ImagineAI LLC

Privacy Policy

This notice explains what information ImagineAI LLC collects, how we use and share it, and the choices and rights you have. It applies to our websites and apps (the “Service”). Your use of the Service is also governed by our Terms of Use. For use through a school or program, our Student Privacy Terms apply to Student Data and control over this policy if they conflict.

Last updated: July 17, 2026

kyle@imagineai.one

Privacy at a glance

  • We never sell or rent personal information.
  • No advertising networks, no targeted ads, and no third-party analytics trackers.
  • We do not use Student Data or children's personal information to train AI models.
  • You own the stories, art, and books you create; you can delete them and your account.
  • Children's use is protected by parental consent or school authorization, and parents can review, delete, and stop further collection at any time.

For Schools, Camps & Programs

Student Privacy (COPPA / FERPA / PPRA)

ImagineAI is designed for classroom and program use, including by students under 13, under the authorization and supervision of a school, district, or program (the “LEA”). When the Service is used this way, our Student Privacy Terms and any signed student data privacy agreement govern student data and control over any conflicting term in this Privacy Policy.

  • Students and teachers own the content (books, text, images) they create.
  • The LEA owns and controls Student Data; ImagineAI acts as a “School Official” under FERPA and Massachusetts 603 CMR 23.00, and uses Student Data only to provide and support the Service for the school's educational purposes, never for commercial purposes unrelated to the school's requested services.
  • Consistent with FTC guidance, we rely on the school's authorization in place of individual parental consent for classroom use; the school, district, teacher, or program is responsible for providing any notice and obtaining any consent required under COPPA, FERPA, PPRA, and applicable state law (including 603 CMR 23.00).
  • We never sell or rent Student Data, and we do not target ads to, market to, or profile students or families.
  • We do not use Student Data to train AI models; prompts and outputs sent to our model providers are processed only to generate the requested result and are not retained by them for training.
  • We improve the Service using only de-identified or aggregated data, and never attempt to re-identify students.
  • Parents/guardians or eligible students should direct requests to review, correct, or delete a student's information to their school or program (the LEA). If you contact us directly, we will refer you to the LEA and act on its instructions; we honor LEA-directed deletion.

Children's privacy (COPPA notice)

This section is our online notice under the Children's Online Privacy Protection Act (COPPA) for children under 13. Children can use ImagineAI in two ways: (1) through a school, district, or program under the Student Privacy Terms above, or (2) with a personal account created with verifiable parental consent.

What we collect from children and why

  • Account identifiers(login email or username, hashed password, classroom code if joining a class) — to create and secure the account.
  • A parent or guardian's email address— to request consent and send required notices. For a consent request that is not completed, we delete the request record after it expires.
  • Content the child creates(stories, prompts, images, books, optional narrated audio) — to provide the creation features the child asks for.
  • Optional private Friends information(a generated author name, optional AI-avatar prompt and image, one-use invite and friend-connection state, linked-adult approvals, and explicit book-collaboration grants) — to provide the parent-approved Friends and co-writing features. This is not a public child profile.
  • Limited usage information and persistent identifiers(such as session cookies and service logs) — used only to operate, secure, and support the Service (“support for internal operations”), not for advertising or profiling.

We do not collect biometrics, precise location, or sensitive categories of information from children, and we do not condition a child's participation on disclosing more information than is reasonably necessary to use the Service.

How consent works for personal child accounts

  • When a child under 13 starts signup, we collect a parent/guardian email and send the parent a consent request describing our practices, with a link to this policy.
  • The account is created only after the parent consents and shares the resulting claim code with their child.
  • Children's personal information from personal accounts is used to provide the Service and is shared only with the service providers listed in this policy, who are bound to use it solely to provide services to us. We do not disclose children's personal information to third parties for their own purposes, and we obtain new consent before any material change to these practices.
  • Public publishing and community features are not part of the child experience unless and until a parent expressly enables and consents to them.

Parents' rights

  • Review the personal information we have collected from your child.
  • Ask us to delete it.
  • Revoke your consent and refuse to permit further collection or use of your child's information (which may end their access to the Service).
  • Use our Parent Controls features, where available, to manage your child's account settings. We use Kids Web Services (KWS, an Epic Games service) solely to verify that a parent or guardian is an adult.

To exercise any of these rights, email kyle@imagineai.one from the parent email on file (we verify requests before acting on them). For students using ImagineAI through a school, contact the school, and we will act on the school's instructions. Our data retention practices for children's information are described in the “Data retention” section below, which is part of this notice.

Information we collect

  • Account information: your email address and password, a phone number if you sign up or verify by SMS, or federated sign-in (e.g., Google) credentials. For classroom use: teacher email, student login email or username, an optional student name entered on a book title page, and a classroom code.
  • Age information: at signup we ask for your birth month and year to determine an age band (such as under 13) so we can apply the right protections. We keep the age band, not your birth month and year or a full birth date.
  • Optional adult-account verification:where this feature is offered, we keep the account's result (verified or self-declared), method, and timestamps, plus short-lived session identifiers and non-identifying outcome events. A mobile wallet check asks only whether the credential shows age 18 or over and is processed in memory; we do not keep the credential, legal name, birth date, or government-ID number or image. Apple's Declared Age Range shares a lower age bound and declaration, not a birth date. A card check makes a real $0.50 charge and attempts an immediate refund; Stripe processes the card and we do not store the full number. If Stripe Identity is selected, Stripe processes the identity document and live selfie while ImagineAI reads only the bounded verification-session result. This adult-account option is not a child verification feature.
  • Parent/guardian information:a parent email for the consent flow; for Parent Controls, a parent email, optional display name, and adult-verification status returned by KWS; and, where Friends is enabled, approval/decline/sever state for the child's private friend connections.
  • Private Friends identity and relationship information: a generated author name, seeded/chosen and claim/cooldown state, an optional AI-avatar prompt and private saved/worn image paths, one-use invite-code state, linked-adult approvals, friend connection state, and explicit book-collaboration grants. The author identity is separate from a public Profile and from classroom pen names.
  • Content you create or upload:the stories, text, prompts, images, books, audio narration, uploaded or pasted manuscripts and supporting materials for “Bring Your Book” intake, and any photos or images you upload to use in your projects. If you collaborate, this also includes shared manuscript changes, comments, server-verified comment attribution, and content-safety review results.
  • Payment and order information: if you buy a paid plan or a print order, payment is processed by Stripe (web) or by Apple through the App Store (mobile); we do not store full payment-card numbers. The optional adult card-check lane also uses Stripe for a real $0.50 charge followed by an attempted refund. For printed books, we collect the recipient name and shipping address to produce and deliver your order.
  • Usage and device information: limited service logs (such as timestamped requests and error traces) and basic app information. In our mobile app, we access your device microphone or photos only if you grant permission, and only to provide the related feature. If you enable notifications, we also keep a service-only device token and installation/generation state for transactional delivery.
  • Communications: messages you send us, such as support requests.
  • ImagineAI does not receive or store biometric templates, government-ID images or numbers, or adult-verification selfies. If an adult chooses optional Stripe Identity, Stripe processes the document and live selfie on its hosted service and returns a bounded session result. We do not collect precise location, and we use no third-party analytics or advertising trackers.

Cookies and similar technologies

We use only the cookies and similar technologies needed to run the Service: keeping you signed in, remembering your session, protecting against fraud and abuse, and balancing load. We do not use advertising cookies, cross-site tracking, or third-party analytics cookies. Because we do not track users across other sites or apps over time, the Service does not respond differently to browser “Do Not Track” signals; there is no tracking to turn off.

How we use information

  • Provide, operate, and maintain the Service and your account.
  • Authenticate sign-in and keep accounts secure.
  • Process payments and fulfill print orders.
  • Provide support and respond to your requests.
  • Individual review for operations.As part of providing the Service, we may review an individual account, session, or its content when needed — for example, to diagnose and fix a problem, respond to a support request from a user, teacher, parent, or school, investigate unusual activity, or confirm that a fix worked. This access is limited to authorized ImagineAI personnel, as described in our public Data Security & Privacy Plan.
  • Protect the Service against fraud, abuse, and security risks.
  • Safety.We may review content and messages, including with automated tools, to enforce our rules and to identify signals that a user may be at risk of harm. If content is flagged, it may be reviewed by authorized ImagineAI personnel, and we may notify a parent, guardian, teacher, or — in an emergency — appropriate authorities.
  • Improve the Service. We study usage patterns and service performance to make ImagineAI better. For Student Data and children's data, this improvement analysis uses only de-identified or aggregated data, and we never attempt to re-identify anyone.
  • Communicate with you about the Service. We send marketing only to adult account holders, and you can opt out at any time.
  • Comply with legal obligations.

How AI features handle your content

ImagineAI's writing, illustration, narration, and video features are powered by artificial intelligence. To generate results, your prompts and the resulting outputs are sent to the AI providers we use, which currently include Anthropic, OpenAI, Fireworks AI, and Together AI for text and chat; Google, FAL.ai, and WaveSpeed for image and video generation; and ElevenLabs and OpenAI for audiobook narration. These providers process your prompts and outputs only to generate the requested result; they are not permitted to use your content to train their models, and we do not use Student Data or children's personal information to train AI models. AI-generated content is created by a machine, not a person, and should be reviewed before you rely on it.

How we share information

We share personal information only as described here. The service providers (subprocessors) below help us run the Service, are bound by confidentiality and data-protection obligations, and may use the information only to provide services to us:

  • Supabase— database, authentication, and file storage (US).
  • Google Cloud (Firebase/Firestore)— storage of generated books and related content (US).
  • Railway— application hosting (US).
  • Trigger.dev— background job processing (for example, long book-generation tasks).
  • Resend— transactional email (account, consent, and operational notices).
  • Stripe— payment processing for web purchases and, where offered, optional adult card-charge/refund or hosted Identity document-and-selfie verification.
  • Apple— mobile subscription billing, Sign in with Apple, Apple Push Notification service, and optional Declared Age Range processing in the native app.
  • Lulu— printing and shipping of physical book orders (receives the book file, recipient name, and shipping address).
  • Kids Web Services (Epic Games)— parent/guardian adult verification for Parent Controls.
  • AI providers— Anthropic, OpenAI, Fireworks AI, Together AI, Google, FAL.ai, WaveSpeed, and ElevenLabs, as described in “How AI features handle your content.”
  • Content you choose to share privately: a parent-approved friend connection does not itself expose a book. When the collaboration feature is enabled, an owner must explicitly invite a connected friend to a particular book. Access is limited to that authenticated relationship/grant and ends when the grant or relationship is revoked.
  • Content you choose to publish: some features let users share content publicly (for example, a public story page or a public author profile). Anything you publish, and the profile name attached to it, is visible to others; you can unpublish it at any time. Public publishing requires an account aged 13 or over, and submissions are reviewed before they are listed. Accounts for children under 13 cannot publish publicly, and classroom sharing stays within the classroom under teacher control.
  • Legal and safety: when required by law, or to protect the rights and safety of users and the integrity of the Service. For Student Data, we direct third-party requests (including from law enforcement) to the school or district (LEA) and, where lawful, give the LEA prior notice.
  • Business transfers:in connection with a merger, financing, or sale of assets, subject to this policy's commitments; we will provide notice before personal information becomes subject to a materially different policy.
  • We do not sell or rent personal information, we do not share it for cross-context behavioral advertising, and we do not show targeted advertising to anyone — students, families, or other users.

Data retention (our retention policy)

We keep personal information only as long as reasonably necessary for the purposes we collected it, and never indefinitely. This section is our written data retention policy, including for children's personal information:

  • Account information:kept while your account is active. When you (or a parent) ask us to delete an account, the account is locked and scheduled for deletion with a 30-day cancellation window (sign back in during that window to restore it). When the window ends we delete or de-identify the account's personal information through an ordered deletion process, normally within 7 days. If a step fails, access remains locked while we complete the deletion. Residual copies leave encrypted backups as backup retention windows expire.
  • Content you create: kept until you delete it or delete your account.
  • Friends and device data: private author identity/cooldown state, every saved/worn private avatar/media object, and device registrations are removed or de-identified when the applicable account deletion completes. Severing a friend relationship revokes its derived book grants and access. Invite codes expire after seven days and cannot authorize access once expired, consumed, or rotated; terminal relationship and invite-code state may remain as service-only operational/security records until account deletion or earlier cleanup.
  • Adult-verification data:you may revoke the current account conclusion in the verification flow where offered. Completed account deletion removes the conclusion, short-lived sessions, and outcome events. Provider-side transaction or compliance records remain subject to the provider's own legal retention obligations.
  • Children's personal information: retained only as long as reasonably necessary to provide the Service the child is actively using and never used for any other purpose; deleted on parental request or consent revocation as described above. Expired, uncompleted parental-consent requests are deleted.
  • Student Data:retained and deleted per the LEA's instructions and the Student Privacy Terms, including returning or deleting data on request (target within 3 days).
  • Order and billing records: kept as required for tax, accounting, and legal compliance. Account deletion removes account links, shipping/contact fields, and private print-artifact pointers from retained order evidence where applicable.
  • Safety records: records needed to document and respond to imminent danger or serious safety reports may be retained after account deletion for safety, legal, and accountability purposes, with access restricted to authorized operations.
  • Operational logs: short-lived; purged on a rolling basis and not retained beyond what security and reliability require.
  • De-identified or aggregated data (for example, total books created) may be retained to improve the Service; we never attempt to re-identify it.

Security

We maintain a written information security program aligned to the NIST Cybersecurity Framework, summarized in our public Data Security & Privacy Plan. It includes encryption in transit (HTTPS/TLS) and at rest, hashed passwords, least-privilege access controls that limit production-data access on a need-to-know basis, periodic risk reviews, and an incident-response plan. If a breach affects Student Data, we notify the LEA within 72 hours of confirmation (faster where state law requires); if it affects other users, we notify affected users and regulators as required by law. No method of storage or transmission is perfectly secure, but we work continuously to protect your information and remediate issues we identify.

Your choices and rights

  • You can access, correct, or delete your account information and content by signing in (account deletion is at imagineai.one/account/delete), or by emailing kyle@imagineai.one. We verify requests before acting on them and respond within the time required by applicable law (generally within 45 days).
  • Parents and guardians can exercise the rights described in “Children's privacy” above at any time.
  • For Student Data, parents and eligible students should make requests through their school or program (the LEA); if you contact us directly, we will refer you to the LEA and act on its instructions.
  • You can opt out of marketing email using the link in any message.
  • We will never discriminate against you for exercising a privacy right.

US state privacy rights

Depending on where you live, state law may give you rights to access, correct, delete, or obtain a portable copy of your personal information, and to appeal a decision we make about a request. We honor these requests for all users regardless of state. We do not sell personal information, share it for cross-context behavioral advertising, or use it for profiling that produces legal or similarly significant effects, so there is nothing to opt out of in those categories. To exercise any right or appeal a decision, email kyle@imagineai.one.

Users outside the United States

ImagineAI is operated from the United States and directed to US users. If you use the Service from elsewhere, your information is transferred to and processed in the US, where privacy laws may differ from your jurisdiction's. Where local law grants you additional rights, you may exercise them through the contact below.

Changes to this policy

We may update this policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, notify account holders (for example, by email or in-product notice). If we ever materially change how we collect, use, or disclose children's personal information, we will obtain fresh parental consent before the change applies to a child's account.

Governing law

This policy is governed by the laws of the Commonwealth of Massachusetts.

Contact us

ImagineAI LLC (Massachusetts, USA)
Email: kyle@imagineai.one
Privacy/Security contact: Kyle Maloney
Our postal address is included in the direct notices we send parents and is available to any parent, school, or regulator on request.