Privacy
Privacy policy
This policy explains how StoryLexi handles personal data across the website and the iOS and Android apps.
- Effective date
- 2026-08-12
- Privacy contact
- support@storylexi.com
- Arjan Zijderveld Holding B.V.
- Baan 34F-20, 3011 CB Rotterdam, Netherlands
- Registration number
- 60352043
Data we collect
We process account and profile details such as email address, display name, username, language and course preferences.
We store learning and community activity, including course plans, interests, optional about-me text, stories, flashcards, answers, progress, XP, follows, reports, listening activity and public profile information.
We process purchase history, sessions, short-lived one-time-code security records, essential cookie and local-storage preferences, push tokens, installation identifiers, IP addresses in security and web-server records, and an optional photo when you ask for a photo-inspired story.
Why we use data
We use data to create and secure your account, provide and personalize language learning, generate stories and media, maintain progress, enable community features, send requested service messages and push notifications, process purchases, prevent abuse and operate and improve StoryLexi.
Our legal bases are performance of the service contract, legitimate interests in security and reliable operation, consent for optional notifications and other permission-based features, and legal obligations for records we must retain.
Artificial intelligence and photos
Story topics, the relevant course plan and generated content are sent to OpenAI to provide story, language, speech and image features. If you choose photo generation, the optimized photo is sent to OpenAI to create a short text brief. StoryLexi then deletes the photo bytes and stores only the generated brief, story and normal illustrations.
StoryLexi does not use automated decision-making that produces legal or similarly significant effects.
Providers and international transfers
We use OpenAI for AI features, Google and Apple for optional sign-in, Resend for account email, Mollie for web payments, Firebase and Apple Push Notification service for optional native notifications, browser push providers for Web Push, and hosting and database infrastructure to operate the service.
Some providers may process data outside the European Economic Area. We rely on applicable adequacy decisions, contractual safeguards or another lawful transfer mechanism and limit the data shared to what the feature needs.
Public and shared information
Your display name, username, learning milestones and follow relationships can be visible to other signed-in learners. A story is public only after publication. Public browsing does not show the author’s account identity.
Cookies, storage and tracking
StoryLexi uses essential session and language cookies and local storage for functional preferences such as audio, filters and onboarding prompts. StoryLexi currently has no advertising, cross-service tracking or third-party advertising analytics, so no marketing-cookie consent banner is used.
Retention
Account and learning data are kept while your account is active. Expired authentication and security records are cleaned after their operational period. Successful background records are normally kept for 30 days and failed records for up to 90 days. Database backups are retained for up to 30 days.
When you delete your account, associated account data is deleted from the live service. A payment provider may retain legally required transaction records under its own obligations.
Security
We use HTTPS, short-lived one-time email codes and session tokens, access controls, rate limiting, encrypted provider tokens and restricted production credentials. No online service can guarantee absolute security.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and withdraw consent for optional processing. Contact the privacy address above. You may also complain to the Dutch Data Protection Authority or your local supervisory authority.
Account deletion
Use the Delete account section in Account or the public deletion page. We email a short-lived confirmation link before permanent deletion. Purchased tokens are not refundable merely because an account is deleted.
Children
StoryLexi is not directed to children. A child who cannot lawfully provide their own data should not create an account without the authorization required in their country. Contact us if you believe a child provided data without the required authorization.
Changes
We update this policy when StoryLexi’s data practices change and publish a new effective date. Material changes will also be communicated in the service where appropriate.
