StoryKind is a personalised reading app for children aged 3-10. It is operated by Firmify EOOD ("Firmify"), a company registered in Bulgaria. StoryKind is a product brand of Firmify.
For all privacy enquiries: [email protected]
For school / district procurement and DPA requests: [email protected]
Full legal details: Privacy Policy · Terms of Service
We collect the minimum data necessary to generate personalised stories and track reading progress.
We collect:
We never collect:
StoryKind operates a three-stage consent model. All consent events are recorded with a UTC timestamp and IP address, and can be reviewed under Dashboard → Settings.
1. Account consent — required before any child profile is created.
Before creating a child's profile, a parent must pass a math-challenge parental gate (a
simple arithmetic question to confirm an adult is in control) and explicitly accept our Privacy
Policy. This is StoryKind's implementation of COPPA verifiable parental consent.
2. Voice consent — required before enabling Duet (read-aloud) mode.
Duet mode records a few seconds of a child reading aloud to score fluency. A separate consent
notice explains this before the parent can activate the feature.
3. Teacher-share consent — required before a child's reading data is shared with a teacher.
Teachers cannot access a child's data without the parent first sharing the child's enrollment
code — an explicit action that records consent. Parents can withdraw this at any time by
unenrolling the child from the class.
Children cannot self-register. All accounts are parent or teacher accounts.
| Data category | How long we keep it | How to delete |
|---|---|---|
| Child profile, stories, quizzes, Lexile history | While the child profile exists | Delete child profile in Dashboard → Children |
| Face embedding vector | While the child profile exists | Deleted automatically with the profile |
| Story illustrations and audio | While the story exists | Deleted with child profile |
| Duet mode voice audio | Never stored — ephemeral (seconds) | N/A |
| Parent account, email, preferences | While account is active | Dashboard → Settings → Account |
| Parental consent records | While parent account exists | Account deletion |
| Inactive accounts | No auto-delete — families pause and return | Email [email protected] to request deletion |
Deleting a child profile permanently removes all associated data including stories, quiz results, Lexile history, the face embedding vector, and associated media files. This cannot be undone.
When a parent configures a child's avatar (choosing hair colour, skin tone, eye colour, and hair style), StoryKind converts those categorical choices into a list of numbers called a face embedding vector. This vector is used to keep the child's illustrated character looking consistent across different stories.
What it is not: The vector is not a photograph, biometric scan, or facial recognition template. It is derived from categorical style selections (e.g., "brown hair, medium skin tone") — not from any image of the child. It cannot be used to identify the child.
Deletion: The vector is stored only while the child profile exists. It is deleted automatically when the profile is deleted.
Who sees it: The vector is passed to our illustration provider (Replicate) as part of each story's illustration request, to anchor the character's appearance. It is not shared with any other party.
For technical detail, see our Privacy Policy §3a.
These are the third-party services we use to deliver StoryKind. All AI providers are contractually required not to retain or train on child data.
| Provider | Purpose | Child data sent | Transfer safeguards |
|---|---|---|---|
| Clerk | Login and authentication | Parent email, name only | Standard Contractual Clauses (SCC) |
| Stripe | Payment processing | Billing info only — no child data | SCC |
| Cloudflare R2 | Story illustrations and narration audio | Media files linked to child | SCC |
| OpenAI | Story text generation | Child first name, age, interests, story prompt | SCC; not used to train |
| Anthropic (Claude) | Story text generation (fallback) | Child first name, age, interests, story prompt | SCC; not used to train |
| ElevenLabs | Text-to-speech narration | Story text — no child identifiers | SCC |
| Replicate | Illustration generation | Story context, avatar vector — no child identifiers | SCC |
| Deepgram | Read-aloud fluency scoring | Voice audio, processed ephemerally — not stored | SCC |
All EU-to-US data transfers are covered by Standard Contractual Clauses in accordance with GDPR. Our lead supervisory authority is the Commission for Personal Data Protection (KZLD), Bulgaria.
A teacher with enrolled students can see each student's:
Teachers cannot see parent email addresses, school names, or any data beyond the reading and comprehension scope.
StoryKind is designed for children and is built with FERPA-aligned data practices:
StoryKind is not a student information system or school official record system. For school or district deployments where a formal Data Processing Agreement (DPA) is required — including for FERPA compliance — contact [email protected]. We provide a template DPA in which StoryKind acts as a data processor for the school.
Teachers cannot add students directly. A parent must first share the child's unique enrollment code with the teacher. This sharing constitutes explicit parental consent for the teacher to access reading data. Parents can revoke access at any time from Dashboard → Children.
| Purpose | Contact |
|---|---|
| Privacy questions, data rights requests, GDPR/COPPA | [email protected] |
| School / district DPA requests, procurement questionnaires | [email protected] |
| General support | [email protected] |
We respond to all data rights requests within 30 days (GDPR Art. 12).
Firmify EOOD, operating StoryKind — a Firmify Company
Sofia, Maestro Kanev 66B, Bulgaria