Privacy Policy

Last Updated: January 20, 2026

At earsy, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personalized audio storytelling platform.

By using earsy, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

Personal Information

When you register for earsy, we collect:

  • Email address (for account creation and communication)
  • Name (for personalisation and account management)
  • Password (stored securely using BCrypt hashing)
  • Organisation name (for multi-tenancy features)

Child Profile Information

If you create child profiles, we collect:

  • Child's name (for story personalisation)
  • Gender (optional, for story filtering and personalisation)
  • Age (optional, for age-appropriate content recommendations)
  • Custom personalisation fields (e.g., favorite places, pet names)

We do not share child profile information with third parties for marketing purposes.

Usage Information

We automatically collect:

  • Story generation history (which stories you've personalized)
  • Story likes and reviews
  • Credit usage and subscription status
  • Session data for authentication
  • Leaderboard participation data (anonymized unless you opt in)

Payment Information

Payment processing is handled by Stripe. We do not store your credit card information directly. Stripe collects payment card details, billing address, and payment history according to their Privacy Policy.

2. How We Use Your Information

We use your information to:

  • Provide personalized stories: Generate audio content with your child's name and custom details
  • Manage your account: Authentication, session management, and user preferences
  • Process payments: Handle subscriptions and credit purchases via Stripe
  • Send transactional emails: Account verification, password resets, invitation emails, and subscription updates
  • Improve our service: Analyze usage patterns to enhance story recommendations and platform features
  • Customer support: Respond to inquiries and resolve technical issues
  • Legal compliance: Fulfill legal obligations and enforce our Terms of Service

We do not: Sell your personal information to third parties or use it for targeted advertising.

3. Third-Party Services

We work with trusted third-party service providers to deliver our platform. These services have access to limited information necessary to perform their functions:

ElevenLabs (Text-to-Speech)

Purpose: Generates personalized audio segments with your child's name

Data Shared: Text snippets containing names and personalisation fields (no email addresses or account information)

Privacy Policy: elevenlabs.io/privacy

Stripe (Payment Processing)

Purpose: Handles subscription billing and payment processing

Data Shared: Email, name, payment card details (processed directly by Stripe, not stored by earsy)

Privacy Policy: stripe.com/privacy

Mailtrap (Email Delivery)

Purpose: Delivers transactional emails (verification, password reset, invitations)

Data Shared: Email address, name, and email content

Privacy Policy: mailtrap.io/privacy-policy

Amazon Web Services (AWS)

Purpose: Cloud infrastructure for audio file storage and caching

Services Used: S3 (audio file storage), DynamoDB (audio insert caching)

Data Shared: Generated audio files and cached audio segments

Privacy Policy: aws.amazon.com/privacy

Axiom (Log Aggregation)

Purpose: Server log aggregation and observability (EU region)

Data Shared: Server logs which may include IP addresses, request paths, timestamps, and error information (no personal account data or passwords)

Privacy Policy: axiom.co/privacy

Note: All third-party services are carefully selected for their security and privacy practices. We ensure data is transmitted securely using encryption and only share the minimum information necessary.

4. Data Storage and Security

We implement industry-standard security measures to protect your information:

  • Password Protection: All passwords are hashed using BCrypt encryption
  • Secure Connections: All data transmitted to and from earsy is encrypted using HTTPS/TLS
  • Database Security: User data is stored in secure PostgreSQL databases with access controls
  • Session Management: Secure, time-limited session tokens with HttpOnly cookies
  • Access Controls: Organisation-based data isolation ensures users only access their own data

While we take reasonable measures to protect your information, no internet transmission is completely secure. You are responsible for maintaining the confidentiality of your account credentials.

5. Children's Privacy

earsy is designed for parents and guardians to create personalized content for children. We do not knowingly collect personal information directly from children under 13.

  • Child profiles are created and managed by adult account holders
  • Child information is used solely for story personalisation
  • We do not share child data with third parties for marketing
  • Parents can delete child profiles at any time from their account settings
  • ElevenLabs receives only text snippets for audio generation (e.g., "Emma" or "London") without identifying information

If you believe we have inadvertently collected information from a child, please contact us immediately.

6. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

Access: Request a copy of the personal information we hold about you
Correction: Update or correct inaccurate information via your account settings
Deletion: Request deletion of your account and associated data
Portability: Download your generated stories and data
Objection: Object to certain processing of your information

To exercise these rights, please contact us at privacy@earsy.ai

7. Cookies and Tracking

earsy uses cookies for essential functionality:

  • Authentication Cookies: Session token to keep you logged in (auth_token)
  • Security Cookies: CSRF protection tokens to prevent unauthorized requests

We do not use: Third-party advertising cookies, tracking pixels, or analytics cookies.

8. Data Retention

We retain your information for as long as necessary to provide our services:

  • Account Data: Retained while your account is active
  • Generated Stories: Stored for re-download; deleted when you delete your account
  • Payment Records: Retained for 7 years for accounting and legal compliance
  • Session Tokens: Automatically expire after period of inactivity

When you delete your account, we remove personal information within 30 days, except where retention is required by law.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

  • Posting the updated policy on this page with a new "Last Updated" date
  • Sending an email notification to your registered email address

Continued use of earsy after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

We aim to respond to all privacy inquiries within 7 business days.

0:00 / 0:00