What we collect
We collect the minimum a bookmaker needs, and nothing that a bookmaker doesn’t:
- Your account: an email address, used for six-digit sign-in codes. When you connect Google, Apple, Facebook, or Amazon sign-in, we store that provider’s account identifier to recognize your linked Fable Designer account. These methods work without a Fable Designer password. Connecting a new method can require an email code to confirm which account and library it belongs to.
- What you write for a character: an age, an optional first name, and an optional short description in your own words (“curly hair, obsessed with excavators”). The form has no field for a last name, a birthday, or an address.
- Your commission: the lesson or story idea you type when you ask for a book, and any edits you make to the manuscript afterward.
- If you arrived from an ad: the labels and the click code that were on that link, and the time our cookie noted them. When the request that creates your account carries that cookie, they are saved with the account (described below).
There is nowhere in the product to put a photo of your child. No screen accepts an image upload, and our database has no column to store one. Characters are drawn from the written description you give us.
What we generate and store
Making your book produces work product, and we keep it:
- Manuscripts: storyline pitches, page text, titles, dedications, and refrains, including your edits.
- Illustrations: character sheets, covers, and page art, including earlier versions you re-rolled past.
- Review verdicts: every manuscript is read by an independent editorial model, and we store its verdict and its critique. That review is a second opinion on craft, not a gate. It runs in the background, its suggestions reach you as optional edits you can apply or dismiss, and your book does not wait on it.
- Recordings you make: if you read your book aloud in the recording studio, we keep each page’s take and the word timings we derived from it, stored on that book the way its art and its narration are. Silence at the start and end of a take is cut before it leaves your device, and the studio shows what was cut and offers to put it back. Re-reading a page replaces that page’s take and deletes the audio the old one pointed at.
- An event log: a running record of each book’s progress (state changes, review verdicts, moderation flags, what each step cost us). It powers the progress screen you watch while your book is being made, and it is our audit trail if something goes wrong.
Which providers see what
A small number of providers help us make your book. Each one sees only what its job requires:
- Google sign-in: when you choose this option, Google verifies your identity and sends us your account identifier and verified email address. The sign-in request asks for identity and email access; it does not request access to your inbox, contacts, or Drive files.
- Apple, Facebook, and Amazon sign-in: when you choose an available option, that provider authenticates you and returns an account identifier. Apple can also return a verified email address or private relay address. Facebook requests its required basic public-profile permission; Amazon requests its user identifier. Our sign-in code uses the identifier rather than importing photos, posts, contacts, or purchase history. Your books and character descriptions are not included in these authentication requests.
- Apple authorization: we keep an encrypted authorization credential so account deletion can revoke the connection with Apple. Cleanup retries if Apple is unavailable; the encrypted credential is removed after revocation succeeds.
- The writing and reviewing models (Anthropic and OpenAI): story text (which can include your child’s first name, age, and the description you wrote) goes to the model that writes the manuscript and to a second, independent model that reviews it.
- The illustration models (OpenAI, and Google for print covers): receive written illustration prompts describing invented characters and scenes. Written prompts are all they get, because written prompts are all we hold.
- Narration and alignment (ElevenLabs): when you create a read-aloud share, the book’s page text goes to ElevenLabs to be turned into audio. If you record the book in your own voice instead, that page’s recording goes to them as well, alongside the same page text, so their alignment service can report where each word falls in what you read. Those timings are what let the words light up in time with your voice. Either way, what leaves here is the page: no account details, nothing you wrote about a character.
- Following along while you read (your browser): in the recording studio the words light up as you say them, and what does the listening is your own browser’s speech feature. Where the browser can transcribe on the device (recent versions of Chrome, once you install its language pack), the audio stays on your machine. Where it cannot, which today includes every browser on an iPhone or iPad, the browser sends what it hears to its maker’s speech service (Apple’s or Google’s) under their privacy policy, not ours. The studio says which of the two is happening while you record. The text it produces is used to move the highlight and then discarded; it is not stored and does not reach us. Recording without this is a matter of declining the microphone prompt for speech, or reading with the highlight off.
- Printing (Lulu): when you order a printed copy, Lulu receives the finished book files and the delivery name, address, and contact phone you enter at checkout. That is what a printer needs to make and ship your book, nothing more.
- Email delivery (Resend): your email address, to send sign-in codes, “your book is ready” notes, and print-order updates.
- Payments (Stripe): the card and billing-address fields on our checkout page are Stripe’s own, so your card details and billing address go to Stripe, not to us. We give Stripe your account email for the receipt. What comes back to us and is stored is Stripe’s reference IDs for the purchase, the amount, currency and tax, the payment status, and its dates. If you save a card to your account for a free first book, you enter it on Stripe’s own page and Stripe keeps it on your account at Stripe. Saving it charges nothing; it is saved so the free book can be tied to a valid card. A later purchase asks for payment on Stripe’s page again. We store Stripe’s references to the saved card, the date it was saved, and the card fingerprint Stripe provides (an identifier Stripe derives from the card number, not the number itself).
Our infrastructure (application hosting and database) is provided by Vercel and Neon, which store the data described on this page on our behalf.
We advertise, and advertising involves measurement. Rather than summarize that here in a sentence you’d have to take on faith, we describe it item by item under Cookies and tracking below: which tools run, what each one receives, and what is held back from all of them.
And us: when you report a problem we can’t reproduce, a named person here can open your account and see it as you see it. It is limited to the addresses listed in our operations settings, a reason is recorded every time, the session ends on its own, and it can read your account but not change it, spend from it, or buy anything with it.
How long we keep things
- Your books (manuscripts, art, audio, PDFs) are kept until you delete them. They’re yours; we don’t expire them.
- Moderation and abuse records (declined commissions, moderation flags, review failures) are kept for 90 days so we can investigate misuse, then purged down to anonymous aggregate counts.
- Ad-source information (the labels, the click code and the first-arrival time saved with an account) is kept for as long as the account exists, and deleting the account deletes it.
- Payment and provider-cost records (limited payment references, amounts, dates, usage and reconciliation status) support accounting, refunds, disputes and verification of charges. After a book or account is deleted, these financial references have a 7-year retention window, extended by later financial activity. Delivery-event receipts use the event date and remain while related financial records need them. Access is restricted to financial operations. Unresolved obligations and documented recordkeeping holds can require longer retention and are flagged for review. The financial records are separate from manuscripts, illustrations and recordings. Anonymous daily totals can remain afterward.
Deleting your data
You can delete an individual book, a character you created, or your whole account. We remove the associated account and story content from Fable Designer’s active services, with the limited financial records described above retained separately. Our infrastructure providers may retain limited backup copies temporarily under their standard retention schedules.
To request account deletion, sign in and open your account page, then choose Delete my account and everything in it. If you cannot sign in, email support@fabledesigner.com for help confirming account ownership. Deleting your Fable Designer account removes its linked sign-in identifiers; it does not delete your Google, Apple, Facebook, or Amazon account. An encrypted Apple authorization credential can remain while revocation is retried.
Shipping addresses
When you order a printed copy of your book, we ask for a shipping address at order time only. Nothing asks for one earlier. The address is used to price and ship the printed book. It is kept with that order, and shared with Lulu, our printer, so they can print and deliver your book.
The tablet reading app
Books can be read on a tablet through our reading app, which is a companion to your account rather than a second place to sign in. There is no account in the app and no password: on your shelf you generate a code, an adult types it into the tablet once, and that code is exchanged for a token stored on the tablet. The token identifies that tablet, not a person, and the pairing screen is the only place in the app where anything can be typed at all.
Each time the tablet opens its shelf, it records the time it last did so. You see that on your own shelf as a date (the tablet last opened on the 8th), and it is the only thing the tablet reports back to us. To keep someone from guessing codes, the pairing step also counts recent attempts against a hashed form of the requesting network address rather than a stored one.
The reading screens load no advertising or analytics code. The measurement tools described elsewhere in this policy run on the website only, and the reading surfaces sit outside where they are mounted.
Removing the tablet from your shelf revokes its token, and the app stops loading books with it. Books and narration already downloaded to the tablet stay on the tablet, and read there without a connection.
Cookies and tracking
A few things run in your browser: the session cookie that keeps you signed in, a cookie that notes which ad you arrived from (described below), Google Analytics, which we use to count visits and see which steps of making a book people reach, and the Meta (Facebook) Pixel, which shares visit and conversion events with Meta so we can measure and target advertising. The events we send any of these tools are steps, buttons, and product choices: ids, labels, and listed prices, along with the address of the page they happened on. Your child’s name, age, and description stay out of them, as do your book and guidance text. Neither tool loads at all on the read-aloud share pages or in the reader app, so a share’s secret address is not part of what is sent. Deeper operational measurement stays in our server-side event and generation logs (described above).
If you arrived from an ad, the link you clicked carried labels naming which ad it was: the platform, whether the placement was paid, the campaign, and the version of our pitch it showed you. Facebook and Google also attach a code to the link that identifies that one click. Google Analytics collects the labels so we can tell which ads bring people who go on to make a book they love. We run both tools with their standard settings. With those, each receives the address of every page you view on our main site (on the page you landed on, that address includes the code), and the Pixel keeps the Facebook code in a cookie of its own. We write the labels on our own ads, and they name the ad. A link can be written by anyone, so what we keep from one is cut down first, as described next.
Our own site notes those labels and the click code in a cookie in your browser, which lasts up to 30 days. If the request that creates your account carries that cookie, we save them with it, along with the time the cookie noted, so we can tell which ads bring people who go on to make a book. Account creation is the one place our server reads that cookie. Six things are read off the link: the four labels and the two click codes. Each label is trimmed to a short label of letters, digits, dots, dashes and underscores, and a value carrying an @, a run of seven or more digits, the shape of a phone number, or an email address with the @ spelled out is discarded instead of stored. A click code is kept only if it is made of letters, digits, dashes and underscores and is no longer than 256 characters.
Children’s privacy
Fable Designer is a service for adults. Accounts are held by parents and guardians (18+) who commission books on behalf of a child. There is no sign-up and no sign-in for a child to use. On the website every screen that accepts text sits behind the account holder’s sign-in, and in the tablet app the only thing that can be typed is the pairing code an adult enters once. When a child reads on a paired tablet, what that produces is the last-opened time described above, which only the account holder sees. The small amount of child-related information we hold (age, optional first name, optional description) comes from the guardian, is used only to make their books, and is deleted on request as described above.
Changes to this policy
If this policy changes, the date at the top of this page is updated.
How to reach us
Questions, deletion requests we can help with, or anything that worries you: support@fabledesigner.com. A person reads it. The service is operated by Fable Designer LLC, a Massachusetts limited liability company.
See also our Terms of Service.