Privacy Policy

Last updated: 29 June 2026

1. Who We Are

StoryHop is a service operated by Aleksandr Gorin. Legal provider information is available in our Impressum.

Address: Käthe-Kollwitz-Str. 10b, 14943 Luckenwalde, Germany

Privacy contact: privacy@storyhop.io

Support contact: support@storyhop.io

We are the data controller for StoryHop unless this policy says otherwise.

We have not appointed a Data Protection Officer. You can contact us about privacy at privacy@storyhop.io.

2. What This Policy Covers

This policy applies to StoryHop websites, mobile apps, parent accounts, child profiles, free public stories, QR/magic-link child access, support, email communications, and related services.

StoryHop is designed for children aged 6 and older, but accounts are created and managed by parents or legal guardians. Children cannot access parent settings.

StoryHop does not currently provide school, classroom, or teacher accounts.

3. How StoryHop Works

Parents create a StoryHop account and may create child profiles. A parent may provide a child with a QR code or magic link so the child can use StoryHop without receiving a username or password.

On the website, some free stories may be read without an account. In that mode, StoryHop does not save child profile data, reading progress, quiz answers, XP, achievements, favorites, or reading history.

When a parent account and child profile are used, StoryHop stores progress data so parents can see reading activity and so StoryHop can recommend similar stories.

4. Personal Data We Collect

4.1 Parent Account Data

We may collect and process:

  • parent email address;
  • login credentials or authentication data;
  • sign-in provider data if a parent chooses Google or Apple sign-in;
  • parent settings and consent choices;
  • marketing email preferences;
  • support messages and privacy requests;
  • session, security, and device information needed to operate the service.

StoryHop does not currently process payments or subscriptions.

4.2 Child Profile Data

Parents may create child profiles. A child profile may include:

  • child profile name or nickname;
  • age;
  • abstract reading level;
  • content language, such as English, German, or Russian;
  • avatar selected from a predefined set;
  • reading progress;
  • quiz answers;
  • XP, achievements, and similar progress indicators;
  • favorites and reading history;
  • recommendations based on reading activity.

Parents should avoid entering a child’s real name unless they choose to do so. StoryHop does not require child email addresses, phone numbers, postal addresses, photos, voice recordings, or location data.

4.3 Free Website Visitor Data

Visitors may read selected free stories on the website without an account. We may process basic technical data such as IP address, browser information, device information, pages viewed, cookie consent choices, and security logs.

For EU/EEA users, Google Analytics is blocked until analytics-cookie consent is given.

4.4 Mobile App Data

The StoryHop mobile app may process:

  • app session data;
  • device and app technical information;
  • QR-code scan result data used for login;
  • optional push notification token data if notifications are enabled;
  • camera permission for QR-code scanning.

QR scanning is processed locally on the device. StoryHop does not upload camera images or video for QR scanning. After a QR code is scanned, only the decoded login token is sent to the server for login exchange.

The app does not currently use microphone access, speech recognition, photo library access, precise location access, IDFA, Android Advertising ID, or advertising tracking.

5. Analytics

We use, or plan to use, Google Analytics to understand how StoryHop is used and to improve the service.

We do not send parent email addresses, child profile names, account IDs, child profile IDs, QR codes, magic-link tokens, or story answers as user identifiers to Google Analytics.

Analytics events may include technical information such as device or browser information, approximate location, pages or screens viewed, and interaction events. We do not use Google Analytics for behavioral advertising, remarketing, or building advertising profiles for children.

6. AI and Content Processing

StoryHop uses AI tools internally to prepare and improve content. This may include:

  • rewriting stories;
  • adapting stories to different reading levels;
  • translating stories or story variants;
  • categorizing story content;
  • generating new illustrations.

StoryHop currently uses OpenAI for text-related content processing and Google for illustration generation.

StoryHop does not allow parents or children to enter custom free-text prompts for AI generation. StoryHop sends only StoryHop story/content materials to AI providers, not child profile data, parent account data, progress data, quiz answers, or reading history.

Generated illustrations are reviewed by a human before children can see them. Approved illustrations are stored on StoryHop-controlled servers.

7. Why We Process Data

We process personal data to:

  • create and manage parent accounts;
  • create and manage child profiles at a parent’s request;
  • authenticate parents and child devices;
  • provide stories, quizzes, and progress tracking;
  • show parent progress reports;
  • recommend similar stories;
  • operate and secure the website, app, and backend;
  • respond to support and privacy requests;
  • send transactional emails;
  • send marketing emails to parents who consent;
  • generate and moderate StoryHop content;
  • comply with legal obligations.

8. Legal Bases for EU/EEA/UK Users

Where GDPR or similar law applies, our legal bases may include:

  • contract: to provide StoryHop accounts, child profiles, stories, progress tracking, and support;
  • consent: for analytics cookies, marketing emails, and parental consent to child profile processing where required;
  • legitimate interests: to secure the service, prevent misuse, keep limited logs, improve functionality, and understand aggregate usage where permitted;
  • legal obligation: to respond to valid legal requests and comply with applicable law.

Parents may withdraw consent where processing is based on consent. Withdrawal does not affect processing that happened before withdrawal.

9. Children’s Privacy and Parent Controls

StoryHop is parent-managed. Parents create accounts, create child profiles, approve child profile processing, and control child access.

Parents can:

  • view child progress;
  • create or delete child profiles;
  • delete the parent account;
  • request a copy of parent and child-profile data by email;
  • withdraw marketing consent;
  • contact us to review, correct, or delete child-related personal data.

Children cannot access parent settings.

StoryHop does not sell child data, use child data for behavioral advertising, or knowingly allow child profile data to be used to create advertising profiles.

10. QR Codes, Magic Links, and Sessions

Parents may generate child-device login QR codes or magic links.

Child-device login tokens are single-use and expire after 5 minutes. After successful exchange, the device receives an authenticated session scoped to the selected child profile.

Parent access tokens last 14 days. Refresh tokens last 30 days from issue or rotation and may keep the session active if refreshed before expiry. Parent PIN authorization grants are separate from login sessions and last 15 minutes.

Parents can log out or revoke sessions. Parent settings remain protected from child access.

11. Notifications

StoryHop may add push notifications. Parents will be able to disable child notifications.

Notifications will be story-related or reading-reminder messages. They will not include a child name, progress, quiz result, reading level, or other sensitive child profile details.

Push notification delivery may require Apple or Google push-notification services depending on the device platform.

12. Marketing Emails

StoryHop may send marketing emails only to parents or guardians who separately opt in.

Marketing consent is optional and separate from account creation. We use double opt-in where required or appropriate. Every marketing email includes an unsubscribe option.

Transactional emails, such as login, security, support, or service messages, may still be sent even if marketing consent is withdrawn.

13. Cookies and Local Storage

StoryHop may use cookies, local storage, or similar technologies for:

  • authentication sessions;
  • language preferences;
  • cookie consent choices;
  • security;
  • analytics, if consent is given where required.

Analytics cookies are not loaded for EU users unless analytics consent has been given.

14. Who We Share Data With

We share personal data only where needed to operate StoryHop, comply with law, or protect the service.

Current or planned service providers include:

  • DigitalOcean: hosting infrastructure in Frankfurt, Germany;
  • MongoDB database operated on StoryHop-controlled infrastructure;
  • Resend: transactional and marketing email delivery;
  • Google: Google sign-in, Google Analytics, and illustration generation;
  • Apple: Apple sign-in and app platform services;
  • OpenAI: text-related content processing for StoryHop story/content materials;
  • Apple and Google push notification services, if notifications are enabled.

We do not sell personal data.

We do not share child profile data with AI providers for story/content generation, and we do not send child profile identifiers to Google Analytics.

15. International Transfers

StoryHop is operated from Germany. Core hosting is currently on a DigitalOcean droplet in Frankfurt, Germany.

Some providers, including Google, Apple, OpenAI, and Resend, may process data in other countries, including the United States. Where required, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, Data Privacy Framework participation, or other lawful transfer mechanisms.

StoryHop is available worldwide, but we do not store user data in every country where StoryHop can be accessed.

16. Data Retention

We keep personal data only as long as needed for the purposes described in this policy.

Current retention commitments:

  • parent accounts and child profiles: kept until deleted by the parent or until no longer needed;
  • deleted account/profile data: removed from active systems and then removed from backups after the backup retention period;
  • database backups: retained for 7 days;
  • internal server and error logs: retained for 7 days;
  • child-device login tokens: single-use and expire after 5 minutes;
  • parent PIN authorization grants: expire after 15 minutes;
  • approved story illustrations: retained while used in StoryHop content.

We may keep limited records longer if required for security, fraud prevention, legal compliance, or dispute handling.

17. Security

We use technical and organizational measures designed to protect personal data, including:

  • HTTPS for data transmission;
  • limited administrator access;
  • internal-only production data access by Aleksandr Gorin unless additional authorized staff are added later;
  • short retention for logs and backups;
  • no upload of camera images or video during QR scanning;
  • server-side controls to separate parent settings from child access.

No online service can guarantee absolute security.

18. Your Rights

Depending on where you live, you may have rights to:

  • access your personal data;
  • correct inaccurate data;
  • delete data;
  • restrict or object to processing;
  • receive a copy of data in a portable format;
  • withdraw consent;
  • opt out of marketing;
  • lodge a complaint with a data protection authority.

Parents may exercise these rights for their own account and for child profiles they manage.

To make a privacy request, contact privacy@storyhop.io. We may need to verify that you are the parent or account holder before fulfilling a request.

19. US Children’s Privacy

For users in the United States, StoryHop is designed so parents create and manage accounts and child profiles.

Parents can contact us at privacy@storyhop.io to review, correct, or delete child-related personal data, or to refuse further collection of child-related personal data.

StoryHop does not require a child to provide more information than reasonably necessary to use the service.

20. App Store and Google Play Disclosures

StoryHop’s App Store privacy information and Google Play Data Safety disclosures must match this policy and the actual app behavior.

Current intended app disclosures include:

  • account information for parent accounts;
  • child profile data entered by the parent;
  • app activity such as reading progress, quiz answers, favorites, and achievements;
  • device or technical data used for operation, security, analytics, and diagnostics;
  • optional camera permission for QR-code scanning;
  • optional push notification token data once notifications are enabled;
  • no payments;
  • no precise location;
  • no microphone or voice recording;
  • no IDFA or Android Advertising ID;
  • no sale of personal data;
  • no behavioral advertising to children.

21. External Links

Children cannot open external links from inside the child experience. If external links are added later, they should be placed behind a parent gate.

22. Changes to This Policy

We may update this policy as StoryHop changes. If changes are material, we will provide appropriate notice, such as by email, in-app notice, or website notice.

23. Contact

Privacy requests: privacy@storyhop.io

Support: support@storyhop.io

Operator: Aleksandr Gorin. See the Impressum for legal provider information.

Address: Käthe-Kollwitz-Str. 10b, 14943 Luckenwalde, Germany