Skip to main content

Sprongsy

StoriesAbout UsPricingLogin

Sprongsy

Magical stories for children

Information

  • About us
  • FAQ
  • Privacy Policy
  • Terms and Conditions
  • Beta Tester Agreement
  • Contact

© 2026 Sprongsy. All rights reserved.

PrivacyTerms and ConditionsBeta Tester Agreement

Privacy Policy

Last update: February 16, 2026

Beta/Testing Phase

1. Who are we?

Sprongsy is a product of van der Smissen - IT services, based in the Netherlands. During this beta/testing phase, we make our service available to a limited group of users to test functionality, payments, and user experience.

Chamber of Commerce (KvK) number: 75008521 — Contact info@sprongsy.com for questions about our company details.

Contact: info@sprongsy.com

2. Who is Sprongsy for?

Sprongsy is a platform for generating child-safe stories for children aged 4-10 years. Although the stories are intended for children, the account and service are intended for adults (parents/guardians) who share the stories with their children.

Children may only use the service under the supervision of a parent or guardian. We do not collect personal data from children.

Parental responsibility: If a minor creates an account by providing incorrect age information, full responsibility lies with the parent(s) or legal guardian(s). Parents are responsible for supervising their children's internet use. Sprongsy is not liable for use by minors.

3. What personal data do we process?

We only process data necessary to provide our service:

Account data

  • Email address (required)
  • Name (optional)
  • Profile photo (optional)
  • Account ID and creation date

Content you create

  • Generated stories (title, content, theme)
  • Story elements (characters, settings)
  • Generated audio files
  • Favorite marking

Payment data

  • Subscription status and type
  • Stripe customer and subscription ID
  • Payment period and renewal date
  • Operational billing metadata (such as idempotency keys and change timestamps) for fraud prevention and duplicate-mutation protection
  • Webhook event logs and error records for audit, support, and recovery after failed processing
  • Usage of Stripe customer portal sessions (creation timestamp and status) to manage payment details
  • We do not store credit card or bank details

Technical data

  • IP address (for security and rate limiting)
  • Session data (cookies)
  • Device type and browser (via standard HTTP headers)
  • Language preference (stored in your profile for interface and story generation)
  • Timezone (derived from browser for correct date display)

4. Use of AI (OpenAI & Google Gemini)

Our service uses AI for stories and read-aloud audio: OpenAI (GPT) for generating story text, and Google Gemini for text-to-speech (audio). Both process only story-related content, not personal data.

Input: The story settings you choose (theme, characters, story elements) are sent to OpenAI to generate story text. The generated text is sent to Google Gemini (text-to-speech) for the read-aloud feature. We do not store prompts or content with these providers; they may have their own retention policies.

Privacy: We do not send personally identifiable information (such as your email or name) to OpenAI. Only story-related input.

Safety: All generated stories are checked for child safety before being saved.

Disclaimer: AI output may contain inaccuracies. The stories are intended for entertainment, not as educational or professional advice.

Please note: OpenAI is based in the United States. By using our service, you agree to the processing of story-related data outside the EU.

EU AI Act – transparency In accordance with the EU AI Act, we inform you that the stories and read-aloud audio on this service are generated by AI (OpenAI for text, Google Gemini for audio). The content may contain inaccuracies and is for entertainment only.

5. Purposes of processing

We use your data to:

  • • Provide the service and generate stories
  • • Create audio versions of stories
  • • Store your stories in your library
  • • Manage subscriptions and payments
  • • Inform you about your subscription
  • • Secure your account
  • • Prevent abuse (rate limiting)
  • • Comply with legal obligations

6. Legal basis for processing (GDPR)

We process your personal data based on the following legal grounds:

  • Performance of contract: For providing our service, generating stories, managing your account and subscription.
  • Legitimate interest: For security, fraud prevention, rate limiting, and improving our service.
  • Legal obligation: For retaining payment data (tax retention requirements) and complying with other legal obligations.
  • Consent: For sending newsletters and marketing (if you have signed up for this). You can withdraw this consent at any time.

7. Payments & Stripe

Payments are processed by Stripe, Inc., our payment provider. Stripe is responsible for processing your payment details (including card details).

  • • We do not store credit card or bank details ourselves
  • • Stripe processes payments in compliance with PCI-DSS standards
  • • You receive invoices and receipts directly from Stripe
  • • Stripe is based in the United States

See Stripe's privacy policy for more information.

8. Third parties & Sub-processors

We use the following services to provide our service: Supabase (database, authentication, storage), Stripe (payments), OpenAI (story text), Resend (email), Inngest (background jobs).

ServicePurposeLocation
SupabaseDatabase, authentication, file storageEU (AWS Frankfurt)
OpenAIAI story generation (text)US
StripePayment processingUS
ResendEmail deliveryUS
VercelWeb hostingWorldwide (CDN)
Google (Gemini)Text-to-speech (read-aloud audio)US
InngestBackground processing (story generation, audio generation)US

For payments and age verification, Stripe may temporarily process your birth year in checkout session metadata; we do not store this in our database. See Stripe's privacy policy for their processing.

9. International Data Transfer

Sprongsy focuses on the Netherlands and the United Kingdom. To provide our services, your data may be transferred to and processed in countries outside the European Economic Area (EEA).

Data transfer to the US:

  • • OpenAI (story text) - US
  • • Stripe (payment processing) - US
  • • Google (Gemini text-to-speech) - US
  • • Resend (email delivery) - US

Safeguards for international transfers:

  • • We only work with service providers that maintain appropriate security measures
  • • Where possible, we use EU-based data centers (e.g., Supabase in AWS Frankfurt)
  • • OpenAI processes data under their Data Processing Addendum
  • • Google Cloud processes data under their Data Processing Addendum (DPA)
  • • Stripe and other US providers use standard contractual clauses or other approved safeguards for data transfer outside the EEA

By using Sprongsy, you consent to these international data transfers that are necessary to provide our service.

10. Parental Verification

To ensure certain actions are only performed by adults, we use a parental verification system:

  • • For sensitive actions, a 6-digit code is sent to your email
  • • This code is valid for 30 minutes
  • • Verification codes are automatically deleted after use or expiration
  • • We only store verification codes temporarily for security purposes

11. Cookies & Session Data

We only use strictly necessary cookies for:

  • • Authentication and session maintenance
  • • CSRF protection (security tokens)
  • • Temporary storage of verification status
  • • Local storage of app settings (such as language and preferences)
  • • Cache storage for offline functionality for stories you explicitly download

No external analytics

We do not use external analytics tools such as Google Analytics, Facebook Pixel, or other tracking services. We only collect data strictly necessary for the operation of our service.

Service Worker

Our app uses a service worker for improved performance and offline functionality. It runs locally on your device and uses local cache for stories you explicitly download for offline use. The service worker does not send personal data to external servers.

Offline availability

Only stories you explicitly download on this device are available offline. Offline availability still depends on browser and device limitations (such as storage limits or automatic cache cleanup), which may cause locally stored audio to be removed in some cases.

12. Retention Periods

  • Account data: Until you delete your account
  • Stories & Audio: Until you delete them or close your account
  • Payment history: 7 years (legal retention requirement)
  • Rate limit data: 24 hours
  • Verification codes: 30 minutes (automatically expired)
  • Scheduled subscription changes: Until the change is processed or canceled (max. 24-hour cancellation period)
  • Webhook event logs: 24 months for audit and incident investigation
  • Billing operation and idempotency logs: 24 months for duplicate-processing prevention and support

Please note: When you make a plan change (downgrade), you have 24 hours to cancel it. After this period, the change is final. We store the timestamp of the change to enforce this cancellation period.

13. Your rights (GDPR)

As a data subject, you have the following rights:

Access

You can request what data we have about you

Correction

You can have incorrect data corrected

Deletion

You can have your account and all data deleted

Portability

You can export all your data via your account page

Restriction

You can have processing temporarily stopped

Objection

You can object to certain processing

Contact us at info@sprongsy.com to exercise your rights.

Via your account page you can:

  • Download all your data (data export)
  • Delete your account and all data

When you delete your account, we permanently erase all data we hold: your profile, generated stories, audio recordings, and other account data. This aligns with your right to erasure (GDPR Art. 17).

If you have an active paid subscription, we schedule the permanent deletion at the end of your paid period. You keep access until then and no further payments will be charged. You can cancel your deletion request before that date via your account page.

Backups may temporarily contain copies until overwritten. Where the law requires retention (e.g. for invoicing), we may retain certain data; this is set out in our retention policy or we can explain on request.

Response time

We respond within 30 days to requests regarding your privacy rights. For complex requests, this period may be extended by a maximum of 60 days, about which you will be informed in time.

14. Data Breach Procedure

In the unlikely event of a data breach, we take the following measures:

  • Notification to authority: In case of a data breach that poses risks to data subjects, we report this to the Data Protection Authority within 72 hours, in accordance with GDPR requirements.
  • Notification to users: If the data breach is likely to result in a high risk to your rights and freedoms, we will inform you as soon as possible by email about the nature of the breach and the measures you can take.
  • Measures: We immediately take measures to close the breach, limit the damage, and prevent recurrence. This may include: password resets, temporary account blocking, or other security measures.

15. Automated Decision-Making

We use AI (OpenAI) to generate stories. However, this does not constitute automated decision-making within the meaning of Article 22 GDPR:

  • • The AI generates creative content (stories), not decisions about you
  • • No automated decisions are made that have legal effects concerning you or similarly significantly affect you
  • • You always have the option to contact us

Profiling: We do not use profiling for marketing or advertising purposes. We do not analyze your behavior to show personalized advertisements.

16. International Privacy Laws

Sprongsy focuses on the Netherlands and the United Kingdom. UK residents have additional rights under UK GDPR:

United Kingdom - UK GDPR

For UK residents, similar rights apply as under EU GDPR:

  • • Same rights as mentioned in section 13 (access, correction, deletion, etc.)
  • • You can file a complaint with the Information Commissioner's Office (ICO)
  • • Data transfer to the UK is covered by adequacy decisions

17. Security

We take appropriate technical and organizational measures to protect your data:

  • • Encrypted connections (HTTPS/TLS)
  • • Secure authentication via Supabase Auth
  • • CSRF protection on all forms
  • • Rate limiting to prevent abuse
  • • Input validation and sanitization
  • • Row Level Security (RLS) in the database
  • • Webhook signature verification for payments

18. Beta Status

This service is in a testing phase

  • • Features may change or be temporarily unavailable
  • • This privacy policy may be adjusted as the service evolves
  • • Important changes will be communicated by email

19. Complaints

Do you have a complaint about the processing of your personal data? Please first contact us at info@sprongsy.com. You also have the right to file a complaint with the Dutch Data Protection Authority.

20.5. Data Processing Agreements

In accordance with GDPR, we only work with service providers that maintain appropriate security measures and have Data Processing Agreements (DPAs) in place.

The following service providers have Data Processing Agreements with us:

  • • OpenAI - For AI story generation (text)
  • • Stripe - For payment processing
  • • Resend - For email delivery
  • • Google (Gemini) - For text-to-speech (read-aloud audio)
  • • Inngest - For background processing of story and audio generation
  • • Vercel - For web hosting, CDN, and serverless functions

All DPAs include Standard Contractual Clauses (SCCs) for international data transfers as required by GDPR.

20. Contact

Sprongsy

A product of van der Smissen - IT services

info@sprongsy.com

Country: Netherlands

Privacy Policy - Sprongsy