Skip to content

Privacy policy

STORY BUG LTD – PRIVACY POLICY

This privacy policy applies to Story Bug Ltd, trading as "Jules Stories" (we, us or our). It covers our mobile application, our website, our forthcoming web application, and the Jules device and its accessories.

Our service allows a parent (account holder) to create an account and add one or more child profiles. Child profiles are not separate accounts: the account holder manages consents and exercises data protection rights on behalf of each child. References in this policy to "you" mean the account holder, and references to a "child" or "child profile" mean a minor whose data is processed through your account.

Please note

  • We never sell personal data.
  • We never share a child's conversations, voice or profile with advertisers or marketing providers.
  • We never use a child's data to target advertising, and we never profile children for marketing.
  • No child-level data is ever sent to an analytics provider.

Information we collect

Account holder information

  • Email address, full name, display name and phone number
  • Locale and timezone
  • Last login and account status
  • Subscription and purchase records
  • Free-text support tickets and correspondence with us

Child profile information

  • Nickname (which may include the child's actual name if you choose to enter it)
  • School year
  • Primary language and language the child optionally wants to develop through Jules
  • Learning goals
  • Session frequency and quiet hours settings
  • Timezone
  • Consent flags recorded at profile set-up
  • Verbatim transcriptions of the child’s spoken or typed interactions with the device
  • Story prompts typed or spoken by the child
  • To let Jules carry on a story from one moment to the next, we keep a short running summary of the current conversation and a small list of continuity notes, for example the name of a character in the story or that your child chose to practise Spanish. These are created automatically, limited in length and number, checked by a safety filter before they are stored, and used only to keep the conversation coherent. They are tied to a conversation, not built into a profile of your child.

Device information

  • Device serial number, firmware version and battery level
  • Last-seen/connectivity timestamp
  • Wi-Fi network name
  • Wi-Fi signal strength
  • Names of paired Bluetooth devices
  • Free-text error logs

As each device is linked to one child, all device information is treated as personal data about that child.

Service related information

  • Transaction details for products and services you’ve purchased from us or enquiries about our products and services
  • Your preferences for our services and your marketing preferences
  • Feedback, complaints and compliments and survey responses

Financial and payment information

  • Payment details for products and services you’ve purchased from us (including where relevant, credit reference information) and where relevant banking or payment card information

Digital information

  • IP address and general location information derived from your IP address
  • Search and browsing behaviour and user journeys
  • Website usage patterns
  • Cookie preferences and tracking

Professional information (for job applicants and workers)

  • Employment history
  • Professional experience
  • Required authorisations and licences
  • Professional registrations
  • Information about your right to work in the UK

Special category data

This is special information that the law says is more sensitive (sometimes called “sensitive personal data”). We handle special category data with extra care and protection, and we only collect and use these where legally permitted. Because our service is used by children, we treat certain data with the heightened protections that apply to special category and children’s data. In particular this includes:

  • Language spoken at home may indirectly reveal a child’s ethnic or cultural background. We collect it only to present our content in the selected language as well as, where you have provided consent for us to do so, personalise the child’s learning experience.
  • Session frequency and quiet hours settings, taken together, may allow inferences about a child’s sleep routine.
  • Our automated safety review of conversations includes a category for detecting mentions of medical or health topics. Where this is triggered, we may hold an inferred indication of health-related context, even though we do not ask for or store health information directly.
  • We use a child’s voice recording only to convert speech to text (transcription). We do not use voice recordings to identify or verify who a child is.

We only collect and use this information with the account holder’s explicit, informed consent, given at the time a child profile is created. This is a higher standard of consent than we rely on for other, non-special category processing described in this policy.

How we collect personal data

  • Directly from you when you: when you interact with us, contact us, fill out forms.
  • Automatically when you: visit our website, use our technologies, interact with our online services.
  • From third parties: our service providers (including Shopify and our AI providers), and organisations or people authorised by you.

How we use your information

Data protection law requires us to have proper legal reasons for using your personal data. We can only use your information when we have one or more of these legal bases.

  • Consent – You have clearly agreed to us using your personal data for a specific purpose.
  • Performance of a contract – We need to use your information to fulfil a contract with you, or because you’ve asked us to do something before entering into a contract.
  • Legal duty – We must use your information to comply with the law.
  • Vital interests – We need to use your information to protect someone’s life.
  • Public interest – We need to use your information to perform a task in the public interest or carry out official functions that have a clear legal basis.
  • Legitimate interests – We have a genuine business reason to use your information, or a third party does, but only if this doesn’t unfairly override your rights and interests. Where we rely on legitimate interests as our legal basis, we have conducted balancing tests to ensure our interests do not override your fundamental rights and freedoms. These assessments consider:
    • The nature of our legitimate interest
    • The impact on you
    • Any safeguards we can implement
    • Your reasonable expectations
    • The broader context of our relationship

Note that we may process your personal data for more than one legal basis depending on the specific purpose for which we are using your data. We have listed the reasons we process your data and the legal basis below. Please reach out to us if you need further details about the specific legal basis we are relying on to process your personal data.

Managing your account and providing our services

What we use your information for:

  • To enable you to access and use our software, including providing login credentials
  • To provide our services to you, including enabling access to the app, device pairing, and managing your subscription.
  • To contact and communicate with you about our services, including responding to support requests and enquiries and for dealing with complaints or claims
  • Internal record keeping, administrative, invoicing and billing purposes

Legal basis for using this information:

  • Performance of a Contract
  • Legal Duty (for billing and record-keeping requirements)
  • Legitimate interests

Types of information we use:

  • Identity and contact details
  • Service related information
  • Financial Information
  • Digital information

Website enquiries and customer service

What we use your information for:

  • To contact and communicate with you about any enquiries you make with us via our website

Legal basis for using this information:

  • Legitimate interests

Types of information we use:

  • Identity and Contact Data
  • Digital Information

Business improvement and development

What we use your information for:

  • Analytics including profiling on our website
  • Market research and business development
  • To operate and improve our services, associated applications and associated social media platforms

Legal basis for using this information:

  • Legitimate interests

Types of information we use:

  • Digital Information

Marketing and communications

What we use your information for:

  • To send you promotional information about our events and experiences and information that we consider may be of interest to you
  • To run promotions, competitions and offer additional benefits to you

Legal basis for using this information:

  • Legitimate interests

Types of information we use:

  • Identity and Contact Data
  • Digital Information

Legal compliance

What we use your information for:

  • Comply with our legal obligations or if otherwise required or authorised by law

Legal basis for using this information:

  • Legal Duty

Types of information we use:

  • All relevant Personal Data

Automated decision making and profiling

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we use automated decision-making, we will:

  • Inform you of the logic involved
  • Explain the significance and envisaged consequences
  • Provide you with the right to human intervention
  • Allow you to express your point of view
  • Enable you to contest the decision

Safeguarding

Safeguarding children

If, through a child’s use of our device or app, we become aware of information suggesting a child may be at risk of harm or abuse, we may need to act outside the account holder’s usual instructions in order to protect that child. Depending on the circumstances, this may involve sharing relevant information with the account holder, the relevant local authority or social services, or the police.

We assess each situation individually. Any such disclosure is made on the basis that it is necessary to protect the vital interests of the child, and only to the extent necessary for that purpose.

Artificial Intelligence (AI) Technologies

Overview

We use artificial intelligence and machine learning technologies in our business operations and services, including AI tools provided by third parties. We only use these technologies when legally permitted and necessary for our business.

How we use AI

We may use AI technologies to:

  • Convert children’s spoken voice into text
  • Generate conversational responses and story content from that text
  • Convert generated text back into spoken voice
  • Conduct analysis and data processing
  • Generate and modify content and coding
  • Improve and optimise our services and operations
  • Automate routine tasks and communications
  • Personalise your experience with our services
  • Support quality assurance processes
  • Assist with customer support and queries

Data protection and security

  • When we work with third-party AI providers, we ensure they handle your personal data in accordance with privacy laws through contractual requirements and appropriate safeguards.
  • Any information generated or inferred about you by AI technologies is treated as personal data, and you maintain all the rights outlined in this privacy policy. When using AI with your personal data, we commit to transparency and control. We’ll inform you when AI is used to make decisions that may significantly affect you.
  • We maintain human oversight and review of significant AI-generated decisions.
  • Our staff are trained to understand AI limitations and verify outputs before relying on them.
  • We implement processes to verify the accuracy of AI-generated outputs.

Security

  • We use appropriate technical and organisational measures to maintain the security and integrity of your personal data
  • We regularly test and monitor AI outputs for accuracy and reliability

Risk mitigation

  • We regularly assess and document risks associated with using AI to process personal data
  • We implement appropriate measures to address these risks
  • We continuously monitor AI performance and regularly review their impact

Our disclosures of personal data to third parties

We may disclose personal data to:

Service providers

  • AI service providers. This is the core of how Jules works. A child speaks. A transcription provider converts that speech to text. A language model generates the reply or story. A speech provider converts the text back into Jules's voice. A separate safety service screens both what the child says and what Jules says back. We cannot deliver the product without these providers. Our contracts with these providers prohibit them from using your child's data to train their own models.
    • Involves child data: yes. This is the only category that receives a child's voice.
  • IT service providers including external providers for error monitoring and system diagnostics, so we can detect faults and fix them before they affect your child's experience.
    • Involves child data: incidentally. Error reports can contain technical request details. These systems are configured to strip personal information by default. 
  • Data storage providers: Your data has to be stored somewhere, and we store it in London.
    • Involves child data: yes. This is where everything is held.
  • Web hosting and server providers: including for running our website, app and device services requires hosting infrastructure.
    • Involves child data: yes, as above.
  • Payment processors. We use Shopify for the device purchase and Apple and Google Play for in-app purchases. They receive the account holder's payment details. We never see or store your full card number.
    • Involves child data: no.
  • Marketing and advertising providers. Used only on our public website, for people browsing or buying, and only where you have accepted marketing cookies.
    • Involves child data: no, never. We do not advertise to children and we do not profile children for marketing.
  • Analytics providers. Used to understand how our website is used so we can improve it. Our product analytics runs on aggregated figures only.
    • Involves child data: no. No child-level records are ever sent to an analytics provider.

Professional advisers

  • Bankers. To operate the company's accounts and process payments to and from us.
  • Auditors. Because company accounts must be independently examined, which can require access to transaction records.
  • Insurers and insurance brokers. To arrange cover, and if we ever needed to make a claim.
  • Legal advisers. To get legal advice, meet our obligations, or defend a claim.

Business partners

  • Our existing or potential agents including companies that help us sell or distribute the Jules device, such as retail or distribution partners.
  • Our business partners or contractors which may include external developers and specialists to build and maintain the service. Contractors are bound by contract to the same protections we apply ourselves and only get access to what their work requires.
    • Involves child data: possible, for technical contractors working on the systems that hold it.

Corporate transactions

If Story Bug Ltd were ever sold, merged, or raised investment, the buyer or investor and their advisers would need to review what the business holds, including customer records, as part of that process. If a sale completed, customer data would transfer to the new owner. Your rights and this policy's protections travel with the data: a new owner takes it on the same terms and cannot repurpose it without telling you. Any review before a sale happens under confidentiality obligations, and we share the minimum necessary.

Legal and regulatory bodies

We do not hand over information on request. We check that a request is lawful and properly made, and we disclose only what is legally required.

  • Courts and tribunals. Where a court orders disclosure, or where information is needed for legal proceedings.
  • Regulatory authorities. Where a regulator such as the ICO requires it, including mandatory reporting obligations.
  • Law enforcement officers. Where the police make a lawful request, or where we have a legal duty to report.

Other parties

  • Third parties you have authorised. Where you have asked us to share your information with someone, or have connected another service yourself.
  • Emergency services when necessary. This is the safeguarding case, and it should be stated plainly: if we ever became aware that a child was at immediate risk of serious harm, we would contact emergency services or social services.
  • Any other parties as required or permitted by law.

What we never do

  • We never sell personal data.
  • We never share a child's conversations, voice or profile with advertisers or marketing providers.
  • We never use a child's data to target advertising, and we never profile children for marketing.
  • No child-level data is ever sent to an analytics provider.

Overseas transfers

Where we store and access your information

We store your personal data in the United Kingdom. However, your information may be transferred to locations outside the United Kingdom in these circumstances:

  • When our service providers are located overseas
  • When we work with overseas business partners
  • When using cloud-based services or data storage solutions
  • When required by law or legal proceedings

Our approach to overseas transfers

When we transfer your personal data outside the United Kingdom, we ensure it receives appropriate protection by:

  • Only transferring your information to countries that UK data protection law recognises as providing adequate protection for personal data, or
  • Putting in place a contract with the third party that means they must protect personal data to the same standards as the UK.
  • Transferring personal data to organisations that are part of specific agreements on cross-border data transfers with the UK.

What this means for you

We only transfer the minimum amount of personal data necessary and require all recipients to:

  • Protect your information to the same standards required by UK law
  • Use your information only for the purposes we've agreed
  • Allow us to monitor how they handle your information
  • Provide you with the same rights over your information that you have under UK law

Data retention

How long we keep your information

We only keep your personal data for as long as we need it to:

  • Provide our services to you
  • Meet our legal, tax, accounting or regulatory obligations
  • Handle any complaints or legal issues that may arise

We may keep your information for longer periods if:

  • You make a complaint that we need to investigate or respond to
  • We reasonably believe legal action involving our relationship with you might occur
  • The law requires us to keep it for specific timeframes

How we decide retention periods

When determining how long to keep your information, we consider:

  • How much information we have and how sensitive it is
  • The risk of harm if the information was accessed without permission
  • Whether we can achieve our purposes in other ways
  • What legal, regulatory, tax or accounting rules require
  • The nature of our relationship with you and the services we provide

What happens when we no longer need your information

Once we no longer need your personal data, we will securely delete or destroy it in accordance with our data retention policies and legal requirements.

Your Rights

You can request information about retention periods for your data and ask for early deletion where legally possible.

Your privacy rights and choices

Providing information

You can choose whether to provide personal data to us, however, if you don't provide certain information, we may not be able to provide some services. Let us know if you don’t want to provide information and we will let you know when information is required versus optional.

Right of Access

You have the right to ask us for copies of your personal data. You can request other information such as details about where we get personal data from and who we share personal data with. There are some exemptions which means you may not receive all the information you ask for.

Exercising rights on behalf of a child

Child profiles are managed through an account holder's account rather than as independent accounts, so the account holder exercises data protection rights (including access, rectification and erasure) on behalf of each child linked to their account. We may ask the account holder to verify their relationship to the child before acting on a request.

Right to Rectification

You have the right to ask us to correct or delete personal data you think is inaccurate or incomplete.

Right to Erasure (“Right to be forgotten”)

You can request deletion of your personal data in certain limited circumstances as set out in data protection law, such as where the data is no longer necessary or has been unlawfully processed. This right is not absolute and we may be required or entitled to retain your data for legal, regulatory or legitimate business reasons.

Right to Restrict Processing

You can ask us to suspend processing where:

  • You contest the accuracy of the data
  • Processing is unlawful but you don't want erasure
  • We no longer need the data but you need it for legal claims
  • You've objected to processing pending verification of our legitimate grounds

Right to opt-out of marketing communications

You can opt-out of receiving marketing communications at any time. Each marketing communication will include an unsubscribe option. You can change your marketing preferences by contacting us. We will process your request without undue delay.

Right to Data Portability

Where technically feasible, you can receive your personal data in a structured, commonly used format or have it transmitted to another controller where:

  • Processing is based on consent or contract
  • Processing is automated

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds.

Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

How to Exercise Your Rights

To exercise any of these rights, contact us using the details below. We may ask for proof of identity and will respond within one month (extendable to three months for complex requests).

These rights are available under data protection law, though some may not apply in every situation. We'll let you know if any limitations apply when you make a request.

Making a complaint

If you're unhappy with how we've used your personal data, please get in touch with us first using the contact details at the end of this policy. When you contact us:

  • Give us full details about your complaint and we will acknowledge your complaint within one month of receiving it (starting the day after we receive it). We will usually respond using the same method you used to contact us, unless you ask us to use a different method. If you contact us through social media, we will ask for an alternative secure contact method.
  • We will investigate your complaint without undue delay. We will begin investigating as soon as we receive your complaint. We will review all relevant facts, speak to relevant staff, and check that we have followed our own policies and standards. The time this takes depends on the complexity and scale of the issue and any harm you are suffering.
  • We may contact you for more information if we are not sure what your complaint is about or to ask what outcome you are looking for. This helps us resolve your complaint more quickly.
  • We will keep you updated on progress throughout our investigation. We will provide you with updates on timeframes, explain any delays, give you an expected completion date, and provide a point of contact for any questions.

If you are not satisfied with our response to your complaint, you can also make a complaint directly to the Information Commissioner's Office (ICO), the UK's data protection regulator, at any time.

The ICO’s address:           

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Helpline number: 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint

You don't have to contact us first before going to the ICO, but we'd appreciate the opportunity to try to resolve your concerns directly with you.

Protecting your information

We use multiple layers of security to protect your information.

Technical safeguards

  • Enterprise-grade encryption for data storage and transmission
  • Regular security testing and monitoring
  • Automated threat detection systems

Operational security

  • Staff training on security and privacy
  • Strict access controls based on job requirements
  • Regular security audits and incident response procedures testing

Physical security

  • Secure premises with controlled access
  • Secure disposal of physical documents
  • Equipment security protocols

Public information

Please note that any information you choose to share publicly on online platforms (such as comments or reviews) can be accessed and used by others. We cannot control or protect information that you make publicly available.

Cookies and analytics

Cookies and pixels

We use cookies and similar tracking technologies on our website to enhance your browsing experience and improve our services.

What are cookies?

Cookies are small text files that are stored on your device when you visit our website. They help us remember your preferences and understand how you use our site.

Types of cookies we use

  • Essential cookies: Necessary for the website to function properly
  • Performance cookies: Help us understand how visitors interact with our website
  • Functionality cookies: Remember your preferences and settings
  • Marketing cookies: Used to deliver relevant advertisements and track campaign effectiveness

Cookie consent

When you first visit our website, you will see a cookie notice explaining our use of cookies. You can choose which types of cookies to accept through our cookie preference centre. You’ll find more information about the cookies we use in our cookie pop-up.

Managing your preferences

You can change your cookie preferences at any time by:

  • Using our cookie preference centre on the website
  • Adjusting your browser settings to refuse or delete cookies
  • Visiting our cookie policy for detailed information about specific cookies

Please note that disabling certain cookies may affect the functionality of our website and your user experience.

Google Analytics

We use Google Analytics to understand how people use our website. This involves cookies that collect information about your browsing activity. You can opt out of Google's advertising features through your Google account settings, browser add-ons, or your device's privacy settings. Google provides various tools and options to control how your data is used for advertising purposes. You can learn more about how Google uses your data and your available options on Google's privacy pages.

Meta advertising tools

We use Meta's advertising tools (such as Meta Pixel) to understand how our ads perform and to show you more relevant advertisements on Meta platforms like Facebook and Instagram when you visit our website or app. You can manage whether we connect information from our website with your Meta account for advertising purposes by adjusting your settings within your Meta account preferences.

When you sign in with another account (like Apple or Google)

What we collect

When you use single sign-on to connect with us, we'll receive personal data from that provider based on your privacy settings with them. This may include your name, username, profile picture, and other details you've chosen to share.

How we use it

We use this information to create your profile on our platform and give you access to our services.

Use of location services data

The Android and iOS operating systems require location permission to be granted before an app can scan for and connect to nearby Bluetooth devices. We request this permission solely to allow your mobile device to pair with the Jules device - we do not read or store any location coordinates, and location permission will not be used to determine where you or your child are.

You may see a request for location permission during device set-up, and this permission will be listed on the Apple App Store and Google Play Store privacy labels for our app as a result.

Separately, we store the name of your Wi-Fi network as part of your device's connection settings. Wi-Fi network names can, in some cases, be used together with public databases to estimate a general location, and we treat this as a privacy-sensitive piece of information accordingly.

If you do not wish to grant location permission, you can decline it in your device settings, though this will prevent the Jules device from pairing with your mobile device.

Amendments

We may update this policy at any time by posting the revised version on our website. We recommend that you review our website regularly to stay current with any policy changes. When material changes warrant active notification and re-consent for consent-dependent purposes, we will notify our users directly.

Our contact details

Privacy contact email: support@JulesStories.com

Address: 124 City Road, London, England

ICO Registration Number: ZB928887

Last update: 29 August 2026

© LegalVision Law UK Ltd