Privacy Policy

Last Updated: December 14, 2025

1. Introduction

We ("we," "our," or "us") are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at legacytalecraft.com (the "Service").

By using our Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address (required for authentication)
  • Full name (optional)
  • Profile information you choose to provide

2.2 Project Data

When you use our Service to create comic books, we store:

  • Story content, characters, scenes, and chapters
  • Images and reference materials you upload
  • AI-generated content (panels, images, text)
  • Project settings and preferences

2.3 Google Account Integration

If you choose to connect your Google account for Drive or Photos sync, we collect and store (with encryption):

  • OAuth Refresh Tokens: Encrypted and stored securely to maintain your Google account connection
  • Synced Content: Files and photos you select to sync from Google Drive and Google Photos
  • Sync Preferences: Your folder and album selections for syncing

Important: We only access Google Drive and Photos with read-only permissions. We never modify, delete, or share your Google content. You can disconnect your Google account at any time.

Google Limited Use Compliance: We comply with Google API Services User Data Policy and Limited Use requirements. We only use your Google data to provide user-facing features in our app. We do not share, sell, or transfer your Google user data to third parties. We do not allow humans to read your Google data except for security purposes or with your explicit consent.

2.4 Usage Analytics

We collect usage data to improve our Service:

  • AI generation usage (credits consumed, models used)
  • Feature usage statistics
  • Error logs and performance metrics

2.5 Technical Information

Automatically collected information includes:

  • IP address and browser type
  • Device information
  • Cookies and session data (for authentication)
  • Page views and navigation patterns

3. How We Use Your Information

We use the collected information for:

  • Service Delivery: Creating and managing your comic book projects
  • AI Generation: Generating images, text, and story content based on your input
  • Google Sync: Syncing selected files and photos from your Google Drive and Photos accounts
  • Authentication: Verifying your identity and maintaining your account security
  • Communication: Sending service-related emails (notifications, updates)
  • Improvement: Analyzing usage to improve our Service and develop new features
  • Support: Responding to your inquiries and providing customer support

4. Data Storage and Security

4.1 Storage

Your data is stored using:

  • Supabase: Database and authentication services (hosted on secure cloud infrastructure)
  • Google Cloud Storage: For synced Google Drive/Photos content
  • Vercel: Application hosting and content delivery

4.2 Security Measures

We implement industry-standard security measures:

  • Encryption: OAuth tokens are encrypted using AES-256-GCM encryption before storage
  • Row-Level Security: Database-level access controls ensure users can only access their own data
  • Secure Authentication: Password-less authentication via secure email links
  • HTTPS: All data transmission is encrypted using SSL/TLS
  • Access Controls: Strict access controls and authentication for all data access

4.3 Google Data Deletion

When you disconnect your Google account, we delete your Google-related data as follows:

  • Immediate: We immediately revoke access to your Google account and delete your encrypted OAuth refresh token
  • Within 24 hours: We delete your OAuth connection record from our database
  • Within 30 days: We delete all synced files and photos from our storage systems, including:
    • All files synced from Google Drive
    • All photos synced from Google Photos
    • All metadata associated with your Google sync
    • All files stored in Google Cloud Storage related to your Google sync

You can request immediate deletion of all Google-related data by contacting us at legacycrafttale@gmail.com. We will process your request within 7 business days.

5. Third-Party Services

We use the following third-party services that may process your data:

5.1 Google Services

When you connect your Google account, your data is processed by Google according to Google's Privacy Policy. We only request read-only access to your Drive and Photos.

5.2 AI Services

We use third-party AI services (such as OpenAI, FAL, and others) to generate content. Your prompts and generated content may be processed by these services according to their privacy policies.

5.3 Other Services

6. Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and associated data
  • Data Portability: Export your project data
  • Disconnect Google: Disconnect your Google account at any time through the settings page
  • Opt-Out: Unsubscribe from non-essential emails

To exercise these rights, contact us at ycohney@gmail.com.

7. Data Retention

We retain your data for as long as:

  • Your account is active
  • Necessary to provide our Service
  • Required by law or to resolve disputes

When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal purposes.

8. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

9. International Data Transfers and Jurisdiction

Our Service is operated from Israel, and data may be stored and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from those in your country of residence.

We ensure appropriate safeguards are in place to protect your data, including:

  • Standard contractual clauses for international data transfers
  • Encryption of sensitive data in transit and at rest
  • Compliance with applicable data protection regulations

If you are located in the European Economic Area (EEA) or other jurisdictions with specific data protection requirements, you may have additional rights as outlined in Section 6 (Your Rights and Choices).

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

    LegacyTaleCraft - Create Your Family Story as a Comic Book