HeroTeller privacy
Privacy, in plain language
HeroTeller is an adult-facing private beta operated by INPOSOL d.o.o. Parents, guardians, and other adults use it to make stories for children. Please review this notice with the company information and contact details before production launch.
What we process
We process the account identity and email managed through Clerk, your privacy-consent record, access tier and usage totals, and the information you choose in the story form. That form may include a child's first name or nickname, age band, gender choice, interests, story preferences, optional friend names, and an optional story note.
A completed story and its optional narration are saved in your account until you delete them. The saved story may include a small story-bound presentation of the validated display name, age band, selected interests, story choices, and local artwork key. HeroTeller does not create a reusable child profile from this information.
Why and where
- Clerk provides authentication, sessions, invitations, and account identity.
- Neon Postgres stores the HeroTeller account, consent, usage, story, and deletion records.
- Vercel hosts the application and privately stores narration files in Vercel Blob.
- One configured story model provider—Anthropic, OpenAI, or DeepSeek—receives tokenized story choices to generate a story.
- ElevenLabs receives story text only when you explicitly request narration. Its retention mode and region are deployment settings.
- Tally hosts the optional beta questionnaire and retains questionnaire responses under its own notice. HeroTeller stores only limited completion metadata.
The provider list above reflects integrations present in the codebase. The exact provider, region, retention settings, contractual safeguards, and any transfer mechanism must be confirmed for the deployment before real child-related data is used.
Minimisation and children's data
Use a first name or nickname only. Do not enter a surname, address, school, exact date of birth, health information, photographs, or other sensitive information about a child. The structured choices are designed to reduce unnecessary personal data. Parents and guardians should review generated content before sharing it with a child.
Retention and deletion
You can delete individual stories, including their narration, or delete your account from Account → Data & Privacy. Account deletion removes HeroTeller profile, consent, story, narration, invitation, feedback-correlation, and credit data; historical usage is anonymised. External providers may have separate retention obligations, which are documented in their notices and must be handled through the applicable processor process. Tally questionnaire responses are not controlled by HeroTeller's account-deletion cascade.
Limited security and usage records may be retained for operational or legal reasons. The protected retention job removes identifiable usage metadata after at most 12 months under the current system design. Exact legal and accounting retention periods require owner and legal confirmation.
Cookies and tracking
The audited application does not currently include advertising pixels, behavioural analytics, or non-essential tracking. Authentication cookies are necessary for sign-in. Session storage is used only for short-lived in-progress workflow state such as recovery and dismissing an optional feedback prompt; it is not used for advertising or profiling. A consent banner is therefore not currently shown.
Your rights and contact
Depending on the applicable law, you may have rights to access, correct, delete, restrict, or object to processing, and to lodge a complaint with a supervisory authority. The operational contact email and complete company registration details are still an owner-configured launch item; see Company information and Contact for the explicit placeholder that must be completed before public launch.