Privacy Policy
This Privacy Policy explains how LuluStories collects, uses, stores, and protects personal data when you use our platform to create personalized children's stories. LuluStories is designed primarily for parents, educators, and families. We take privacy seriously—especially where children's data is involved.
1. Who We Are (Data Controller)
LuluStories is operated by:
LuluHoldings AB
Registration number: [TO BE ADDED]
Registered address: [TO BE ADDED]
Country of establishment: Sweden
LuluHoldings AB is the data controller responsible for the processing of personal data described in this Privacy Policy.
If you have questions or wish to exercise your privacy rights, you can contact us at: privacy@lulustories.com
2. What Personal Data We Collect
2.1 Account Information
• Name
• Email address
• Encrypted password
• Account preferences and settings
2.2 Story and Content Data
• Story prompts, preferences, and customization choices
• Uploaded photos or images (if you choose to include them)
• Generated stories, illustrations, and previews
2.3 Usage and Technical Data
• Device type, browser, operating system
• IP address
• Log data and interaction data
• Feature usage and performance metrics (collected in aggregated form)
2.4 Payment and Transaction Data
• Subscription status and purchase history
• Payment details (such as card numbers) are processed only by our payment providers and are not stored by LuluStories.
2.5 Cookies and Similar Technologies
We use cookies and similar technologies for essential functionality, analytics, and performance. More details are provided in our Cookie Policy.
3. How We Use Personal Data
We use personal data to:
• Create and manage user accounts
• Generate personalized stories, illustrations, and print-ready files
• Store your story library so you can revisit, edit, or reorder content
• Process payments and manage subscriptions
• Provide customer support
• Improve our templates, illustration styles, and platform performance using anonymized and aggregated data
• Ensure platform security and prevent misuse
We do not sell your personal data, photos, or story prompts.
4. Legal Bases for Processing (GDPR)
We process personal data under the following legal bases in accordance with Article 6 GDPR:
• Performance of a contract – to provide the LuluStories service you request
• Consent – for optional features, marketing communications, and non-essential cookies
• Legitimate interests – to improve and secure our service, provided these interests do not override your rights
• Legal obligation – where required to comply with applicable laws
Where consent is required, you may withdraw it at any time.
5. Children's Privacy
LuluStories is intended to be used by parents, guardians, or educators.
• We do not allow children under the age of 13 to create accounts on their own.
• Any personal data relating to a child is provided by a parent or legal guardian.
• Parents are responsible for ensuring they have the right to upload any child-related information or images.
• We minimize the collection of children's data and apply heightened security safeguards.
• If we become aware that personal data has been collected from a child without appropriate consent, we will delete it promptly.
6. AI-Generated Content and Automated Processing
LuluStories uses artificial intelligence to generate personalized stories and illustrations based on the inputs you provide.
• Content generation is automated
• No automated decision-making produces legal or similarly significant effects
• AI outputs may be imperfect, non-unique, or inaccurate
• You remain responsible for reviewing content before sharing it with children or third parties.
7. Sharing and Community Features
Stories remain private by default. If you choose to share a story in our community library:
• Only the story title, content, illustrations, and first name (if provided) may be visible
• You can remove shared stories at any time
• Cached previews are removed within 24 hours after removal
8. Data Sharing and Third Parties
We may share personal data with trusted service providers who help us operate the platform, such as:
• Hosting and infrastructure providers
• Analytics providers
• Payment processors
• Customer support tools
These providers process data only on our instructions and under appropriate data processing agreements.
9. International Data Transfers
Some service providers may process data outside the EU/EEA (e.g. in the United States). Where this occurs, we ensure appropriate safeguards are in place, such as:
• EU Standard Contractual Clauses (SCCs)
• Equivalent lawful transfer mechanisms
10. Data Retention
We retain personal data only as long as necessary:
• Account data: retained while your account is active
• Generated content: retained until you delete it or your account is closed
• Uploaded photos: automatically deleted 30 days after a story is deleted, unless you archive them
• Legal and billing records: retained as required by law
11. Security Measures
We implement appropriate technical and organizational security measures, including:
• Encryption in transit (HTTPS/TLS) and at rest
• Access controls and role-based permissions
• SOC-2-aligned infrastructure
• Multi-factor authentication for internal systems
No system is 100% secure, but we continuously work to protect your data.
12. Your Rights Under GDPR
You have the right to:
• Access your personal data
• Correct inaccurate or incomplete data
• Request deletion ("right to be forgotten")
• Restrict or object to processing
• Request data portability
• Withdraw consent at any time
• Lodge a complaint with a supervisory authority
In Sweden, the supervisory authority is Integritetsskyddsmyndigheten (IMY).
13. Marketing Communications
You may opt out of marketing emails at any time by:
• Clicking the unsubscribe link in any email
• Updating your account settings
Service-related communications may still be sent when necessary.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will notify you via the platform or email.
Continued use of LuluStories after updates take effect constitutes acceptance of the revised policy.
Have Questions About Privacy?
If you have any questions about this Privacy Policy or our data practices, please contact us at privacy@lulustories.com. We aim to reply within 2-3 business days.