Privacy Policy
Version 2026-06-29 · 29 June 2026
1. Who We Are
StoryHop is operated by Aleksandr Gorin. Aleksandr Gorin is the controller responsible for StoryHop.
Privacy contact: privacy@storyhop.io
Support contact: support@storyhop.io
Postal address and legal provider information are available in the Impressum.
We have not appointed a Data Protection Officer. You can contact us about privacy at privacy@storyhop.io.
2. What This Policy Covers
This policy applies to StoryHop websites, mobile apps, parent accounts, child profiles, free public stories, QR and magic-link child access, support, email communications, and related services.
StoryHop is designed for children aged 6 and older, but accounts are created and managed by parents or legal guardians. Children cannot access parent settings.
StoryHop does not currently provide school, classroom, or teacher accounts.
3. How StoryHop Works
Parents create a StoryHop account and may create child profiles. A parent may provide a child with a QR code or magic link so the child can use StoryHop without receiving a username or password.
On the website, some free stories may be read without an account. In that mode, StoryHop does not save child profile data, reading progress, quiz answers, XP, achievements, favorites, or reading history.
When a parent account and child profile are used, StoryHop stores progress data so parents can see reading activity and so StoryHop can recommend similar stories.
4. Personal Data We Collect
Parent account data may include parent email address, login credentials or authentication data, sign-in provider data, parent settings and consent choices, marketing email preferences, support messages, privacy requests, and security or device information needed to operate the service.
StoryHop does not currently process payments or subscriptions.
Child profile data may include a child profile name or nickname, age, abstract reading level, content language, avatar, reading progress, quiz answers, XP, achievements, favorites, reading history, and recommendations based on reading activity.
Parents should avoid entering a child's real name unless they choose to do so. StoryHop does not require child email addresses, phone numbers, postal addresses, photos, voice recordings, or location data.
Visitors may read selected free stories on the website without an account. We may process technical data such as IP address, browser and device information, pages viewed, cookie consent choices, and security logs.
The mobile app may process app session data, device and app technical information, QR-code scan result data used for login, optional push notification token data if notifications are enabled, and camera permission for QR-code scanning.
QR scanning is processed locally on the device. StoryHop does not upload camera images or video for QR scanning. After a QR code is scanned, only the decoded login token is sent to the server for login exchange.
The app does not currently use microphone access, speech recognition, photo library access, precise location access, IDFA, Android Advertising ID, or advertising tracking.
5. Analytics
We use, or plan to use, Google Analytics to understand how StoryHop is used and to improve the service.
We do not send parent email addresses, child profile names, account IDs, child profile IDs, QR codes, magic-link tokens, or story answers as user identifiers to Google Analytics.
Analytics events may include technical information such as device or browser information, approximate location, pages or screens viewed, and interaction events. We do not use Google Analytics for behavioral advertising, remarketing, or building advertising profiles for children.
6. AI and Content Processing
StoryHop uses AI tools internally to prepare and improve content, including rewriting stories, adapting stories to reading levels, translating stories or variants, categorizing content, and generating illustrations.
StoryHop currently uses OpenAI for text-related content processing and Google for illustration generation.
StoryHop does not allow parents or children to enter custom free-text prompts for AI generation. StoryHop sends only StoryHop story and content materials to AI providers, not child profile data, parent account data, progress data, quiz answers, or reading history.
Generated illustrations are reviewed by a human before children can see them. Approved illustrations are stored on StoryHop-controlled servers.
7. Why We Process Data
We process personal data to create and manage parent accounts and child profiles, authenticate parents and child devices, provide stories, quizzes and progress tracking, show parent progress reports, recommend similar stories, operate and secure the service, respond to requests, send transactional emails, send parent marketing emails with consent, generate and moderate StoryHop content, and comply with legal obligations.
8. Legal Bases for EU, EEA, and UK Users
Where GDPR or similar law applies, our legal bases may include contract, consent, legitimate interests, and legal obligation.
Contract covers providing StoryHop accounts, child profiles, stories, progress tracking, and support.
Consent covers analytics cookies, marketing emails, and parental consent to child profile processing where required.
Legitimate interests cover securing the service, preventing misuse, keeping limited logs, improving functionality, and understanding aggregate usage where permitted.
Parents may withdraw consent where processing is based on consent. Withdrawal does not affect processing that happened before withdrawal.
9. Children's Privacy and Parent Controls
StoryHop is parent-managed. Parents create accounts, create child profiles, approve child profile processing, and control child access.
Parents can view child progress, create or delete child profiles, delete the parent account, request a copy of parent and child-profile data, withdraw marketing consent, and contact us to review, correct, or delete child-related personal data.
Children cannot access parent settings.
StoryHop does not sell child data, use child data for behavioral advertising, or knowingly allow child profile data to be used to create advertising profiles.
10. QR Codes, Magic Links, and Sessions
Parents may generate child-device login QR codes or magic links.
Child-device login tokens are single-use and expire after 5 minutes. After successful exchange, the device receives an authenticated session scoped to the selected child profile.
Parent access tokens last 14 days. Refresh tokens last 30 days from issue or rotation and may keep the session active if refreshed before expiry. Parent PIN authorization grants are separate from login sessions and last 15 minutes.
Parents can log out or revoke sessions. Parent settings remain protected from child access.
11. Notifications
StoryHop may add push notifications. Parents will be able to disable child notifications.
Notifications will be story-related or reading-reminder messages. They will not include a child name, progress, quiz result, reading level, or other sensitive child profile details.
Push notification delivery may require Apple or Google push-notification services depending on the device platform.
12. Marketing Emails
StoryHop may send marketing emails only to parents or guardians who separately opt in.
Marketing consent is optional and separate from account creation. We use double opt-in where required or appropriate. Every marketing email includes an unsubscribe option.
Transactional emails, such as login, security, support, or service messages, may still be sent even if marketing consent is withdrawn.
13. Cookies and Local Storage
StoryHop may use cookies, local storage, or similar technologies for authentication sessions, language preferences, cookie consent choices, security, and analytics if consent is given where required.
Analytics cookies are not loaded for EU users unless analytics consent has been given.
14. Who We Share Data With
We share personal data only where needed to operate StoryHop, comply with law, or protect the service.
Current or planned service providers include DigitalOcean, MongoDB on StoryHop-controlled infrastructure, Resend, Google, Apple, OpenAI, and Apple or Google push notification services if notifications are enabled.
We do not sell personal data.
We do not share child profile data with AI providers for story or content generation, and we do not send child profile identifiers to Google Analytics.
15. International Transfers
StoryHop is operated from Germany. Core hosting is currently on a DigitalOcean droplet in Frankfurt, Germany.
Some providers, including Google, Apple, OpenAI, and Resend, may process data in other countries, including the United States. Where required, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, Data Privacy Framework participation, or other lawful transfer mechanisms.
StoryHop is available worldwide, but we do not store user data in every country where StoryHop can be accessed.
16. Data Retention
We keep personal data only as long as needed for the purposes described in this policy.
- parent accounts and child profiles: kept until deleted by the parent or until no longer needed;
- deleted account/profile data: removed from active systems and then removed from backups after the backup retention period;
- database backups: retained for 7 days;
- internal server and error logs: retained for 7 days;
- child-device login tokens: single-use and expire after 5 minutes;
- parent PIN authorization grants: expire after 15 minutes;
- approved story illustrations: retained while used in StoryHop content.
We may keep limited records longer if required for security, fraud prevention, legal compliance, or dispute handling.
17. Security
We use technical and organizational measures designed to protect personal data, including HTTPS, limited administrator access, short retention for logs and backups, no upload of camera images or video during QR scanning, and server-side controls to separate parent settings from child access.
No online service can guarantee absolute security.
18. Your Rights
Depending on where you live, you may have rights to access your personal data, correct inaccurate data, delete data, restrict or object to processing, receive a portable copy, withdraw consent, opt out of marketing, and lodge a complaint with a data protection authority.
Parents may exercise these rights for their own account and for child profiles they manage.
To make a privacy request, contact privacy@storyhop.io. We may need to verify that you are the parent or account holder before fulfilling a request.
19. US Children's Privacy
For users in the United States, StoryHop is designed so parents create and manage accounts and child profiles.
Parents can contact us at privacy@storyhop.io to review, correct, or delete child-related personal data, or to refuse further collection of child-related personal data.
StoryHop does not require a child to provide more information than reasonably necessary to use the service.
20. App Store and Google Play Disclosures
StoryHop's App Store privacy information and Google Play Data Safety disclosures must match this policy and the actual app behavior.
Current intended app disclosures include parent account information, child profile data entered by the parent, app activity, device or technical data, optional camera permission for QR-code scanning, optional push notification token data if enabled, no payments, no precise location, no microphone or voice recording, no advertising identifiers, no sale of personal data, and no behavioral advertising to children.
21. External Links
Children cannot open external links from inside the child experience. If external links are added later, they should be placed behind a parent gate.
22. Changes to This Policy
We may update this policy as StoryHop changes. If changes are material, we will provide appropriate notice, such as by email, in-app notice, or website notice.
23. Contact
Privacy requests: privacy@storyhop.io
Support: support@storyhop.io
Controller: Aleksandr Gorin
Postal address and legal provider information are available in the Impressum.