Privacy Notice
Last updated: March 11, 2026
1. Who we are
My Little Hero is a personalised story platform for families. It is operated under the laws of England and Wales.
For general questions, email [email protected] . For privacy questions, email [email protected] .
2. What data we collect
- account details such as your name and email address
- household and persistent profile data such as child, adult, pet, and companion names, ages, interests, traits, household roles, relationship links, and visual-reference choices
- story titles, story-project cast setups, themes, support choices, prompts, generated text, and generated images
- optional story reference images, optional profile photo uploads, and saved generated story avatars where available
- manual support preferences and runtime reading controls stored with a story when you choose them
- billing and subscription records handled through Stripe
- security, session, moderation, and audit data needed to operate the service safely
3. How we use your data
We use personal data for specific purposes. The table below shows the current working legal basis and retention summary for each core use. Some positions remain marked as provisional until final legal review is completed.
| Purpose | Legal basis | Retention summary |
|---|---|---|
| Consumer account registration, authentication, and account settings | Contract | Active-account lifecycle, then account-deletion / accountability rules. |
| Household management, persistent profile creation, and saved relationship graphs for children, adults, pets, and companions | Contract | While the household/profile remains live or until account deletion. |
| Consent-version and notice-acceptance records | Provisional working position: contract-accountability record, pending final legal review. | Retained with the account and linked accountability records. |
| Billing, subscriptions, credit allocation, and payment operations | Contract, with legal-obligation retention where finance rules apply. | Six-year finance/accountability working rule. |
| Story-project setup, story generation, story delivery, and story snapshots | Contract | While the story remains in your library or until account deletion. |
| Optional profile photo uploads, generated story avatars, and story reference images | Provisional working position: contract for the optional feature, pending final legal review. | Story reference images are temporary; uploaded profile photos are deleted after avatar processing; saved generated avatars remain while the linked profile stays live. |
| Manual story support preferences and support snapshots | Provisional working position: contract for the requested support feature, pending final legal and Article 9 review. | Retained with the story while it remains in your library. |
| Kid Mode session access and sealed child reader access | Contract / service necessity | Short session window only. |
| Moderation, abuse-prevention, safety review, and AI audit logging | Likely legitimate interests | Moderation logs: 12 months. Consumer AI audit logs: 180 days. Safety/accountability exceptions may apply. |
| Data export, deletion, and accountability logging | Rights fulfilment / controller obligation, plus legitimate-interests accountability for deletion/export logs pending final legal review. | Deletion/export accountability logs: six-year working rule. |
4. Child data and the adult-controlled model
Consumer accounts are adult-owned. Parents, carers, or other authorised adults decide what child information to provide so the service can create and manage households, persistent profiles, and personalised stories.
We ask adults to provide only what is needed to make the story work, and we keep the child-facing reading surfaces high-privacy by default. If you want the child-friendly version of this notice, read our child-friendly privacy notice .
5. Optional images and AI analysis
If you upload a story reference image, we send that image to Google Gemini so it can help keep story visuals consistent during generation. If you upload a profile photo in Family Studio, we send that image to Google Gemini so it can analyse consistent visual features and create a child-friendly story avatar linked to the saved profile. We do not use these features for biometric identification, identity verification, or age estimation.
Story-specific reference images are temporary and are deleted after generation settles or if the story is deleted earlier. Uploaded profile photos are also temporary and are deleted after the story avatar has been created or the processing fails. The saved generated avatar, anchoring description, and visual-reference selection remain linked to the saved profile while you keep it in the service. If you delete that saved profile and no other saved profile still uses the same avatar, we delete the saved avatar too.
6. Support preferences and sensitive-data caution
We try to store functional support preferences such as pacing, sensory, and communication choices instead of diagnosis labels. That keeps the feature more privacy-proportionate.
Even so, support preferences or free text can still reveal information about disability or health. That is treated as a higher-risk data type in our internal review, and it is one of the areas that remains under ongoing legal and privacy scrutiny.
7. Cookies and similar technologies
We use essential cookies and a small amount of functional browser storage so the service can stay secure and remember appearance and accessibility choices. Read the full detail in our cookies and similar technologies notice .
8. AI and other providers
We use Google Gemini for story generation and story-reference-image analysis. Google's API terms state that data submitted via the API is not used to train Gemini models by default.
We use Stripe for billing and subscription operations. We also rely on hosting and storage providers to run the platform securely. We do not sell child or family data to advertisers.
My Little Hero does not use story generation to make solely automated decisions that have legal or similarly significant effects about children. The service generates content, but adults remain in control of account settings, deletions, exports, support choices, and which stories are kept or shared.
9. International transfers
Some providers, including Google and Stripe, may route or support data outside the UK. Where a restricted transfer applies, we work on the basis of the relevant safeguard such as an adequacy position or contractual transfer terms.
Our provider and transfer wording is still part of the wider legal-review pack, so this section is intended to be transparent without overstating final contract language.
10. Retention summary
| Data set | Retention period | Control |
|---|---|---|
| Account, household, profile, and relationship-graph data | While the account remains active, then deletion/accountability rules apply. | Self-service deletion plus operational accountability retention where justified. |
| Stories, story-project setups, pages, and story snapshots | While the story remains in your library or until account deletion. | Self-service story deletion and account deletion flows. |
| Story reference images | Deleted after generation settles or when the story is deleted earlier. | Automated cleanup on completion/permanent failure plus story deletion. |
| Profile-photo uploads, saved generated avatars, and visual-reference selections | Uploaded profile photos are temporary; saved generated avatars remain while the linked household/profile record stays live. | Uploaded profile photos are deleted after processing. If you delete the linked profile and no other saved profile still uses the same avatar, the saved generated avatar is deleted too. |
| Manual story support preferences and support snapshots | While the linked generated story remains live. | Story deletion or account deletion. |
| Moderation logs, content reports, and strike records | 12 months unless a legal, safety, or abuse hold applies. | Scheduled purge job plus hold exceptions. |
| Consumer AI audit logs | 180 days unless a legal, safety, or abuse hold applies. | Scheduled purge job plus hold exceptions. |
| Billing and accountability records | Six years under the current working schedule. | Manual finance/accountability retention pending final sign-off. |
| Deletion and export logs | Six years under the current working schedule. | Manual accountability retention pending final sign-off. |
11. Your rights
Under UK data protection law, you may ask to access, correct, export, restrict, or delete personal data we hold about you and your linked family account data.
- Access and export: you can request a copy of your data through Account Settings .
- Correction: you can update core account details in Account Settings.
- Deletion: you can delete stories, saved family groups, saved characters, or your whole account. If you need help with anything else, contact us.
If a school uses the education version of My Little Hero, classroom rights requests should normally go through the school because we may be acting as a processor for that classroom data.
You can also raise a concern with the UK Information Commissioner's Office at ico.org.uk .
12. Contact
For legal or privacy questions, email [email protected] . For general support, email [email protected] .