content involving minors, hate, graphic violence, and self-harm, and we offer an extra-gentle mode. Generated illustrations also pass an automated content-safety check before they are shown. Automated filtering is commercially reasonable but not perfect and may miss or over-flag content; we recommend you review each story before sharing it with a child. We may remove, refuse, or limit content at our discretion. We report suspected child-sexual-abuse material to the appropriate authorities as required by law and cooperate with law enforcement. See our Community & Acceptable Use Policy and Child Safety Policy.
8. Biometric information
Creating a character from a photo involves analyzing facial characteristics to generate a cartoon likeness. Depending on where you live, this may be considered biometric or sensitive information (for example, sensitive information under Australia's Privacy Act or sensitive personal data under Brazil's LGPD).
- We use this analysis only to create the cartoon likeness and to maintain that character's visual consistency in stories — never to identify or verify a person, never for one-to-one matching, and we do not build an identity database.
- We obtain your separate, specific consent before any photo is processed (see the Consent & Eligibility Policy).
- The original Character Photo is never saved — it is held in memory, sent for a single generation flow, and discarded immediately; it is never written to disk, database, or backup. A written description derived from it is kept. The analysis produces a short set of words describing that person's facial and appearance characteristics, retained so the character still looks like itself in stories generated later. It is not the photograph, and we treat it as biometric information wherever applicable law requires us to do so. It is kept in two contexts with different lifetimes: with the character (for the life of the character) and frozen inside stories already generated (for the life of that story). The cartoon portrait is also retained. That portrait is a stylized drawing rather than a photograph — but it is drawn to resemble the person, so we do not claim it cannot be recognised as them. Full schedule and destruction triggers: Data Retention & Deletion Policy §4.
- This section is about Character Photos only. Memory Story photos (§3(c).2) are not subject to facial recognition or biometric identification — they are read for occasion, people, place, objects and context, and no facial geometry, biometric identifier or template is derived from them — so they do not create biometric information. They are briefly written to storage and then deleted; that is governed by §3(c).2 and §13, not by this section.
- We do not sell, lease, or profit from biometric information, and we follow a published retention and destruction schedule (see the Data Retention & Deletion Policy).
- You may withdraw consent at any time. Withdrawal stops any further photo processing and deletes the photo-derived character, its cartoon portrait, and the active appearance description held with that character. What it does not reach is the description already frozen into stories you have generated — that stays with those stories so their illustrations remain coherent, cannot be used to create a new character or restore a deleted one, and is removed when you delete those stories or your account. Withdrawing this consent does not affect Memory Story photos, which are not processed under it and are deleted automatically in any event (see §3(c).2 and §13). Stories that were already generated may remain available, including illustrations already made using that character, unless you separately delete those stories or your account (see §12).
9. International data transfers
Your account, characters, stories, and generated images are stored in Australia (Sydney, ap-southeast-2). Our website is hosted by Vercel on a global edge network, with page rendering currently in the United States, so a visitor's ordinary web-request details are processed there. Our AI providers process data in the United States: story text is sent to Anthropic, and illustrations (plus any uploaded photo, transiently) to OpenAI. We safeguard these transfers with data-processing agreements that bind each provider to our instructions and to not using the data to train their models, and we minimize what leaves our systems (a Character Photo never reaches our storage and is discarded after processing; Memory Story photos are held in Australia only for the seconds it takes OpenAI to read them once from the United States, then deleted — see §3(c).2).
By launch market: for Australia, we take reasonable steps to ensure the overseas recipient handles your information consistently with the Australian Privacy Principles, and we remain accountable for it (APP 8); for Brazil (LGPD), a Child's photo is transferred to the United States on the parent's specific, informed consent, we disclose the destination countries (Australia for storage; the United States for AI processing) and the safeguards applied, and our provider agreements apply contractual safeguards consistent with ANPD requirements (details available on request); for Japan (APPI), the transfer is made on your prior consent after informing you of the destination countries (Australia and the United States), the general status of data-protection law there, and the safeguards each provider applies; for Canada, we bind the provider by contract to a comparable level of protection and remain accountable, information transferred abroad may be accessible to the courts and authorities of those countries, and for Québec we assess the transfer and hold a written agreement with the provider; for New Zealand, our providers act as our agents under contractual safeguards and we remain responsible; for Singapore, we transfer only under contractual protection comparable to the PDPA. For the United States, your information is stored in Australia (§6), so using the Service involves a transfer out of the United States: we remain accountable for it, bind each provider by contract, and apply the same protections described in this policy wherever the information sits. AI processing happens in the United States, so for a US user that step involves no international transfer at all. The App is not offered in the United Kingdom, the EU/EEA, mainland China, Russia, or South Korea at this time.
10. Your rights and choices
Parental controls — in one place. As the adult Account Holder you are always in control of your Child's information. From within the App you can review the profile, characters, stories, and worlds you have created; correct them; delete any item or your entire account; and withdraw photo/biometric consent (which deletes the photo-derived character, its portrait and the appearance description held with it; stories already created keep their illustrations and the appearance description frozen into them — see §8 and §12). These controls are available at any time and do not require contacting us; anything you cannot complete in-app, we will action on request (see below and the Data Retention & Deletion Policy).
You can, at any time:
- Access, correct, or delete your information and your child's — including characters and stories — from within the App. Memory Story photos need no delete control (§3(c).2): they are erased automatically once read, so there is nothing left for you to remove.
- Withdraw consent (including photo/biometric consent), which stops further Character Photo processing and deletes the active character, its cartoon portrait and the appearance description held with it. Limited appearance information already incorporated into stories you have generated remains solely with those stories, as described in §8 (see also §12).
- Withdrawing consent for a Child's information stops further processing of it and deletes the nickname you stored. The age range is kept: it is a content-appropriateness setting used to pitch stories at the right level, not information that identifies a Child (see §3(b)). Stories and characters already created remain in your library unless you delete them or your account.
- Delete your entire account and all associated personal data in-app (see §12).
- Request a copy of your data — access and, where applicable, portability — by emailing
support@cleverlabs.com.au; we provide it in a commonly used format.
Region-specific rights:
- Australia (Privacy Act 1988 / APPs): access and correction, and the right to complain to the Office of the Australian Information Commissioner (OAIC); we treat facial images as sensitive information collected only with your consent.
- Brazil (LGPD): confirmation, access, correction, deletion, portability, and information about sharing, with children's data handled in the child's best interest.
- Canada (PIPEDA / Québec Law 25): access and correction, data portability, and the right to complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
- Japan (APPI): disclosure, correction, and cessation of use as provided by the APPI.
- New Zealand (Privacy Act 2020): access and correction, and the right to complain to the Office of the Privacy Commissioner.
- Singapore (PDPA): access, correction, and withdrawal of consent; our Data Protection Officer can be reached at the contact in §15.
- Taiwan (PDPA) / Hong Kong (PDPO): access, correction, and the rights those ordinances provide, including (Hong Kong) opting out of any direct marketing.
- United States (COPPA): as the parent or guardian you may review the personal information we hold about your child, refuse to permit any further collection or use of it, and have it deleted — using the in-app controls above, or by writing to
support@cleverlabs.com.au; we verify the request through the account holder. Exercising these rights may mean we can no longer provide part of the Service to that child, and we will say so plainly rather than quietly degrading it. Complaints may be made to the Federal Trade Commission atftc.gov. - Illinois (BIPA): we obtain your written release before any facial characteristics are analysed, we publish a retention schedule and destruction guidelines (the Data Retention & Deletion Policy), we never sell, lease, trade or otherwise profit from biometric information, and we never disclose it without your consent.
- Spanish-speaking Latin American markets (for example Mexico's LFPDPPP, Colombia's Law 1581, Chile's data-protection law, Argentina's Law 25.326): access, rectification, cancellation/deletion, and opposition ("ARCO") or equivalent rights as provided by local law; other regions' rights as provided by local law.
We do not sell personal information or share it with third parties for advertising, behavioural profiling or targeted marketing, and we serve no advertising. If you choose to share a story, we make that story available to anyone who opens the unlisted share link you create, as described in §3(g).
To exercise a right you cannot complete in-app, contact support@cleverlabs.com.au. We verify requests through the account holder.
11. Children's privacy
Staris Kids is designed so that the adult account holder provides and controls the information about a child that is added to the account. A child may interact with or experience content through the adult-controlled account, but is not intended to create an account, independently submit personal information, or control the account — and we do not knowingly permit it. A parent supplies this information through an adult account created behind an 18+ / parent-or-guardian attestation, which records who the account holder is rather than serving as permission for any particular processing, and gives a separate parental consent on the setup screen, before adding anything about a child (see §5 and the Consent & Eligibility Policy) — that separate consent is what covers a child's information. Where the account holder purchases a subscription, the payment card and the app store's per-charge receipt are a further indication that an adult is in control: an additional signal, never a basis.
We are in the children's programmes on both stores, and their rules bind us. Staris Kids is listed in the App Store Kids Category and takes part in Google Play's Designed for Families programme. Among other things that means the App ships no third-party analytics and no advertising of any kind (§6), and Apple restricts what a Kids Category app may transmit to third parties — the rule is a restriction on transmitting children's personal or device information, not something a consent unlocks. We meet it by not shipping third-party analytics or advertising at all (§6); the only third parties that receive anything are the service providers listed in §6, for the purpose you asked for — which is why the photo consent and the Child-information consent in §5 are load-bearing rather than formalities. These obligations continue to apply to later versions of the App.
The operative children's-privacy rules are those of our markets and the app-store platforms: the United States (COPPA, and Illinois' Biometric Information Privacy Act for facial analysis), Australia (Privacy Act 1988 / APPs, and the Children's Online Privacy Code once it is registered), Brazil (LGPD — children's data handled in the child's best interest — and the ECA Digital, Lei 15.211/2025, whose child-protection duties we design for even though only adults hold accounts), Canada (PIPEDA and Québec's Law 25), Japan (APPI), New Zealand (Privacy Act 2020), Singapore (PDPA and its children's-data guidelines, under which we treat a child's data to a higher protection standard), Taiwan (PDPA), Hong Kong (PDPO), and the Latin American markets where the Service is offered (each requiring parental consent for a child's data), together with Apple's and Google's children's-app and data-use policies. In the United States, the Children's Online Privacy Protection Act (COPPA) applies. Personal information about a child reaches us because you, the adult account holder, provided it — profile details, photographs and the inputs you give to create content — through the adult-controlled account and behind the grown-up check described below, not through a child account. The App also generates limited operational and engagement data as it is used — how worlds and stories are used, reading activity, and crash diagnostics carrying a persistent installation identifier. That data is first-party, tied to the account rather than to a child's profile, and we use it only to operate, secure, personalize, support and improve the App — not for advertising, cross-service tracking, third-party marketing, or profiling unrelated to running the App. The installation identifier specifically is used only for crash diagnostics, security and integrity: it is never used to contact anyone and never to build a profile (see §3(f)). There is no child account and no child sign-in path, and every place where a child's information can be added sits behind a grown-up check. What that check is: before a child's profile information can be added or changed, before a photograph can be chosen to make a character, and before a story can be shared out of the App, the App asks the device owner to authenticate — Face ID, Touch ID, or the device passcode. Where the device has no passcode set, it asks for the account holder's own password instead. For these actions we never fall back to an arithmetic puzzle, because a child can solve one. What we collect, how we use it, and every third party we disclose it to and why are set out in §3, §4 and §6; the persistent identifier we collect and its sole purposes are in §3(f); your rights to review, refuse further collection and delete, and how to exercise them, are in §10; and the retention schedule is the Data Retention & Deletion Policy. We do not condition your child's participation on disclosing more information than is reasonably necessary. The United Kingdom and the EU/EEA remain excluded, so the Service is not offered to users there.
Across all markets we collect the minimum necessary, never condition a child's use on providing more than needed, serve no advertising, perform no behavioral profiling, and follow a written retention schedule. Parents can review, correct, and delete a child's information and withdraw consent at any time. If we learn a child has created an account without parental involvement, we will delete it. Questions about a child's data: support@cleverlabs.com.au.
12. Data retention & deletion
We keep information only as long as needed for the purposes above and per our Data Retention & Deletion Policy. Character Photos are never stored — they are processed in memory and discarded immediately. That is the photograph itself; a written description of facial and appearance characteristics derived from it IS kept — see §8 and the Data Retention & Deletion Policy §4. Memory Story photos are deleted automatically as soon as they have been read once, normally within seconds of upload and regardless of whether the story succeeds; drafts never hold them, an automatic sweep clears anything an interrupted upload leaves behind, and account deletion purges the area regardless (see §3(c).2). You can delete individual stories and characters, or your entire account and its data, from within the App.
Stories saved on your device. Stories you have opened are also kept on your device so you can read them offline. That copy lives in the App's own storage: it is removed when you delete the App, and a different account signing in on the same device does not see it. Deleting your account removes your data from our systems — it does not reach into a copy already saved on your device. See Terms of Use §13(c) for what this means if the Service is ever discontinued.
Deleting a character does not delete the stories already made with it. Deleting a character — or withdrawing photo consent — removes the character, its cartoon portrait and the appearance description held with it, but the stories you already created keep the illustrations they were generated with and the appearance description frozen into those pages (see §8 and the Data Retention & Deletion Policy §4). To remove those too, delete the stories individually or delete your account.
On account deletion we purge your personal data from our systems and instruct our billing provider to delete its subscriber record; the app stores (Apple / Google) keep their own transaction records under their own terms, and Firebase Crashlytics crash diagnostics — device-level signals we do not tie to your account identity — age out on Google's retention schedule. Limited records are retained where the law requires (tax, security, consent proof). See the Data Retention & Deletion Policy.
Deleting your account is not the same as cancelling a subscription. Instructing our billing provider to delete its subscriber record does not stop billing: an App Store or Google Play subscription keeps renewing until you cancel it in your store account. Cancel there as well if you want the charges to stop (see Terms of Use §5).
13. Security
We use appropriate technical and organizational measures — encryption in transit, access controls, and secure cloud infrastructure — to protect information. Authentication tokens are stored securely on your device. No system is perfectly secure; we maintain an incident-response process and will notify affected users and regulators of a breach as required by law.
14. Changes to this policy
We may update this policy — for example because the App changes, our practices change, or to meet legal, regulatory, safety, security, or operational requirements. We will change the version and effective date above and, for a material change, give you reasonable notice in the App or by email before it takes effect, where notice is required or appropriate. This operates subject to applicable law. Where a materially different processing activity relies on your consent, we will obtain fresh consent before that processing begins where applicable law requires it — we do not treat continued use of the App, on its own, as consent to it.
Language versions. We publish this policy in English, Portuguese, Japanese, French, and Spanish. The English version is the original and controls. Where the law of your place of residence entitles you to rely on the version in your own language, that version prevails for you to the extent it is inconsistent with the English. We intend every version to say the same thing; if you find a difference, tell us at support@cleverlabs.com.au and we will correct it.
15. Contact
Clever Labs Pty Ltd (ACN 700 956 010) · 30 St Kevins Avenue, Benowa QLD 4217, Australia · support@cleverlabs.com.au · +61 403 652 981.
Privacy Officer. Our Privacy Officer is responsible for our compliance with this policy and applicable privacy laws — including as the "person in charge of the protection of personal information" under Québec's Law 25, the data-protection contact ("encarregado") under Brazil's LGPD, the accountable individual under Canada's PIPEDA, and the Data Protection Officer for the purposes of Singapore's PDPA. Contact: support@cleverlabs.com.au (attention: Privacy Officer / DPO).
Privacy complaints. If you believe we have mishandled personal information — yours or your Child's — write to our Privacy Officer at the address above and describe your concern. We will acknowledge your complaint, investigate it, and respond within a reasonable period. If you are not satisfied with our response, you may complain to the privacy regulator where you live; §10 lists the regulator for each of our markets, including the Office of the Australian Information Commissioner (OAIC) in Australia. You do not have to complain to us first, but it usually resolves things faster.