Your data, your story.
Last updated: 28 April 2026
At cuentoconlaIA.com (the “Service”) we process only the data strictly necessary to generate and deliver your personalised book. This policy is governed by Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD) and Spanish Law 34/2002 on Information Society Services (LSSI-CE).
1. Who we are
The data controller is Nexo Apex S.L. (trading as cuentoconlaIA.com), Spanish CIF B55467146, registered at Edificio Camí Reial, c/ Camí Reial 13-17, 3rd floor, 43700 El Vendrell, Tarragona, Spain.
For any matter related to your personal data:
- General email: hola@cuentoconlaIA.com
- Privacy: privacidad@cuentoconlaIA.com
- Phone: +34 659 696 741
- Data responsible person (functional DPO): David Pelayo — david@nexoapex.com / dpo@cuentoconlaIA.com
2. What data we collect
We collect only the following data:
- Email. Required to deliver your book and notify you when it’s ready.
- IP address & user-agent. Collected automatically by API Gateway (CloudFront access logs are disabled in this release). Retained in application logs for the period in §4 and used solely for technical diagnostics and abuse prevention.
- Onboarding prompts & choices. What you write or select while creating the book (mode, mission, style, title, etc.).
- Uploaded photos. The images you upload to personalise the book. They may include biometric data insofar as AWS Rekognition performs face detection solely for moderation purposes (no training, no identity recognition). They are deleted automatically after 30 days. They are never used to train AI models.
- Payment metadata. Stripe processes your card data — we never see or store it. We retain only the PaymentIntent identifier (
pi_…), the last four digits, and the issuing country, for billing and incident-investigation purposes. - Cookies. Detailed in the cookies policy.
Children’s data. The Service is intended for adults. Photos uploaded may include images of minors — by uploading them, the adult buyer declares to hold parental authority or legal guardianship and to authorise the processing pursuant to Article 7 LOPDGDD.
3. Purpose & legal basis
We process your data for the purposes below on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Book generation & delivery | Performance of contract — Art. 6(1)(b) GDPR |
| Transactional notifications (preview ready, book ready, error) | Performance of contract — Art. 6(1)(b) GDPR |
| Payment processing & invoicing | Performance of contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) (tax retention) |
| Marketing communications (newsletters, offers) | Consent — Art. 6(1)(a) (opt-in checkbox at checkout) |
| Web analytics (GA4) | Consent — Art. 6(1)(a) (cookie banner) |
| Abuse prevention, content moderation, security | Legitimate interest — Art. 6(1)(f); parental consent for biometric data — Art. 9(2)(a) + Art. 7 LOPDGDD |
4. Retention
We retain data for the following periods:
- Uploaded photos: 30 days from upload, then automatically deleted.
- Generated books (PDFs & pages): 365 days, or until you request deletion.
- Account data & email: until you withdraw consent or exercise erasure rights.
- Invoices & tax data: 6 years per Spanish Commercial Code (Art. 30 CCom).
- Application logs (incl. IP, user-agent): 30 days.
- Analytics data (GA4): 14 months, EU default.
5. Recipients
We do not sell your data. To deliver the Service we rely on the following processors, with whom we have signed the corresponding Data Processing Agreements:
| Provider | Function | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, storage, transactional email (SES), moderation (Rekognition) | Luxembourg / Ireland (EU) |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) |
| OpenAI L.L.C. | AI text and image generation | USA (SCC + DPF) |
| Anthropic PBC | Optional AI image-safety verification | USA (SCC) |
| Cloudflare, Inc. | Anti-abuse (Turnstile) | USA / EU (SCC + DPF) |
| Google Ireland Ltd. (Analytics) | Web analytics — only if you accept analytics cookies | Ireland and USA (SCC + DPF) |
6. International transfers
Some processors (OpenAI, Anthropic, Cloudflare, Google) process data in the United States. Such transfers are based on:
- The Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914).
- The provider’s adherence to the EU-US Data Privacy Framework (adequacy decision of 10 July 2023), where applicable.
- Additional technical measures: encryption in transit (TLS 1.3) and at rest.
Under no circumstances do we authorise these providers to train their models on your data: usage is contractually limited to providing the Service.
7. Your rights
As a data subject you have the following rights, exercisable free of charge:
- Access the data we hold about you.
- Rectification of inaccurate data.
- Erasure (“right to be forgotten”) when no longer needed for the purpose.
- Objection to processing based on legitimate interest.
- Restriction of processing while accuracy or legitimacy is verified.
- Portability of data in a structured, common-use format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Not be subject to automated decisions with legal/significant effect. AI book generation is a creative tool that, in our current interpretation, does not constitute an automated decision with legal effect on you within the meaning of Art. 22 GDPR. If AEPD or another competent authority reinterprets this classification, we will update this policy and notify you.
To exercise any right, email privacidad@cuentoconlaIA.com indicating the right you exercise and including reasonable proof of identity (e.g. the email used to purchase). We respond within 30 days.
8. Changes to this policy
This policy was first published on 28 April 2026. We may update it to reflect legal, functional or sub-processor changes. For material changes (e.g. new sub-processors, new purposes) we will notify registered users by email at least 30 days before the new policy takes effect.