Privacy Policy

Version 2026-09-15 · 15 September 2026

1. Who We Are

StoryHop is operated by Aleksandr Gorin. Aleksandr Gorin is the controller responsible for StoryHop.

Controller: Aleksandr Gorin, StoryHop, Käthe-Kollwitz-Str. 10b, 14943 Luckenwalde, Germany

Privacy contact: privacy@storyhop.io

Support contact: support@storyhop.io

Contact form: https://storyhop.io/contact

Further legal provider information is available in the Impressum.

We have not appointed a Data Protection Officer. You can contact us about privacy at privacy@storyhop.io.

2. What This Policy Covers

This policy applies only to the StoryHop app for iOS, including parent accounts, child profiles, StoryHop Plus subscriptions, child-device login, support, and emails we send in connection with the app. Other StoryHop services have their own documents.

StoryHop is offered only in the European Union, the European Economic Area, and Switzerland.

StoryHop is designed for children aged 6 to 15. Accounts are held by adults: the person who creates an account confirms that they are 18 or older and a parent or legal guardian. Parents or legal guardians create and manage child profiles. Children cannot access parent settings.

StoryHop does not currently provide school, classroom, or teacher accounts.

3. How StoryHop Works

Parents create a StoryHop account and may create child profiles. In the parent area, a parent can create a one-time QR code and six-digit login code that signs a child's device in to StoryHop without giving the child a username or password.

StoryHop stores each child's progress so parents can see reading activity and so StoryHop can recommend similar stories.

StoryHop has free features and an optional paid subscription, StoryHop Plus, which unlocks additional content such as more stories and riddle themes. A subscription belongs to the parent account and applies to every child profile on that account. It is offered only in parent-only parts of the app.

4. Personal Data We Collect

Parent account data:

  • email address and name (if you use Sign in with Apple and hide your email, we receive Apple's relay address instead);
  • your password, stored only as a secure hash, or the identifier we receive from Google or Apple if you sign in with them;
  • your parent PIN, stored only as a secure hash;
  • sign-in sessions and app settings such as app language;
  • when the account last started or renewed a sign-in session, and when we sent a notice before deleting an inactive account (see section 18);
  • a random account token used to match App Store purchases to your account (see section 5);
  • consent and confirmation records (see section 7);
  • support messages and privacy requests you send us.

Child profile data:

  • the name or nickname the parent types in;
  • age (6 to 15);
  • avatar;
  • reading level, which StoryHop may adjust automatically based on completed stories and quiz results;
  • interface language and content language.

Learning activity for each child profile:

  • stories finished and quiz answers;
  • riddle rounds and whether each answer was correct (the answer the child types is sent to our server to check it, but only the result, correct or incorrect, is stored);
  • XP, levels, badges, streaks, and reading statistics;
  • reading history shown in the parent dashboard.

The page a child last reached in a story is stored only on the device and is not sent to StoryHop.

Subscription data, if you use StoryHop Plus, is described in section 5. Paywall events are described in section 6.

Parents should avoid entering a child's real name unless they choose to do so. StoryHop does not require child email addresses, phone numbers, postal addresses, photos, voice recordings, or location data.

When the app connects to our servers, our servers record technical request information, which can include IP address and device information, to operate and secure the service. These server request logs are deleted after 14 days.

The app also processes sign-in session data, technical information about the device and app version, and the QR-code result or typed login code used for child-device login. The camera is used only to scan login QR codes, and only if you allow camera access.

QR scanning is processed locally on the device. StoryHop does not upload camera images or video for QR scanning. After a QR code is scanned, only the decoded login token is sent to the server for login exchange.

The app does not currently use microphone access, speech recognition, photo library access, precise location access, IDFA, or advertising tracking.

5. StoryHop Plus Subscriptions and Payments

StoryHop Plus is sold only through Apple in-app purchase in the iOS app. Apple takes the payment. StoryHop does not receive or store your payment card details, bank details, or Apple ID password.

To link a purchase to your StoryHop account, we create a random account token for your account. The app passes it to Apple with the purchase, and Apple includes it in the purchase records it sends us. The token is stored with your account and deleted when you delete your account; Apple keeps its copy in its own purchase records.

For your subscription, we keep a subscription record containing the plan, subscription status, whether a free trial applies, whether the subscription will renew, purchase and expiry dates, whether it is a test or real purchase, and the Apple transaction identifier.

Apple also sends our server signed notifications about the subscription, such as renewals, cancellations, billing problems, and refunds. A notification contains the App Store country or region, price and currency, the product, purchase and expiry dates, Apple transaction identifiers, and our random account token. It does not contain your email address, name, or Apple ID.

We use subscription data to give your account access to StoryHop Plus, keep that access in line with what Apple reports, restore purchases, and prevent one purchase from being claimed by several StoryHop accounts. If one StoryHop account has two active subscriptions at the same time, we mark both subscription records for manual review.

We keep Apple's notifications for 90 days to recognise repeated deliveries of the same notification (Apple retries a failed delivery for up to about a week) and as a short billing log for investigating disputed charges and technical problems. They are stored by Apple's delivery and transaction identifiers, not by StoryHop account, so notifications received before you delete your account are kept for the full 90 days. For a subscription that no longer belongs to any StoryHop account, we keep only the delivery identifier, type, and date of later renewal and status notifications, not their content; a few rarer notification types, such as a price increase notice, are still kept in full for 90 days.

Subscription data is linked to the parent account, not to a child profile.

Apple processes your Apple ID, payment details, and purchase history under its own terms and privacy policy.

Deleting your StoryHop account or the app does not cancel your subscription. See section 19.

6. Internal Product Analytics

The StoryHop app contains no third-party analytics or advertising SDKs.

StoryHop records a small set of events about the StoryHop Plus offer screen (the paywall) on our own servers. We use them to understand whether parents find and understand the offer and where the purchase process fails, so we can improve it. They are never used for advertising.

Each event contains only:

  • one of eight event types: paywall shown, paywall closed, plan selected, purchase started, purchase completed, purchase failed, restore purchases tapped, or parent gate opened;
  • where it happened: in a story, in a riddle theme, or in settings;
  • the internal ID of the active child profile;
  • the time of the event.

Events never contain names, ages, avatars, story text, answers, free text, or advertising identifiers. Because every event contains a child profile ID, it is linked to that child profile within StoryHop.

Events are sent and stored only for a child profile whose parent consented. Consent is optional and is asked separately for each child profile when the profile is created. If you do not consent, the app works the same and does not send events for that profile. No events are sent before a child profile with this consent exists, for example while the account is being set up.

All paywall events are deleted automatically 90 days after we receive them.

You can give or withdraw consent for each child profile at any time with the Paywall statistics switch for that profile in the parent area under Privacy, or by contacting privacy@storyhop.io. After you withdraw consent, no further events are sent or stored for that profile; events already stored are deleted after the 90 days, or earlier if you ask us. Deleting the child profile or your account also deletes the stored events of that profile.

7. Consents and Confirmations

StoryHop asks for the following:

  • adult confirmation: required, once per account, during account setup. You confirm that you are 18 or older and a parent or legal guardian. Child profiles cannot be created without it;
  • emails about new stories: optional consent, for the account, during account setup or later in the parent area under Privacy;
  • parent confirmation for each child profile: required, when the profile is created. You confirm that you are the child's parent or legal guardian and authorise StoryHop to create the profile and process the child's data described in section 4 to provide the app. The profile cannot be created without it;
  • paywall events linked to a child profile: optional consent, for each child profile, when the profile is created; you can change it at any time in the parent area under Privacy (see section 6);
  • the Terms of Use and this Privacy Policy: during account setup, together with the adult confirmation, you accept the Terms and acknowledge this policy. If you have not accepted the current version of the Terms for the iOS app, for example because we published a new version, the app asks you after you enter the parent PIN to accept the Terms and confirm that you have read this policy (see section 24). This request is never shown in a child's session.

The parent confirmation for a child profile authorises StoryHop to provide the service for that child. Under GDPR, the child profile data needed to provide the app is processed to perform our contract with you, not on the basis of consent (see section 10).

For each choice, we store whether it was given or refused, the time, the language, the edition of the legal documents shown (for this app: iOS), the version of the wording shown to you, and the versions of the Terms and this Privacy Policy shown to you. We keep these records so we can show what was agreed and when.

Consent and confirmation records are deleted together with the child profile or account they belong to.

8. AI and Content Processing

StoryHop uses AI tools internally to prepare and improve content, including rewriting stories, adapting stories to reading levels, translating stories or variants, categorizing content, and generating illustrations.

StoryHop currently uses OpenAI for text-related content processing and Google for illustration generation.

StoryHop does not allow parents or children to enter custom free-text prompts for AI generation. StoryHop sends only StoryHop story and content materials to AI providers, not child profile data, parent account data, progress data, quiz answers, or reading history.

Generated illustrations are reviewed by a human before children can see them. Approved illustrations are stored on StoryHop-controlled servers.

9. Why We Process Data

We process personal data to create and manage parent accounts and child profiles, authenticate parents and child devices, provide stories, quizzes, riddles, and progress tracking, show parent progress reports, recommend similar stories, provide and manage StoryHop Plus subscriptions, record consents and confirmations, understand how the StoryHop Plus offer performs, operate and secure the service, respond to requests, send transactional emails, send parent marketing emails with consent, generate and moderate StoryHop content, and comply with legal obligations.

StoryHop does not make decisions based solely on automated processing that have legal effects on you or your child or similarly significantly affect you (Article 22 GDPR). The automatic reading-level adjustment only changes which stories and story versions are offered, and parents can see and change the reading level.

10. Legal Bases

We rely on the following legal bases under the GDPR.

Contract (Article 6(1)(b) GDPR) covers providing the parent account, child profiles, and the core app service for each child: reading progress, stories read, quiz and riddle results, XP, badges, streaks, reading level, and the statistics shown in the parent dashboard. It also covers sign-in and child-device login, service emails such as email address verification and password reset, support, and StoryHop Plus, including checking purchases with Apple and keeping access in line with the subscription status. This data is needed to provide StoryHop and is not optional. When a parent creates a child profile, the parent concludes this contract for the child's benefit. Where the child is not treated as a party to that contract, we process the child profile data listed above because we and the parent have a legitimate interest in providing the service the parent chose for the child (Article 6(1)(f) GDPR). You can object at any time (see section 21).

The required parent confirmation given when a child profile is created (see section 7) is not the legal basis for this processing under GDPR. It confirms that the parent is authorised to set up the profile.

Consent (Article 6(1)(a) GDPR) covers marketing emails and paywall events linked to a child profile. For paywall events, which the app sends from the device, consent is also required by section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Both are optional. If consent for paywall events is not given, those events are not sent or stored.

Legitimate interests (Article 6(1)(f) GDPR) cover securing the service and keeping server request logs, preventing misuse such as one purchase being claimed by several accounts, keeping Apple's subscription notifications to recognise repeated deliveries and investigate disputed charges, sending a notice before an inactive account is deleted, answering messages sent through the contact form, and keeping records of the confirmations described in section 7.

Legal obligation (Article 6(1)(c) GDPR) covers keeping records that show consent was given, and handling privacy requests under sections 21 and 25.

You may withdraw consent at any time. Withdrawal does not affect processing that happened before withdrawal.

11. Children's Privacy and Parent Controls

StoryHop is parent-managed. Parents create accounts, create and confirm child profiles, and control child access. The parent area is protected by a parent PIN.

In the app, parents can view child progress, create, edit, or delete child profiles, turn paywall events on or off for each child profile, withdraw marketing consent, and delete the parent account. Parents can contact us to request a copy of parent and child-profile data, or to review, correct, or delete child-related personal data.

Children cannot access parent settings. Children may see that some content is locked, but prices and purchase buttons are shown only in parent-only parts of the app.

StoryHop does not sell child data, use child data for behavioral advertising, or knowingly allow child profile data to be used to create advertising profiles.

12. Child-Device Login and Sessions

Parents may create a child-device login QR code and six-digit login code in the parent area. The QR code contains a sign-in link with the same one-time code.

A login code can be used once and expires after 5 minutes. We store only a secure hash of it, together with the account and child profile it belongs to, and delete it within 24 hours after it expires. After successful login, the device receives a session for the parent account with the selected child profile opened. Parent settings on that device remain protected by the parent PIN.

Each signed-in device has its own session, made up of an access token, valid for 14 days, and a refresh token, valid for 30 days. The app renews the session with the refresh token, which is replaced each time it is used. A device that does not connect to StoryHop for 30 days has to sign in again.

Logging out on a device removes that device's refresh token and ends parent PIN authorisation on it. Resetting your password removes the refresh tokens of all devices. A device that already holds a valid access token can stay signed in until that token expires, at most 14 days.

Parent PIN authorisation is separate from the sign-in session and lasts 15 minutes.

13. Notifications

The app does not send push notifications and does not ask for permission to send them.

14. Marketing Emails

StoryHop sends marketing emails only to parents or guardians who separately opt in.

Marketing consent is optional, separate from account creation, and does not affect how the app works. You can opt in during account setup or in the parent area under Privacy, after your email address has been verified.

We have not started sending marketing emails yet. When we do, every marketing email will include an unsubscribe link. You can also withdraw consent at any time in the parent area under Privacy.

Service emails, such as email address verification, password reset, and a notice before an inactive account is deleted, are sent regardless of marketing consent. We also reply to messages you send us.

15. On-Device Storage

The app keeps sign-in session tokens in the device's secure storage.

The app also stores the app language and other settings, the selected child profile, and the page each child has reached in a story on the device. This is needed for the app to work as you requested (section 25(2) no. 2 TDDDG).

StoryHop does not use cookies, advertising identifiers, or tracking technologies in the app.

16. Who We Share Data With

We share personal data only where needed to operate StoryHop, comply with law, or protect the service.

Service providers that process personal data on our behalf and under our instructions (data processing agreements under Article 28 GDPR):

  • DigitalOcean: hosting of our servers, database, and backups in Frankfurt, Germany;
  • Resend: sending service emails from info@storyhop.io, currently email address verification, password reset, and notices before an inactive account is deleted, and receiving emails sent to our storyhop.io addresses.

Independent controllers, which process data under their own terms and privacy policies when you use their services:

  • Apple: in-app purchases and payments, Sign in with Apple, subscription notifications, and subscription status checks;
  • Google: Google Sign-In, only if you choose to sign in with Google.

AI providers used for content preparation (see section 8) receive only StoryHop story and content materials, not personal data.

We do not sell personal data or share it for targeted advertising.

17. International Transfers

StoryHop is operated from Germany. Our servers, database, and backups are hosted by DigitalOcean in Frankfurt, Germany.

Resend may process the emails it sends and receives for us in the United States. This transfer is based on Resend's certification under the EU-U.S. Data Privacy Framework and on the European Commission's Standard Contractual Clauses (controller to processor), which Resend's data processing agreement also applies to transfers from Switzerland.

DigitalOcean is a US company. Where DigitalOcean accesses data from outside the EU, this is based on its certification under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework, with the Standard Contractual Clauses as a fallback.

Apple and Google transfer data as independent controllers under their own safeguards.

You can request a copy of the safeguards we use from privacy@storyhop.io.

18. Data Retention

We keep personal data only as long as needed for the purposes described in this policy.

  • parent account data, including sign-in sessions and the random account token: until you delete your account, or until an inactive account is deleted;
  • child profiles and their learning activity: until you delete the child profile or your account, or until an inactive account is deleted;
  • inactive accounts: if an account has not started or renewed a sign-in session on any device for 24 months, and it has no StoryHop Plus subscription that still gives access (active, in a free trial, or in Apple's billing grace or retry period), we email the parent once. Unless someone signs in by the date given in the email, 30 days after the email, we delete the account in the same way as described in section 19. If our email provider rejects the email address when we try to send the email, the account is not deleted automatically; we review it manually;
  • consent and confirmation records: until the child profile or account they belong to is deleted;
  • subscription record: while your account exists; the Apple transaction identifier is removed 90 days after the subscription has ended and Apple last reported on it, or immediately when you delete your account; after account deletion, only the record described in section 19 is kept;
  • signed subscription notifications from Apple: deleted automatically 90 days after they are received, including after account deletion (see section 5 for subscriptions without an account);
  • paywall events: deleted automatically 90 days after they are received, or earlier when the child profile or account they belong to is deleted;
  • server request logs: deleted after 14 days;
  • messages sent through the contact form (https://storyhop.io/contact): deleted automatically 90 days after they are received;
  • emails you send us and our replies: until your request is resolved; for privacy requests, we keep a short record of the date, type of request, and outcome to show how we handled it;
  • email delivery records at our email provider Resend: kept according to Resend's retention period, currently 30 days;
  • server backups: weekly backups are kept for up to 4 weeks, so deleted data is removed from backups at the latest 4 weeks after it is deleted from the database;
  • child-device login codes: expire 5 minutes after they are created and are deleted within 24 hours after they expire;
  • parent PIN authorisation: expires after 15 minutes;
  • approved story illustrations: retained while used in StoryHop content.

If we need specific data to establish, exercise, or defend legal claims, we keep only that data for as long as needed for that purpose.

19. Deleting Your Account or a Child Profile

You can delete your account in the app, in the parent area under Privacy. This immediately deletes all child profiles, their learning activity (including riddle history) and statistics, consent and confirmation records, paywall events, child-device login codes, parent PIN data, sign-in sessions, and the random account token, and then the account itself.

You can also delete a single child profile in the parent area. This immediately deletes that profile, its learning activity (including riddle history) and statistics, its consent and confirmation records, its paywall events, and its child-device login codes.

Deleted data is removed from backups when those backups expire (see section 18).

Deleting your account does not cancel StoryHop Plus. Before you delete your account, the app reminds you of this and offers a link to Apple's subscription settings. StoryHop cannot cancel an Apple subscription or issue refunds. To stop future charges, cancel the subscription in the settings of the Apple ID that bought it (on iPhone or iPad: Settings, your name, Subscriptions). Refunds can only be requested from Apple.

When you delete your account, we remove the Apple transaction identifier and the link to your account from your subscription record. What remains (the plan, subscription status, whether a free trial applied and whether it would renew, purchase and expiry dates, and whether it was a test or real purchase) contains no identifier, is not linked to any account, and is kept only for statistics. If you later create a new StoryHop account, you can restore a subscription you are still paying for with the same Apple ID.

Apple's subscription notifications received before you deleted your account (see section 5) are not deleted with it. They are kept until 90 days after they were received and then deleted automatically. Notifications that arrive later about a subscription you are still paying for are stored only with their delivery identifier, type, and date, except the rarer types described in section 5.

You can also ask us to delete your account by contacting privacy@storyhop.io.

20. Security

We use technical and organizational measures designed to protect personal data, including HTTPS, limited administrator access, passwords and parent PINs stored only as secure hashes, checking the signature of purchase data received from Apple, short retention for server logs and backups, no upload of camera images or video during QR scanning, and server-side controls to separate parent settings from child access.

No online service can guarantee absolute security.

21. Your Rights

Under the GDPR, you have the right to access your personal data, to have inaccurate data corrected, to have data deleted, to restrict processing, to receive a portable copy of data you provided, to object to processing, and to withdraw consent at any time. In Switzerland, you have comparable rights under the Swiss Federal Act on Data Protection.

Parents may exercise these rights for their own account and for child profiles they manage.

In the app, you can edit and delete child profiles, turn paywall events on or off for each child profile, withdraw marketing consent, and delete your account. The app does not currently offer a self-service data download. Requests for a copy of your data, access, correction, restriction, objection, or deletion are handled manually by email, free of charge, within one month; for complex requests this can be extended by up to two further months, and we will tell you within the first month.

To make a privacy request, contact privacy@storyhop.io. We may need to verify that you are the parent or account holder before fulfilling a request, for example by replying to the email address of the account.

Right to object: where we process your or your child's data on the basis of legitimate interests (section 10), you can object at any time on grounds relating to your particular situation. Contact privacy@storyhop.io.

Right to complain: you can lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live or work. The authority responsible for StoryHop is Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany (https://www.lda.brandenburg.de). In Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC, https://www.edoeb.admin.ch).

22. App Store Privacy Information

StoryHop's privacy information on the App Store summarises the data described in this policy. All of it is linked to the parent account, and none of it is used to track you across other companies' apps or websites. StoryHop does not collect payment card details, precise location, contacts, photos, voice recordings, or advertising identifiers, and the app contains no third-party analytics or advertising SDKs.

23. External Links

The child experience contains no links to websites or other apps. Links to outside services, such as Apple's subscription settings or email, appear only in parent-only parts of the app.

24. Changes to This Policy

We may update this policy as StoryHop changes. Each version is identified by its date, and a published version is never changed afterwards.

When we publish a new version, the app shows it to you the next time you enter the parent PIN and asks you to confirm that you have read it. Before we use personal data for a new purpose, we will inform you, and where the law requires consent, we will ask for it separately.

The current and all earlier versions of this policy are available at https://storyhop.io/en/legal/ios/privacy.

25. Contact

Privacy requests: privacy@storyhop.io

Support: support@storyhop.io

Contact form: https://storyhop.io/contact

Controller: Aleksandr Gorin, StoryHop, Käthe-Kollwitz-Str. 10b, 14943 Luckenwalde, Germany

Further legal provider information is available in the Impressum.