Brand & usage rules
These are conditions of access, not suggestions. They exist because families trust this badge with their children, and because we can revoke access in a single field if that trust is abused.
Do
- Label the button exactly “Continue with Storytailor” or “Sign in with Storytailor.”
- Use the mark we provide, unmodified (no recolouring, cropping, or effects) on the sign-in affordance and connection settings.
- Describe truthfully what you receive. The consent screen’s “never sees” list is the canonical wording and you may quote it.
- Keep your registered purpose strings true to what the feature actually does the day a parent taps Allow.
- Point parents to their Storytailor account to disconnect, alongside any in-app disconnect you offer.
Don’t
- Imply endorsement or certification beyond the integration. Never “Storytailor-approved” or “COPPA-certified via Storytailor.”
- Use “Storytailor,” “Story Intelligence,” or confusingly similar names in your product name, domain, or store listing.
- Dark-pattern the flow: no marketing consents bundled with the button, no gating unrelated features behind it, no nagging after a parent declines.
- Request scopes for features you have not shipped.
- Attempt to de-pseudonymise a child, or store claims beyond your registered purpose.
- Resell, broker, or transfer credentials.
How this is enforced
Access continues while your client is active. Drift in copy or a stale legal URL gets a notice and 14 days. False purpose strings, dark patterns, unauthorised mark use, or security negligence get an immediate suspension, reinstated on verified remediation. De-pseudonymisation attempts, child-safety violations, deception, or resale are permanent.
Suspension is instant and total: the authorisation page stops rendering for you, token exchange fails, and refresh fails, so live sessions end at their next refresh at the latest. Parents can additionally revoke any individual connection at any time, and that is not something we can override.