Privacy policy
Last updated 14 September 2026
The short version
Bedtime STEM is a service for parents. You create an account with your email address, add a profile for each child, and we generate bedtime stories for them. To do that we keep a small amount of information about you and your children, we send the text of a child’s profile to an AI provider to write each story, and that is the whole story. We do not show advertising, we do not sell data, and we do not track anything in the screen you read from at bedtime. You can delete a child, or your whole account, at any time from Settings.
This policy explains the details in plain English. It is written for the United Kingdom and follows UK data protection law (the UK GDPR and the Data Protection Act 2018) and the ICO’s Age Appropriate Design Code (the “Children’s Code”).
Who we are
Bedtime STEM is operated by [Company name, company number, registered address — to be completed], who is the “data controller” for the information described here. You can contact us about privacy at stonempv@gmail.com (placeholder address — to be replaced before launch).
What we collect
About you, the parent or guardian:
- Your email address, used to sign you in (we send a one-time link rather than storing a password) and to send you service emails such as a recall reminder or a receipt.
- Your subscription status and billing history. Card details are handled entirely by our payment provider, Stripe, and never touch our servers.
- Ordinary technical records that any web service keeps to run and secure itself: IP address, browser type, and the times you signed in.
About each child, as entered by you:
- A first name (or nickname) and the pronouns to use in the story.
- Year group and reading level.
- A few favourite things (for example dinosaurs, the sea, building things).
Generated as you use the service:
- The stories written for each child, including drafts you rejected or edited, and the “world” the stories build up over time (recurring characters and places).
- Which door was chosen at the end of each story.
- Recall results: which questions you asked and how it went, as you record it.
- A record of which curriculum ideas have been covered.
We deliberately do not ask for a child’s surname, date of birth, school, photograph, or location. Please do not type these into the favourite-things box or into a story edit; we will not ask for them and we would rather not hold them.
Why we collect it
- To generate and personalise stories. The child profile, previous stories, door choices and recall results are what make each new story fit the child. This is the core purpose and there is no way to offer the service without it.
- To run your account. Signing you in, taking payment, sending you service emails, and answering your questions.
- To keep the service safe and working. Security logs, error reports, and reviewing stories that you or our reviewer flag as inaccurate or inappropriate, so we can improve the generation and checking.
We do not use your data, or your child’s, for advertising, profiling for marketing, or any purpose unrelated to the service.
Our lawful basis
- Your account: performance of a contract. We need your email address and subscription details to provide the service you have signed up for.
- Your child’s profile and stories: your consent as their parent or guardian. When you create a child profile you confirm that you are the child’s parent or legal guardian and that you agree to us using the details you enter to generate stories. You can withdraw that consent at any time by deleting the child profile, which deletes their data.
- Security, fraud prevention and improving the service: our legitimate interests in running a safe and reliable service, balanced against your rights. We do not rely on this basis for anything involving a child’s profile beyond keeping it secure.
Children never use the service directly
Bedtime STEM is designed to be used by a parent, on the parent’s device. Children do not have accounts, cannot sign in, and never interact with us or with any AI system. When a child “picks a door”, the parent records that choice in the app. We do not collect any information from a child; everything about a child is entered by the parent or generated by us from what the parent entered.
Who else sees the data
We use a small number of providers to run the service. Each only receives what it needs for its job.
- Anthropic (AI story generation and review). To write a story we send the text of the child’s profile (first name, pronouns, year group, reading level, favourite things), the story world, summaries of earlier stories, door choices and recall results to Anthropic’s API, along with the curriculum scaffold. Anthropic processes this to return the story and the review. We use their API under commercial terms, which do not permit training on our data.
- Stripe (payments). Handles your card details and subscription. We receive confirmation of payment and your subscription status, never your card number.
- Resend (email). Sends the sign-in links and service emails to your address.
- Our hosting provider — [Fly.io / hosting provider name and region — to be completed] — where the application and database run. We host in the United Kingdom or the European Economic Area wherever we can; where a provider processes data outside the UK we rely on the UK’s adequacy decisions or the International Data Transfer Agreement.
We do not sell, rent or share personal data with anyone else, and we do not use analytics or advertising trackers anywhere in the app. We would only disclose data if the law required it.
How long we keep it
- Your account and your children’s data are kept for as long as you have an account.
- You can delete a child profile at any time from Settings. Their profile, stories, door choices and recall results are deleted within 30 days.
- You can delete your whole account at any time from Settings. Everything, including every child profile, is deleted within 30 days. Billing records that we are legally required to keep (for example for tax purposes) are retained for the required period but contain no child data.
- Backups are rotated out within the same 30-day window.
Your rights
Under UK data protection law you can ask us to:
- Access the personal data we hold about you and your children.
- Correct anything that is wrong (you can edit a child profile yourself at any time).
- Erase your data (Settings does this instantly, or email us).
- Export your data in a portable format, including the stories.
- Object to or restrict particular processing.
- Withdraw consent for a child’s data at any time by deleting their profile.
Email stonempv@gmail.com and we will respond within one month. If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We would appreciate the chance to put things right first.
Our age-appropriate design commitments
Although children do not use the service directly, the service exists for them. We commit to:
- Collecting the minimum about a child needed to write a good story, and nothing else.
- No advertising, no nudges, no in-app purchases, and no tracking in the reading screen.
- Reviewing every story for age-appropriateness before it is offered to you, and requiring your approval before it can be read.
- Giving you a clear, one-tap way to delete a child’s data.
- Never using a child’s data for any purpose other than their stories.
Security
Sign-in is by one-time email link, so there is no password to leak. Data is encrypted in transit and at rest by our hosting and database providers. Access to production data is limited to the people who run the service and is logged. If we ever suffered a breach affecting your data we would tell you, and the ICO, promptly.
Cookies
We use one strictly necessary cookie to keep you signed in. We do not use analytics, advertising or third-party cookies, so there is no cookie banner to click through.
Changes to this policy
If we change how we handle data in a way that matters, we will email you before the change takes effect and update the date at the top of this page. See also our terms of service.