Privacy Policy
August 6, 2026
Fabulada is a free bedtime-story generator. This page explains, plainly, what information passes through the service, why, and for how long. If a sentence here doesn’t match what the product actually does, that’s a bug in the policy — tell us at privacy@fabulada.com.
The short version
There is no account, no sign-up, and no email collection. You type a story topic; we generate a story. There is no child-age field or audience profiling. We do not ask for, and do not store, your child’s name, age, photo, school, location, or any other identifying detail. Nothing about your child is ever saved.
Information we receive
Story topic. The text you type to describe tonight’s story. It is sent to an AI provider to draft the story (see “Who else sees this,” below), and — if the story passes our safety checks — the topic and the finished story become part of the public community library, visible to any visitor. If it doesn’t pass, we still keep a private, unpublished copy so the check can be reviewed later.
IP address. Used briefly to enforce rate limits (so the free service can’t be automated into the ground) and, for 24 hours, to stop the same visitor voting on a story twice. It is not linked to a profile, and we don’t use it to guess who or where you are beyond a coarse, automated region signal used only to pick a dialect for the story’s wording — see “Region and dialect,” below.
Basic request and error logs, generated automatically by our hosting provider, of the kind any web server keeps.
Page views and load performance. Our hosting provider counts which pages are opened, which site linked to them, and how quickly they loaded, so we can tell whether anyone is finding Fabulada and whether the site is fast enough. It sets no cookie, assigns no identifier, and follows nobody from one visit to the next — it is a count of pages, not of people.
Information that stays on your device
Your browser keeps a local, private history of stories you’ve generated — just the story’s id, its link, the topic you typed, and when — so you can find last night’s story again after closing the tab. This lives in your browser’s local storage. It is never sent to us, except that the topic of a story you’ve already read is sent along with a new request so we can avoid handing you a repeat.
Two cookies, and neither is used to track you across sites. One remembers the language you read the site in, and is written only when you pick one yourself. The other holds the two-letter country your browser worked out for itself — nothing more precise — so the site can open in your language the next time you arrive instead of guessing from our host’s reading of your network; it is discarded after a day. Both stay between your browser and this site.
Region and dialect
If your browser or network signals a general region, we use it to choose how a story is worded — verb forms, pronouns, idiom — for the language you’re reading in. When that regional register shapes a published story, its two-letter dialect region is stored with the public story and may guide subtle, non-identifying everyday visual details in an illustration. It is not linked to you, and your precise location is never named, described, or written into a story.
To get that right, your browser asks an outside geolocation service which country your connection is in, and separately reads the time zone your device is set to. The lookup is a direct request from your browser to that service, so it sees your IP address the way any site you visit does; we receive nothing back but a two-letter country code, and neither the service nor the country code is linked to your topic, your story, or anything else about you. The answer is remembered in your browser for a day so the request isn’t repeated. If you block that request — many ad blockers do — everything still works: your time zone decides the dialect instead, and if that is unavailable too the story is written in the standard form of your language.
Who else sees this
Generating and running Fabulada relies on a small number of outside providers, each of which receives the information needed for its role: AI providers draft and moderate story text; a database provider stores stories, rate limits, and the vote and moderation records described above; and a hosting provider runs the site and its automated logs. Their handling is governed by their contracts and published data policies. We do not sell, rent, or trade information to anyone — Fabulada has no advertising and nothing to sell it for.
Because these providers operate in the United States and elsewhere, using Fabulada can involve your topic text crossing borders as part of generating your story.
If an illustration is considered for a verified public story, Cloudflare Workers AI receives the public story inputs needed to create it: the title, safe topic, a short opening excerpt, language, and any stored dialect region. Cloudflare R2 stores the resulting normalized image in a private staging area, public storage after approval, or a private quarantine area after a takedown. We do not send a reader’s age, precise location, account details, or private browser history to either service.
Upstash QStash receives a small signed queue message containing a story identifier and why it was selected; it delivers that message to our worker, which loads the current verified public story itself. Upstash may process service data for operations, security, analytics, and service improvement as described in its published terms and data-processing addendum. Candidate images are not sent to an automated image-moderation provider: an authenticated operator reviews each private candidate and explicitly confirms the child-safety review before publication. The queue message does not contain the story body, and neither provider receives a child profile because Fabulada does not create one.
The community library
A story that passes our safety checks joins a shared library so a similar request from another family costs nothing and arrives instantly. That means the topic you typed and the resulting story are public once published — anyone can read them, and anyone can like them. Nothing that identifies you personally is attached to a published story; only type carefully if the topic itself is something you’d rather not see published, since we can’t always tell a fictional topic from a real one.
Not every public story receives an illustration. A verified story can become eligible after reader likes or be selected by an operator; neither event creates an image in the reader’s browser or on a page view. At launch, generated illustrations are reviewed by a person before publication. Once approved, an illustration is public with its story; a missing, deferred, rejected, or removed illustration is not public.
How long we keep things
Published stories are kept indefinitely — they’re the product’s content, not a cache, and other families keep benefiting from them. Approved illustrations are kept with their published stories unless they are replaced or taken down. Candidate images remain private while they are being reviewed; an illustration that is rejected or taken down is removed from public storage and moved to, or retained in, a private quarantine area only as needed to operate, review, or handle the request. A moderation verdict on a topic is cached for 30 days if the topic was judged safe, keyed to a one-way hash of the topic text rather than the text itself. Rate-limit records expire automatically within minutes. The double-vote guard expires after 24 hours.
Children’s privacy
Fabulada is meant to be used by a parent or guardian on behalf of a child, not directly by a child providing information about themselves. We do not knowingly collect personal information from a child, and by design there is nowhere in the product to enter a child’s name, age, photo, or any other identifying detail. If you believe a child has submitted personal information to us some other way, contact us at privacy@fabulada.com and we’ll remove it.
Your choices and rights
Because there’s no account, there’s usually nothing to log into to exercise a right — clearing your browser’s local storage removes your local history immediately. If you’d like a specific published story removed, or have any other question about your information — access, correction, deletion, or an objection under a law like the GDPR or CCPA that applies to you — email privacy@fabulada.com with a link to the story or a description of the request, and we’ll respond and act on it within a reasonable time.
Security
We rely on our providers’ standard security practices (encryption in transit, access-controlled infrastructure) and keep the amount of information Fabulada handles deliberately small, on the theory that data we never collect can’t be exposed. No online service can guarantee perfect security.
Changes to this policy
Fabulada is pre-launch and still changing. If this policy changes in a way that matters, we’ll update the date at the top of this page. Continuing to use Fabulada after a change means you accept the update.
Contact
Questions, requests, or concerns about privacy: privacy@fabulada.com.