StoryBox is a voice AI storytelling service for children, featuring the character Yarny. This Policy explains what information we collect, how we use it, and what rights parents have. Because StoryBox is directed to children under 13, we comply with the U.S. Children's Online Privacy Protection Act (COPPA), 16 CFR Part 312, as amended in 2025, and with applicable U.S. state privacy laws.
1. Who we are
StoryBox is operated by Evgeny Gortsev, a sole proprietor registered under Argentina's simplified tax regime (Monotributo), tax ID (CUIT) 27-96502694-6, address: Santo Domingo 2980, Planta Baja, Apt. 8, C1293, Autonomous City of Buenos Aires, Argentina ("StoryBox," "we," "us," "our").
Contact: hello@storybox.now · +54 9 11 5021-0052.
Scope. StoryBox is offered to users in the United States. It is not directed to users in the European Union or the United Kingdom; if we enter those markets in the future, this Policy and our consent practices will be revised for GDPR / UK GDPR.
2. How StoryBox works — two apps
StoryBox consists of two apps: one for the parent and one for the child. The parent app is for adults only (18+). A parent or legal guardian creates and controls the account, sets up each child's profile, and gives consent. The child app can be entered only through the parent app — the child signs in with a one-time code generated by the parent. A child cannot create an account or sign in on their own.
Before any of a child's personal information is collected, the parent passes an adult gate: they confirm that they are at least 18 years old and are the child's parent or legal guardian, and they complete adult verification through our verification provider, Kids Web Services. That is how we obtain verifiable parental consent, as described in Section 7.
3. What information we collect
We practice data minimization and collect only what is necessary to run the service:
From the parent
The parent's email address (to create the account, send notifications, and obtain consent).
A verification transaction reference from Kids Web Services and, if a subscription is purchased, a transaction reference from Apple or Google (we never receive or store card numbers).
Device and log data needed to operate and secure the service (persistent identifiers, IP address, app/device identifiers, user agent).
About the child (set by the parent)
The child's name or nickname.
Age or age group (3–6 / 7–9 / 10–12), to match the complexity of the plot and the vocabulary.
The child's gender, if the parent sets it (a gentle starting point for the story; optional).
Up to seven growth qualities chosen by the parent (for example, kindness, courage), to gently shape story themes.
Stories and related content generated in response to the child's requests, and limited interaction data needed to run the service.
Voice. When voice mode is used, the child's spoken request is processed in real time under the narrow rules in Section 4. We do not store raw voice recordings.
StoryBox does not allow a child to make personal information publicly available: the service has no chat, no comments, no public profiles, and no open posting; stories can enter the shared story library only if the parent explicitly chooses to allow it (publishing is off by default), only under a pseudonym and an illustrated avatar, and only after an automated screening for personal details, which blocks a story from being published if it finds any (Section 5).
Yarny never asks a child for personal data and never encourages a child to share it; we ask children not to give out personal information. In any case, the raw voice recording is deleted immediately after the response. Any details a child may volunteer on their own are not used for any purpose other than creating the story the child asked for, and are not disclosed. Verbatim transcripts of what the child says are used only to carry on the current session. When the session ends, that text is erased; if the session ended abnormally (for example, the app closed unexpectedly), a backstop process erases it no later than 60 minutes afterward. This brief retention exists solely to close out the conversation reliably and to guarantee cleanup — the transcripts are not used for any other purpose.
4. Voice and audio recordings
Voice is the most sensitive category of data in the Service, and we handle it under a narrow rule built on parental consent and zero retention.
A child can use voice only after verifiable parental consent is completed (Section 7). When voice mode is used, the child's spoken request is processed in real time: the audio is streamed to our speech-recognition provider, which acts solely as our processor under a data processing agreement and a zero-data-retention configuration — the audio is not logged, not stored, not used to train models, and not retained after the response is generated. We do not store raw voice recordings on our servers either. The resulting transcript is handled under the session rule described in Section 3, and the generated story may be saved in the child's story history (see Section 9).
In the adult preview mode, voice belongs to the adult user and is processed under our standard practices for adults, including a retention window of up to 30 days at our speech provider used solely for trust-and-safety review (see Section 7).
We do not use voice for biometric identification, voice cloning, profiling, or advertising.
5. How we use information
To provide the storytelling service and answer the child's requests.
To personalize stories according to the age, gender, and qualities set by the parent.
To create and protect accounts, prevent abuse, and maintain the service.
To obtain and record verifiable parental consent and to communicate with parents.
To comply with legal obligations and to enforce our StoryBox Terms of Use (storybox.now/terms).
We do not use children's personal information for behavioral advertising, and we do not build advertising or behavioral profiles of children.
Shared story library. Stories may appear in the StoryBox shared story library, which is visible to other users — under a pseudonym (not the child's real name) and an illustrated avatar. Before a story is published, its text goes through an automated screening for personal details: a story the screening flags is not published and goes to human review instead. The screening cannot be guaranteed to catch everything, including deliberate attempts to get around it; if personal details do end up in a published story, tell us and we will promptly take the story down (Section 8).
While a child's profile is active, publishing is OFF by default: a child's stories go into the library only if the parent has turned publishing on — through a separate setting when the child's profile is created, or later in Parent Controls. Publishing can be turned off at any time; turning it off removes the child's stories from the library.
When a child's profile is deleted — by the parent, or by us after 12 months without use — the stories are de-identified: they are separated from the child and from the parent account, the pseudonym and the avatar are removed, and they are shown, if at all, under our own "Yarny" label, with nothing indicating who created them. StoryBox may keep and publish such de-identified stories as its own content, including stories that were never published while the profile was active (Section 9 and our Terms of Use). A parent who does not want a particular story to remain may ask us to remove it at hello@storybox.now, before or after the profile is deleted.
6. Service providers
We share information only with vendors that act as our processors, strictly on our instructions, under data processing agreements that prohibit using the data to train their models and require appropriate security. They may not use the data for their own purposes. Our current providers:
DigitalOcean — cloud hosting and infrastructure.
OpenAI (OpenAI OpCo, LLC) — large language models, speech recognition, content moderation, and image generation; also a backup provider for speech synthesis. Children's content is processed under a data processing agreement with zero data retention: it is not logged, not stored, and not used to train models.
Inworld — speech synthesis (the voice of Yarny).
Recraft, Inc — backup provider for image generation, under a data processing agreement and an order form providing that prompts and generated images are deleted no later than 24 hours after processing, are not used to train models, and are processed only by Recraft's own models on Recraft-controlled infrastructure. Only sanitized scene descriptions are sent; no personal information about the child is included.
Apple and Google — app distribution and payment processing through In-App Purchase.
Kids Web Services Ltd (an Epic Games company) — adult verification of the parent when consent is obtained; we send the parent's email address, country, and language. The verification details the parent enters are submitted on KWS pages, are not passed to StoryBox, and are not retained after verification (see Section 7).
Google Workspace (Gmail) — delivery of service emails to the parent (consent confirmation, notifications): it processes the parent's email address and the contents of the emails.
Because these providers act as our processors, sharing information with them is not a "disclosure" of children's personal information under COPPA. We do not sell children's personal information, do not share it with third parties for their own purposes, and do not otherwise disclose it — except where disclosure is required by law (for example, in response to a lawful request from a government authority) or is necessary to protect the safety of a child, of other users, and of the service. The full list of processor recipients and the purpose of each transfer is set out above in this section.
7. Verifiable parental consent
Before a child gets full access to the Service (a persistent profile, saved stories, direct voice interaction), we obtain verifiable parental consent. Before the first child profile is created, the parent reviews a direct notice (what information we collect about the child, how we use it, and whom we share it with), confirms that they are at least 18 years old and are the child's parent or legal guardian, and completes adult verification through our verification provider — Kids Web Services (Kids Web Services Ltd, an Epic Games company) — using a link in an email sent by Kids Web Services.
Verification is performed using the adult-verification methods our provider offers for the United States — currently (a) a payment card: a small $0.05 charge that appears on the cardholder's statement and is automatically refunded within 8–13 business days, a method expressly provided for by the COPPA Rule (16 CFR § 312.5(b)(2)(ii)) as a transaction that notifies the primary account holder of each charge; and (b) the last four digits of a Social Security number (SSN), checked against databases. Those details are entered on secure Kids Web Services pages, are not passed to StoryBox, are used only for verification, and are not retained after verification is complete. Our provider may update the methods it offers from time to time; the methods currently available are always shown on the verification page itself.
We keep a record of every consent event: the method, the date and time, the IP address, the verification transaction ID, and the version of the notice shown. Until consent and verification are complete, we do not create a child profile and do not collect the child's data, apart from the technical identifiers described below. The free preview mode does not require consent: it is intended for parents and other adults and is age-gated — visitors who indicate they are under 13 cannot use voice in the preview and are invited to ask a parent to set up an account. The preview does not create a child profile and does not collect children's personal information. An adult's voice and transcripts in the preview are processed under our standard (non-children's) practices: our speech provider may retain them for up to 30 days solely for trust-and-safety review, after which they are deleted. In the preview we process only limited persistent identifiers (IP address, session/device identifier) — solely to support the internal operations of the service under 16 CFR § 312.5(c)(7): security, anti-fraud and abuse prevention, keeping the service running, rate limiting, and diagnostics. The specific internal operations for which these identifiers are collected are: authentication and session maintenance; rate limiting; fraud and abuse prevention; maintaining the security and integrity of the service and debugging it; and meeting legal obligations (the security event log and consent records). The means by which we ensure that these identifiers are not used or disclosed to contact a specific person, for behavioral advertising, to build a profile of a specific individual, or for any other purpose: our apps and our pages carry no advertising, no advertising SDKs, and no third-party trackers; the identifiers are not combined with other data for any purpose other than the operations listed above and are not used to personalize content (the story feed is chronological); they are not shared with third parties, except with our processors under data processing agreements and only within those same operations; access to them is limited on a least-privilege basis, and they are retained for approximately 90 days (Section 9).
You can withdraw consent at any time: delete the child's profile in Parent Controls (this stops further collection and deletes the child's data) or write to us at hello@storybox.now.
8. Parental rights and choices
At any time, through the parent app or by contacting us, a parent can:
review the personal information we have about their child;
delete the child's personal information;
refuse to permit further collection or use of the child's information; and
withdraw consent (which will stop further collection and lead to deletion of the child's data).
To exercise these rights, write to hello@storybox.now. We will verify the request and act on it without undue delay. Withdrawing consent or deleting data may end the child's ability to use features that require that information.
9. Data retention
We do not keep children's personal information longer than is reasonably necessary for the purposes for which it was collected, and we do not keep it indefinitely. Below is our data retention policy (16 CFR § 312.10): for each category it states the purpose of collection, the business need for retention, and the deletion period or trigger:
Raw voice recordings. Purpose of collection: to recognize the child's specific request and answer it. Business need for retention: none. Retention: not stored — deleted immediately after the response.
Verbatim transcripts of what the child says. Purpose of collection: to carry on the current conversation with Yarny. Business need for retention: keeping the active session running. Retention: erased when the session ends; if the session breaks off abnormally, no later than 60 minutes afterward.
Child profile (nickname or name, age or age range, gender, qualities, public pseudonym). Purpose of collection: personalizing stories and running the account. Business need for retention: so the child can use StoryBox correctly and comfortably. Retention: until the parent deletes the profile, the account is closed, or 12 months of inactivity — whichever comes first; after that, the profile and the child's personal information are deleted.
Stories and related content (titles, summaries, images, narration). Purpose of collection: the child's story library, continuing stories, family viewing. Business need for retention: preserving and building on the stories the child has created and other results of interacting with Yarny. Retention: while the child's profile exists — together with the profile; when the profile is deleted or after 12 months of inactivity — the child's verbatim transcripts are erased and the stories are de-identified (separated from the child and from the parent account) and may be kept and published by StoryBox indefinitely as its own content.
Parent contact (email) and parent account data. Purpose of collection: creating the account, obtaining consent, notifications. Business need for retention: meeting legal requirements and allowing StoryBox to communicate with parents. Retention: deleted together with the account; an email address where consent was never completed — 30 days.
Consent records (the method and the date/time consent was obtained, the version and hash of the notice shown, the IP address, the verification transaction ID). Purpose of collection and business need for retention: legal proof that verifiable parental consent was obtained (COPPA). Retention: the life of the account plus 3 years.
Security and moderation logs (they contain nothing the child said). Purpose of collection: security, abuse prevention, the crisis protocol. Business need for retention: investigating incidents and mandatory reporting. Retention: about 12 months; records of crisis protocol events — until the account is deleted (evidence to protect the child's rights and to resolve any disputes); de-identified aggregate crisis protocol metrics — 3 years (annual reporting under California SB 243).
Persistent identifiers (IP address, session/device identifiers) and technical logs. Purpose of collection: internal operations of the service only (16 CFR § 312.5(c)(7)) — security, anti-fraud and abuse prevention, keeping the service running, rate limiting, and diagnostics. Business need for retention: short-term operational. Retention: about 90 days.
Payment and financial records (transaction references; we do not receive card numbers). Purpose of collection: accounting and tax obligations. Business need for retention: meeting legal requirements and keeping proper books and records. Retention: up to 7 years, as required by law.
We do not keep children's personal information indefinitely. Deletion extends to backups as they cycle through rotation. A parent may ask for earlier deletion at any time (Section 8).
De-identified content. We may de-identify generated stories — separate them from the child and from the parent account, remove the pseudonym and the avatar, and screen the text for personal details — and then store, use, publish, and make such de-identified content available to other users indefinitely as StoryBox content, including after a child's profile has been deleted. De-identified content is not a child's personal information. We do not attempt to re-identify de-identified content, and we do not permit others to do so. A parent may ask us to remove a particular story from StoryBox at any time (Section 8).
10. Data security
We maintain a written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of children's data, including encryption in transit and at rest, least-privilege access controls, logging, and a designated security coordinator. No method of transmission or storage is completely secure, but we work to protect children's information and to respond promptly to incidents.
11. Personalization for the child
Personalization is set by the parent; it is not inferred by the system. The parent can set the age, gender, and up to seven growth qualities; these are stored as the child's personal information and are used only to tailor stories. The qualities come across gently through what the characters do — they are never named to the child and never turned into a lecture — and the child always leads the story. Guests and profiles without these settings do not get this personalization.
12. California residents' rights
California residents have rights under the CCPA/CPRA, including the right to know, access, correct, and delete personal information, and the right to opt out of the "sale" or "sharing" of it. We do not sell or share children's personal information. For users under 16, California law requires opt-in before any sale or sharing; we do neither.
Companion chatbot (California SB 243). Yarny is an AI companion. On first use we clearly disclose that Yarny is an AI and not a real person; for minors we show a reminder at least every three hours to take a break and that Yarny is an AI; we note that AI companion features may not be suitable for every minor; and we maintain a crisis protocol that, on signs of self-harm, pauses the story, directs the user to the 988 Suicide & Crisis Lifeline, and, for child profiles, notifies the parent of the event. Our public protocol is available on our website.
Age-appropriate design (California AADCA). We apply child safety protections and the highest privacy settings by default to all child profiles, and we use plain language, regardless of which AADCA provisions are currently enforceable.
13. International users
StoryBox is intended for users in the United States. Information is processed by our service providers, primarily in the United States. We do not currently target other markets.
14. Business transfers and change of operator
StoryBox is currently operated by the individual named in Section 1. If the Service changes operator — for example through a corporate reorganization, the creation of a company that takes over the Service from its current operator, or a sale of all or substantially all of the Service's assets — personal information, including children's personal information and parental-consent records, may be transferred to the successor operator. Any such transfer is subject to all of the following conditions:
the information is transferred only together with the Service itself, as part of that transaction, and is never sold or transferred as a separate asset;
the successor operator assumes this Privacy Policy, including its children's-privacy commitments, and is subject to the Children's Online Privacy Protection Act (COPPA) and all other applicable privacy and child-protection laws, including U.S. state laws, to the same extent as the current operator;
the successor operator may use personal information only for the purposes for which verifiable parental consent was originally obtained;
the successor operator may not materially change the collection, use, or disclosure practices described in this Policy without first obtaining new verifiable parental consent;
we will notify parents by email, at the address associated with the parent account, at least 30 days before the transfer takes effect, and that notice will identify the successor operator; and
until the transfer takes effect, parents may review or delete their child's personal information as described in Section 8; deletion requests received before the effective date are completed before any information is transferred.
Parental-consent records — including the exact, hash-verified text of the notice each parent agreed to — transfer with the Service unchanged, so every consent remains verifiable after the transfer.
15. Changes to this Policy
If we materially change our data practices, we will notify parents and, where required, obtain consent again. We version this notice; the version and effective date appear at the top.
16. How to contact us
For any privacy question or to exercise a parental right:
Evgeny Gortsev (StoryBox)
Santo Domingo 2980, Planta Baja, Apt. 8, C1293, Autonomous City of Buenos Aires, Argentina
hello@storybox.now · +54 9 11 5021-0052