DreamPages — Privacy Policy
Effective Date: July 31, 2026
This Privacy Policy ("Policy") explains how Amplified Imagination LLC ("DreamPages," "we," "us," "our") collects, uses, and shares information when you use dreampages.ai and related services (the "Service").
We designed this Policy for a parent/caregiver‑managed service that generates children's stories. It applies worldwide and includes notices for California and (if applicable) EEA/UK residents.
Email practices (what we send): Password‑reset emails and essential service/security communications. For purchases sold through Link, Link sends receipts, invoices, refund notices, and certain subscription and renewal notices directly. DreamPages does not use these addresses for marketing email.
1. Information We Collect
1.1 Account & Contact Information (from the parent/caregiver)
- Email address and display name
- Authentication data (hashed password) or OAuth identifiers (Google)
- Purchase history and Stripe or Link transaction identifiers (no card numbers)
- Support communications
1.2 Child Profile & Preferences (provided by the parent)
- Child's name
- Child's age setting (0–11 or 12+)
- Optional preferences (themes, lessons/values)
- Optional narrator/voice selections and character library choices
We do not ask children to create accounts or directly provide contact details, photos, or precise location. An authenticated adult account holder may choose to upload a photo through the Photo Character feature as described below.
1.3 Story & Feature Content
- Story prompts and creator ideas, character descriptions, generated stories, images, narration, and private Series continuity details saved to your library
- Before account creation, the child name or nickname, age, interests, story idea, generated text story, and temporary story settings that an adult submits to create a guest story
- Feature settings, lengths, and metadata (timestamps, counts)
- Sharing choices and records, including approved share content and assets, share-link and attribution tokens, intended audience and channel, enable/export/rotation timestamps, aggregate funnel events, and reports submitted about a shared story
A pre-account story is a private, temporary draft. It is not added to a permanent child profile or library unless the adult creates or signs in to an account and saves it.
1.4 Photo Character Inputs
DreamPages Plus account holders may choose to upload one photo of a child, adult, pet, toy, object, plant, vehicle, or other subject to create a reusable illustrated character. We collect the normalized photo, the name and description you provide, your combined photo consent and Photo Privacy Notice versions and acceptance time, automated safety and human/non-human/uncertain classification results, job status, and the resulting character details and portrait. We do not use face recognition to identify a person and do not ask an AI provider to identify a person or infer sensitive traits.
The source photo is private and temporary. DreamPages strips embedded metadata, keeps only a normalized copy in private temporary storage, and deletes that copy promptly after the request succeeds, is rejected, or fails—normally within minutes. If processing has not finished, DreamPages schedules automatic source deletion one hour after upload and returns the credit. An isolated one-day storage-lifecycle rule remains as disaster-recovery protection if an application deletion must retry. The source photo is not added to your library, analytics events, permanent media storage, or DreamPages backups. Generated job descriptions and provider evidence are removed after processing; recent status and refund details remain available for seven days. The generated character details and portrait remain in your account until you delete them or your account, subject to ordinary backup and legal-retention limits.
The normalized photo is processed first by Google Cloud Vision for safety and privacy classification. Google states that online Vision API image content is processed in memory and not persisted to disk, and is not used to train or improve its models. If the request passes that boundary, OpenAI processes the photo for image moderation, privacy-preserving character analysis, and illustration. Under DreamPages' current API configuration, OpenAI does not use this content to train its models, but may retain API content in abuse-monitoring logs for up to 30 days. Content flagged for possible child sexual exploitation or abuse may be retained longer for safety review or legal reporting. Provider practices can change; current provider terms and legally required handling control.
DreamPages automatically prevents public sharing of any character classified as human or uncertain and every story that includes that character. A user cannot override that classification. A confidently non-human photo character may use the ordinary story-sharing controls and safety review.
1.5 Technical & Security Data
- IP address, device/browser type, system activity, and logs for security, rate‑limiting, and fraud prevention
- Cookies necessary for login/session integrity and temporary guest-story ownership (e.g., HTTP‑only, secure session cookies) and a CSRF token
- Browser storage for your account information (including email, settings, and credit balances) to keep you logged in—not used for advertising
- Random first-party visitor and session identifiers used to understand whether shared stories are opened, read, remixed, or lead to an account or first story. We transform these identifiers with a keyed one-way hash before storing growth events.
- For guest-story abuse prevention, keyed one-way hashes (HMACs) derived from the requesting IP address and network prefix. Guest-story records do not store the raw IP address.
1.6 Payments & Subscription Billing
DreamPages uses Stripe Checkout for purchases. For transactions identified at checkout as "Sold through Link," Sold through Link, LLC ("SMP"), a Stripe affiliate, acts as merchant of record and facilitates the sale on DreamPages' behalf. Stripe, SMP, and Link may collect and process your name, email address, phone number, billing address, tax location, selected currency, Link account and order information, payment details, transaction history, fraud and dispute signals, and support or refund communications. Their handling is also governed by the applicable Link Privacy Policy and Stripe privacy notices.
DreamPages does not receive or store full card numbers, card brand, card last four digits, bank credentials, or reusable payment-method details. We retain only the Stripe customer, Checkout Session, subscription, invoice, PaymentIntent, and related transaction identifiers needed to deliver entitlements, reconcile payments, prevent duplicate fulfillment, and meet accounting or legal obligations. For a Managed Payments subscription, the payment authorization is held for SMP's Managed Payments charges and is not treated as authorization for an unrelated DreamPages charge outside Managed Payments.
1.7 Subscription Status Data
We maintain plan type (for example, Annual Premium, Lifetime Premium, Plus Monthly, Plus Annual, or another grandfathered legacy plan), start and renewal dates, cancellation timestamps, applicable credit-ledger activity, and billing history to operate your account and comply with accounting and legal obligations.
1.8 Public Story Sharing
Stories are private by default. If the authenticated parent/caregiver deliberately enables a public share link, DreamPages publishes that story on a page that does not require a DreamPages account to view and may generate downloadable share images or video. The public page and share assets include only the content approved in the sharing flow. This can include the story title, selected age, length and style information, creation date, page text, generated illustrations and narration, character names/descriptions, and an optional short, safety-reviewed version of the creator idea entered by the account holder.
Characters created from photos that are classified as human or uncertain, and all stories containing those characters, are never eligible for public sharing through DreamPages.
A public story page does not intentionally disclose the account email address, password, parent/caregiver name, billing information, the underlying child-profile record, system instructions or model-expanded prompts, private preferences not included in the approved share, other library stories, or private account activity. Story text, titles, creator ideas, and character details can nevertheless contain names or other information entered by the parent/caregiver. Review the complete share preview and remove identifying or sensitive information before sharing it publicly.
Personal share pages request that search engines not index, archive, or follow them, although we cannot guarantee that every third party will honor those instructions. Example or promotional stories owned by DreamPages may be intentionally indexable. We process share and attribution tokens, approved share-package settings, export and handoff status, reports, referrer information, internal engagement milestones, and ordinary security and delivery logs to operate, protect, and improve sharing. The account holder can disable sharing or rotate the share link. Disabling makes the DreamPages page and hosted share assets unavailable and rotating invalidates prior DreamPages attribution links, but search engines, social platforms, browser caches, or recipients may retain copies or previews outside our control.
1.9 No Third‑Party Ads/Analytics
We do not use third‑party ad networks, cross-site tracking pixels, or third-party advertising identifiers. We use first-party service analytics to measure product operation and the sharing funnel described in this Policy.
2. How We Use Information
We use information to:
- Provide the Service, including generating stories/illustrations/narration via AI, saving your library, and authenticating sessions;
- Create and operate story links and share assets when requested by the account holder; measure genuine opens, reading milestones, remix actions, account creation, and first-story completion; and process abuse reports;
- Tailor content to the child's age and preferences provided by the parent;
- Maintain safety and integrity, including rate‑limiting, abuse prevention, and content moderation;
- Normalize, safety-check, classify, and illustrate a photo only when an adult account holder requests a Photo Character;
- Process purchases, calculate applicable indirect tax, deliver purchased entitlements, reconcile refunds and disputes, and provide transaction support;
- Set up and manage subscriptions, including auto‑renewal, renewal notices when configured or legally required, payment collection, failed-payment recovery, cancellation, and payment-method updates;
- Operate, maintain, and improve core features (e.g., understanding popular features and technical performance); and
- Comply with law and enforce terms.
We do not use personal data for advertising or marketing communications.
3. AI Providers and Data Handling
We use third-party business and API services to generate and moderate stories, illustrations, voice direction, and synthetic narration, and to store and deliver related content. Depending on the feature and service configuration, these providers may include OpenAI, Google, Anthropic, X.AI LLC, and fal – Features & Labels, Inc. ("fal.ai"). Not every provider processes every request.
Information provided to these services may include story prompts and content; character descriptions; a child's name or nickname, age, interests, or preferences when included in or needed for the story; selected synthetic voices and performance instructions; and related technical metadata. Providers may return generated text, images, synthetic audio, timing information, and safety or technical results. We disclose only information reasonably necessary to provide, protect, and maintain the requested feature.
We use business or API offerings rather than consumer chatbot accounts. Under our current agreements and configurations, providers do not use identifiable DreamPages API inputs or outputs to train their general-purpose or foundation models. Providers may create or use de-identified or aggregated usage data, including to analyze, support, improve, or develop their services and models, and may process limited content and metadata to provide the Service, detect abuse, maintain security, and comply with law, as permitted by their agreements. Our X.AI LLC account uses Zero Data Retention, which prevents persistent storage of API request and response content. DreamPages stores prompts and outputs in your library or temporary guest story; we do not keep additional copies for model training.
Story authoring may use Google Vertex AI. Google states that it does not use customer data to train or fine-tune managed models without the customer's permission or instruction. Google's published Gemini models may use project-isolated, in-memory caching with a default retention period of up to 24 hours, and Google may log prompts for abuse monitoring when permitted by the applicable Google Cloud terms. DreamPages does not enable Google Search or Maps grounding, session resumption, or explicit context caching for story authoring.
Before an anonymous story is generated, Cloudflare Turnstile may process browser and network signals to distinguish people from automated abuse. We use that result only for security and service integrity, not advertising.
International processing: Our service providers, including the AI providers listed above, Google Cloud Platform, Stripe, and Cloudflare, may process data globally. Where required, we rely on Standard Contractual Clauses or comparable transfer safeguards.
4. Cookies and Local Storage
We use only essential cookies for session management, temporary guest-story ownership, and CSRF protection. The guest-story cookie lets us return the temporary story only to the browser that created it. You can block cookies in your browser, but login and guest-story features may not function correctly without essential cookies. We use limited localStorage for app state and random first-party visitor/session identifiers that help us measure the operation of shared-story links. These identifiers are not used for advertising or cross-site tracking.
5. Children's Privacy
- The Service is managed by the parent/caregiver. Children do not create accounts.
- Parents may enter a child's name, age, and preferences so the Service can tailor content.
- We do not knowingly collect personal information directly from a child.
- When a child views content under a parent's account, the Service may process persistent identifiers (e.g., cookies/IP) only for internal operations, such as authentication, security, and delivery of the content; not for advertising or marketing.
- The Photo Character feature is available only inside an authenticated adult-managed account. The adult must be at least 18 and confirm ownership or permission to use each photo. If a child appears, the adult must be the child's parent or legal guardian. DreamPages does not ask a child to upload a photo directly.
- Only the authenticated parent/caregiver account can enable a public story link. Because a public story or share asset may display the selected age, story content, narration, character names/descriptions, and an optional creator-idea excerpt, the parent/caregiver must review it and remove identifying or sensitive child information before sharing.
- If we learn we have collected a child's personal information without required consent, we will delete it promptly upon verification.
- Parents may review or update child information in Settings, delete profiles or stories, or request a copy or deletion through support. Deleting a reusable child profile does not alter completed stories.
6. Sharing and Disclosures
We do not sell or share personal information for cross‑context behavioral advertising. We disclose data to:
- AI, infrastructure, storage, and communications service providers acting on our behalf (including the AI providers described in Section 3 and Google Cloud Platform), bound by applicable confidentiality and data‑use restrictions;
- Stripe, SMP, and Link for checkout, merchant-of-record services, tax calculation and remittance where covered, fraud and dispute management, receipts and invoices, order and subscription management, transaction support, refunds, and their own legal obligations. Depending on the activity, these parties may act as our provider or in an independent merchant-of-record or controller role;
- Cloudflare, which provides the Turnstile abuse-prevention check used before anonymous generation;
- The public, search engines, social or messaging platforms, and anyone who receives a public story link, but only when the account holder has deliberately enabled public sharing for that story;
- Law enforcement or legal process, where required; and
- In connection with safety, fraud prevention, or corporate transactions (if applicable).
7. Data Security
We use reasonable safeguards, including TLS encryption in transit, encryption at rest via our cloud providers, hashed passwords, OAuth where applicable, HTTP‑only secure cookies, CSRF protections, and rate limiting. No system is perfectly secure; we will notify users of a data breach as required by law without undue delay.
8. Data Retention
We retain account and library information while your account is active or as needed to provide the Service. An unclaimed pre-account story and its submitted child details are deleted through automated cleanup when they are no longer needed for the temporary experience and service protection. Guest-session, abuse-prevention, analytics, sharing, billing, and security records follow separate retention periods based on their purpose; aggregate records without story content may be kept longer.
Deleting a child profile removes the reusable profile but does not change completed stories or Journey history. Deleting your account removes the account and its owned content from the application, revokes public links, and starts any remaining media cleanup. Limited billing, accounting, provider-usage, analytics, and security records may be retained where needed or required. Rolling backups and provider-held copies may persist for their applicable retention periods. A customer may separately ask Link to delete information associated with Managed Payments transactions and a Link account. Stripe states that this process cancels affected Managed Payments subscriptions, deletes data from associated Stripe objects where applicable, and notifies DreamPages. A Link-side deletion does not by itself delete the customer's DreamPages library or account, which remains subject to DreamPages' deletion process.
DreamPages source-photo retention is shorter: the temporary normalized source is deleted promptly after processing, with automatic deletion scheduled one hour after upload and an isolated one-day storage-lifecycle rule as disaster-recovery protection. Provider safety retention is governed by Section 1.4 and is not controlled by deleting the DreamPages character.
9. Your Choices
- Emails. DreamPages sends password‑reset and essential service/security communications. Link sends transaction receipts, invoices, refund notices, and certain subscription notices for Managed Payments transactions. These required transactional messages are separate from marketing email.
- Cookies. You can adjust browser settings to block cookies; essential cookies are required for login and to keep a temporary guest story connected to the browser that created it.
- Public story links. Stories are private unless you enable sharing. From the story's sharing controls, you can disable public access or rotate the link. Disabling also schedules hosted share assets for deletion. These controls cannot delete copies already downloaded, posted, cached, or saved by a recipient or third party.
- Photo characters. You may delete an unused photo-created character from its details page. Characters already used in a story or Series may be hidden, while the immutable completed story remains in your private library. The source photo has already been removed under Section 1.4.
- Manage or cancel a subscription. You can manage an auto‑renewing Managed Payments plan through Link, through an available billing option in Settings → Plan & credits, or by emailing support@dreampages.ai; cancellation takes effect at the end of the current term.
10. Your Privacy Rights
10.1 California (CCPA/CPRA)
California residents may request: (i) access to categories/specific pieces of personal information; (ii) correction of inaccuracies; (iii) deletion; and (iv) information about our disclosures. We do not sell or share personal information. We do not use or disclose Sensitive Personal Information beyond "necessary" purposes. We will respond within 45 days (extendable as permitted) after verifying your request. Submit requests to support@dreampages.ai.
Categories we collect may include: identifiers (email, IP), commercial information (purchases), internet/electronic activity (log data), and inferences (preferences derived from your settings). Sources are you (parent account) and your use of the Service. Purposes are described in Sections 2–3. Disclosures are to service providers (Section 6).
10.2 EEA/UK (GDPR), if you use the Service from there
DreamPages acts as controller for the account, family, library, and product data it determines how to use. Stripe, SMP, or Link may separately act as a controller or merchant of record for payment, tax, fraud, transaction support, and their legal obligations. Our legal bases include:
- Contract (to provide the Service) and Legitimate interests (security, service improvement) for parent account data;
- Consent (parental) for child profile (name, age, preferences) tailoring;
- Legal obligation for payment records/financial compliance.
You may have rights to access, rectify, erase, restrict, object, or obtain a copy of your data. Contact support@dreampages.ai. We do not currently appoint an EU/UK representative; if our obligations change, we will update this Policy and our notices accordingly.
11. Do Not Track
We do not respond to browser "Do Not Track" signals.
12. Changes to This Policy
We may update this Policy by posting a new version with a new Effective Date. When changes are material or when required by law (e.g., expanding child data collection), we will provide additional notice.
13. Contact Us
Amplified Imagination LLC
Email: support@dreampages.ai