Back to Good Night Tales
Privacy Policy
Last updated July 17, 2026
Status: This document is pending final review by qualified legal counsel. By using the Service, you agree to the current version. Material updates will be posted here.
PRIVACY POLICY (DRAFT)
Status: DRAFT — last updated July 17, 2026. Not legal advice. Drafted for review by qualified privacy counsel before public use.
Signal Loom AI ("we," "us," or "our") operates the Good Night Tales service (the "Service") through goodnighttales.io and related properties. This Privacy Policy describes how we collect, use, and share information when you use our Service. By using the Service, you agree to the terms of this Privacy Policy.
1. Information We Collect
1.1 Information you provide directly
- Parent/guardian account information: Email address (via Stripe checkout), name (if voluntarily provided during support interactions)
- Child information (provided by parent/guardian): Child's first name or nickname, age, optional story interests/preferences
- Story content: Stories generated for your child based on the above inputs
- Communications: When you contact us, we collect the information you provide in your message
1.2 Information collected automatically
- Technical data: IP address, browser type, device type, operating system, referring URL, pages viewed, time spent
- Cookies and similar: We use essential cookies and may use analytics cookies (see Section 6)
- Server logs: Cloudflare Workers logs may include request metadata (URI path, response code, timing) but not story content
1.3 Information from third parties
- Stripe (payment processor): When you subscribe, Stripe processes payment and may share transaction metadata (amount, date, last 4 of card) with us
- OpenAI (AI provider): Story content you submit is sent to OpenAI for story text generation and voice synthesis; OpenAI may retain data per its own privacy policy
2. How We Use Information
We use the information we collect to:
- Generate personalized bedtime stories for your child
- Process your subscription and payment
- Send you service-related communications (subscription confirmations, important updates)
- Improve our Service (analyze aggregate usage patterns, fix bugs, develop new features)
- Respond to your support requests
- Comply with legal obligations
- Detect and prevent fraud or abuse
We do NOT use children's information for:
- Behavioral advertising or targeted advertising
- Building user profiles for marketing
- Selling or renting to third parties
3. Children's Privacy (COPPA Compliance)
We comply with the Children's Online Privacy Protection Act (COPPA). The Service is intended for use by parents and guardians on behalf of their children. We do not direct the Service at children under 13.
3.1 Parental consent
By creating a profile, providing your child's information, or using the Service to generate stories, you confirm:
- You are the child's parent or legal guardian
- You consent to our collection, use, and disclosure of your child's information as described in this Policy
- You understand your rights under COPPA (see Section 4)
3.2 Information we collect from children
We collect only the minimum information necessary to provide the Service:
- Child's first name or nickname (used to personalize the story)
- Child's age (used to age-appropriate story content and vocabulary)
- Optional story interests (used to generate relevant content)
- Generated story content (text, audio, cover art)
We do not collect more information from children than is reasonably necessary for their participation in the Service.
3.3 Parental access and control
Parents and guardians can:
- Access: View all information we have collected about their child
- Correct: Update or correct their child's information
- Delete: Request deletion of all information about their child
- Refuse further use: Stop using the Service and have all data deleted
To exercise these rights, contact us at privacy@signalloomai.com (or update through your account settings).
4. Your Rights and Choices
4.1 Parents/guardians
You have the right to:
- Access the personal information we have collected about you and your child
- Correct inaccurate information
- Delete your account and all associated data
- Export your data in a portable format
- Opt out of any future data collection (which will require account deletion)
- Non-discrimination for exercising these rights
4.2 California residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:
- Right to know what personal information is collected and shared
- Right to delete personal information
- Right to opt out of sale or sharing (we do not sell)
- Right to non-discrimination
4.3 European Union residents (GDPR)
If you are in the EU/EEA, you have rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, object to processing, and data portability. Contact us to exercise these rights.
5. How We Share Information
We do not sell, rent, or trade your personal information or your child's information. We share information only in the following limited circumstances:
- AI service providers (OpenAI): Story prompts and content are sent to OpenAI for story text generation and voice synthesis. Cover art is generated locally as a unified brand asset (no external provider receives story data for cover generation). These providers process data per their own privacy policies and are bound by data processing agreements with us. We update our AI providers from time to time without notice; the current provider list and their privacy practices are documented at the privacy policy links in Section 10.
- Payment processor (Stripe): When you subscribe, we share necessary information (email, payment method) for transaction processing.
- Cloud infrastructure (Cloudflare): Our worker code, KV storage, and assets are hosted on Cloudflare.
- Legal requirements: If required by law, court order, or to protect our rights or the safety of others.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred (with notice to you).
- With your consent: For any other purpose disclosed at the time of collection.
6. Cookies and Tracking
We use a minimal set of cookies and similar technologies:
- Essential cookies: Required for the Service to function (e.g., authentication)
- Analytics cookies (optional): We may use privacy-friendly analytics to understand usage patterns; you can opt out
We do not use third-party advertising cookies or tracking technologies.
7. Data Security
We implement reasonable security measures to protect your information:
- Encryption in transit: All data transmitted between you and the Service uses TLS
- Encryption at rest: Cloudflare KV data is encrypted at rest
- Access controls: Limited personnel access; principle of least privilege
- Rate limiting: API endpoints are rate-limited to prevent abuse
- Secrets management: API keys and secrets are stored securely via secret management
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
8. Data Retention
We retain personal information for as long as necessary to provide the Service:
- Active accounts: For the duration of your subscription, plus a reasonable period to handle cancellations and support
- After account deletion: 30 days to allow for recovery, then permanently deleted
- Stories you've generated: Retained until you delete them or your account
- Anonymized analytics: May be retained indefinitely
9. International Data Transfers
We are based in the United States. If you are using the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
For EU/EEA users, we rely on Standard Contractual Clauses or other lawful mechanisms for international data transfers.
10. Third-Party Services
The Service relies on the following third-party services:
These services have their own privacy practices. We encourage you to review them.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on the Service
- Sending you an email (if you have an account)
- Providing notice through the Service
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about your child's privacy:
Signal Loom AI
Email: privacy@signalloomai.com
Mail: [address to be added]
---
DRAFT NOTES FOR ATTORNEY:
This draft was prepared by an AI assistant (Aster) as a starting point for the founder's privacy counsel to review and customize. It is based on:
- Children's Online Privacy Protection Act (COPPA), 16 C.F.R. Part 312
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
- General Data Protection Regulation (GDPR) for EU users
- FTC COPPA Safe Harbor Program guidance
- Common SaaS privacy policy structure
Specific items requiring attorney review and customization:
1. Address and contact information (Section 12) — needs accurate company address
2. Governing law and jurisdiction — needs to be specified per company incorporation
3. Specific data retention periods — confirm with business operations
4. State-specific disclosures (e.g., Virginia VCDPA, Colorado CPA) if applicable
5. International transfer mechanisms — confirm SCC adequacy decisions and current status
6. Specific Stripe / OpenAI data handling — verify against current sub-processor agreements
7. Whether to pursue COPPA Safe Harbor certification (e.g., through iKeepSafe, TRUSTe, or PRIVO) — recommended for production
8. Insurance coverage — confirm E&O policy covers data handling
9. Specifics of any future commercial launch — current beta terms below
10. Custom data deletion API — current "delete account" flow should be tested and documented
Recommendations:
1. Have privacy counsel finalize this document before any public release
2. Consider iubenda ($0-50/year) or Termly for auto-updating policies
3. Pursue COPPA Safe Harbor certification for production launch
4. Set up a privacy@signalloomai.com inbox and add it to footer of all pages
5. Add "Privacy Choices" link in footer of all pages
6. Update Privacy Policy on every product feature change
7. Get explicit, documented parental consent at child profile creation