Security & compliance

Written for the people who have to approve this: security reviewers, privacy counsel, and whoever signs. Where something is not in place yet, this page says so rather than implying otherwise.

What we hold about a child

As little as the product can function on. Through Sign in with Storytailor a partner receives a pseudonymous subject, an ID name, a character avatar and an age band. Real name, birthdate, email and address are on an explicit never-disclosed list enforced in the provider, not by convention.

DataWho can see it
Real name, birthdate, addressNobody outside Storytailor. Never in a token or a claim.
AgeA band by default. Exact age in years only when a parent grants it against a registered, parent-visible purpose, and they can refuse or downgrade to a band.
Child credentialsDo not exist. A child never authenticates. A parent authorises.
Story contentThe account that created it. Story Intelligence tenants are isolated per service principal.
Original child drawingsDeleted from storage once the character pipeline completes. We do not retain children’s artwork.

Safety that cannot be turned off

Every piece of content passes a server-side verdict before a child can see it. No flag, tier, key or plan disables it, including ours. The layer fails closed: if the safety check itself errors, the answer is no story, never an unchecked one. Every verdict carries the evidence behind it rather than a bare score.

We never diagnose

This is binding on every tier and every future tool. Storytailor and Story Intelligence never state that a child is depressed, anxious, traumatised or has been harmed. Emotion and insight surfaces show what a child actually expressed, with the material it came from, so a qualified adult can interpret it, in observed vocabulary only, never a score, flag or risk rating. The human diagnoses; the product observes. This is also what keeps the product outside medical-device territory.

Access and isolation

  • Organisation API keys are stored hashed and compared in constant time. The secret is shown once, at creation, and never again.
  • Each tenant executes against an isolated service principal, so one partner’s key cannot reach another partner’s data.
  • Per-organisation rate limits and daily ceilings are enforced server-side, so a leaked key has a bounded blast radius.
  • Sign in with Storytailor is standard OIDC: authorization-code flow with PKCE (S256), RS256 id_tokens, single-use codes, rotating refresh tokens, and revocation that kills consent, live tokens and refresh together.
  • Suspension is one field. A suspended client stops rendering the authorisation page, cannot exchange tokens, and cannot refresh, so live sessions end at their next refresh at the latest.

Children’s privacy posture

Storytailor accounts are for adults, 13 and over, with the age floor enforced at signup. Children are represented through a StorytailorID inside a parent’s account and never hold an account of their own. Parents see and revoke every partner connection in one place, and a parent’s revocation always outranks a partner.

Partners who are child-directed attest to their own obligations at intake; they remain the controller for their own users. We are the consent holder for the StorytailorID surface we operate.

What we do not claim

We hold no SOC 2 report, ISO certification, or COPPA safe-harbour certification today, and no partner may describe us as certified or as certifying them. If your review requires a completed questionnaire, a DPA, or a BAA, ask on the access request and it reaches a human. Saying this plainly is deliberate: a children’s platform that overstates its compliance posture is exactly the kind of vendor you should not buy from.

Reporting something

Security issues go to security@storytailor.com. Please include enough to reproduce. We will not pursue anyone acting in good faith to report a vulnerability. Child-safety concerns go to the same address and are treated as the highest priority we have.


Commercial terms and what each tier includes are on Pricing. The rules partners agree to, and what gets access revoked, are in Brand & usage rules.