Last updated: 3 May 2026 — Version 2.0
TaleBuzzer Ltd ("TaleBuzzer", "we", "us", "our") is a company registered in England and Wales (Company No. [INSERT Companies House number]). We operate the TaleBuzzer platform, accessible at talebuzzer.com and through our mobile applications.
We are the data controller for personal data processed through this platform. We are registered with the Information Commissioner's Office (ICO) under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our ICO registration number is [INSERT ICO registration number].
We have completed a Data Protection Impact Assessment (DPIA) for TaleBuzzer. This document is available to the ICO on request.
For all privacy and data matters, contact us at: privacy@talebuzzer.com
We collect the minimum data necessary to operate TaleBuzzer safely and effectively.
Parent or guardian account data
When you register, we collect your email address, a hashed password, and your year of birth. We collect your year of birth solely to verify that you are aged 18 or over before creating a child profile. We do not store your full date of birth beyond this verification step.
If you subscribe to a paid plan, Stripe processes your payment details directly — we do not store card numbers or bank details on our servers. We receive only a payment confirmation and subscription status from Stripe.
Child profile data
We collect the child's first name, age (used to select the appropriate reading level), pronouns (optional), interests (optional), and supporting characters such as friends or pets (optional). All child profile data is entered by you, the parent or guardian. We do not collect a child's email address, home address, phone number, photograph, or any information that would directly identify a child to a third party.
Reading and usage data
We collect data about stories read, comprehension question responses, Bee point balances, reading streaks, and time spent in the app. This data is used solely to personalise your child's reading experience and provide you with progress insights.
Technical data
We collect standard server logs including IP addresses, browser type, and device information. We use this for security, fraud prevention, and to ensure the platform functions correctly.
What we do not collect
We do not collect location data from any user. We do not collect biometric data. We do not use your data or your child's data for advertising. We do not sell your data to any third party.
We process personal data for the following purposes and on the following legal bases under UK GDPR:
Providing the service — processing your account data, generating personalised stories, and tracking reading progress. Legal basis: contract performance (Article 6(1)(b)).
Child profile personalisation — using the child's first name, age, interests, and supporting characters to generate personalised stories. Legal basis: consent (Article 6(1)(a)), given by you as parent or guardian at registration.
Age verification — confirming you are aged 18 or over before allowing child profile creation. Legal basis: legal obligation and legitimate interests (Article 6(1)(c) and (f)).
Processing payments — managing subscriptions, billing, and renewals via Stripe. Legal basis: contract performance (Article 6(1)(b)).
Safety and security — preventing fraud, detecting abuse, and maintaining platform security. Legal basis: legitimate interests (Article 6(1)(f)).
Legal obligations — complying with applicable law, including responding to lawful requests from authorities. Legal basis: legal obligation (Article 6(1)(c)).
Service improvement — analysing aggregated, anonymised usage patterns to improve our product. We do not use children's personal data for this purpose. Legal basis: legitimate interests (Article 6(1)(f)).
We do not use your data or your child's data for advertising, marketing profiling, or to train AI models for sale to third parties.
TaleBuzzer is designed for children aged 3 to 11. We apply the highest level of data protection to all child profile data, in accordance with the ICO Age Appropriate Design Code (UK Children's Code) and UK GDPR. We have completed a full Data Protection Impact Assessment covering all child data processing, available to the ICO on request.
Accounts are held by a parent or guardian aged 18 or over. We verify this at registration by collecting your year of birth. Children do not have independent accounts and cannot register directly. The parent or guardian is responsible for all account activity.
We do not use children's data for commercial profiling, behavioural advertising, or any purpose other than delivering the reading service. We do not share children's personal data with advertisers, data brokers, or marketing platforms under any circumstances.
We apply data minimisation by default. We collect only what is strictly necessary for the service to function. All child profile data, stories, and reading records are deleted within 30 days of account closure or on your request.
All notification settings default to off. We do not use nudge techniques, dark patterns, or persuasive design to encourage children to share more personal data than is necessary.
Accessibility preferences (OpenDyslexic font, high contrast, reduced motion) are stored in your child's device browser only and are never transmitted to our servers.
We share personal data only with the following trusted sub-processors, each bound by appropriate data processing agreements:
Supabase Inc — our database and authentication provider. Data is stored in the EU (Frankfurt). Supabase is SOC 2 Type II certified and processes data under a Data Processing Agreement compliant with UK GDPR.
Stripe Inc — payment processing. Stripe is PCI DSS Level 1 certified. We share only the minimum data required to process your subscription. No card data passes through TaleBuzzer systems.
OpenAI LP — AI story generation. We send the child's first name, age, interests, and story subject to OpenAI's API. We do not send any other personal data, including email addresses or contact details. OpenAI processes this data under their API usage policy, which prohibits training on API inputs by default.
Vercel Inc — hosting and deployment. Vercel is SOC 2 Type II certified and processes standard web request data including IP addresses for performance and security purposes.
We do not sell personal data. We do not share personal data with third parties for their own marketing or commercial purposes.
Parent account data is retained for as long as your account is active, plus 30 days after account closure to allow for reinstatement requests. After 30 days, parent account data is permanently deleted.
Child profile data and all associated stories and reading records are deleted within 30 days of account closure or immediately on your request to delete a child profile.
Accounts with no login activity for 24 months will be contacted before deletion. If no response is received, the account and all associated data will be permanently deleted.
Payment records are retained for seven years as required by UK tax law (HMRC regulations). This is a legal obligation.
Server logs are retained for 30 days for security purposes and then deleted.
Records of data subject rights requests (deletion requests, access requests) are retained for six years as required for GDPR compliance evidence.
Under UK GDPR, you have the following rights regarding your personal data and your child's personal data:
Right of access — you may request a copy of all personal data we hold about you and your child. We will provide this within 30 days.
Right to rectification — you may request correction of inaccurate personal data. Child name, age, interests, and supporting characters can be updated directly in your account settings at any time.
Right to erasure — you may request deletion of your account and all associated personal data at any time. You can also delete individual child profiles directly from your account settings. We will complete any deletion request within 30 days of receipt. Note: billing records are retained for 7 years as required by HMRC regulations regardless of account deletion.
Right to restriction — you may request that we pause processing of your personal data while a complaint or dispute is being resolved.
Right to data portability — you may request a machine-readable copy (JSON format) of your personal data for transfer to another service.
Right to object — you may object to processing based on legitimate interests.
Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at privacy@talebuzzer.com. We will acknowledge your request within 5 working days and complete it within 30 days. In exceptional circumstances we may extend this to 3 months — if so, we will notify you in writing before the original 30-day deadline.
We maintain an internal Data Deletion and Subject Rights Process document that sets out the exact steps we follow to action your request. This document is available to the ICO on request.
You have the right to lodge a complaint with the ICO at any time: ico.org.uk or 0303 123 1113.
Some of our sub-processors are based outside the UK. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including the International Data Transfer Agreement (IDTA) approved by the ICO, or adequacy decisions where applicable.
Supabase stores all data within the EU (Frankfurt). OpenAI and Vercel are US-based and process data under appropriate IDTA safeguards.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. These include AES-256 encryption at rest, TLS 1.3 encryption in transit, hashed passwords (bcrypt), hashed child PINs (SHA-256 with salt), Row Level Security on all database tables, and server-side API key management.
No system is completely secure. If we become aware of a data breach that poses a risk to your rights, we will notify you and the ICO within 72 hours of discovery as required by UK GDPR Article 33.
We will notify registered users of any material changes to this Privacy Policy by email at least 14 days before the changes take effect. Continued use of TaleBuzzer after that date constitutes acceptance of the updated policy.
Previous versions of this policy are available on request by emailing privacy@talebuzzer.com.