Trust & Privacy Centre

Who We Are

StoryKind is a personalised reading app for children aged 3-10. It is operated by Firmify EOOD ("Firmify"), a company registered in Bulgaria. StoryKind is a product brand of Firmify.

For all privacy enquiries: [email protected]
For school / district procurement and DPA requests: [email protected]
Full legal details: Privacy Policy · Terms of Service


What We Collect About Children

We collect the minimum data necessary to generate personalised stories and track reading progress.

We collect:

  • First name only (never a last name)
  • Age (3-10)
  • Avatar choices (hair colour, skin tone, eye colour — see Face Embedding below)
  • Story interests (e.g., "dinosaurs", "space")
  • Reading history, quiz scores, and Lexile level

We never collect:

  • Last names, physical addresses, or school names
  • Email addresses for children
  • Photographs or facial scans
  • Precise location data
  • Any contact information about the child

How Parental Consent Works

StoryKind operates a three-stage consent model. All consent events are recorded with a UTC timestamp and IP address, and can be reviewed under Dashboard → Settings.

1. Account consent — required before any child profile is created.
Before creating a child's profile, a parent must pass a math-challenge parental gate (a simple arithmetic question to confirm an adult is in control) and explicitly accept our Privacy Policy. This is StoryKind's implementation of COPPA verifiable parental consent.

2. Voice consent — required before enabling Duet (read-aloud) mode.
Duet mode records a few seconds of a child reading aloud to score fluency. A separate consent notice explains this before the parent can activate the feature.

3. Teacher-share consent — required before a child's reading data is shared with a teacher.
Teachers cannot access a child's data without the parent first sharing the child's enrollment code — an explicit action that records consent. Parents can withdraw this at any time by unenrolling the child from the class.

Children cannot self-register. All accounts are parent or teacher accounts.


Data Retention

Data category How long we keep it How to delete
Child profile, stories, quizzes, Lexile history While the child profile exists Delete child profile in Dashboard → Children
Face embedding vector While the child profile exists Deleted automatically with the profile
Story illustrations and audio While the story exists Deleted with child profile
Duet mode voice audio Never stored — ephemeral (seconds) N/A
Parent account, email, preferences While account is active Dashboard → Settings → Account
Parental consent records While parent account exists Account deletion
Inactive accounts No auto-delete — families pause and return Email [email protected] to request deletion

Deleting a child profile permanently removes all associated data including stories, quiz results, Lexile history, the face embedding vector, and associated media files. This cannot be undone.


Face Embedding — Plain Language

When a parent configures a child's avatar (choosing hair colour, skin tone, eye colour, and hair style), StoryKind converts those categorical choices into a list of numbers called a face embedding vector. This vector is used to keep the child's illustrated character looking consistent across different stories.

What it is not: The vector is not a photograph, biometric scan, or facial recognition template. It is derived from categorical style selections (e.g., "brown hair, medium skin tone") — not from any image of the child. It cannot be used to identify the child.

Deletion: The vector is stored only while the child profile exists. It is deleted automatically when the profile is deleted.

Who sees it: The vector is passed to our illustration provider (Replicate) as part of each story's illustration request, to anchor the character's appearance. It is not shared with any other party.

For technical detail, see our Privacy Policy §3a.


Our Subprocessors

These are the third-party services we use to deliver StoryKind. All AI providers are contractually required not to retain or train on child data.

Provider Purpose Child data sent Transfer safeguards
Clerk Login and authentication Parent email, name only Standard Contractual Clauses (SCC)
Stripe Payment processing Billing info only — no child data SCC
Cloudflare R2 Story illustrations and narration audio Media files linked to child SCC
OpenAI Story text generation Child first name, age, interests, story prompt SCC; not used to train
Anthropic (Claude) Story text generation (fallback) Child first name, age, interests, story prompt SCC; not used to train
ElevenLabs Text-to-speech narration Story text — no child identifiers SCC
Replicate Illustration generation Story context, avatar vector — no child identifiers SCC
Deepgram Read-aloud fluency scoring Voice audio, processed ephemerally — not stored SCC

All EU-to-US data transfers are covered by Standard Contractual Clauses in accordance with GDPR. Our lead supervisory authority is the Commission for Personal Data Protection (KZLD), Bulgaria.


For Schools and Teachers

What Teachers Can See

A teacher with enrolled students can see each student's:

  • First name
  • Current Lexile level and trend
  • Story reading history (titles and dates)
  • Quiz scores per story
  • Vocabulary progress and reading streak

Teachers cannot see parent email addresses, school names, or any data beyond the reading and comprehension scope.

FERPA and School Data Agreements

StoryKind is designed for children and is built with FERPA-aligned data practices:

  • We collect only first names and reading data — no contact information, photographs, or school identifiers
  • We do not sell or share student data with any third party for commercial purposes
  • Parents retain full data access, export, and deletion rights at all times

StoryKind is not a student information system or school official record system. For school or district deployments where a formal Data Processing Agreement (DPA) is required — including for FERPA compliance — contact [email protected]. We provide a template DPA in which StoryKind acts as a data processor for the school.

Classroom Enrollment Requires Parent Consent

Teachers cannot add students directly. A parent must first share the child's unique enrollment code with the teacher. This sharing constitutes explicit parental consent for the teacher to access reading data. Parents can revoke access at any time from Dashboard → Children.


Contact

Purpose Contact
Privacy questions, data rights requests, GDPR/COPPA [email protected]
School / district DPA requests, procurement questionnaires [email protected]
General support [email protected]

We respond to all data rights requests within 30 days (GDPR Art. 12).

Firmify EOOD, operating StoryKind — a Firmify Company
Sofia, Maestro Kanev 66B, Bulgaria