Privacy policy
Last updated 13 August 2026
We take privacy seriously. Build Me A Story is an app for making illustrated stories with young children. This policy explains exactly what it collects and, importantly, what it does not collect.
The short version. There is no personal data collection, no advertising,
no profiling, and no advertising/device identifiers.
The story character’s name and the story idea are used to
write the story and for nothing else. They are never sent to us, or included in usage statistics, error
logs or crash reports.
This website sets no cookies.
Who we are
This app and this website are operated by Engram Ltd, a company registered in England and Wales (number 08498127), whose registered office is at 35 Eaton Road, Norwich NR4 6PR, United Kingdom. If you have a question about anything here, write to support@BuildMeAStory.com.
What never leaves your device
These are the four things the app collects that matter most, and they are handled carefully.
- The character’s name (which may be the child’s name)
- The story idea that’s typed
- The story’s title and the text of the generated pages
- The generated illustrations
None of these are sent to us. They don’t appear in any usage statistic, any diagnostic log, or any crash report.
They are stored on your device, and they are included in your device’s own backups if you have backups switched on.
The one time your words are sent somewhere
To write and illustrate your story, the character name and idea are sent to Google’s Gemini service, which generates the text and the pictures. This is the only purpose for which they leave the device, and the only place they go.
Nothing is sent when you re-read a story you already have - finished stories are kept on the device, pictures included, and open without a connection.
What we do collect
The app records how it is being used, so we can tell which parts are broken and which are never touched. It records the shape of what you did, never the content.
| Instead of | What is actually recorded |
|---|---|
| The name | Whether a name was given at all - yes or no |
| The story idea | Whether it was short, medium or long. Not the words, and not the exact length |
| The story’s contents | How many pages it has, and if any page numbers failed to illustrate |
| - | Which age band, art style and length you chose; whether a story finished, failed or was abandoned; how long it took; when the app was opened and closed |
Alongside each event we record some facts about the app and the device:
- Whether it is Android or iOS, and which store it came from
- Whether it is a phone or a tablet, the device model, and whether it is a Fire tablet
- The operating system version, the app version, and your language setting
How this is not linked to you
The above data is not linked to you. There is no account, and you are never asked for a name, an email address or anything else that identifies you.
- No advertising identifier and no device identifier. No IDFA, no Google Advertising ID, no Android ID, nothing derived from your hardware.
- One random installation number. Generated on your device the first time you open the app. It is a random value with no connection to you or your device, and it exists so that two events can be known to have come from the same install - otherwise we could not tell one person opening the app ten times from ten people opening it once.
- A session number that lasts until you close the app and is then discarded.
Deleting the app removes the installation number. Reinstalling produces a new one, unconnected to the old.
Crash reports
When the app crashes or hits an error, a report is sent through Firebase Crashlytics describing what broke and where in the code - the type of error and the sequence of internal steps that led to it.
Story text, names and pictures are excluded from these reports by the same rule as everywhere else. Internal diagnostic messages that could quote what you typed are kept on the device and never sent; only the higher-severity messages leave, and those are written so as not to contain your content.
Who else receives anything
- Google (Gemini API)
- The main character name and story idea you type, in order to write and illustrate the book. This is the only place that text leaves your device.
- Google (Firebase Crashlytics)
- Crash and error diagnostics — what broke and where in the code. No story text, no names, no pictures.
Nothing is sold. Nothing is shared with advertisers or data brokers. There is no advertising in the app.
How long it is kept
- Individual usage events: 90 days.
- Daily totals: indefinitely. These are counts - how many stories were made on a given day, how many failed.
- Crash reports: kept by Firebase Crashlytics under Google’s retention policy.
Your choices
You can switch off collection of these app statistics in the app’s settings. One switch covers both the usage statistics and the crash reports. We request you not to do this, as the data does not identify you and is very useful for improving the app. However you are free to do so if you wish.
Deleting what has been collected
You can ask us to delete everything recorded from your installation. Find your installation number in the app’s settings and send it to support@BuildMeAStory.com. We will remove the events and mark the installation deleted.
That number is the only thing that identifies your records, precisely because nothing collected is linked to your name or email address - we hold neither, so neither is something we could use to look you up. Deleting the app also removes everything held on the device, including every story you have made.
Children
This app is meant to be used by an adult with a child. The fields a child would actually fill in - the character and the story idea - are the ones that never appear in any usage statistic, diagnostic log or crash report at all, and that is enforced in the app’s code.
One thing is collected that the law treats as personal information about a child: the random installation number described above. We use it without asking a parent first, which the Children’s Online Privacy Protection Act permits where a persistent identifier is the only personal information collected and it is used solely to support the internal operation of the service. It is worth being specific about what that covers here, because the general phrase is not worth much on its own. It is used to:
- Tell whether the app is working. How often a story finishes, fails or is abandoned, and on which devices - which requires distinguishing one install that tried five times from five installs that tried once.
- Diagnose errors. Recognizing that several crash reports came from the same install, so one fault repeating can be distinguished from five unrelated ones.
- Act on a deletion request. It is the only thing that could identify which records are yours - see “Deleting what has been collected” above.
It is not used to contact anyone, to advertise, or to build up a picture of a person. These are the specific things that stop it being used that way:
- It is a random value generated on the device. It is not derived from your hardware and it is not an advertising identifier, so there is nothing outside this app that it can be matched against.
- It is never attached to a name, an email address or an account, because we hold none of those. There is nothing to contact anyone with.
- There is no advertising in the app and no advertising software in it, so it cannot feed behavioral advertising. Nothing is sold, and nothing is shared with advertisers or data brokers.
- The transmissions to us have nowhere to put free text - the app can send a fixed list of events, and none of them has a field that a sentence would fit in.
- Individual events are deleted after 90 days. What outlives them is daily totals of events but not the content of them.
This website
The website records which pages are viewed and which links off the site are clicked, so we know whether anyone is reading it. Alongside that it records the name of the site you followed a link from, if any, and whether you are on a phone, a tablet or a desktop - that last one because the app is built for tablets and we would like to know whether we are reaching them. It is a choice between three or four words; nothing more detailed about your browser or your device is kept. It:
- sets no cookies, which is why there is no cookie banner;
- loads nothing from anyone else - no fonts, no scripts, no embeds;
- uses no third-party analytics and no advertising;
- does not store your IP address. It is converted into an irreversible value used only to tell repeat visits apart, and the address itself is discarded.
If your browser has JavaScript switched off, nothing at all is recorded about your visit.
One thing we cannot yet claim. Our web host keeps its own standard server access logs, and those do contain IP addresses. That is the hosting provider’s configuration rather than something this site controls, and we have not finished dealing with it. We would rather say so than describe a cleaner position than we have.
Where the data is held
Usage statistics are stored on our web hosting, on servers in the EU. We are a UK company, so we access them from the United Kingdom. Crash reports are held by Google, who may process them outside both the UK and the EU under their own terms. Stories, ideas and names stay on your device and are not stored by us anywhere.
Why we are allowed to collect this
If you are in the UK or the EU, we should say which lawful basis each part of this rests on rather than leave you to work it out.
- Making a story. Sending the main character’s name and the story idea to Gemini is necessary to provide the thing you asked for. There is no story without it, which is why it is not a separate choice.
- Usage statistics and crash reports. Our legitimate interest in knowing whether the app works and which parts of it are broken. We have weighed that against the fact that this is an app used by children, and the way it is built is the result: shape rather than content, no advertising or device identifier, no profiling, no sharing, and 90-day deletion.
Your right to object. Because the usage statistics and crash reports rest on our legitimate interest rather than on your consent, you have the right to object to that collection at any time, for any reason. You do not have to justify it to us.
The switch in the app’s settings is the immediate way to act on that: turning it off stops both the usage statistics and the crash reports, and deletes anything already waiting to be sent to us. You can also write to support@BuildMeAStory.com.
Your other rights
Depending on where you live, you may also have the right to ask what we hold about you, and to have it corrected or deleted. Write to support@BuildMeAStory.com, quoting your installation number as above - it is the only thing that can identify your records, which is a genuine limitation of collecting as little as we do.
Changes
If this policy changes in substance, the date at the top changes with it. We will not retrospectively broaden what is collected under a policy you read before the change.