Privacy policy
Last updated: 6 September 2026
1. What data we collect
- Your email address, through the site's own sign-in (we do not create or store passwords).
- The protagonist's name and approximate age, and the language and theme chosen for the story.
- The photo you upload to create the story.
- The generated story text and illustrations, and optionally a coloured version and a narrated audio track.
- If you rate a story when you finish it: the score from 1 to 5 and, if you write one, your comment. And only if you tick the box to publish it, the name you want it to appear under.
- If you buy a story or a gift voucher, transaction data handled by Stripe: we never see or store your card number.
2. The legal basis for processing your data
The GDPR requires every processing activity to have a legal basis, and requires us to tell you which one. These are ours:
- Performance of a contract (art. 6(1)(b)): your email address, your account, and creating, generating and storing the story you asked for. Without this data there is no service to provide.
- Consent (art. 6(1)(a)): the photo and the protagonist's details (name and age). We ask for it expressly on the first step of the wizard, with a box that is never pre-ticked, in which you confirm that you are the parent or legal guardian of the child or children whose data you provide, or that you act with the authorisation of whoever holds parental responsibility or guardianship over them, and we keep a record of when you ticked it, with which wording and under which version of this policy.
- Consent (art. 6(1)(a)), also, for usage measurement: the random identifier and the source campaign described in section 5 are only stored in your browser if you accept the question we ask when you arrive (art. 22.2 of Spain's LSSI), and the usage data they generate is processed on that same answer. We keep a record of your acceptance (when you gave it and under which version of this policy), tied only to that random identifier and never to your email. You can change it at any time from the page footer or from section 5.
- Legitimate interest (art. 6(1)(f)), for the review you leave us privately: when you finish a story you can rate it from 1 to 5 and write a comment. We process it for one purpose only — to know whether the product is worth it and where it falls short — and only we read it. We have an interest in improving it, you tell us voluntarily, and we do not combine it with anything else or use it to profile you, so we consider that interest does not override your rights. You can object to this processing at any time (section 8), and delete it yourself by deleting the story.
- Consent (art. 6(1)(a)), additionally and separately, to publish that review: only if you tick the separate, never pre-ticked box to publish it on the site do we store the name you want it to appear under, together with the record of when you ticked it, under which wording, in which language you read it, and under which version of this policy. Without that box we store no name at all. You can withdraw the permission yourself, from the story itself, with the "Withdraw permission to publish it" button: it stops being published and we delete the name. Withdrawal does not affect the lawfulness of what was published before it.
- Legal obligation (art. 6(1)(c)): billing records, which tax and accounting law requires us to keep for its own retention periods.
- Legitimate interest (art. 6(1)(f)): keeping the service secure — protecting it against attacks and automated traffic, and being able to investigate an incident — with the strictly necessary technical cookies described in section 5 and the server logs essential for that.
While the story is being created you can withdraw consent for the photo with the «Withdraw consent and cancel» button on that same screen: it stops any further processing based on that consent and deletes the pending copy of the photo. Withdrawal does not affect the lawfulness of processing already carried out before it. Once generation has finished the original photo is no longer kept (section 3), so there is no processing left to withdraw; deleting the story from "My stories" is a different right — erasure of the stored result — and you can exercise it whenever you like.
3. What we do with the photo
The photo is used only to generate the story. It is sent to the two AI providers listed in section 4: to the model that writes the story, so it can describe the protagonist recognisably, and to the one that draws the illustrations.
While generation is running we keep a copy in our storage (Cloudflare R2), solely so the process can be retried if it fails partway. That copy is deleted as soon as the story text has been written. If generation fails before reaching that point, the copy is deleted automatically within 24 hours at the latest. Closing your account deletes it immediately, along with the rest of your data.
What is saved in your library are the AI-generated illustrations (drawings inspired by the photo), not the photo itself. If you later create a continuation of a story, we use the already-generated illustration of the protagonist as the visual reference, not the original photo.
4. Who we share data with
To generate and provide the service, we share strictly the necessary data with:
- Anthropic (Claude), which writes the story text from your details and the photo.
- OpenAI, which generates the illustrations from your details and the photo.
- Cloudflare, which hosts this site and stores the service's data (database and illustrations).
- Google, through which you can sign in (we don't create or store passwords).
- Stripe, if you make a payment, to process it securely.
Anthropic and OpenAI receive the photo because it is essential to generate the story, and they process it as data processors. Each may retain the request for a limited time under its own API data-retention policy; in OpenAI's case the request is stored on their system because the illustrations are generated in the background and the result is retrieved afterwards. Under the terms of their APIs, this data is not used to train their models.
These providers are based, or run part of their infrastructure, outside the European Economic Area. Where that involves an international data transfer, it relies on the European Commission's standard contractual clauses or on the applicable adequacy framework.
We do not sell your data or use it for advertising purposes.
5. Cookies and storage in your browser
We use no advertising or third-party cookies. What the site keeps in your browser is this:
- Sign-in session cookies (set by Auth.js when you sign in with Google): necessary to keep you signed in and to protect the sign-in form. They last at most 30 days, or until you sign out.
- Your answers in the creation wizard, kept in the tab's memory for one hour so they are not lost if you need to sign in or come back from a payment. They never include the photo.
- Your answer to the measurement question (accept or reject), kept for 13 months so we do not ask you every time.
- Only if you accept measurement: a random identifier for your browser and the campaign you arrived from (the «utm» parameters in the address), kept for 13 months and not renewed on each visit. They tell us which steps of the process work and which campaigns bring visits. They contain neither your name nor your email, are not shared with third parties and are not used for advertising. The usage data they generate is kept on our servers for at most 25 months.
- Also only if you accept measurement: an identifier for the creation attempt, kept only in the tab's memory. It is deleted when you close the tab, when you open another story, when you start a new one, when a purchase completes, and if you reject or withdraw measurement. It tells us whether one attempt made it from start to finish without using the 13-month identifier for that. It contains neither your name, nor your email, nor anything from the story.
- Also only if you accept measurement: when you confirm a purchase we keep a local marker so the same purchase is not counted twice if you return to that screen. It is kept for the same 13-month period.
- Cloudflare, which hosts the site, may set strictly necessary technical cookies to protect it against attacks and automated traffic.
The first three are necessary for the site to work and need no consent. Measurement does: we ask when you arrive, and you can change your answer at any time from the page footer or with this button. Rejecting or withdrawing it deletes the identifier and campaign stored in your browser and removes from our servers the usage data collected under that answer; we keep only the record that you gave it and when you withdrew it, for at most 25 months after the last associated usage data. If our server cannot confirm the withdrawal at that moment, your browser temporarily keeps a technical copy of that identifier solely to retry the request, never to measure, and deletes it as soon as the withdrawal is confirmed.
6. Children
The story's protagonist may be a child, but the account and consent always belong to an adult. PageHero is not intended to be used directly by minors, and we do not collect data about children beyond the information (photo, name, age) that a responsible adult chooses to provide to create the story.
7. How long we keep your data
The original photo is not kept: it is deleted within the time frames in section 3. Stories are kept in your library until you decide to delete them, which you can do at any time from "My stories". When you close your account, your stories, their illustrations and audio, and your account data are permanently deleted. Billing records are kept for as long as tax and accounting law requires, and are handled by Stripe as data processor.
The reviews described in section 1 are kept for as long as the story they are about exists: if you delete that story from "My stories", its rating and comment go with it, and closing your account deletes them all, published or not. We do not set a separate period because a review of a story that no longer exists is of no use to us. Withdrawing the permission to publish does not delete the review: it deletes the name and stops publishing it.
The technical and security logs described in section 2 (which may include your email address, internal story or request identifiers and the reason an error occurred, never the photo or the story text) are kept by Cloudflare as part of the hosting for at most 7 days and are deleted automatically afterwards. They are only consulted to detect, investigate and resolve incidents.
8. Your rights
The data controller is established in Spain, so your data is processed under the GDPR wherever you live. You have the right to access, rectify, delete and port your data, to object to its processing and to request its restriction. Where the basis is consent, you also have the right to withdraw it at any time. You can exercise all of these by writing to hola@pagehero.app.
9. Security
We apply reasonable technical measures to protect your data, including encryption in transit and storage on managed infrastructure. No system is 100% secure; if we become aware of an incident affecting your data, we will notify you as required by applicable law.
10. Changes to this policy
We may update this policy from time to time. The last-updated date is shown at the top of this page.
11. Contact
The data controller is Rubén Amaro Parrado, tax id (NIF) 45545664Y, at Calle Camp de l'Oliver 112, 17401 Arbúcies (Girona), Spain. For any privacy question or to exercise your rights, contact us at hola@pagehero.app. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).