Back to Good Night Tales

Privacy Policy

Last updated July 17, 2026

Status: This document is pending final review by qualified legal counsel. By using the Service, you agree to the current version. Material updates will be posted here.

PRIVACY POLICY (DRAFT)

Status: DRAFT — last updated July 17, 2026. Not legal advice. Drafted for review by qualified privacy counsel before public use.

Signal Loom AI ("we," "us," or "our") operates the Good Night Tales service (the "Service") through goodnighttales.io and related properties. This Privacy Policy describes how we collect, use, and share information when you use our Service. By using the Service, you agree to the terms of this Privacy Policy.

1. Information We Collect

1.1 Information you provide directly

1.2 Information collected automatically

1.3 Information from third parties

2. How We Use Information

We use the information we collect to:

We do NOT use children's information for:

3. Children's Privacy (COPPA Compliance)

We comply with the Children's Online Privacy Protection Act (COPPA). The Service is intended for use by parents and guardians on behalf of their children. We do not direct the Service at children under 13.

3.1 Parental consent

By creating a profile, providing your child's information, or using the Service to generate stories, you confirm:

3.2 Information we collect from children

We collect only the minimum information necessary to provide the Service:

We do not collect more information from children than is reasonably necessary for their participation in the Service.

3.3 Parental access and control

Parents and guardians can:

To exercise these rights, contact us at privacy@signalloomai.com (or update through your account settings).

4. Your Rights and Choices

4.1 Parents/guardians

You have the right to:

4.2 California residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:

4.3 European Union residents (GDPR)

If you are in the EU/EEA, you have rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, object to processing, and data portability. Contact us to exercise these rights.

5. How We Share Information

We do not sell, rent, or trade your personal information or your child's information. We share information only in the following limited circumstances:

6. Cookies and Tracking

We use a minimal set of cookies and similar technologies:

We do not use third-party advertising cookies or tracking technologies.

7. Data Security

We implement reasonable security measures to protect your information:

No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

8. Data Retention

We retain personal information for as long as necessary to provide the Service:

9. International Data Transfers

We are based in the United States. If you are using the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.

For EU/EEA users, we rely on Standard Contractual Clauses or other lawful mechanisms for international data transfers.

10. Third-Party Services

The Service relies on the following third-party services:

These services have their own privacy practices. We encourage you to review them.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about your child's privacy:

Signal Loom AI

Email: privacy@signalloomai.com

Mail: [address to be added]

---

DRAFT NOTES FOR ATTORNEY:

This draft was prepared by an AI assistant (Aster) as a starting point for the founder's privacy counsel to review and customize. It is based on:

Specific items requiring attorney review and customization:

1. Address and contact information (Section 12) — needs accurate company address

2. Governing law and jurisdiction — needs to be specified per company incorporation

3. Specific data retention periods — confirm with business operations

4. State-specific disclosures (e.g., Virginia VCDPA, Colorado CPA) if applicable

5. International transfer mechanisms — confirm SCC adequacy decisions and current status

6. Specific Stripe / OpenAI data handling — verify against current sub-processor agreements

7. Whether to pursue COPPA Safe Harbor certification (e.g., through iKeepSafe, TRUSTe, or PRIVO) — recommended for production

8. Insurance coverage — confirm E&O policy covers data handling

9. Specifics of any future commercial launch — current beta terms below

10. Custom data deletion API — current "delete account" flow should be tested and documented

Recommendations:

1. Have privacy counsel finalize this document before any public release

2. Consider iubenda ($0-50/year) or Termly for auto-updating policies

3. Pursue COPPA Safe Harbor certification for production launch

4. Set up a privacy@signalloomai.com inbox and add it to footer of all pages

5. Add "Privacy Choices" link in footer of all pages

6. Update Privacy Policy on every product feature change

7. Get explicit, documented parental consent at child profile creation