Draft for founder input
Privacy policy
This review draft records practices visible in the current TaleTrellis app. Items marked “Founder input needed” need a company decision before this can serve as a complete privacy notice.
Founder input needed: Confirm the effective date and approve the final policy wording. This draft does not represent that the policy has received legal review.
Information TaleTrellis handles
Depending on which features you use, the app handles information associated with your account and the content you create:
- Account details used for sign-in, including your name and email address, along with authentication and session records.
- Child profile details you enter, such as a child’s name, age, pronouns, and selected avatar.
- Story content and personalization details, including the text and situation details you provide or save.
- Preparation plans, including a situation, event date, and lead time; visual schedules and their step labels; and first-then boards and their labels.
- Story media associated with features you choose to use, including illustrations, narration, uploaded audio recordings, and narrated video.
Founder input needed: Confirm whether other information is collected, including information from visitors who do not create an account, device or log data, and information received from other sources.
How the app uses information
The app uses account and saved-content records to provide sign-in and the TaleTrellis features you choose, such as creating stories, profiles, plans, schedules, boards, and related media. The app sends account verification email. It also offers AI-assisted story generation, illustration and narration features, media storage, and a hosted billing checkout.
Founder input needed: Identify each service provider and its role, the specific information sent to each provider, how each provider handles that information, and any retention or model-training terms that should be disclosed.
Account access
The current app scopes saved child profiles, stories, preparation plans, visual schedules, first-then boards, and related story media to the signed-in account in its product endpoints. The existing FAQ also describes saved stories and child-profile details as private to your account. This describes application access controls; it does not determine what service providers or authorized personnel may access.
Founder input needed: Confirm any operational or support access to account content and the safeguards and disclosures that apply to it.
Analytics and browser storage
The app loads Meta Pixel and sends page-view events. Its current code also sends a signup lead event and, after a verified purchase, a purchase event with the purchase value and currency. When the deployment has its analytics setting enabled, the app sends an optional Polsia page-view beacon and stores a visitor identifier in browser local storage. The app also uses browser storage for some analytics event handling.
Founder input needed: Confirm cookie and local-storage behavior, the analytics data and recipients, retention, and whether consent controls or additional disclosures are required. This draft does not claim that tracking or third-party sharing is absent.
Retention, deletion, and requests
This draft does not describe a retention or deletion period because those practices have not been confirmed here.
Founder input needed: Set account-closure and content-deletion practices, retention periods for account records and user-created content, backup handling, and the process and contact channel for formal privacy requests.
For general company inquiries, use taletrellis-5@polsia.app.
Additional decisions for the founder
- Company identity: legal operating entity, postal address, and effective date.
- Service providers: provider roles and disclosures for AI story generation, illustration and narration, object storage, verification email, hosted checkout, Meta Pixel, and the optional Polsia beacon; also confirm what each receives and its retention or training terms.
- Tracking: cookie and browser-storage inventory, analytics retention, and any consent requirements.
- Data lifecycle: retention, deletion, backup, and account-closure practices.
- Children and legal scope: age and guardian-consent practices, applicable jurisdictions and user rights, and whether personal information is sold or otherwise shared.
- Security: any specific security commitments the company intends to make.