Legal

Privacy Policy

Last updated: 23 September 2026

Effective date: 23 September 2026 · Version 1.2

This Privacy Policy explains what personal data Vladi's Library collects, why, and what your rights are. It covers the mobile applications for iOS and Android and the website vladislibrary.com (together, the "Service").

Summary for parents, in plain words: you — an adult — hold the account; your child never does. About your child we store only what you type in yourself: a first name, an age, an optional cartoon-animal avatar and story preferences. No photos, no birthdates, no surnames. There are no ads, no analytics trackers, and we never sell data. Personal Stories are private by default. You may share one with a recipient you choose, and authorized administrators may access Personal Stories in a restricted, audited area for support and curation. Publication requires a separate explicit licence and produces an anonymous editorial copy. AI providers process feature data under their applicable business terms, data-processing agreements and account settings; their retention rules differ and are described below. Your private originals can be deleted at any time; limited anonymized licence evidence and an already-promoted editorial copy may remain as explained below.

1. Who is responsible for your data

The data controller is Codera Labs S.R.L., a limited liability company incorporated in Romania:

  • Registered office: Aleea Biruinței nr. 7, Et. P, Ap. 30, Sibiu, Sibiu County, Romania
  • Trade Registry number: J2026003376003 · Fiscal identification code (CUI): 53345450
  • Privacy contact: hello@vladislibrary.com

We have not appointed a data protection officer, as the law does not require one for processing of this scale; the contact above answers every privacy request.

2. Scope

The Service is offered to adults (18+) — parents and legal guardians. Children aged 2–8 are its audience, but they cannot create accounts and we collect no data directly from children. The Service is directed at the European Union and European Economic Area.

3. What we collect

Your account. Your e-mail address (used for one-time sign-in codes — we have no passwords), or, if you sign in with Apple or Google, the e-mail address (possibly an Apple private-relay address) and account identifier those providers give us; your language preference and app settings (evening-reminder time, notification preferences, autoplay).

Child profiles you create. A first name (or nickname — any name you choose), an age, an optional cartoon-animal avatar, and preferred story categories. These fields are typed in by you and remain editable and deletable by you at any time.

Listening activity. Which stories were played, playback progress and completion, which child profile was listening, and timestamps — this powers resume, recommendations shown inside the app, listening streaks and badges.

Stories you create. The inputs you type when generating an AI story (main character description, an optional "tonight's goal", story length), the generated story text, and stories you write yourself, together with their narrations and cover illustrations.

Recipient-bound sharing. When you share a story, we store the story, sender, the recipient Account after the link is claimed, claim and revocation timestamps, and a one-way hash of the invitation token. Personal Story text and audio are disclosed only after the recipient authenticates and claims the link.

Editorial submission and consent. If you submit a Personal Story for library consideration, we store the exact Contribution Licence version and hash you accepted, the consent time, a non-identifying content hash, submission status, and promotion attribution. If accepted, we also retain the link to the separate anonymous editorial copy.

Notifications. A device push token, if you enable notifications, and your per-type notification preferences.

Subscription status. Whether your account has an active subscription, its plan and period — mirrored from the app-store subscription system (RevenueCat). We never receive or store card numbers or payment details; Apple and Google process payments.

Support. E-mails you send us, and our replies.

What we deliberately do not collect: photos, birthdates, surnames or gender of children; contacts; precise location; advertising identifiers. The Service contains no advertising and no third-party analytics, and we do not track you across other companies' apps or websites.

4. Why we use your data, and on what legal basis

Purpose Data used Legal basis (GDPR)
Providing your account and signing you in e-mail, sign-in identifiers, settings Contract — Art. 6(1)(b)
Personalizing stories and the home screen for your children child profile fields, listening activity Contract — Art. 6(1)(b)
Generating and narrating stories you request your generation inputs, story texts Contract — Art. 6(1)(b)
Delivering a story to a recipient you choose sharing record, sender/recipient Accounts, selected story Contract — Art. 6(1)(b), at your request
Restricted support and editorial curation Personal Story and access audit; submission and promotion records Legitimate interest — Art. 6(1)(f): support, removing identifying details before publication and operating the voluntary contribution channel
Creating and managing an editorial copy you explicitly submit submitted content, accepted Contribution Licence and consent evidence Contract — Art. 6(1)(b) and the separate licence you accept
Streaks, badges and listening history features listening activity per child profile Contract — Art. 6(1)(b)
Safety screening of AI story requests the request text (checked, not stored); on refusal, only an aggregate category Legitimate interest — Art. 6(1)(f): protecting children and the integrity of the Service
Service notifications you configured (evening reminder, monthly recap) device token, reminder settings Contract — Art. 6(1)(b)
Occasional news and offers by push notification device token, notification preference Consent — Art. 6(1)(a); opt-in, withdrawable at any time in Profile → Notifications
Managing your subscription entitlement subscription status from RevenueCat Contract — Art. 6(1)(b)
Answering support requests your correspondence Contract / legitimate interest
Security, abuse prevention, service logs technical logs (IP address, request metadata) Legitimate interest — Art. 6(1)(f): keeping the Service secure

Providing an e-mail address (or Apple/Google sign-in) is necessary to have an account; child profile details beyond a name and age are optional. We make no automated decisions producing legal or similarly significant effects about you or your child (Art. 22 GDPR): recommendations and safety screening are feature personalization and protective filtering, nothing more.

5. Children's privacy

  • Accounts can be created only by adults; we do not knowingly allow children to create accounts.
  • All child data is entered by the parent, is limited to the minimum the features need, and can be edited or deleted by the parent at any time (deleting a child profile removes it and its listening records).
  • Children's data is never used for advertising or marketing, never used to build profiles for commercial purposes, and never sold or shared for others' purposes.
  • A Personal Story may contain details about a child. It is disclosed to another user only when the parent creates a share and that recipient authenticates. Before an editorial copy can be published, an administrator must remove or replace real-world identifiers; the public copy carries no parent, child or Account attribution.

6. AI features and safety screening

Story generation and narration use third-party AI providers under data-processing agreements: OpenAI (the current default for new story text, safety moderation and some voice and illustration generation), Anthropic (only legacy story-generation jobs created before the OpenAI migration) and ElevenLabs (voice narration). Provider retention and model-improvement rules are not identical. OpenAI and Anthropic process commercial API data under their applicable business terms and account controls. ElevenLabs currently receives TTS text through its standard API retention mode; our integration does not claim or request Enterprise Zero Retention Mode. ElevenLabs may therefore retain request text and generated audio according to our provider account settings, agreement and its published policy. We do not state that every provider deletes all API data after 30 days.

Before a story is generated, the request text is automatically checked for content that would be harmful or inappropriate for children. The request text itself is not stored by the check; if a request is refused, we keep only an aggregate category of the refusal (for example "violence") to monitor the safety gate — when an account is deleted, even these aggregates lose their link to the account and become anonymous statistics.

7. Who receives your data

People you choose and authorized staff. An authenticated recipient you authorize receives the shared story text and narration while the grant remains active. Authorized administrators protected by two-factor authentication may access Personal Stories through the restricted User Stories area for support and curation; every such view is audited. Sharing never gives our staff publication rights. Publication requires your separate acceptance of the Contribution Licence.

We share personal data only with the processors needed to run the Service, under Art. 28 GDPR data-processing agreements:

Provider Role Location
Hetzner Online GmbH hosting and file storage Germany (EU)
OpenAI default AI story text generation, safety moderation, voice/illustration generation USA
Anthropic legacy story-generation jobs created before the OpenAI migration EU entity; processing partly in the USA
ElevenLabs voice narration USA
Google (Firebase) sign-in with Google, push notifications EU/USA
Apple sign-in with Apple; App Store purchases EU/USA
RevenueCat subscription management USA
Hostinger e-mail delivery (sign-in codes, service e-mails) EU

Apple and Google additionally act as independent controllers for your app-store purchases, under their own privacy policies. We never sell personal data, and we disclose it to authorities only where the law requires.

8. International transfers

Your data is primarily stored in the European Union (Germany). Where a provider processes data in the United States, the transfer relies on the European Commission's adequacy decision for the EU–US Data Privacy Framework for providers certified under it (currently including OpenAI, ElevenLabs and Google), and otherwise on the Commission's Standard Contractual Clauses (Decision 2021/914) with supplementary measures (currently Anthropic, Apple and RevenueCat). You can request a copy of the relevant safeguards at hello@vladislibrary.com.

9. How long we keep data

Data Retention
Account, child profiles, private story originals, listening history, settings for the life of your account; deleted when you delete the account
Story sharing records while the story and sender Account exist; access ends on revocation, recipient erasure, or deletion of the source story or sender Account
Unpromoted submission and consent record while the private original and Account exist, including a withdrawn status so you can later resubmit under the current licence; deleted with the original or Account
Promoted editorial copy and limited licence evidence the anonymous editorial copy may remain under the accepted licence; we retain only the licence version/hash, consent time, promotion attribution, anonymous content hash and copy link needed to evidence that permission
Sign-in codes (OTP) minutes — single-use and expiring
Data processed by AI providers according to each provider agreement, account setting and published policy; ElevenLabs TTS currently uses standard retention rather than Zero Retention Mode
Safety-refusal aggregates category only; anonymized (unlinked) when the account is deleted
Technical/server logs up to 90 days
Support correspondence up to 2 years after the request is closed
Subscription records life of the account, plus any period required by Romanian fiscal law for our own accounting records
Encrypted backups rolling window of up to 35 days; deleted accounts age out of backups within that window, and backups are never used to restore deleted accounts

Account deletion is permanent and takes effect immediately in live systems.

10. Security

Data is hosted in the European Union (Hetzner, Germany) and encrypted in transit. Story audio is served through short-lived signed links. Staff access to the content-management system is role-based and protected by two-factor authentication. Personal Stories appear only in a restricted administrator surface for support and curation, and each list, detail and parent-profile access is audited without copying private story text into the audit log. No system is perfectly secure; if a breach were ever to put your rights at risk, we will notify the supervisory authority and, where required, you, as GDPR obliges.

11. Cookies and local storage

The Service uses only strictly necessary storage: your sign-in session/token, your language preference, and on-device caches (including offline downloads you request). These are exempt from consent requirements, which is why you see no cookie banner. We use no analytics, advertising or third-party cookies. If we ever introduce non-essential cookies, we will ask for your consent first.

12. Notifications

Service notifications exist only if you configure them: the evening reminder you schedule, and the monthly listening recap governed by the "recaps" toggle. Marketing notifications (news and offers) are sent only with your opt-in consent and can be turned off at any time in Profile → Notifications or by disabling notifications at the device level.

13. Your rights

Under the GDPR you can, at any time: access the data we hold about you; rectify it; have it erased; restrict processing; receive it in a portable format (portability); object to processing based on legitimate interest; and withdraw consent (for marketing notifications) without affecting past processing. Many of these you can exercise directly in the app — editing your profile and child profiles, deleting stories, toggling notifications, deleting the account. For everything else, write to hello@vladislibrary.com; we answer within one month.

14. Deleting your account

You can delete your account yourself, at any time: in the app (Profile → Delete account) or on the web at vladislibrary.com/delete-account. Deletion is immediate and permanent for your account, child profiles, private story originals, narrations, generation inputs, listening history and settings. Unpromoted submissions and their consent records are deleted. If a submitted story was already promoted, the separate anonymous editorial copy may remain under the Contribution Licence you accepted, together with only the limited anonymized evidence described in Section 9; the private original and parent/child identity are removed. Remember to also cancel any active subscription in your App Store / Google Play settings — the stores manage billing, and deleting the account does not stop their billing cycle by itself.

15. Complaints

If you believe we process your data unlawfully, please contact us first — we take it seriously. You also have the right to lodge a complaint with the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 București, România Tel: +40 31 805 9211 · anspdcp@dataprotection.ro · www.dataprotection.ro

or with the supervisory authority of your habitual residence.

16. Changes to this policy

We will update this policy when the Service or the law changes. Significant changes are announced in the app or by e-mail before they take effect; the effective date at the top always tells you which version you are reading.

17. Contact

Codera Labs S.R.L. · Aleea Biruinței nr. 7, Et. P, Ap. 30, Sibiu, Sibiu County, Romania · hello@vladislibrary.com