Moonthread

Privacy Policy

Effective May 26, 2026

1. Who we are

Moonthread ("we", "us") provides personalized AI bedtime stories for children. This policy explains what we collect, how we use it, and the rights you have over your data.

2. What we collect

  • Account data: email address, authentication identifiers (e.g., Google sign-in subject).
  • Child profile inputs: first name, age, chosen archetype, fears or themes you enter to personalize a story. We recommend using a nickname rather than a full name.
  • Generated content: the stories and illustrations created for you, stored in your library.
  • Billing data: handled by Stripe. We receive subscription status, plan, and customer identifiers — never your full card number.
  • Technical data: cookies for sign-in sessions, basic device and usage logs for security and debugging.

3. Why we process it

  • To create your account and provide the Service (legal basis: contract).
  • To generate personalized stories based on your inputs (contract).
  • To process payments and manage subscriptions (contract, legal obligation).
  • To secure the Service and prevent abuse (legitimate interests).
  • To send essential service emails (contract).

4. Service providers

We rely on a small set of trusted processors:

  • Lovable Cloud — hosting, database, authentication, and file storage.
  • Stripe — payments and subscription billing.
  • Google — optional OAuth sign-in.
  • AI model providers — used to generate story text, illustrations, and narration audio from the inputs you provide. Inputs are sent to these providers solely to produce your story.

We do not sell your personal data, and we do not use it to train third-party AI models for other customers.

5. Cookies

We use strictly necessary cookies to keep you signed in. We may use a small number of analytics cookies to understand how the Service is used. You can accept or reject non-essential cookies via the banner shown on your first visit.

6. Retention

We keep your account data and generated stories for as long as your account is active. When you delete your account, we delete your stories and profile data within 30 days, except for limited records we are required to retain (e.g., billing records for tax compliance).

7. Your rights

If you are in the EU/EEA, UK, or a similar jurisdiction, you have the right to access, correct, delete, restrict, port, and object to processing of your personal data, and to lodge a complaint with your local supervisory authority. To exercise any of these rights, email hello@moonthread.app.

8. Children

Moonthread is designed to be used by parents and legal guardians on behalf of their children. We do not knowingly create accounts for children. Parents are responsible for the inputs they enter about their child and for reviewing generated content before sharing it.

If you believe a child has created an account without parental consent, contact us and we will delete the account.

9. International transfers

Our processors may store and process data in jurisdictions outside your country of residence (including the United States). Where required, transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses.

10. Security

We protect data with industry-standard practices: encrypted transport (TLS), encrypted storage, row-level access policies, and least-privilege access for our team. No service can guarantee perfect security, but we take this seriously.

11. Changes

We may update this policy. Material changes will be communicated via the app or email. The "Effective" date above always reflects the current version.

12. Contact

For privacy questions or data requests: hello@moonthread.app