ocoboco Terms of Service →

ocoboco

Privacy Policy

Effective date: [TO BE SET AT PUBLISH] · Last updated: 2026-07-09

DRAFT — pending legal review. This document was prepared by the engineering team as an accurate, code-grounded description of how ocoboco handles data. It is not legal advice and is not yet in effect. Bracketed [PLACEHOLDERS] must be completed and the whole document approved by counsel before launch.

ocoboco creates personalized, illustrated, interactive stories about a subject you choose — an invented character, yourself, or someone you know. A grown-up describes the subject; our service uses AI to weave a short story that plays in the browser. This policy explains what information we collect, how we use it, who we share it with, and the choices you have — including how we handle information about a child when a story happens to be about one.

ocoboco is a general-audience tool for grown-ups. Only adults (18+) create accounts and provide information. Children do not sign up, log in, or provide information to us directly. If a story features someone else — and especially if it features a child — you must have the right to depict them; for a child, you must be their parent or legal guardian or have that guardian's permission.

1. Who we are & the scope of this policy

ocoboco (“ocoboco,” “we,” “us”) is a service operated by [LEGAL ENTITY NAME / OPERATOR], [ENTITY TYPE & JURISDICTION], located at [BUSINESS ADDRESS]. This policy applies to the ocoboco website, story studio, and story player at ocoboco.co and related subdomains (the “Service”).

[FOR COUNSEL — operator location] The Service is offered to users in the United States, but the operator is currently based outside the United States (Israel). Please confirm the correct data-controller identity, whether Israel's Privacy Protection Law (including Amendment 13) applies, the appropriate cross-border transfer disclosure, and how the operator's location should be described here and in the Terms' governing-law section.

United States only. The Service is offered to and intended for users in the United States. It is not directed to, and we do not knowingly onboard, users in the European Union, United Kingdom, or other regions. Do not use the Service if you are outside the United States.

The Service is currently in a limited, invite-only beta. Access is gated by an approved-email list, and features described here may change.

2. The short version

3. Information we collect

3.1 Account information

When a grown-up creates an account, we collect and store:

We do not collect a name, phone number, or physical address at signup, and we do not collect payment information (the Service has no paid billing in this release — see §12).

3.2 The story brief (information about a child)

To generate a story, you fill in a short brief. You choose how much to provide. Fields include:

Please provide only a first name and keep free-text fields free of sensitive information. Do not include last names, addresses, birthdates, health information, or other sensitive personal details.

3.3 Uploaded reference images (optional)

You may optionally upload an image (a photo or a drawing) as a visual reference for a character. If you do:

Only upload an image if you have the right to do so and the right to depict anyone shown in it. If the image depicts a child, you must be the child's parent or legal guardian, or have their guardian's permission. Do not upload images of other people without their consent.

3.4 Content we generate for you

When we compile a story, we create and store, on your behalf: the story text, illustrated scenes, character portraits, cover art, and audio narration (together, a “story tape”). The child's first name and your dedication are embedded in the finished story tape. We may also retain short character “memory” notes so recurring characters stay consistent across stories.

3.5 Usage, analytics & referral data

3.6 Diagnostic & error data

3.7 Technical & device data

Like most websites, our hosting and content-delivery provider (Cloudflare) automatically processes technical data such as IP address, browser type, and request metadata to serve the site, provide security, and prevent abuse.

3.8 Cookies & local storage

Our own application does not set tracking cookies. We use your browser's local storage to remember preferences (such as audio, volume, and theme settings), an onboarding flag, and a referral token. On the grown-up studio, the PostHog analytics SDK may set its own cookies or local-storage entries; we honor your browser's “Do Not Track” signal for analytics.

4. How we use information

We do not use the child's information, or content about the child, for targeted advertising, and we do not sell or rent personal information.

5. Children's information (our approach)

The Service is a general-audience creative tool for adults; it is not directed to children. You can create stories about invented characters, yourself, or people you know — who may or may not be children. Because a story can be about a child, we take deliberate steps to minimize and protect any information about a child that an adult chooses to provide:

We do not knowingly collect personal information directly from a child under 13. If you believe a child has provided us information directly, or that a child under 13 has used the Service to create an account, contact us at the address in §12 and we will delete it.

[FOR COUNSEL] This section was reframed to a general-audience, not-directed-to-children posture, and the prior verifiable-parental-consent build-out was removed on that basis. Please confirm the positioning holds given the product's overall presentation, and advise on the interactive player (a viewer taps to choose story branches) and any point-of-collection notice still required.

6. AI generation & the providers who receive story information

Stories are generated by artificial intelligence. To create your story, we send the brief text (and any uploaded reference image) to third-party AI providers that generate the words, artwork, and narration. These providers process the information to return generated content to us. We select providers whose terms permit our use, and we do not authorize them to use your content to train their models beyond what is necessary to provide their service to us [CONFIRM PER PROVIDER — COUNSEL].

7. Email

We use Resend to send transactional email: your passwordless sign-in link, and a “your story is ready to play” message that includes the child's first name, the story title, and a private link to play the story. We do not send marketing email in this release.

8. How we share information (subprocessors)

We share information only with service providers (“subprocessors”) who help us run the Service, under contracts that restrict their use of the information. We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer. The subprocessors we use are:

ProviderPurposeInformation it receives
SupabaseAccounts & databaseEmail, account identity, story & brief metadata (child first name, age, brief text)
Cloudflare (R2, Pages, network)Storage, hosting, securityFinished story tapes (incl. child name & dedication), audio, images, uploaded reference images; technical/IP data
Fly.ioApplication computeProcesses all of the above transiently to run the app
Anthropic (Claude)Story writing (AI)Brief text: child name, age, interests, avoid list, setting, lesson, dedication
OpenRouterAI model gateway & image analysisModel prompts; uploaded reference images for visual analysis
fal.aiImage & sound generation (AI)Text prompts derived from the story and characters
ElevenLabsNarration text-to-speech (AI)Story text to be narrated
ResendTransactional emailRecipient email, child first name, story title
PostHogProduct analytics (studio only)Account-keyed usage events (no child name/age)
SentryError trackingError diagnostics; studio errors may include account id/email; player errors are anonymous
GoogleOptional sign-in (OAuth)Email/identity, only if you choose Google sign-in
PaddleBilling (not active in this release)Would process payment/customer data only if paid billing is turned on later

[FOR COUNSEL] Confirm each provider's commercial-use, data-retention, model-training, and child-directed-use terms; add data-processing-agreement references and each provider's own privacy policy link before publishing.

9. Public share links, retention & deletion

Share links

A finished story is reachable only through a private link containing an unguessable identifier. We never list, index, or make stories searchable, and shared story pages carry a “no-index” instruction so search engines do not list them. Sharing is off by default: until you choose to share a story, its social preview is not personalized with the child's name. Anyone who has the link can open the story without signing in, so share links only with people you trust. You can revoke a share link at any time, after which it stops opening the story for everyone; note that because content is briefly cached by our content-delivery network, revocation may not be instant.

Retention & deletion

10. Security

We use industry-standard measures to protect information, including encrypted transport, access controls, and reputable infrastructure providers. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

11. Your choices & rights

12. Billing

This release of the Service has no paid billing and does not collect payment information. If we introduce paid features later, we will update this policy and provide the required payment and billing disclosures before charging anyone.

13. Changes to this policy

We may update this policy. If we make material changes, we will update the “last updated” date and, where appropriate, notify account holders. Continued use after an update means you accept the revised policy.

14. Contact us

Questions, requests, or concerns about privacy: privacy@ocoboco.co · [LEGAL ENTITY NAME / OPERATOR, BUSINESS ADDRESS].