Privacy Policy
Last updated: 2026-05-12 · Draft v1
Short version
- We collect only what's needed to make and deliver your audiobook.
- We never sell your data.
- Your kids' names are never used to train AI models.
- We don't share data with advertisers or marketers.
- We don't track you across the web.
- Audio files belong to you. Ask for deletion any time and we remove everything within 30 days.
1. What we collect
To make and deliver your audiobook, we collect:
- Your email — to deliver the audiobook and account-related notices.
- Your trip — cities, activities, dates you provide in the wizard.
- Your kids' first names + ages — to personalize the audiobook. Just first names. No last names, no addresses, no school information.
- Voice + character picks — your choices for narrator, companion, and per-kid voices.
- Payment metadata — Stripe handles the actual card data. We see only a transaction ID and the last 4 digits.
- Generated content — the audiobook script and audio files we produce for you, plus the cartoon trip image.
- Service logs — basic usage information (IP address, user agent, anonymous session ID) for debugging, fraud prevention, and rate limiting. These are kept for 90 days then automatically deleted.
2. What we don't collect
- Kid last names, school names, addresses, photos, or biometrics.
- Browsing history outside the AudioVenture site.
- Advertising identifiers.
- Health, religious, political, or sexual orientation data.
3. How we use what we collect
- To make and deliver your audiobook.
- To send you the magic-link email and (rarely) service updates about your specific order.
- To prevent abuse of the free wizard tools.
- To improve the service generally (e.g., voice quality, cost dashboards) — using aggregate, non-identifying patterns only.
We do not use your kids' names, your trip details, or any other personal information to train AI models. The AI vendors we work with (Anthropic, OpenAI, ElevenLabs) receive your data only to complete your request, governed by their no-training contractual commitments to us as their business customer.
4. Who we share with
We share data only with vendors who help us deliver the service, each under a written data-processing agreement and confidentiality obligation:
- Anthropic — generates the audiobook script. Receives kid first names, ages, cities, activities.
- ElevenLabs — generates the voice audio. Receives the script text.
- OpenAI — Whisper (audio QA) and gpt-image-1 (cartoon image). Receives audio bytes and the image prompt.
- Resend — delivers the ready email. Receives your email and the player URL.
- Supabase — stores your data (Postgres + audio files). US-based.
- Vercel — hosts the website and runs the audio pipeline. US-based.
- Stripe — processes payments. Sees card data; we don't.
- Inngest — orchestrates the audio generation workflow.
We never sell or rent your data to any third party for advertising, marketing, or any other purpose.
5. How long we keep it
- Order data + audio files: indefinitely, so your magic link keeps working. You can request deletion any time.
- Service logs: 90 days, then automatically deleted.
- Payment records: 7 years (US tax law).
6. Your rights
You can ask us to:
- See a copy of the data we have about you.
- Correct anything that's wrong.
- Delete everything, including audio files (we keep only payment records as legally required).
- Export your data in a portable format.
- Opt out of any future marketing email (we don't do marketing email today, but if we ever do, you'll have an unsubscribe link).
Email customerrelations@audioventure.cc and we'll respond within 30 days, usually within 2 business days.
7. Children's privacy
AudioVenture is purchased by parents on behalf of children. Children under 13 should not create accounts or purchase audiobooks themselves. We handle children's information per our Kids Notice.
8. Where your data lives
Data is stored on US-based servers (Supabase, Vercel, AWS via our vendors). We currently serve US customers only. If you're visiting from outside the US, your data is transferred to and processed in the United States.
9. Security
We use industry-standard practices: encryption in transit (HTTPS), encryption at rest (Supabase Postgres + Storage), service-role keys kept on the server, two-factor authentication on operator accounts. No system is perfectly secure; if a breach occurs, we'll notify affected customers within 72 hours.
10. Changes
We'll update the "Last updated" date when we change this policy. For material changes that affect your rights, we'll send you email notice if we have your email.
11. Contact
Privacy questions go to customerrelations@audioventure.cc.