PRIVACY POLICY

Privacy, in plain language

StoryCubby is a children's reading app, but accounts and cloud controls are for parents and caregivers. We designed the app to work with little personal information.

Effective and last updated: 13 August 2026

The short version

StoryCubby has no advertising SDK, does not sell personal data, and does not ask children for a name, birth date, location, photo, voice recording, or contacts. Reading can begin with a randomly generated guest account. A grown-up may add a parent email to sync reading choices across devices.

1. Who we are and what this covers

This policy describes the StoryCubby mobile app, its public privacy and account deletion website, and the StoryCubby account service. In this policy, “StoryCubby,” “we,” and “us” refer to Storry Cubby, the developer of the StoryCubby app identified in its app store listing.

Story content may be downloaded for offline reading. The app's parent account area controls sign-in, sync, data export, and account deletion.

2. Data we handle

DataWhen and why
Guest accountA random account ID, generic “Little Reader” name, generated non-deliverable email, and timestamps let the app sync without asking a child for identity details.
Parent accountIf a grown-up chooses to sign up, we store the parent email, an optional parent name, email-verification status, account dates, and secure session records.
Reading choicesBook IDs, current page, completion, favourites, last-opened time, selected theme, and narration settings are stored on the device and mirrored to the account service when sync is available.
DownloadsStory images, text, audio, and catalog metadata are cached on the device so downloaded books can work offline.
Security dataIP address, browser or device user-agent, session tokens, one-time-code records, request timing, and basic server logs help authenticate users, limit abuse, and diagnose failures.
PurchasesThe current Android build does not offer checkout or collect payment-card details. If an entitlement exists from another supported build, StoryCubby may hold its product ID, provider, transaction reference, status, amount, currency, and dates.

Coloring marks and the words a child reads are not uploaded as child profile data. The app does not request precise location, contacts, camera, or microphone access.

3. How we use data

  • Provide sign-in by email code and keep parent accounts secure.
  • Save and sync reading progress, favourites, app settings, and valid entitlements.
  • Deliver and cache story content for online and offline reading.
  • Export account data when a signed-in parent asks for it.
  • Prevent abuse, investigate errors, and maintain service reliability.
  • Delete an account after the parent email is verified.

We do not use this data for behavioural advertising, cross-app tracking, or building a marketing profile of a child. We do not sell personal information.

4. Providers that help us run StoryCubby

We disclose only what is needed to service providers acting for us:

  • Cloudflare hosts the account API, stores account and sync data in D1, delivers story files, provides network security, and keeps limited operational logs.
  • Resend receives the parent email address and one-time code needed to deliver sign-in and deletion-verification emails.
  • Your app store and device platform may process installation, diagnostics, or purchase information under their own terms; StoryCubby does not receive a payment-card number.

These providers may process data in countries other than yours. Their handling is governed by their contracts and privacy terms. We may also disclose information when required by law, to protect users, or to secure the service.

5. Children's privacy

StoryCubby is made for children ages 4–9 to enjoy with a parent, caregiver, or educator. The app does not ask a child to create a named profile. Account creation, email entry, data export, and deletion are placed in the grown-up area behind a parent check. Parents should enter their own email address, not a child's.

If you believe a child's personal information was submitted to us, contact us. We will investigate and delete it where appropriate.

6. How long we keep data and how deletion works

  • Parent account and synced reading data remain while the account is active.
  • Inactive guest accounts are automatically removed after 30 days when they have no active session.
  • One-time codes stop working after five minutes. Expired verification and rate-limit records are removed by scheduled cleanup.
  • Cloudflare Worker operational logs are retained for no more than seven days under the configured service plan.

A verified deletion removes the StoryCubby user row and its sessions, linked sign-in records, synced progress, favourites, settings, entitlements, and purchase references from the live D1 database. Cloudflare's point-in-time disaster-recovery history may retain an older encrypted database state for up to 30 days before it expires. We do not use recovery history to recreate a deleted account unless required to recover from a service-wide incident; any restored deletion would be applied again.

Deleting the cloud account from this website cannot remove files stored only on a phone or tablet. Uninstall StoryCubby or clear its app storage to remove local reading history and downloaded stories from that device.

7. How we protect information

We use HTTPS in production, short-lived six-digit email codes stored as hashes, secure device storage for session credentials, access controls, input validation, rate limits, and Cloudflare's managed infrastructure. No system is perfectly secure, but we limit the data collected and review the service for avoidable exposure.

8. Your choices and controls

  • Use StoryCubby without adding a parent name or personal email by remaining a guest.
  • Export synced account data from the in-app parent account screen.
  • Clear reading progress in the app.
  • Delete the account in the app or through the public web flow.
Open the account deletion page →

9. Changes to this policy

We may update this policy when StoryCubby's features or providers change. The date at the top will change, and material changes will be presented in the app or on this site when appropriate. Store disclosures must be updated to remain consistent with this policy and the released app.

10. Contact us

StoryCubby is developed and operated by Storry Cubby.

StoryCubby's privacy contact is help@storycubby.com. Parents and caregivers may write with privacy questions or requests.

For account deletion, use the web form so we can verify ownership safely.