✶ The Night Library
Terms of ServiceSign in

Privacy Policy — The Night Library

Effective: 2026-08-03 · Last updated: 2026-08-03 Operated by: Eidetic LLC, a Texas limited liability company ("we," "us") Contact: privacy@eidetic.bot

Draft — not yet reviewed by counsel. Every factual statement here was written against the running code and is accurate as of 2026-08-03. Where the code changes, this document must change with it.


The short version

You upload a few photographs of your child. We use them once — to draw an illustrated character sheet, a picture of your kid as a storybook character. After that, the photographs are deleted. Everything afterward is drawn from the illustration, never from the photos.

  • We do not use anything you upload to train AI models. Not ours — we don't have any — and not our providers'.
  • We delete the photographs 30 days after you lock a character's sheet, automatically. You can delete them sooner, yourself, at any time.
  • We don't sell your data. We don't run ads. There are no third-party trackers or analytics scripts in this product.
  • You can delete your account yourself, from your account page, and it takes effect immediately.

The rest of this document is the detail behind those sentences. It is longer than the short version because the short version is worth checking.


1. Who this policy is about

The account holder is an adult — a parent or legal guardian. Children do not have accounts, do not log in, and cannot upload anything.

Children appear here as subjects: their photographs, their names, and the traits you write about them. When we say "your information" below, we mean both your own account details and everything you provide about the children and pets in your household.

You must be 18 or older to hold an account, and you must be the parent or legal guardian of every child whose photograph you upload. Do not upload photographs of other people's children.


2. What we collect

2.1 Information you give us

What Why How long we keep it
Email address and name Sign-in, receipts, service emails Until you delete your account
Google account identifier (if you sign in with Google) Sign-in only. We do not read your Gmail, Drive, contacts, or calendar Until you delete your account
Photographs of your child or pet (up to 5 per character) Drawing that character's illustrated sheet Deleted 30 days after you lock the sheet — see §4
What you write about a character — name, age, personality notes, outfit, appearance details Making the character look and behave like your child in the story Until you delete the character or your account
Story premises and the books you create The product Until you delete them or your account
Feedback you send us through the in-app form Fixing what's broken See §7 — this one survives account deletion, de-identified

2.2 Information we generate

Character sheets, page illustrations, cover art, narration audio, and the story text itself. These are created from your inputs and stored with your account.

We also keep operational records of each AI call — which model ran, how long it took, how much it cost, whether it failed. These records contain no prompts, no story text, and no images.

2.3 Information collected automatically

  • A session cookie, so you stay signed in.
  • A visitor cookie (nl_vid), stored for one year, which lets us count how many distinct people opened a shared book link. It is a random identifier. It is not linked to an advertising profile, and it is not shared with anyone.
  • Standard server logs — IP address, timestamp, and requested URL — kept for operational and security purposes.
  • In-app product events — for example "a book was finished," "a share link was viewed." These record what happened and when.

There are no third-party analytics, advertising, or tracking scripts anywhere in this product. No Google Analytics, no Meta pixel, no session recorders. We looked, because we wanted to be able to write this sentence.

2.4 What we deliberately strip

When you upload a photograph, we immediately re-encode it before storing anything. That process removes the embedded metadata — including GPS coordinates, camera serial numbers, and timestamps. The original file is never stored. What we keep is a resized copy, at most 2048 pixels on its longest edge.


3. Where a photograph actually goes

This is the part most policies leave vague, so here is the whole path.

  1. You upload it. It travels over an encrypted connection to our server.
  2. We normalize it — rotate, resize, strip metadata, re-encode.
  3. We store it on our own server infrastructure, in private storage. Only you can retrieve it. Photographs are never visible to other members of your household, never included in a shared book link, and never included when a character is published.
  4. We send it to an AI provider — twice, at most:
    • Google (Gemini) draws the character sheet from your photographs.
    • Anthropic (Claude) reads the photographs to write an appearance description, and — when enabled — checks that the finished sheet actually resembles the child.
    • If one of those providers is temporarily unavailable, the description and verification steps may fall back to xAI (Grok).
  5. The sheet locks. From here on, the photographs are never used again. Every page illustration is drawn from the locked character sheet, previous pages, and style references — never from the photographs. This is a property of how the drawing pipeline is built, not a promise about intent.
  6. The photographs are deleted, 30 days later.

The providers, named

We use these companies to run the AI features. They are the only third parties that receive anything you provide.

Provider Receives Their commitment
Google (Gemini) Photographs, character descriptions, story text, generated images We are on Google's paid API tier. Under those terms Google does not use prompts or responses to improve its products, and there is no human review of content.
Anthropic (Claude) Photographs, character descriptions, story text Anthropic's commercial terms state it may not train models on customer content.
xAI (Grok) Story text and helper tasks; photographs only when a description or verification step falls back after a Google or Anthropic failure xAI does not train on API inputs or outputs. API requests are retained encrypted for 30 days for abuse detection, then deleted automatically.
OpenAI and ElevenLabs Story text only, when generating narration audio. No photographs, ever. Neither trains on API content by default.
Stripe Your name, email, and payment details when you subscribe. We never see or store your card number. Stripe is the payment processor; its own privacy policy governs.
Resend Your email address, to deliver service email. Email delivery only.

None of these providers is permitted to use your photographs, your children's information, or your stories to train an AI model. If we ever change providers or add one, we will update this table before the change goes live.


4. How long we keep things — and how you delete them

4.1 Photographs delete themselves

When you lock a character's sheet — the moment you tell us the drawing looks right — a 30-day clock starts. When it expires, we delete the source photographs: the attachment, our record of it, and the stored file.

This runs automatically. It is not a manual cleanup someone has to remember.

What this means for you: after the photographs are gone, that character's sheet can no longer be regenerated from scratch. You can still edit the existing sheet, still write new books with that character, still read everything you've made. But a fresh redraw would need fresh photographs.

One exception, and it's in your favour: if the same photograph is attached to a second character, it survives until that character's window expires too. We won't break one child's cast to hit a deadline on another.

4.2 What you can delete yourself, right now

Action What it removes
Delete a photo (on the character, or in your photo library) The photograph and the stored file, immediately, unless another character still uses it
Remove a companion Takes them out of your library. Finished books keep their existing artwork so they still read. Photographs and sheets remain until you use the option below
Permanently erase a companion The character, their sheet, their icon, and their photographs — files and all
Delete your account Everything in §4.3

4.3 Deleting your account

You can delete your account yourself, from your account page. There is no waiting period and no recovery window — when it's done, it's done. You can preview exactly what will be removed before you confirm.

Deleted immediately: your account and sign-in records, every character, sheet, photograph and book, all page images and narration audio, your photo library, your household (if you were its only member), quota records, and anything you'd joined a waitlist for.

Kept, and here's why:

  • Billing records — your Stripe customer and subscription rows. We are required to keep records of money that changed hands. These contain identifiers and amounts, not card numbers. Deleting your data at Stripe is a separate request; write to us and we will make it.
  • AI cost logs, with your identity removed. We keep which model ran, how long, and what it cost, so we can understand our own economics. Your user ID is erased, and so are the free-form fields that could echo a name.
  • Product events, fully de-identified — the fact that "a book was finished" on a date, with no link to you.
  • Feedback you sent us, detached from your identity. Your device details are erased. We keep the message itself, because it usually describes a bug we still need to fix. If your feedback contained your child's name and you want it removed, ask and we will delete it.
  • Your household, if other members remain in it. Their libraries are theirs.

Two honest caveats:

  • Backups. Our database is backed up nightly and those backups are kept for 7 days. Deleted data persists in encrypted backups until they roll off.
  • Published characters. If you published a character to the in-app marketplace and another family imported it, their copy — the illustrated sheet, not your photographs — stays with them after you delete your account. Your photographs are never copied when a character is published. If you don't want this, don't publish.

5. Sharing a book

When you create a share link, anyone holding the link can read that book. That's the point — it's how grandparents see it.

Two things you should know before you send one:

  1. A share link is a capability, not a login. Anyone the link is forwarded to can open the book. We do not check who they are.
  2. Revoking a share link stops new visits, but does not reach copies already taken. If someone opened the book and saved an image, or bookmarked a direct image address, that saved copy keeps working after you revoke the link. We are telling you this plainly rather than implying that revocation is a recall. Treat a shared book like a photo you texted someone: once it's out, it's out.

We are working on making revocation complete. Until this section says otherwise, it isn't.


6. How we protect information

  • Encrypted connections (HTTPS) everywhere.
  • Photographs are stored in private storage and served only through an authenticated proxy that checks, on every request, that you own the file. There are no public links to a photograph.
  • Household isolation: every new account gets its own private household. Members of one household cannot see another's library.
  • API keys and secrets live in server environment configuration, never in the app you run.

No system is perfectly secure, and we won't pretend otherwise. If we discover a breach affecting your information, we will tell you.


7. Children's privacy

The Night Library is a product for parents, about their children. It is not directed to children, does not accept accounts from children, and collects nothing directly from a child.

Everything we hold about a child, we hold because a parent or guardian provided it. You can see it, correct it, and delete it at any time using the controls in §4.

If you believe a child has created an account, contact us at privacy@eidetic.bot and we will remove it.


8. Your rights

Wherever you live, you can ask us to:

  • See what we hold about you and your household
  • Correct anything inaccurate
  • Delete your account and its contents — you can do this yourself, immediately (§4.3)
  • Export your books and artwork
  • Object to a specific use, or ask us to restrict processing

Depending on where you live, some of these are legal rights and some are simply how we operate. We don't distinguish — you get them either way. Write to privacy@eidetic.bot. We aim to respond within 30 days.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We never have.


9. Where data lives

Our servers are in the United States. Our AI providers process requests in their own regions. If you use The Night Library from outside the US, your information is processed in the US.


10. Changes

If we change how we handle your information — particularly anything in §3, §4 or §5 — we will update the date at the top and notify account holders by email before it takes effect. We will not quietly broaden what we do with photographs of your children.


11. Contact

Eidetic LLC Pearland, Texas, United States privacy@eidetic.bot


The Night Library is a product of Eidetic LLC. "The Night Library" is a brand name; the legal entity is Eidetic LLC.

Questions about this document? Write to privacy@eidetic.bot.

Terms of Service·Home

Privacy Policy · Eidetic LLC, a Texas limited liability company