Privacy Policy
Last updated: April 22, 2026
This Privacy Policy describes how Gaman Lab (" Company", " we", " us", or " our") collects, uses, and shares information when you use https://edustories.ai and https://app.edustories.ai(collectively, the " Services").
Please read this policy carefully. By using the Services, you agree to the practices described here.
1. Information We Collect
1.1 Information You Provide Directly
- Account data: name, email address, password when you register.
- Story content: when you create a social story you provide the name, age range, and gender of the child the story is written for, along with the situation, goal, interests, and characters. This information is used solely to generate the story and is stored in your account.
- Payment data: payment is processed by Stripe, Inc. We store only the last four digits of your card, card type, and your Stripe customer ID. We never receive or store your full card number.
- Communications: emails or messages you send to us.
1.2 Information Collected Automatically
- Log data: IP address, browser type and version, operating system, pages visited, timestamps, and session duration.
- Cookies and similar technologies: session cookies required for authentication (CSRF token, session ID) and, with your consent, analytics cookies from Google Analytics and Microsoft Clarity. See our Cookie Policy for details.
- Device data: device identifiers, screen resolution, language preferences.
1.3 Information from Third Parties
We may receive limited information from payment processors (Stripe) confirming the status of a transaction.
2. How We Use Your Information
| Purpose | Legal basis (EU/UK GDPR) |
|---|---|
| Provide and operate the Services (account management, story generation, payment processing) | Performance of a contract |
| Send transactional emails (order confirmations, payment failures) | Performance of a contract |
| Send newsletter and marketing emails (only if you opted in) | Consent |
| Analyse usage and improve the Services (Google Analytics, Microsoft Clarity — after consent) | Consent |
| Prevent fraud and abuse | Legitimate interests |
| Comply with legal obligations | Legal obligation |
3. Data About Children
EduStories is designed for use by adults — parents, educators, therapists, and other professionals — who create social stories intended for children or individuals with special educational needs. Registered users must be 18 years of age or older.
When you use the story-creation tool, you may provide information about a child (such as a first name, age range, gender, and personal situation). This information is processed solely to generate the requested story and is stored in your account under your control. You are responsible for ensuring that you have the appropriate authority or parental/guardian consent to submit information about any individual, particularly minors.
We do not knowingly register users under the age of 18. If we become aware that a minor has created an account, we will delete it promptly.
4. AI-Generated Content
Story text and images are generated by artificial intelligence. We use third-party AI models accessed via Replicate(replicate.com). When you create a story, the inputs you provide (situation, goal, characters, etc.) are sent to Replicate's API and processed by these models.
Replicate's privacy policy is available at replicate.com/privacy.
AI outputs may contain inaccuracies, hallucinations, or inappropriate content. Stories generated by EduStories are not a substitute for professional medical, therapeutic, psychological, or educational advice.
5. How We Share Your Information
We do not sell your personal data. We share information only in the following circumstances:
- Stripe – for payment processing. stripe.com/privacy
- Replicate – for AI story and image generation, as described in Section 4. replicate.com/privacy
- Mailchimp (Intuit) – for newsletter delivery, only if you have opted in. mailchimp.com/legal/privacy
- Google Analytics – for usage analytics, only with your cookie consent. policies.google.com/privacy
- Microsoft Clarity – for session recording and heatmaps, only with your cookie consent. privacy.microsoft.com
- Legal requirements: if required by law, court order, or governmental authority.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to the successor honouring this policy.
6. Data Retention
We retain your account data for as long as your account is active. When you delete your account, your personal data and stories are permanently deleted from our active databases. Backups may retain data for a limited additional period before being overwritten. Data shared with third-party processors (Stripe, Mailchimp) is also removed as part of the deletion process.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the data we hold about you.
- Rectification: correct inaccurate data.
- Erasure ("right to be forgotten"): request deletion of your data. You can delete your account directly from your profile settings.
- Portability: receive your data in a machine-readable format. Contact us at info@edustories.ai to request a data export.
- Restriction: ask us to limit processing while a dispute is resolved.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: you can withdraw consent for analytics cookies at any time via the cookie banner. You can unsubscribe from the newsletter at any time via the link in any email or from your profile settings.
To exercise any of these rights, contact us at info@edustories.ai. EU/UK users may also lodge a complaint with their local data protection authority.
8. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (Stripe, Replicate, Google, Mailchimp). These transfers are made under appropriate safeguards, including Standard Contractual Clauses approved by the European Commission.
9. Security
We implement industry-standard security measures including HTTPS encryption, hashed passwords, and access controls. No method of transmission over the Internet is 100% secure; we cannot guarantee absolute security.
10. Cookies
We use cookies and similar tracking technologies. For detailed information, please see our Cookie Policy.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by posting the updated policy with a new "Last updated" date. Continued use of the Services after changes constitutes acceptance.
12. Contact Us
Gaman Lab
Mgarr, MGR1021, Malta
Email: info@edustories.ai
