Hello Storybook
✦ The fine print, kindly

Privacy Policy

Your family's photos and details are precious. Here is exactly what we collect, why, and how we protect it — in plain language, no fine-print games.

Last updated July 2026

Hello Storybook is a service operated by Renji Labs, Inc. (“we,” “us,” “our”), located at 7775 Walton Pkwy, Ste. 100, New Albany, OH 43054, USA. We make personalized, illustrated children's books, and we know that trusting us with a photo of your child is a big deal — so we have written this policy to be readable by an actual human being.

This policy covers hellostorybook.com and the books and services we provide, and explains how Renji Labs, Inc. acts as the controller of the personal information you share with us and the choices available to you. Where consent is required, merely using the site is not consent; we ask through our analytics settings.

What we collect

We collect only what we need to make your book and get it to you:

  • Account & contact details — your name and email address so we can send your preview, receipt, and order updates.
  • Reference photos — one or more photos you choose to upload of the child and, if you add them, family members, friends, pets, or treasured companions, used to create consistent storybook characters.
  • Story details — the child's first name, age, pronouns, and the gentle lesson you'd like the story to teach.
  • Order & shipping information — the format you choose and, for printed books, the delivery address we pass to our print partner.
  • Payment information — processed securely by Stripe. We never see or store your full card number.
  • Usage & diagnostics — sanitized public pages or route templates, referring source and campaign tags, browser and device information, approximate region, clicks and funnel steps, selected product and ecommerce fields, Core Web Vitals and other performance timings, sanitized error diagnostics, and pseudonymous browser or session identifiers. Where enabled, this also includes protected session replay described below.

How we use it

We use your information to:

  • Create your child's personalized book and illustrations.
  • Deliver your finished digital book and keep you updated on your order.
  • Process your order, take payment, and — for printed books — manufacture and ship it.
  • Send transactional emails: order confirmations, shipping updates, and book delivery links.
  • Provide support, measure search and campaign performance, understand and improve the creation and checkout funnels, monitor Core Web Vitals, diagnose errors and confusing experiences, and improve our stories, art quality, and site.

We do not sell your personal information. We do not use your photos to train AI models. We do not send marketing email unless you ask us to.

Automated processing & AI

AI models generate your book's story text and illustrations from the details you provide. That is content generation, not a decision that produces legal or similarly significant effects about you — so the GDPR's rules on automated decision-making (Article 22) are not engaged.

A human reviews flagged books before print fulfilment, and you can always request a human review of any generated book — or ask for a revision — by contacting support.

Your child's photo

This is the part parents care about most, so we keep it simple:

  • Reference photos are used only to create and quality-check your book's artwork — nothing else.
  • Photos are permanently deleted from our systems 30 days after your book is delivered — the same window as our happiness guarantee — and never later than 120 days after upload. If we never deliver your book — a cancelled or refunded order, or one we couldn't complete — we delete your photo 30 days after upload.
  • Photos are never sold, shared with advertisers, posted publicly, or used to train any AI model.
  • You can ask us to delete your photo (and everything else) at any time — see “Your rights” below.

Our full, dedicated explanation lives on the Photo & AI Policy page.

Analytics, search performance & session replay

We use Google Analytics 4, Google Search Console, and PostHog to understand how visitors find Hello Storybook, which public pages and creation steps are useful, where people leave the funnel, whether purchases complete, how the site performs for real visitors, and when technical errors occur:

  • Google Analytics 4 measures traffic acquisition and a limited ecommerce funnel using sanitized page or route information, referrers and campaign tags, approximate location, browser and device information, product format, order value, currency, and a transaction identifier. It uses first-party analytics cookies when analytics storage is allowed.
  • Google Search Console reports how our public pages appear in Google Search, including search queries, impressions, clicks, rankings, indexing, and Core Web Vitals. Adding Search Console does not add a separate tracking script or cookie to our site.
  • PostHog provides product analytics, Core Web Vitals, sanitized client-error reporting, and session replay using pseudonymous browser and session identifiers. We configure PostHog not to retain raw IP addresses after any permitted approximate-location processing.
  • PostHog replay reconstructs navigation, clicks, scrolling, and page layout; it is configured to mask every form input, block uploaded photos, generated portraits, book pages and private text, strip private query values and route tokens, exclude private reader, order, review-share and unsubscribe routes, and not capture network request or response bodies, console logs, canvas content, or cross-origin frames.

We do not intentionally send Google Analytics or PostHog a child's or family member's name, age, photo, appearance, story details, dedication, gift message, an adult's email or shipping address, payment-card information, typed form contents, uploaded or generated media, or private book, order, checkout, review, gift-card, or unsubscribe tokens.

For visitors in the European Economic Area, United Kingdom, and Switzerland, analytics storage and PostHog capture begin only after acceptance. If you decline — or before you have made a choice — Google Analytics is not loaded at all and Google receives nothing, and PostHog capture stays off. Elsewhere these tools operate as permitted by law, and anyone can change the choice at any time through Cookie settings.

Our legal bases are performing our contract with you (creating and delivering an order), your consent where required (including non-essential analytics and marketing), our legitimate interests where permitted (measuring and improving the service, security, and error diagnosis), and compliance with legal obligations.

Who we share data with

We work with a small set of trusted providers, and we share only the minimum each one needs to do its job:

  • Stripe — payment processing. Stripe receives your payment details directly; we do not receive or store your full card number.
  • Gelato — print-on-demand manufacturing and shipping for new softcover and hardcover orders. Gelato receives the print-ready book files, recipient information, and shipping address needed to fulfill the order. Lulu is retained only to reconcile and support legacy orders previously routed to it.
  • Supabase and Railway — database, file storage, application hosting, and background processing for customer, order, book, and operational records.
  • Cloudflare — content delivery, security, abuse prevention, and coarse country detection used to show the appropriate analytics choice.
  • Brevo — transactional order email and, only when you opt in, newsletter delivery and subscriber management.
  • Anthropic, Google Gemini, and OpenAI — depending on the configured generation provider, the story, reference photos, prompts, or generated artwork needed to create and quality-check your book.
  • Google LLC — Google Analytics 4 and Google Search Console for acquisition, ecommerce, public-search, indexing, and performance reporting.
  • PostHog Inc. (US Cloud) — product analytics, Core Web Vitals, sanitized error tracking, and protected session replay.
  • Sentry (Functional Software, Inc.) — error diagnostics. It receives technical error reports that we scrub of personal content first; see “Error diagnostics” below.

We may also disclose information if required by law, to comply with legal process, or to protect the rights, property, and safety of our customers, the public, or our company — including in connection with a merger, acquisition, financing, or sale of assets, in which case your information may be transferred as part of that transaction. We never sell your data.

Error diagnostics

When something goes wrong — a page fails to load, or a book fails to generate — our software sends a diagnostic report so we can find the fault and fix it. Those reports are processed for us by Sentry (Functional Software, Inc.). They are scrubbed of personal content on our own servers, before they are sent, rather than after they arrive.

Before any report leaves our systems, we:

  • Remove your child's name and the names of anyone else in the story from the labelled details in every report — and, where our software knows those names (while we build your book, and in your own browser), from the wording of the error message too.
  • Remove email addresses, order links, and the private link to your finished book.
  • Throw the entire report away, unsent, if it contains a photo or any other image data.
  • Never include session recordings, anything you typed into a form, cookies, or the instructions we send to our AI providers.

What is left is a stack trace, an error message, and internal reference numbers — enough to fix the bug, not enough to identify you or your child. Sentry acts as our processor under its standard terms, stores these reports on infrastructure in the United States, and deletes them automatically after 90 days.

Where your data is processed

Renji Labs, Inc. is based in the United States, and the providers who help us run the service (such as our payment, print, hosting, and email partners) may process your information in the United States or other countries. Data-protection laws in those countries may differ from those where you live.

Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on recognized safeguards. Stripe, Google, Cloudflare, and Sentry are certified under the EU-U.S. Data Privacy Framework, including the UK Extension and the Swiss-U.S. Data Privacy Framework. Our other U.S. providers (Supabase, Railway, OpenAI, and Anthropic) process personal information under executed data-processing agreements incorporating the European Commission's Standard Contractual Clauses, together with the UK Addendum and the Swiss adaptations, and we maintain transfer impact assessments for these transfers. Your information is processed in the United States under these safeguards.

Our EU & UK representative

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:

  • European Union (EU)
  • United Kingdom (UK)

Prighter gives you an easy way to exercise your privacy-related rights (for example, requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit: https://app.prighter.com/portal/renjilabs

Children's privacy

Hello Storybook is a service for parents, grandparents, and gift-givers — our customers are adults. The site is not directed to children, and we do not knowingly collect personal information directly from children under 13.

The photos and details you provide may be about a child but are submitted by you, the adult customer, with the authority to do so. If you believe a child has provided us information directly, contact us and we will delete it.

To be explicit about the child data we hold: it is the child's first name, age, pronouns, appearance details, and the reference photos you upload. It is provided by you, the adult customer, under your parental or guardian authority, and it is used solely to create the book you ordered. All rights over that data — access, deletion, and the rest — are exercised by the parent or guardian through the channels described in “Your rights & choices.”

How long we keep things

  • Uploaded reference photos: kept until 30 days after your book is delivered, so we can still revise or reprint it — and never longer than 120 days from upload, whichever comes first. If your book is never delivered — a cancelled or refunded order, or one we couldn't complete — we delete the photo 30 days after upload.
  • Your finished book files: kept so you can re-download your purchase, until you ask us to remove them.
  • Order records: retained for 7 years to meet accounting, tax, and warranty obligations.
  • Google Analytics user-level event data: up to 14 months; aggregated reports may remain available longer.
  • Google Search Console search-performance data: up to 16 months under Google's current service retention.
  • PostHog session replays: retained for up to 30 days. PostHog product-analytics events and sanitized client-error events: our current PostHog plan specifies an 84-month (7-year) event-retention period. Technical enforcement of that limit is not currently active for our project, so we cannot promise automatic deletion on the exact 84-month date. We may delete this data sooner, will act on valid deletion requests as required by law, and may retain aggregated information that no longer identifies an individual for longer.

Your rights & choices

Wherever you live, you can ask us to show you the data we hold about you, correct it, or delete it, and you can withdraw any consent you've given at any time. You can change analytics choices through Cookie settings. If you are in the EEA, UK, or California, you have specific rights under laws like the GDPR and CCPA — including access, deletion, portability, the right to restrict or object to certain processing, and the right not to be discriminated against for exercising them.

To make any request, email hello@hellostorybook.com. Requests are free of charge. We verify each request against the email address on your order or account, and we answer within one month — where the law allows a longer period for a complex request, we will tell you so and explain why. You can also route any request through our EU & UK representative's portal (see “Our EU & UK representative” above). For users in Canada, the person responsible for the protection of personal information is Renji Labs' Chief Executive Officer, reachable at hello@hellostorybook.com. If you are in the EEA or UK and believe we have not handled your data properly, you also have the right to lodge a complaint with your local data-protection supervisory authority — though we'd appreciate the chance to put things right first.

Security

We protect your information with encryption in transit, access controls, and reputable infrastructure providers. Payment data is handled by Stripe and never touches our servers. No system is perfectly secure, but we treat your family's data with the care we'd want for our own.

Cookies

We use cookies and similar browser storage for the service to function and, when allowed, for analytics:

  • Essential local or session storage remembers the in-progress creation draft and photo handoff, anonymous preview and draft identifiers, consent choice, and purchase-event deduplication. It does not keep a payment-card number. We re-ask for your consent choice at least every 12 months. A necessary first-party cookie (NEXT_LOCALE) remembers the language you pick in the site's language selector for 1 year, so we can keep showing you the site in it. Essential local storage also remembers how you first arrived at the site — the address of the page that referred you and any campaign tags in the link, kept for up to 90 days — so that when you place an order we can record where that order came from.
  • Google Analytics uses first-party cookies such as _ga and _ga_<stream-id>, which last up to 2 years, to distinguish pseudonymous visitors and sessions when analytics storage is granted; the analytics data they help collect is retained for 14 months, and denied visitors do not receive those analytics cookies.
  • PostHog uses pseudonymous browser and session identifiers in browser storage, kept for about 1 year, for permitted product analytics and protected replay; it is opted out when a visitor in a consent region declines analytics.

Use Cookie settings on the site to accept, decline, or change non-essential analytics at any time. You can also clear or block cookies and browser storage through your browser, although clearing essential storage may reset an unfinished creation.

Changes & contact

We may update this policy as the product grows. When we make a material change, we'll update the date at the top and, where appropriate, let you know.

Questions about your privacy? Email us any time at hello@hellostorybook.com, or write to us at Renji Labs, Inc., 7775 Walton Pkwy, Ste. 100, New Albany, OH 43054, USA.

Questions about this policy? Contact us.

Make their book →
Privacy Policy · Hello Storybook