The fine print, made readable
Privacy Policy
This policy explains what personal data BooklyBot collects, why we collect it, who we share it with, and the rights you have over it. Our approach is data minimisation: we collect as little as possible by design. Plain-English summaries sit alongside the sections that matter most.
Last updated 3 July 2026
On this page
1Who we are
BooklyBot (“we”, “us”) turns a photo and a few choices into a personalised children’s storybook, delivered as a digital edition and/or a printed book. For the personal data described in this policy, BooklyBot is the data controller.
We operate from the United Kingdom and process personal data under the UK General Data Protection Regulation and the Data Protection Act 2018, and the EU GDPR where it applies. Our founder acts as our data protection lead and can be contacted using the details at the end of this policy.
2What we collect — and what we don’t
Account and orders. When you create an account we collect your email address. When you order a printed book we collect the recipient name and delivery address you enter at checkout. Payment is handled entirely by Stripe, a PCI-DSS Level 1 certified processor — your card details never reach our servers and we cannot see or store them.
Book details. To personalize a story we collect what you choose to enter: the child’s first name, a reading-age setting, and the interests, themes, characters and story choices you make. We ask for first names only — surnames are never requested and never appear in a book.
Your library. We store the finished books you create — their text and illustrations — so you can read, edit, download and reprint them from your library.
Technical data. We automatically process limited technical information, such as IP address, browser and device type, to keep the service secure, prevent fraud and abuse, and make sure pages work. Analytics runs only with your consent — see “Cookies and analytics” below.
What we deliberately don’t hold: uploaded photos (never stored — see the next section), payment card details, the child’s surname or date of birth, any special-category data, and no behavioural or advertising profile on you or your child.
3Photos of your child
A photo is what makes the book personal — and no uploaded photo is ever stored by BooklyBot. When you upload one, it is transmitted over an encrypted connection directly to our AI image provider solely to generate your child’s illustrated character. It is never persisted in any BooklyBot data store: the source photo exists only for the moment it takes to create the illustration.
We only use AI providers and models whose terms prohibit both retaining the data we send and using it to train AI models, and our primary image provider is independently audited to SOC 2 Type 2, ISO/IEC 27001:2022 and ISO/IEC 27701:2019.
By design, the result is always a stylised illustration — never a photo-realistic likeness — so the finished book evokes your child without reproducing an identifiable photographic image of them.
4How and why we use it
We use personal data only to run BooklyBot:
- To generate, illustrate and store the personalised books you create.
- To take payment and have your printed books produced and fulfilled.
- To deliver printed books to the recipient and address you provide.
- To send order confirmations, delivery updates and essential account emails.
- To answer your messages and put things right when something goes wrong.
- To keep the service secure and to detect and prevent fraud and abuse.
- To understand, in aggregate, how the service is used so we can improve it.
Our legal bases under UK GDPR are: performance of a contract (creating your books, taking payment, fulfilling orders); our legitimate interests (securing the service, preventing fraud, improving how it works); your consent (marketing emails and analytics cookies); and legal obligation (keeping the records tax and accounting law requires).
We send marketing emails only if you opt in, and every one has a one-click unsubscribe. Transactional emails — order confirmations, delivery updates, account notices — are part of providing the service itself.
6International transfers
Some of our processors are based in the United States. When personal data leaves the UK or the European Economic Area, we rely on recognised safeguards: the UK–US Data Bridge and the EU–US Data Privacy Framework where the provider is certified, or the UK International Data Transfer Addendum and the EU Standard Contractual Clauses otherwise.
Whichever mechanism applies, every processor remains contractually bound to protect your data to the standard described in this policy.
8How long we keep it
Your account and the books in your library are kept for as long as your account is open, so you can revisit, edit and reprint them. Uploaded photos are never retained at all — see “Photos of your child” above.
Order and payment records are kept for as long as tax and accounting law requires — typically six years. When you delete your account we delete your personal data, except the records we are legally required to keep.
9How we protect it
Data is encrypted in transit and at rest, and access is restricted to what operating the service requires. The most sensitive data never rests on our systems at all: photos are never stored, and payments are handled end to end by Stripe.
Our best protection is minimisation — the less we hold, the less there is to protect. No system can be guaranteed 100% secure, but if a breach ever affects your personal data we will notify you, and the ICO, as UK GDPR requires.
10Children’s privacy
Because our books feature children, we treat child safety as a first-order design constraint. We have completed a Data Protection Impact Assessment covering the processing of children’s data, and we align our design with the ICO’s Age Appropriate Design Code (the Children’s Code). The details about a child that appear in a book are provided by the account holder, who is responsible for having the right to share them.
We also deliberately limit what any book can contain about a child: first names only, no photo-realistic depictions, and mandatory stylization of every character — personal enough to delight, never enough to identify.
11Your rights
Under UK GDPR (and the EU GDPR where it applies), you have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Have inaccurate or incomplete data corrected.
- Have your personal data deleted.
- Receive your data in a portable, machine-readable format.
- Object to, or restrict, certain processing of your data.
- Withdraw consent at any time — for example, unsubscribe from marketing or change your cookie choices.
You can exercise most of these directly from your account. For anything else, email us using the details below — exercising your rights is free, and we will respond within one month.
If you believe we have mishandled your data, you also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority — though we would welcome the chance to put it right first.
12Changes to this policy
If we make material changes to this policy, we will update the date at the top and, where a change meaningfully affects you, tell you by email before it takes effect. Earlier versions are available on request.
13Contact us
For any privacy question, or to exercise any of your rights, contact our data protection lead at support@booklybot.com.
Still have a question?
If anything here is unclear, ask us in plain English. A real person answers.
Sorted. — the robot