cuento conlaIA
SampleGalleryBlog
Create story
Documents
ImprintTerms & conditionsPrivacy (GDPR)Cookies
On this page
1. Who we are2. What data we collect3. Purpose & legal basis4. Retention5. Recipients6. International transfers7. Your rights8. Changes to this policy
Privacy policy · GDPR

Your data, your story.

Last updated: 28 April 2026

At cuentoconlaIA.com (the “Service”) we process only the data strictly necessary to generate and deliver your personalised book. This policy is governed by Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD) and Spanish Law 34/2002 on Information Society Services (LSSI-CE).

1. Who we are

The data controller is Nexo Apex S.L. (trading as cuentoconlaIA.com), Spanish CIF B55467146, registered at Edificio Camí Reial, c/ Camí Reial 13-17, 3rd floor, 43700 El Vendrell, Tarragona, Spain.

For any matter related to your personal data:

  • General email: hola@cuentoconlaIA.com
  • Privacy: privacidad@cuentoconlaIA.com
  • Phone: +34 659 696 741
  • Data responsible person (functional DPO): David Pelayo — david@nexoapex.com / dpo@cuentoconlaIA.com

2. What data we collect

We collect only the following data:

  • Email. Required to deliver your book and notify you when it’s ready.
  • IP address & user-agent. Collected automatically by API Gateway (CloudFront access logs are disabled in this release). Retained in application logs for the period in §4 and used solely for technical diagnostics and abuse prevention.
  • Onboarding prompts & choices. What you write or select while creating the book (mode, mission, style, title, etc.).
  • Uploaded photos. The images you upload to personalise the book. They may include biometric data insofar as AWS Rekognition performs face detection solely for moderation purposes (no training, no identity recognition). They are deleted automatically after 30 days. They are never used to train AI models.
  • Payment metadata. Stripe processes your card data — we never see or store it. We retain only the PaymentIntent identifier (pi_…), the last four digits, and the issuing country, for billing and incident-investigation purposes.
  • Cookies. Detailed in the cookies policy.

Children’s data. The Service is intended for adults. Photos uploaded may include images of minors — by uploading them, the adult buyer declares to hold parental authority or legal guardianship and to authorise the processing pursuant to Article 7 LOPDGDD.

3. Purpose & legal basis

We process your data for the purposes below on the following legal bases:

PurposeLegal basis
Book generation & deliveryPerformance of contract — Art. 6(1)(b) GDPR
Transactional notifications (preview ready, book ready, error)Performance of contract — Art. 6(1)(b) GDPR
Payment processing & invoicingPerformance of contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) (tax retention)
Marketing communications (newsletters, offers)Consent — Art. 6(1)(a) (opt-in checkbox at checkout)
Web analytics (GA4)Consent — Art. 6(1)(a) (cookie banner)
Abuse prevention, content moderation, securityLegitimate interest — Art. 6(1)(f); parental consent for biometric data — Art. 9(2)(a) + Art. 7 LOPDGDD

4. Retention

We retain data for the following periods:

  • Uploaded photos: 30 days from upload, then automatically deleted.
  • Generated books (PDFs & pages): 365 days, or until you request deletion.
  • Account data & email: until you withdraw consent or exercise erasure rights.
  • Invoices & tax data: 6 years per Spanish Commercial Code (Art. 30 CCom).
  • Application logs (incl. IP, user-agent): 30 days.
  • Analytics data (GA4): 14 months, EU default.

5. Recipients

We do not sell your data. To deliver the Service we rely on the following processors, with whom we have signed the corresponding Data Processing Agreements:

ProviderFunctionLocation
Amazon Web Services EMEA SARLHosting, storage, transactional email (SES), moderation (Rekognition)Luxembourg / Ireland (EU)
Stripe Payments Europe Ltd.Payment processingIreland (EU)
OpenAI L.L.C.AI text and image generationUSA (SCC + DPF)
Anthropic PBCOptional AI image-safety verificationUSA (SCC)
Cloudflare, Inc.Anti-abuse (Turnstile)USA / EU (SCC + DPF)
Google Ireland Ltd. (Analytics)Web analytics — only if you accept analytics cookiesIreland and USA (SCC + DPF)

6. International transfers

Some processors (OpenAI, Anthropic, Cloudflare, Google) process data in the United States. Such transfers are based on:

  • The Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914).
  • The provider’s adherence to the EU-US Data Privacy Framework (adequacy decision of 10 July 2023), where applicable.
  • Additional technical measures: encryption in transit (TLS 1.3) and at rest.

Under no circumstances do we authorise these providers to train their models on your data: usage is contractually limited to providing the Service.

7. Your rights

As a data subject you have the following rights, exercisable free of charge:

  • Access the data we hold about you.
  • Rectification of inaccurate data.
  • Erasure (“right to be forgotten”) when no longer needed for the purpose.
  • Objection to processing based on legitimate interest.
  • Restriction of processing while accuracy or legitimacy is verified.
  • Portability of data in a structured, common-use format.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.
  • Not be subject to automated decisions with legal/significant effect. AI book generation is a creative tool that, in our current interpretation, does not constitute an automated decision with legal effect on you within the meaning of Art. 22 GDPR. If AEPD or another competent authority reinterprets this classification, we will update this policy and notify you.

To exercise any right, email privacidad@cuentoconlaIA.com indicating the right you exercise and including reasonable proof of identity (e.g. the email used to purchase). We respond within 30 days.

Complaints to the supervisory authority. If you believe the processing does not comply with regulations, you may lodge a complaint with the Spanish Data Protection Authority (AEPD): www.aepd.es, C/ Jorge Juan, 6, 28001 Madrid, Spain. EU residents may also contact their national supervisory authority.

8. Changes to this policy

This policy was first published on 28 April 2026. We may update it to reflect legal, functional or sub-processor changes. For material changes (e.g. new sub-processors, new purposes) we will notify registered users by email at least 30 days before the new policy takes effect.

cuento conlaIA
© 2026 cuentoconlaIA.com · A product by Nexo Apex S.L.