Privacy Policy
Version: 1.0
Effective Date: September 12, 2026
Data Controller: FOP Gaitan Kyrylo Oleksandrovych (Sole Proprietor)
Website: Taleino.com
Contact Email: [email protected]
Privacy Contact: [email protected]
1. Introduction
1.1. This Privacy Policy (“Policy”) explains how Taleino (“Taleino”, “Service”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you use Taleino.com and related services.
1.2. Taleino is a digital service that allows parents, legal guardians, and other customers to create personalized children's stories and related digital content.
1.3. The Data Controller is FOP Gaitan Kyrylo Oleksandrovych, a sole proprietor registered in Ukraine.
1.4. We aim to process personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) where applicable and Ukrainian data protection legislation.
1.5. Taleino is primarily designed for parents, legal guardians, and other adults who create personalized stories for children. The Service is not intended to encourage children to independently create accounts or provide personal data.
1.6. Because Taleino may process information relating to children in order to personalize stories, we apply additional safeguards to children's personal data and follow the principles of data minimization, purpose limitation, privacy by design, and privacy by default.
2. Personal Data We Collect
We collect only information reasonably necessary to provide and improve the Service.
2.1. Account and Contact Data
Depending on the features you use, we may collect:
- Email address
- Name or display name, if provided
- Account identifier
- Account creation date
- Login and authentication information
- Communication preferences
Passwords, where applicable, are stored using appropriate security measures and are not stored in plain text.
2.2. Story Creation Data
When you create a personalized story, you may provide information such as:
- Child's first name or nickname
- Age or age range
- Story preferences
- Interests and hobbies
- Preferred characters
- Preferred settings or themes
- Other information voluntarily provided for personalization
You should not provide unnecessary sensitive personal information about a child.
For example, unless specifically necessary for a feature, you should not provide:
- home address
- school address
- telephone number
- exact location
- government identification numbers
- medical information
- passwords
- financial information
- other highly sensitive information.
2.3. Generated Content
We process information submitted by you to generate personalized stories and related content.
Generated stories may contain personal information supplied during the creation process.
2.4. Payment Information
Where you purchase a paid product or subscription, payment processing may be handled by a third-party payment provider.
Taleino does not intend to store complete payment card numbers or security codes on its own systems.
We may receive and retain limited transaction information necessary for:
- confirming a purchase;
- providing the purchased service;
- subscription management;
- refunds;
- accounting and legal obligations;
- customer support.
The specific payment provider(s) used by Taleino will be identified in the applicable list of third-party service providers where required.
2.5. Technical Information
When you access Taleino, certain technical information may be processed automatically, including:
- IP address;
- browser type;
- operating system;
- device type;
- approximate technical location derived from IP address, where applicable;
- language and regional settings;
- timestamps;
- pages or features accessed;
- technical logs;
- security and diagnostic information.
2.6. Usage and Analytics Data
Depending on the services actually implemented on Taleino, we may process:
- page views;
- feature usage;
- interaction events;
- session information;
- performance information;
- error and diagnostic information.
Non-essential analytics technologies will be used only in accordance with applicable consent requirements.
2.7. Communications
If you contact us, we may process:
- your email address;
- name, if provided;
- the content of your message;
- information necessary to respond to your request.
We may retain correspondence where reasonably necessary for customer support, security, legal compliance, or dispute resolution.
3. Children's Personal Data
3.1. Nature of the Service
Taleino creates personalized children's stories. As a result, users may voluntarily provide limited information relating to a child.
The person creating a story is responsible for ensuring that they have the appropriate authority to provide information about the child.
3.2. Data Minimization
Taleino is designed to require only information reasonably necessary for story personalization.
We encourage parents and guardians to use a child's first name, nickname, or fictional name instead of providing unnecessary identifying information.
3.3. No Child-Focused Advertising
We do not intend to use children's personal data for behavioral advertising or targeted advertising.
Children's information submitted for story personalization is not collected for the purpose of building advertising profiles.
3.4. Accounts
Taleino is primarily intended for adults, including parents and legal guardians.
The child is not the account holder or user of the Service. The account holder is the parent or legal guardian, who creates the account and provides the child's information on the child's behalf.
3.5. Parental and Guardian Requests
A parent or legal guardian may contact us regarding personal data relating to a child and may request access, correction, deletion, or other applicable data protection rights.
Where necessary, we may take reasonable steps to verify the identity and authority of the person making such a request.
Children receive special protection under the GDPR, and organisations should take particular care when processing children's personal data.
4. Purposes of Processing
We may process personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Creating and managing user accounts | Performance of a contract |
| Providing personalized stories | Performance of a contract |
| Processing purchases and subscriptions | Performance of a contract / legal obligation |
| Delivering purchased digital content | Performance of a contract |
| Customer support | Performance of a contract / legitimate interest |
| Sending transactional communications | Performance of a contract |
| Sending marketing communications | Consent, where required |
| Improving the Service | Legitimate interest and/or consent, depending on the technology used |
| Security and fraud prevention | Legitimate interest / legal obligation |
| Technical diagnostics | Legitimate interest |
| Accounting and tax compliance | Legal obligation |
| Responding to legal requests | Legal obligation / legitimate interest |
5. Legal Bases for Processing
Where the GDPR applies, we rely on the following legal bases under Article 6 GDPR, as applicable.
5.1. Performance of a Contract
We process data necessary to:
- create and maintain an account;
- provide personalized stories;
- process purchases;
- deliver digital products;
- provide customer support;
- send necessary transactional communications.
5.2. Consent
We may rely on consent where required, including for:
- certain non-essential cookies;
- optional analytics;
- marketing communications;
- other optional processing specifically presented to the user.
Consent may be withdrawn at any time.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5.3. Legitimate Interests
Where appropriate, we may process personal data based on legitimate interests, including:
- maintaining platform security;
- preventing abuse and fraud;
- troubleshooting;
- improving service reliability;
- protecting our legal rights;
- maintaining appropriate business records.
Where we rely on legitimate interests, we consider the rights and interests of the individual, particularly where children's data may be involved.
5.4. Legal Obligations
We may process and retain information where necessary to comply with applicable:
- tax requirements;
- accounting requirements;
- legal requests;
- regulatory obligations;
- dispute resolution requirements.
6. Cookies and Similar Technologies
Taleino may use cookies and similar technologies.
Cookies may be used for:
- authentication;
- security;
- preferences;
- language settings;
- essential functionality;
- analytics;
- marketing, where applicable and permitted.
Details regarding cookies and their purposes are provided in the separate Cookie Policy.
Non-essential cookies and similar technologies requiring consent will not be activated before the required consent is obtained.
7. Third-Party Service Providers
Taleino may use third-party providers to operate the Service.
Depending on the actual technical implementation, these providers may include services for:
- hosting and infrastructure;
- authentication;
- payment processing;
- email delivery;
- analytics;
- customer support;
- content generation or AI processing;
- security and fraud prevention.
Only providers actually used by Taleino will be included in the final public subprocessors list.
Where applicable, third-party providers process personal data on our behalf under appropriate contractual arrangements.
We do not sell users' personal data.
8. AI and Automated Processing
Taleino may use artificial intelligence or automated systems to generate personalized stories.
Where AI or other third-party processing services are used:
- only information necessary for the requested functionality should be submitted;
- personal data should be minimized where technically possible;
- third-party providers may process submitted information in order to provide the requested service;
- the specific providers and applicable processing arrangements will be identified where required.
Taleino does not use children's personal data to create advertising profiles.
Where automated processing produces content, the resulting story is generated content and may contain inaccuracies, unexpected elements, or inappropriate associations. Parents or guardians remain responsible for reviewing generated content before sharing it with a child.
9. International Data Transfers
Taleino may use service providers located outside the country in which the user resides.
Where personal data is transferred outside the European Economic Area and the GDPR applies, Taleino will use an applicable legal transfer mechanism, where required, such as:
- an adequacy decision;
- Standard Contractual Clauses;
- another lawful transfer mechanism under applicable data protection law.
The specific transfer mechanisms may depend on the providers actually used by Taleino.
The EDPB identifies international data-transfer safeguards and appropriate technical and organisational measures as part of GDPR compliance.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required by law.
Retention periods may depend on the type of data.
Account Data
Account information is generally retained while the account remains active.
After account deletion, information is deleted or anonymized within a reasonable period, except where retention is required for legal, accounting, security, fraud-prevention, or dispute-resolution purposes.
Story and Personalization Data
Story personalization data is retained for as long as necessary to provide the requested functionality and maintain the user's account or purchased content.
Users may request deletion of applicable data.
Transaction Records
Certain transaction and accounting records may need to be retained for the period required by applicable tax and accounting legislation.
Technical and Security Logs
Security and technical logs may be retained for a limited period appropriate to security, troubleshooting, and legal requirements.
Backups
Deleted information may remain temporarily in encrypted backups until those backups are overwritten according to the applicable backup cycle.
We do not use backups as a reason to indefinitely retain personal data.
11. Data Subject Rights
Where the GDPR applies, individuals have rights including:
11.1. Right of Access
You may request confirmation as to whether we process your personal data and request access to that data.
11.2. Right to Rectification
You may request correction of inaccurate or incomplete personal data.
11.3. Right to Erasure
You may request deletion of personal data where applicable.
This right is not absolute and certain information may need to be retained where required by law or necessary for the establishment, exercise, or defence of legal claims.
11.4. Right to Restriction
You may request restriction of processing in circumstances provided by applicable law.
11.5. Right to Data Portability
Where applicable, you may request your personal data in a structured, commonly used, machine-readable format.
11.6. Right to Object
You may object to certain processing, including processing based on legitimate interests, where the legal conditions for doing so are met.
11.7. Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal does not affect processing carried out lawfully before withdrawal.
The GDPR provides individuals with rights including access, rectification, erasure, restriction, objection, and portability.
12. Exercising Your Rights
To exercise your privacy rights, contact:
Subject:
“Privacy Request”
Please describe:
- the right you wish to exercise;
- the account email address, if applicable;
- sufficient information for us to understand and process the request.
We may request reasonable information necessary to verify the identity of the requester and prevent unauthorized disclosure of personal data.
We aim to respond to GDPR requests within the time limits required by applicable law.
13. Account Deletion
Users may request deletion of their Taleino account by contacting:
Where the Service provides a direct account deletion function, users may also use that functionality.
Following a deletion request:
- The account may be disabled or access may be restricted.
- Personal data that is no longer required will be deleted or anonymized.
- Data that must legally be retained may be retained for the applicable statutory period.
- Information stored in backups may remain until the normal backup retention cycle expires.
14. Data Security
We implement reasonable technical and organizational measures designed to protect personal data against:
- unauthorized access;
- accidental loss;
- destruction;
- alteration;
- unauthorized disclosure;
- other unlawful processing.
Depending on the actual technical architecture, these measures may include:
- encrypted connections;
- access controls;
- authentication controls;
- password hashing;
- restricted administrative access;
- security monitoring;
- backups;
- software and infrastructure updates.
Specific security measures may change as the Service develops.
No internet-based service can guarantee absolute security.
15. Personal Data Breaches
If we become aware of a personal data breach, we will assess the incident and take appropriate measures in accordance with applicable law.
Where required, we will notify the relevant supervisory authority and affected individuals within the applicable statutory timeframes.
We do not guarantee that every security incident will require notification, as notification requirements depend on the nature and risk of the incident.
16. Children's Privacy and Safety
Taleino treats children's privacy and safety as a priority.
We encourage parents and guardians to:
- provide only information necessary for personalization;
- avoid submitting sensitive information;
- use a nickname or first name where possible;
- review generated stories before giving them to a child;
- contact us if they believe a child's personal information has been submitted improperly.
If we become aware that we have collected personal data from a child in circumstances where appropriate authorization was required, we will take reasonable steps to address the situation, including deletion where appropriate.
17. Supervisory Authorities
If you are located in the European Union or European Economic Area, you generally have the right to lodge a complaint with the data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement.
Information about EU data protection authorities is available through the European Data Protection Board.
For users in Ukraine, complaints may be addressed to the competent Ukrainian data protection authority in accordance with applicable Ukrainian law.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Changes may be made to reflect:
- changes to the Service;
- new processing activities;
- new service providers;
- changes in applicable law;
- improvements to our privacy practices.
The updated version will be published on Taleino.com.
Where required by law, we will provide additional notice or obtain renewed consent before introducing material changes that require it.
19. Contact Information
For privacy-related questions and requests:
Email: [email protected]
General Support: [email protected]
Data Controller:
FOP Gaitan Kyrylo Oleksandrovych
Country of registration: Ukraine
Website: Taleino.com
Privacy Policy URL:
Taleino.com/legal/privacy
This Privacy Policy is effective as of September 12, 2026.