Privacy Policy
Last updated: March 2026
1. Information We Collect
Account information: When you create an account, we collect your email address, name (optional), and a hashed version of your password. We never store your password in plain text.
Child profiles: You provide your child's first name, age, and interests to personalize stories. We do not collect last names, photos, or any other identifying information about children.
Voice recordings: If you use our voice cloning feature, we send your audio recording to a speech synthesis provider to create a voice clone. Recordings are not stored on our servers after processing.
Payment information: Payments are processed by a PCI-compliant payment processor. We never see or store your full credit card number. We store only a payment processor customer ID and payment status.
Usage data: We log story generation events, error logs, and basic request metadata for debugging and improving the service. We do not use third-party analytics or tracking scripts.
2. How We Use Your Information
- To generate personalized stories for your child
- To create and manage your account
- To process payments and manage subscriptions
- To send password reset emails and service-related communications
- To improve our service and fix bugs
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. Third-Party Services
We use trusted third-party services to operate BedtimeCast. These include:
- AI story generation — Your child's first name, age, and interests are sent to an AI service to generate personalized stories.
- Text-to-speech & voice cloning — Story text and voice recordings (if you use voice cloning) are processed by a speech synthesis provider.
- Image generation — Scene descriptions are sent to an image generation service to create illustrations.
- Payment processing — Payments are handled by a PCI-compliant payment processor. We never see or store your full card number.
- Infrastructure & security — We use industry-standard services for DNS, DDoS protection, and content delivery.
We only share the minimum data required for each service to function. No third party receives data for marketing or advertising purposes.
4. Data Storage & Security
Your data is stored in an encrypted database on a secure server. All connections use HTTPS. Session tokens are stored as HTTP-only secure cookies. Passwords are hashed with bcrypt (12 rounds). We apply rate limiting to protect against abuse.
5. Children's Privacy (COPPA)
BedtimeCast is a service for parents, not for children to use directly. We do not knowingly collect information from children under 13. All accounts are created and managed by parents or guardians. Child profiles contain only a first name, age, and interests — no personally identifying information.
6. Your Rights
You can:
- View and edit your account information at any time
- Delete your account and all associated data from your account settings
- Request a copy of your data by contacting us
- Opt out of non-essential emails
7. Cookies
We use a single session cookie (bedtimecast_session) for authentication. It is HTTP-only, secure, and same-site. We do not use advertising cookies, tracking cookies, or third-party analytics.
8. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or a notice on the site. Continued use of BedtimeCast after changes constitutes acceptance.
9. Contact
If you have questions about this privacy policy, contact us at [email protected].