1. Introduction
HSKStory ("we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
2. Data We Collect
Information You Provide:
- Account Information: Email address, password (hashed)
- Payment Information: Processed by Paddle (our merchant of record) - we do not store credit card details
- Story Preferences: HSK level, genre preferences, custom prompts you submit
Automatically Collected:
- Usage Data: Stories generated, stories read, features used
- Technical Data: IP address, browser type, device information
- Analytics: Anonymous usage statistics to improve the Service
3. How We Use Your Data
We use your information to:
- Provide the Service: Generate stories, produce audio, manage your account
- Process Payments: Via Paddle (our payment processor)
- Communicate: Send service updates, respond to support requests
- Improve: Analyze usage patterns to enhance features and quality
- Comply: Meet legal obligations and enforce our Terms
We do not sell your personal data to third parties.
4. Third-Party Services
We use the following third-party services that may access your data:
Paddle (Payment Processing)
- Acts as merchant of record
- Processes all payments
- Handles tax compliance
- Privacy Policy: paddle.com/privacy
Azure Text-to-Speech (Audio Generation)
- Processes story text to generate audio
- Story content sent to Azure for processing
- Privacy Policy: privacy.microsoft.com
AI Language Models (Story Generation)
- Services: OpenAI, Anthropic, Moonshot AI
- Custom prompts and preferences sent for story generation
- Each has their own privacy policy
5. Data Storage & Security
Storage: Your data is stored on secure cloud servers. We use industry-standard encryption and security measures.
Retention: We retain your data while your account is active, plus 90 days after deletion (for legal/backup purposes).
Security: While we implement reasonable security measures, no system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
6. Your Rights (GDPR Compliance)
You have the right to:
- Access: Request a copy of all personal data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your account and data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Objection: Opt out of marketing communications
- Restriction: Request we limit how we use your data
To exercise these rights, contact us at privacy@hskstory.com
7. Cookies & Tracking
We use the following types of cookies:
- Essential Cookies: Required for login and session management (cannot be disabled)
- Analytics Cookies: Anonymous usage statistics (you can opt out)
- No Advertising Cookies: We do not use third-party advertising cookies
8. Children's Privacy
Our Service is not directed to children under 13. We do not knowingly collect personal information from children. If you are under 13, please do not use the Service without parental consent.
If we discover we have collected data from a child under 13, we will delete it promptly.
9. Data Breach Notification
In the event of a data breach that may compromise your personal information, we will notify affected users within 72 hours via email.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email at least 30 days before they take effect. The "Last updated" date at the top indicates when changes were made.
11. Contact Us
Questions about this Privacy Policy or your data? Contact us:
- Email: privacy@hskstory.com
- Support: support@hskstory.com