Your family’s story. Your choice to share.
Read the free stories without an account. Making a book needs an invited, verified account and keeps it private. Our writing and drawing helpers make the book, and they start when you press Next on Who’s in it.
Read freely. Make a book with an account.
The free stories are fictional and free to read without signing in. Making a book needs a signed-in, email-verified account that was invited to the pilot.
On Tell, your story, who’s in it and the story we wrote for you to read are saved privately to your account as you go, so you can carry on after a reload or on another device. Only you can open them. Clear it deletes a story you haven’t made into a book, making the book replaces it, and we keep your 20 most recent unfinished stories.
What our helpers read.
Our helpers are how a book gets made. When you press Next on Who’s in it, we record on your account, with the version of the wording, that our writing helper and our picture helper may work on your books, first sketches included. How this works, under that button, shows the full wording before you press it.
The writing helper is Anthropic’s Claude Opus 5.5. It reads your story, the book’s title, size and languages, the names of the people in it with what you wrote about each of them (part, kind, looks, personality, loves and sayings), the places and things the book keeps, and each page’s words and picture notes. First it writes the story in four parts for you to read. When you approve it, it writes the pages, and they land in your book with Undo. It also reads the book on its own to find people the pages mention and to fill out a short look before a portrait is drawn. Anything else you ask for, like a new version of a page, waits until you keep it.
The picture helper is OpenAI’s GPT Image 2.5. It draws each person’s portrait from their name, kind and written look. Pages, first sketches and the cover are drawn from a written description: the page’s picture note and words, the look of each person on it, the places and things it shows, and the book’s art style. The portraits of the people on the page go with it as reference drawings. First sketches are drawn four pages at a time at low quality. The cover is drawn from its title, the names on it and how the story begins.
Both helpers are reached through Vercel AI Gateway. They never receive file names, account or file identifiers, or email addresses. The only photo ever sent is described next.
A photo, only for that person’s portrait.
You can add a photo of someone in Your world. We save it again as a private WebP copy, which removes where it was taken and other hidden details. A person’s photo is saved only with the box that lets our picture helper draw their portrait from it. We record that on the photo, and we record which photo each portrait was drawn from. The photo is sent as an image, never as a link, and only to draw that person’s portrait. Pages are drawn from the portrait, never from the photo.
A photo of a place or thing is never sent to a model. Replace or remove a photo at any time. A portrait already drawn stays until you draw it again or remove the person. Removing a person deletes their portraits and, unless someone else is based on it, their photo.
What we keep, and what we count.
Your books, the story you approved, Your world, your photos, and the portraits and pictures made for you are stored privately. Neon Postgres holds the records and Vercel Blob holds the files. Pictures and portraits you didn’t keep stay stored privately until you delete the book or the person.
We keep no copy of what goes to a model or what comes back, beyond what lands in your book. For each request we keep a count: which help, which model, the tokens, the time, the cost, and whether you kept it. We use it to hold the limits and to record our costs. Vercel AI Gateway, Anthropic and OpenAI handle the words and pictures under their own terms. We have not turned on any training use, and we don’t add family material to any training set of our own.
Turn our helpers off from a book’s settings. It applies to your whole account, and nothing more is sent until you turn them on again or start another book. You can also pause first sketches for one book. A picture already underway can finish. A book made with the earlier separate first-sketch box keeps drawing first sketches until you pause them in that book.
Your account.
Accounts use Neon’s sign-in service and its session cookies; that service may record the internet address and browser a session started from. When you open an invitation link, we also set one cookie so signing up knows which invitation you used. It lasts a day and is removed when you join.
So that each person has one account, we refuse temporary inboxes. We keep a one-way code made from your email address and, when you join or start a book, one made from your internet connection. We can’t turn a code back into the address, and our own tables don’t keep your IP address. We use these codes only to limit how many books can be started in an hour and to notice many accounts from one person.
The pilot is for invited adults. Please leave out full names, exact birthdays, schools, and anything a story doesn’t need. If you email us, we keep your address, the subject and your message so our studio can answer.
Who can see your books.
You, and our studio staff for the books you ask us to make and for support. Staff can see your photos too. Other families and search engines can’t.
If you make a read-only link for a book, anyone with it can read that book’s title, the name on its cover, its words and its page pictures, and nothing else. It works until you stop sharing it or delete the book. Links aren’t listed anywhere, and we ask search engines not to index them.
We don’t sell family information. We use no advertising pixels and no session replay.
Counting visits to public pages.
We count each day how often the free bookshelf, the comparisons and Tell are opened. The counts hold no names, stories, account IDs, visitor IDs, IP addresses or links.
On public pages only (the home page, the free stories, pricing, our guides, comparisons and these policies), PostHog counts visits so we can see which stories get read and how people find us. It records the page, the site you came from, any campaign tag in the link (utm_…), the kind of browser and device with its language, time zone and screen size, and a few taps: opening or finishing a free story, keeping a copy, and Request an invite. PostHog can receive your internet address and estimate a rough location from it. It sets no cookie and saves nothing in your browser. A random number links one visit’s pages and is forgotten when you close or reload the page.
PostHog never runs on Tell, your library, your account, an invitation or a shared book link. Do Not Track and Global Privacy Control turn off both kinds of counting.
Payments and printing.
Ordering a printed book isn’t open to families yet, and checkout runs in Stripe’s test mode. When it opens, Stripe hosts checkout, handles cards and asks for the delivery name and address. We keep that address, the payment reference and the order’s progress, never card numbers.
Nothing is sent to a printer automatically. When printing opens, our studio sends the printer the approved print files, the recipient’s name and address, and delivery instructions. Addresses stay in orders, never in picture prompts or anything public.
Asking for an invitation.
When you ask for an invitation, we keep the email address you give and your note, if you write one, only to reply to you about an invitation. We also keep the date, the campaign tags of the link you followed (such as utm_source), the part of our site you asked from, and a one-way code made from your internet connection, used only to limit how many requests can come from one network in an hour. Nothing is emailed to you automatically. When a place opens, our studio sends you one invitation.
Only our studio can see these requests. They never appear on public pages, in our sitemap or in files for AI agents. Ask us and we delete your request. If you make an account with the same email, your data export includes it.
Invitations.
When our studio or a family invites you by email, we keep your email address, the note they wrote, if any, and their first name, only if they chose to show it. Invitation emails are sent through Resend. We send that one invitation, and at most one more if it wasn’t used after a day. Every invitation email has a “Don’t email me again” link. After you use it, we keep a simplified form of your address only so no one can send it another invitation.
A family can also share an invitation link. Anyone who opens it sees the first name they chose to show. A family who invites you sees only whether you joined. If you join, we record which invitation you used, never the link itself. Your data export includes the invitations you sent and the one you joined with, and closing your account deletes the invitations you sent that nobody used.
Export, removal, and retention.
Download my library data, in your library, gives you your books, unfinished stories, Your world, orders and invitations as one file. Photos aren’t in it, so save any you want to keep, and keep complete digital copies offline.
Deleting a book without an order deletes its pictures, portraits, records and any link to it. A book with an order needs our studio first, so paid work isn’t lost. To close your account, correct something or raise a concern, write to the studio contact in your invitation.
Sign-in records, provider backups and logs, payment records, and files already downloaded or sent to a printer have their own lifecycles. We don’t promise instant erasure from every provider. A fixed retention schedule and a public privacy contact must be set before general signup and real purchases open.
Children’s information needs care.
Adults make the books. Children should not create accounts or submit information. Adults must have the necessary rights and guardian permission for what they share. An age checkbox is not a substitute for reviewing our legal obligations.
General signup and real purchases remain closed. Our business identity, public contact details, provider retention schedules and the children’s privacy rules that apply need review before launch.