We are committed to protecting your privacy and your children's information. This policy explains how we collect, use, and safeguard your data.
No Data Selling
We never sell your personal information
Child-Safe
COPPA compliant, parental consent required
Data Portability
Download your data anytime
Right to Delete
Delete your account and data anytime
We strictly adhere to international privacy laws to ensure your data remains protected, no matter where you are.
Americas
USA, Brazil, Canada, Argentina
Europe
EU, UK, Switzerland, Turkey, Russia
Asia-Pacific
China, India, Japan, Singapore, Aus...
Middle East
UAE, Israel, GCC Region
Africa
South Africa
Children's Privacy
Global child safety standards
At Nanhe Kissey, we take the privacy of our users, especially children, very seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile application, and services (collectively, the "Service").
By using our Service, you consent to the data practices described in this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
Important: Our Service is designed for parents and guardians to use on behalf of their children. We require parental consent before collecting any child information.
The data controller responsible for your personal information is:
Nanhe Kissey
Plot#10, SK-3, Indirapuram, Ghaziabad, UP-201014, India
privacy@nanhekissey.com
+91-120-4101115
+91-120-4295665
For GDPR purposes, we act as the "Data Controller" for personal data we collect. For India DPDP Act purposes, we are the "Data Fiduciary."
When you create an account, we collect:
For story personalization, we collect (provided by parents only):
Face Detection:: When you upload a photo, face detection runs entirely in your browser (face-api.js) to locate the face and crop to it. No facial recognition data, face template, or measurement is sent to or stored on our servers. Exactly one image is uploaded: the cropped face when detection succeeds, or โ when a face cannot be detected automatically, for example on an unclear photo or on a device without enough free memory โ the single photo you selected, and we tell you on the upload screen that no face was found so you can choose a clearer photo instead. We never upload the cropped face and the full photograph together. Whichever image is uploaded is checked on our servers and rejected if it is blank, too dark, blurred, or an illustration rather than a photograph.
For security purposes, our mobile app collects:
This data is used solely to verify legitimate app installations and prevent fraud. No personal information is collected through these systems.
webMobileAppsStore
Local data remains on your device and can be cleared through your browser or app settings.
toEnhanceExperience
weUseInfoFor
We Never:: Sell your personal data, use children's data for advertising, or share data with third parties for their marketing purposes.
Children's Privacy (COPPA Compliance)
parentsHaveRight
toExerciseRights
childDataProcessed
OpenAI (GPT-5.4 Mini)
Story narrative generation using child's name, age, gender, and selected themes. We use store:false to prevent training on child data.
Google Gemini
AI for story text (all tiers) and image generation (Nano Banana). Receives child's name, age, gender, story preferences, and the child's uploaded photo to create face-consistent illustrations.
Anthropic Claude
Premium tier creative writing. Receives child's name, age, gender for story personalization.
DeepInfra (Llama)
Cost-effective AI models for story generation fallback. Receives same personalization data as other providers.
fal.ai (Nano Banana, FLUX)
Image generation (premium tier and fallbacks) with face consistency. May receive character descriptions and the child's reference photo for illustration.
Replicate
Fallback image generation. Receives same data as fal.ai for illustration continuity.
Supabase
Secure cloud database and storage for stories, images, and account data with encryption at rest.
AI Content Moderation
Automated content safety checks to ensure all generated stories are age-appropriate and safe.
We do not permit these providers to use child data to train their models, and we select them based on their privacy and security practices. They may process child data only to deliver the features described above.
We may share your information in limited circumstances:
weDoNotSell weDoNotSellDesc
We work with the following trusted third-party service providers:
| Provider | Purpose | Data Shared |
|---|---|---|
| OpenAI (GPT-5.4 Mini) | AI story generation (standard/premium) | Name, age, gender, preferences |
| Google Gemini | AI story text (all tiers) + image generation (Nano Banana) | Name, age, gender, preferences, child photo |
| Anthropic Claude | AI story generation (premium) | Name, age, gender, preferences |
| DeepInfra (Llama) | AI story generation (fallback) | Name, age, gender, physical description |
| fal.ai (Nano Banana, FLUX) | Image generation (premium + fallbacks) | Character descriptions, photo references |
| Replicate | Fallback image generation | Character descriptions, photo references |
| Supabase | Database, auth, storage | All account data (encrypted) |
| Razorpay | Payment processing (India) | Payment details only |
| PayPal | Payment processing (Global) | Payment details only |
| Resend | Transactional emails | Email address, name |
| Google Analytics | Website analytics | Anonymized usage data |
| Apple (App Attest) | iOS device verification | Device tokens only |
| Google (Play Integrity) | Android device verification | Device tokens only |
| Vercel | Website hosting | Request logs (anonymized) |
| Hetzner | API server hosting (Germany) | Request processing |
All service providers are bound by data processing agreements and are required to protect your data in accordance with applicable privacy laws.
dataRetentionIntro
| Data Type | Retention Period |
|---|---|
| Account Data | While active; deleted after a 30-day grace period following your request |
| Story Data | While account active; deletable anytime |
| Child Information | Child profile details are kept only while needed and deleted on request. |
| Uploaded Child Photos | Deleted as soon as you accept the illustrated character generated from the image: the stored file is removed and our reference to it is cleared. An image whose character is never accepted is deleted automatically by a background sweep after 24 hours without activity on that character. Deleting a child profile also removes any uploaded image still held for it. The illustrated avatar and the finished story remain with you unless you delete them. |
| Payment Records | 7 years (legal/tax compliance) |
| Analytics Data | Retained per analytics provider settings; account-linked analytics events are deleted with your account |
To request deletion, use the "Delete Account" option in your profile settings or email privacy@nanhekissey.com.
dataSecurityIntro
Encryption
TLS/SSL for data in transit, AES-256 at rest
Access Controls
Role-based access, authentication required
Monitoring
Security event logging and monitoring
Secure Infrastructure
Cloud hosting with enterprise security
While we implement industry-standard security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
You have the following rights regarding your personal data:
How to exercise your rights: Go to My Profile โ Privacy & Data, or email privacy@nanhekissey.com. We respond within 30 days.
We comply with privacy regulations across 28+ countries and regions. Below are your rights based on your location.
USA - COPPA & CCPA/CPRA
Brazil - LGPD
Canada - PIPEDA
Argentina - PDPL
EU/EEA - GDPR & UK GDPR
Turkey - KVKK
Russia - FZ-152
Switzerland - nFADP
China - PIPL
Access, correction, deletion, portability, consent withdrawal rights
India - DPDP 2023
Access, correction, erasure, grievance redressal, nomination rights
Grievance Officer: Nanhe Kissey Privacy Team โ privacy@nanhekissey.com | Acknowledgment within 48 hours, resolution within 30 days
Japan - APPI
Disclosure, correction, cessation of use rights
Singapore - PDPA
Access, correction, consent withdrawal rights
South Korea - PIPA
Access, correction, deletion, suspension rights
Australia - Privacy Act
Access, correction, complaint rights under APPs
New Zealand - Privacy Act
Access, correction, complaint rights under IPPs
Thailand - PDPA
Access, portability, erasure, objection rights
Malaysia - PDPA
Access, correction, consent withdrawal rights
Indonesia - PDP Law
Access, correction, deletion, portability rights
Philippines - DPA
Access, correction, erasure, objection rights
Taiwan - PDPA
Access, correction, cessation, deletion rights
Vietnam - Cybersecurity
Consent-based processing; data processed on our cloud infrastructure outside Vietnam (not localized in-country)
Hong Kong - PDPO
Access, correction rights under DPPs
Pakistan - PDPA
Access, correction, deletion rights
UAE - Federal Data Protection
Access, correction, deletion, objection rights. Consent-based processing.
Israel - Privacy Protection Law
Access, correction, objection rights. Registered database compliance.
GCC Region - Arabic GDPR
Regional privacy standards with Arabic language support.
South Africa - POPIA
Access, correction, deletion, objection rights. Right to lodge complaints with Information Regulator.
Exercise Your Rights: Contact us at privacy@nanhekissey.com with your request. We respond within the timeframe required by your jurisdiction (typically 30-45 days).
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
When we transfer data internationally, we implement appropriate safeguards:
We ensure that your data receives the same level of protection as required in your jurisdiction.
We may update this Privacy Policy from time to time. When we make changes:
We encourage you to review this policy periodically. Previous versions are available upon request.
If you have questions about this Privacy Policy or our data practices, please contact us:
Response Times: We aim to respond to all privacy inquiries within 30 days (45 days for CCPA requests).
Last Updated: 6th September 2026 | Version 1.0
This Privacy Policy is effective as of the date stated above and will remain in effect except with respect to any changes in its provisions in the future.