Privacy
littlelore is a product you hand a child’s name to. This page says exactly what we hold, who else touches it, and how to reach us about it. It is short because we ask for very little — and specific because “we take your privacy seriously” is not something anyone can check.
Last updated 21 August 2026
- We never ask you for a photograph of your child. Their character is drawn from appearance choices you tap, and there is nowhere in the product that asks for a picture of them. You can add photos of up to three things — a favourite toy, the dog, your front door — and we ask you to keep people out of those.
- We ask for a first name, an age, pronouns, and a line or two about your child. No surname, no address, no birthday.
- We do not sell anything to anybody, and no model is trained on your child’s book. We do advertise: four marketing pages carry Meta’s tag, and after you subscribe our own server tells Meta the sale happened too — never a page with a book on it, and never anything about your child, either way.
- Write to us about anything you want done with your information and a person will answer.
What we hold
- Your email address — so you can sign in, so we can tell you a book is ready, and so we can say hello once, the first time you subscribe. Clerk handles signing in and holds your password; we never see it.
- Your child’s first name, age and pronouns — because the story is written about them and in their pronouns, and the reading level is chosen from their age. An age in whole years — never a date of birth — and never a surname.
- The line or two you wrote about them — because it is the difference between a book with their name in it and a book that is really about them. It is the most personal thing on this list, and we know it.
- The character you built — hair, eyes, skin, the outfit — the choices you tapped, from a fixed set. Not a description of a real face, and nothing that could be turned back into one.
- The books themselves — the text, the illustrations, the cover and the reading level, so your shelf still has them tomorrow.
- Whether you have a subscription — and when the period ends, so the button that makes a book knows what to do. Never your card details.
- Whether you want the “their book is ready” email — so that turning it off means something. That switch governs that email and no other: the one-time hello when you first subscribe is sent whatever it is set to, and it is the only other email we send.
- If you have opened the pricing, subscribe or ad-landing pages, or the screen a book of yours is waiting on, while signed in — we keep a row in our own database against your account: your email address hashed, your IP address, which browser you are using, and the identifiers Meta sets as cookies — so that if a subscription starts we can tell Meta which advertising it followed from. This happens on those four pages whether or not you came from an ad. Of the two cookie identifiers, one marks the browser and is set for everyone the tag loads for; only the other, the click identifier, depends on having arrived from an ad. Nothing about your child is in the row, and your address is only ever in it as the hash. Before you have an account, the two cookie identifiers on their own can be stored against a random identifier your browser makes up — see “How long we keep it”. The two sections on advertising below say more.
That is the list. Anything not on it, we do not have: we ask for no postal address, no phone number, no school, no second child unless you make them a book too.
What we do with it
One thing — making the book. The first name, the age, the pronouns and your line go into the prompt that writes the story, which is how a book comes out being about your child rather than about a child. The pages are painted from the character you built.
We look at counts and costs in aggregate to keep the thing running: how many books were made, what they cost to paint. We can see your books — nothing here is encrypted in a way that would hide them from us — and we look at one only when something has gone wrong and we are trying to fix it.
How your child is drawn
Your child’s character is assembled in your own browser out of drawn parts you pick; while you are building them, nothing leaves the page. We never ask you for a photograph of them, and there is nowhere in the product that takes one.
The single drawing every page is painted from is generated from six appearance choices, pronouns, an age band and an art style — not your child’s name, and not the line you wrote. Their name is in the story text and in the descriptions of the scenes, because it is their book. It is not in the picture of them.
Photos of their things
You can add a photo of up to three thingsfrom your child’s world — a favourite toy, the dog, your front door — and we draw them into the pictures, so the rabbit in the book is their rabbit.
We ask you to photograph things rather than people, and to glance at what else is in the shot before you send it. We would rather say that plainly than claim we check every picture and get it wrong: nothing here inspects what a photo contains, and no automatic check of that kind is reliable enough to promise. What you upload is what we use.
Here is what happens to one. The file is re-encoded the moment it arrives and everything the camera attached to it is discarded — including the GPS coordinates a phone routinely writes into a photo, which matter most for the picture of a front door. It is stored privately, never on a public address. It is sent to the image model once per art style, which draws the object on its own and gives us back a small illustration; that drawing, not your photograph, is what the pages are painted from.
Both the photo and the drawing stay with your child’s books, because a book has to keep looking the same when it is reopened next year. Neither is shown to anyone else, sold, or used to train anything — the same as everything else on this page. If you would like one removed, write to us and we will do it.
Who else touches it
littlelore runs on other people’s services. Rather than a list of company names that goes stale the day one changes, here is every kind of service we use and exactly what each one gets:
- Signing in — holds your email address and your password. Nothing about your child.
- The database and the file storage — your child’s first name, age and pronouns, the line you wrote, and the text and pictures of every book. This is where the book itself lives.
- The models that write and paint — the writing prompt carries the first name, the age, the pronouns and the line you wrote. Any photograph you upload of a belonging is sent to the image model once, to be redrawn.
- Payments — your email address and your card details. What comes back to us is whether you are subscribed and when the period ends — we never see a card number.
- Sending email — sends our two emails. The one saying a book is ready carries your address, your child’s first name and the book’s title. The one-time hello, when you first subscribe, carries your address and nothing about your child at all.
- Advertising measurement — Meta, and only Meta — Its tag runs on four pages and nowhere else, never on a book. After you subscribe our own server tells it the sale happened, with your email address hashed rather than sent in the clear. Nothing about your child reaches it either way. Two sections below say more.
- Knowing when the site breaks, and how it is used — which page failed and which browser it happened in, and which screens people move between. Never the contents of a book, never your child’s name, and never a recording of your screen.
Nobody else. We do not sell or share any of it, and littlelore trains no model on your child’s book. Meta is the only advertiser on that list, and it is also the one that gets least — the next section says exactly what. Each of them has its own terms; choosing them was our decision, and the responsibility for that choice is ours. If you would like the current companies by name, ask us and we will tell you.
The advertising tag, and where it is not
People find littlelore through ads on Facebook and Instagram, and Meta can only show those ads to people likely to want them if it can tell that somebody who clicked one arrived. So four pages carry Meta’s pixel: the front page, the pricing page, the subscribe page, and the page our ads link to, where you build the character before there is any account. A pixel is a small piece of code that tells Meta a browser opened the page it is on.
What it collects is a browser identifier Meta sets as a cookie so it can recognise the same browser again, which of those four pages was opened, and the ordinary things every web request carries: your IP address and which browser you are using. Not your child’s name, not their age, not the line you wrote, not a book. There are five things it ever sends, and every one of them is attendance or intent, never a fact about your child: that a page was opened; that the product was looked at; that you tapped one of the buttons that leads to checkout; and — on the page our ads link to — that an account was created, and that you got as far as seeing the story idea we came up with. None of the five carries anything else with it: each one is a name and nothing more, with no room in it for a detail about your child even if somebody wanted to put one there.
It is on no page with a book on it. Not the reader, not your shelf, not the sample book, and not the screens where you make one. That is not a switch we could forget to turn off: a page has to ask for the tag by name, and a test walks every page in the site and fails if any page but those four ever does — the same test fails if this page and that list ever stop agreeing on which four.
One thing above needs saying plainly, because it looks like a contradiction and is not. The list at the top of this page names four pages where we save an advertising row, and one of them is the screen a book of yours is waiting on — a screen with a child’s name on it. Meta’s tag is still not on that screen. What happens there is our own code saving the row the list at the top describes — the hashed address, the IP, the browser, and the two cookie values Meta’s tag set earlier, on one of the four pages that do carry it — so that a subscription bought from that screen can be matched to the advertising it followed from. Meta is told nothing by that page.
If you would rather it did not run, a tracker blocker or your browser’s own protection stops it, and littlelore works exactly the same either way — though see below for a separate report our own server sends, which runs whether or not this tag did.
The purchase report, sent after you subscribe
Everything above is your browser telling Meta about a page or a tap, in the moment it happens. A subscription starting is different: it is finished on RevenueCat’s checkout page, not ours, and it can complete minutes or days after you were last on littlelore at all — too late for anything running in your browser to report it. So when it happens, our own server tells Meta directly, the instant RevenueCat tells us.
What it sends: that a free trial started, or that a purchase happened, and what it was worth. Alongside that, whatever this browser gave us the chance to capture on the four pages named at the top of this page — the pricing, subscribe and ad-landing pages, and the screen a book of yours is waiting on — including, on the page our ads link to, before you had an account at all, which we attach to your account when you create one — your email address, put through a one-way scramble (a “hash”) before it ever leaves our server, so what Meta receives is a string it cannot turn back into your address; the same browser and click identifiers the tag above sets as cookies; and your IP address and which browser you were using, the same ordinary details every web request carries. Never your name as such, never a book, and never anything about your child — the report is about the sale, not about who it was for.
Why your email, hashed.Meta has no way to connect “someone bought a subscription” to “the person who clicked this ad” from the fact alone — it matches against identifiers it already holds, and a hashed email is one it accepts for that. Meta receives only the hash; your actual address still goes to nobody but Resend, to send the two emails described above.
This is the whole reason we can advertise responsibly at all: without it, a campaign would be spending against no evidence anyone who clicked an ad ever became a subscriber. It is not something a tracker blocker or a browser setting can stop — a purchase completing is something our own server always knows about, from RevenueCat directly, with no browser involved in telling us.
Where your email address deliberately is not
It is never written into our logs, and never into the record of how a book was made. It appears in three places in the whole codebase: the two that hand it to Resend — one to say a book is ready, one to say hello the first time you subscribe — and, when you open one of the pages described above while signed in, the one that reads it from Clerk for a single request, turns it into the hash described above, and lets the plaintext go without writing it anywhere. Even the error messages that come back from Resend have any address stripped out of them before anybody writes them down.
That is deliberate rather than tidy. Logs are read by more people, kept in more places, and thought about far less carefully than a database is.
How long we keep it
The books, for as long as you want them — that is the promise on the terms page, that a book you have made stays readable for ever whether you are subscribed or not. Everything else is kept while your account exists.
The one thing that can outlive an account is the pre-account capture described above: if you followed one of our ads, looked around, and never made an account, what is left is a row holding a random identifier this browser made up and the two Meta cookie values — no name, no email address, nothing about a child, and nothing that says who you are. We have no automatic clean-up for those yet, so today they simply stay. That is a gap rather than a decision, and this page will say so until it is closed.
We keep no separate archive of any of it, beyond the short window our database provider holds so that a failure can be undone.
Questions about your information
Email hello@littlelore.app from the address you signed up with and tell us what you would like done with your information — a copy of what we hold, a correction, or anything else. A person reads it and acts on it, as quickly as we can and within 30 days, and writes back to tell you it is done.
Children
The account is yours, as the parent or guardian. Children do not sign in and we collect nothing from a child directly. Everything we hold about your child is something you typed, and you can write to us about it at any time.
When this page changes
When the product changes what it collects, this page changes first or at the same time — never afterwards — and the date at the top moves with it.
Getting in touch
hello@littlelore.app. We read every message, and questions about this page are always welcome.

