Your data, your story.
Last updated: 31 August 2026
At cuentoconlaIA.com and in our iPhone and Android apps “Bedtime Stories with the AI” / “Cuento con la IA para dormir” (together, the “Service”) we process only the data strictly necessary to generate and deliver your personalised book. This policy covers all three surfaces: they are one product on one infrastructure, and the App Store and Google Play listings both link to this same document. This policy is governed by Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD) and Spanish Law 34/2002 on Information Society Services (LSSI-CE).
1. Who we are
The data controller is Nexo Apex S.L. (trading as cuentoconlaIA.com), Spanish CIF B55467146, registered at Edificio Camí Reial, c/ Camí Reial 13-17, 3rd floor, 43700 El Vendrell, Tarragona, Spain.
For any matter related to your personal data:
- General email: hola@cuentoconlaIA.com
- Privacy: privacidad@cuentoconlaIA.com
- Phone: +34 659 696 741
- Data responsible person (functional DPO): David Pelayo — david@nexoapex.com / dpo@cuentoconlaIA.com
2. What data we collect
We collect only the following data:
- Email. Required to deliver your book and notify you when it’s ready.
- IP address & user-agent. Collected automatically by API Gateway (CloudFront access logs are disabled in this release). Retained in application logs for the period in §4 and used solely for technical diagnostics and abuse prevention.
- Onboarding prompts & choices. What you write or select while creating the book (mode, mission, style, title, etc.).
- Uploaded photos. The images you upload to personalise the book. They may include biometric data insofar as AWS Rekognition performs face detection solely for moderation purposes (no training, no identity recognition). They are deleted automatically after 30 days. They are never used to train AI models.
- Payment metadata. Stripe processes your card data — we never see or store it. We retain only the PaymentIntent identifier (
pi_…), the last four digits, and the issuing country, for billing and incident-investigation purposes. - Cookies. Detailed in the cookies policy.
- Data specific to the mobile apps. On iOS and Android only, and only these three:
- A purchase identifier managed by RevenueCat, together with the transaction identifier the store returns. It exists to validate the in-app purchase and to revoke access to the book if the store grants a refund. It is a per-install pseudonym generated on the device at first launch, not something derived from your name or email. It does not include your card details: the charge is processed by Apple or Google, not by us.
- An Expo push token, and only if you accept the “your book is ready” alert at the confirmation step. The alert text is deliberately generic: it carries neither the child’s name nor the book’s title.
- Anonymous usage events (which screens are opened), sent to Plausible. They use no cookies, read no advertising identifier (no IDFA, no AAID) and are not linked to your email. You can turn them off in Settings.
Children’s data. The Service is intended for adults. Photos uploaded may include images of minors — by uploading them, the adult buyer declares to hold parental authority or legal guardianship and to authorise the processing pursuant to Article 7 LOPDGDD.
3. Purpose & legal basis
We process your data for the purposes below on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Book generation & delivery | Performance of contract — Art. 6(1)(b) GDPR |
| Transactional notifications (preview ready, book ready, error) | Performance of contract — Art. 6(1)(b) GDPR |
| Payment processing & invoicing | Performance of contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) (tax retention) |
| Marketing communications (newsletters, offers) | Consent — Art. 6(1)(a) (opt-in checkbox at checkout) |
| Web analytics (GA4) | Consent — Art. 6(1)(a) (cookie banner) |
| Abuse prevention, content moderation, security | Legitimate interest — Art. 6(1)(f); parental consent for biometric data — Art. 9(2)(a) + Art. 7 LOPDGDD |
| Validating the in-app purchase and revoking access to the book if the store grants a refund | Performance of a contract — Art. 6(1)(b) |
| “Your book is ready” push notification in the mobile apps | Consent — Art. 6(1)(a) (the operating-system permission is the act of consent; you can withdraw it from the phone’s settings at any time) |
| Mobile-app usage analytics (Plausible) | Legitimate interest — Art. 6(1)(f). You may object at any time (Art. 21) from Settings → Privacy, without giving a reason and without losing any functionality. |
4. Retention
We retain data for the following periods:
- Uploaded photos: 30 days from upload, then automatically deleted.
- Generated books (PDFs & pages): 365 days, or until you request deletion.
- Account data & email: until you withdraw consent or exercise erasure rights.
- Invoices & tax data: 6 years per Spanish Commercial Code (Art. 30 CCom).
- Application logs (incl. IP, user-agent): 30 days.
- Analytics data (GA4): 14 months, EU default.
- In-app purchase record: 6 years, alongside the rest of the tax records.
- Push notification token: until you delete the app’s data from Settings or uninstall the app.
5. Recipients
We do not sell your data. To deliver the Service we rely on the following processors, with whom we have signed the corresponding Data Processing Agreements:
| Provider | Function | Location |
|---|---|---|
| Amazon Web Services (contracting entity: AWS EMEA SARL, Luxembourg; data hosted by Amazon Web Services, Inc.) | Hosting, storage, transactional email (SES), moderation (Rekognition) | USA — us-east-1 region (SCC + DPF) |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) |
| OpenAI L.L.C. | AI text and image generation | USA (SCC + DPF) |
| Anthropic PBC | Optional AI image-safety verification | USA (SCC) |
| Cloudflare, Inc. | Anti-abuse (Turnstile) | USA / EU (SCC + DPF) |
| Google Ireland Ltd. (Analytics) | Web analytics — only if you accept analytics cookies | Ireland and USA (SCC + DPF) |
| RevenueCat, Inc. | In-app purchase validation and book-access control in the mobile apps (per-install and transaction identifiers only) | USA (SCC + DPF) |
| 650 Industries, Inc. (Expo) | Delivery of the “your book is ready” push notification in the mobile apps | USA (SCC) |
| Plausible Insights OÜ | Mobile-app usage analytics, with no cookies and no advertising identifiers — switchable off in Settings | Estonia (EU) |
Apple and Google are not our processors. When you buy the book inside the app, the charge is processed by Apple Distribution International Ltd. (Ireland) or Google Ireland Ltd. (Ireland) as independent controllers, under their own privacy policies and as the seller of record for that transaction. We never receive your payment-method data — only the transaction identifier the store hands back. On the web, Stripe Payments Europe Ltd. fills that role as our processor for the charge itself, and as an independent controller for fraud prevention and its own regulatory obligations.
6. International transfers
Some processors (AWS — storage and processing in the us-east-1 region —, OpenAI, Anthropic, Cloudflare, Google and, in the mobile apps, RevenueCat and Expo) process data in the United States. Such transfers are based on:
- The Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914).
- The provider’s adherence to the EU-US Data Privacy Framework (adequacy decision of 10 July 2023), where applicable.
- Additional technical measures: encryption in transit (TLS 1.3) and at rest.
Under no circumstances do we authorise these providers to train their models on your data: usage is contractually limited to providing the Service.
7. Your rights
As a data subject you have the following rights, exercisable free of charge:
- Access the data we hold about you.
- Rectification of inaccurate data.
- Erasure (“right to be forgotten”) when no longer needed for the purpose.
- Objection to processing based on legitimate interest.
- Restriction of processing while accuracy or legitimacy is verified.
- Portability of data in a structured, common-use format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Not be subject to automated decisions with legal/significant effect. AI book generation is a creative tool that, in our current interpretation, does not constitute an automated decision with legal effect on you within the meaning of Art. 22 GDPR. If AEPD or another competent authority reinterprets this classification, we will update this policy and notify you.
To exercise any right, email privacidad@cuentoconlaIA.com indicating the right you exercise and including reasonable proof of identity (e.g. the email used to purchase). We respond within 30 days.
8. Changes to this policy
This policy was first published on 28 April 2026. We may update it to reflect legal, functional or sub-processor changes. For material changes (e.g. new sub-processors, new purposes) we will notify registered users by email at least 30 days before the new policy takes effect.