Privacy Policy
Last updated: June 2026
1. Data controller
- Controller: Gabriel Perales
- Contact: hola@talewiz.com
2. Data we collect
- Email address — for library access and to send the sign-in link.
- Child's photo — provided voluntarily to personalize the illustrations. Stored privately and sent to the AI API only to generate the story.
- Payment data — handled entirely by Stripe. TaleWiz does not store card data.
- Usage data — technical logs (IP, browser, date/time) to ensure security.
3. Purpose and legal basis of processing
| Purpose | Legal basis |
|---|---|
| Providing the storybook generation service | Performance of a contract (GDPR art. 6.1.b) |
| Sending the library access link | Performance of a contract (GDPR art. 6.1.b) |
| Payment processing | Performance of a contract (GDPR art. 6.1.b) |
| Security and fraud prevention | Legitimate interest (GDPR art. 6.1.f) |
| Compliance with legal obligations | Legal obligation (GDPR art. 6.1.c) |
4. Service providers (data processors)
- Stripe, Inc. — payment processing. Stripe's privacy policy .
- Google (Gemini API) — AI text and image generation. Google's privacy policy .
- Fly.io, Inc. — web hosting infrastructure and secure storage of data and images.
- Piqo — cookieless web analytics. Collects usage metrics in an aggregated, anonymous way, without tracking users across sites.
5. International transfers
Some providers (Stripe, Google, Fly.io) are located outside the European Economic Area. Such transfers are covered by standard contractual clauses approved by the European Commission or by adequacy decisions.
6. Data retention
Data is retained for as long as necessary to provide the service and for legally required periods (a minimum of 5 years for tax data). Children's photos are deleted upon user request.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction, and portability by emailing hola@talewiz.com. You also have the right to file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es .
8. Security
We apply appropriate technical and organizational measures: encryption in transit (HTTPS/TLS) and at rest, access control, and private image storage.