Privacy Policy

Storybook, by Fabricio Dujardin · Last updated 31 August 2026

Short version. Your records are encrypted on your phone and stay there unless you act. If you subscribe to sync, our server carries copies it is mathematically unable to read. We run no analytics and no advertising, and you can delete everything — from the app, or by emailing dujar.coding@gmail.com.

This policy covers the Storybook mobile app (the "app"), the optional sync service the app can talk to (the "service"), and this website. It describes what information each of them holds, why, and for how long.

1. What stays on your device

Everything you record — entries, milestones, photos, vaccination records, growth measurements, reminders — is stored on your phone in an encrypted database (SQLCipher, AES-256). Photos are encrypted individually. The encryption keys are generated on your device and held in its secure hardware (the iOS Keychain or Android Keystore); they never leave the device and we never receive them. Backups of your device made through iCloud or Google's backup do not contain usable copies of your keys.

The app contains no analytics SDK, no advertising SDK, no trackers, and no crash reporting that sends anything off your device. Diagnostic logs the app writes stay in the app's own storage.

2. What the sync service stores, if you enable it

Sync ("Family") is optional and paid. If you turn it on, your phone sends encrypted batches of changes to our service, and your other paired devices pull them. The service is built so that it can carry your data but cannot read it. It stores:

WhatWhyReadable by us?
A random library id and creation dateOne library is one family's encrypted namespaceYes — it is just an id
Device records: a random id, the SHA-256 hash of a random auth token, a label you chose (e.g. "Sarah's iPhone"), role, datesDeciding which devices may push or pullThe label and dates; the token itself is never stored
Encrypted batches (ciphertext) with size and timestampsCarrying changes between your devicesNo — encrypted on your device with a key we never see
Subscription entitlement: product, state and expiry, as reported by Google Play or the App StoreKnowing the subscription is liveYes

The service holds no names of children, no entries, no photos, no notes, no email addresses, and no key material. Device authentication tokens are random 32-byte values shown once on the device that creates them; only their hashes are stored.

3. Payments and subscriptions

Subscriptions are sold by Google Play and the App Store. They process your payment; we never see your card details. To verify a subscription the service calls Google's and Apple's own APIs with the purchase token your device obtained; from that it learns the product, its state, and its expiry. Purchase records are also held by Google and Apple under their own policies.

4. Share links and exported files

When you share a slice of a story — as a link or as a .storybook file — the content is encrypted before it leaves your phone, and the passphrase or link needed to read it is given to you, not to us. A link's decryption key travels in the URL fragment (the part after #), which browsers do not send to servers. Our service stores the encrypted blob, an expiry, and a use counter — never the key.

Be aware of what encryption cannot do: anyone who has the link, the file, or the passphrase can read, keep, copy, or forward what they received. Expiry and one-time limits stop the link from working; they cannot un-see what was seen.

5. Children's data

Storybook is a tool parents use to record information about their children. The app is not directed at children and collects nothing from children. Where a parent records a child's information, the parent controls it: it is processed on the parent's instruction, under the parent's lock and key (literally — see section 1), and deleted when the parent deletes it. If you enable sync, that processing happens on behalf of the parent, as described in section 2.

6. This website

These pages are static HTML. They load no scripts, no fonts, no trackers, and set no cookies, so this site logs nothing about you beyond what any web server necessarily records to answer the request.

7. Retention and deletion

Deleting a library from the sync service does not touch the copies on your phones, and does not cancel a subscription by itself.

8. Security

Data in transit between your phone and the service travels over TLS; the payload inside it is additionally end-to-end encrypted with AES-256-GCM, with keys derived on your device and never transmitted. There is no password we could lose, and nothing we could hand over that would read your records — by design, that is also why we cannot recover them for you if you lose every device and the recovery kit.

9. Your rights and choices

Depending on where you live you may have rights to access, correct, export, or delete personal data, and to object to processing. Because your records are end-to-end encrypted and held on your own device, the app itself is usually the place to exercise these: you can read, export, and delete everything directly. For anything held by the service (section 2), contact dujar.coding@gmail.com and we will help.

We do not sell personal data, and we do not use it for advertising or profiling — there is nothing to profile with.

10. Changes

If this policy changes materially we will update this page and, for changes that affect the app's behaviour, the app itself.

11. Contact

Fabricio Dujardin · dujar.coding@gmail.com · Support · Request deletion

← Storybook