Cochain Books — Privacy Policy
Version privacy-2026-09 · Supersedes the policy of May 2026
Cochain LLC, doing business as Cochain Books ("Cochain Books", "we", "us"), is the controller of the personal information described here.
Cochain LLC d/b/a Cochain Books 5826 New Territory Blvd PMB 3027, Sugar Land, TX 77479 info@cochainbooks.com · (346) 588-5426
1. What this policy covers
We run two things, and they treat your child's information very differently. This is the most important thing on this page, so it comes first.
The story tool is a web application where an adult creates a personalised story for a child, with AI-assisted writing and optional narration. It asks for a first name and an age, and nothing more. There is no field for a surname. Nothing a child gives us here is published anywhere.
The publishing service turns a child's story into a real book, sold on Amazon and — for some packages — in bookshops through IngramSpark. Publishing a book means putting an author's name on it. So this service collects the child's full name, a photograph and a short biography, and publishes them: on the cover, on the title page, on the About the Author page, and in the retail listing.
That is not a side effect. It is the thing you are buying — a child becoming a published author under their own name. But it is permanent and public, which is why we ask for it separately, in writing, and why you choose how your child is named.
Where something applies to only one of the two, we say so.
This policy covers privacy only — what we collect, why, who it reaches, and how long we keep it. Our Terms of Service cover everything else: what the service does and does not promise, who is responsible for what, and how disputes are handled.
2. Who our account holders are
Accounts are for adults aged 18 or over. An adult holds the account, creates the story, and decides what happens to it — usually the child's parent or guardian, sometimes a relative or friend making a story as a gift. In either case we ask for the same confirmation before a story is created (section 3.2). A child may read and listen to a finished story, but children do not hold accounts, do not sign in, and cannot create or share anything themselves.
We do not knowingly permit anyone under 18 to create an account. If you believe a person under 18 has created one, contact us and we will delete it.
3. What we collect
3.1 When you create an account (story tool)
Our sign-in form asks for your email address and nothing else. There is no name, telephone, address or date-of-birth field.
If you sign in with Google, Google returns more than that, and we want to be straightforward about it. Google's standard sign-in response includes:
- your name, as it appears on your Google account
- a link to your Google profile photograph
- a stable Google account identifier
- your email address and whether Google has verified it
- if your account belongs to a Google Workspace organisation, that organisation's domain
We do not ask for these, we do not display them, and we do not use them. Our authentication provider stores them as part of the sign-in record. If you would rather we did not hold them, sign in with the emailed code instead of with Google.
3.2 When you create a story (story tool)
- Your child's first name. We do not ask for a surname, and there is no field for one.
- Your child's age, as a number, used to set the reading level.
- What you would like the story to be about — free text you write.
- A story title, and which of our characters you have chosen.
That is the whole of what we ask you for about your child. We do not ask for a date of birth, a surname, a school, an address, a telephone number, or a photograph of your child. (Section 3.6 describes the separate record we keep of what your account has done — it holds nothing about your child.)
You give this to us deliberately. Before a story is created you are asked to tick a box confirming that — if the first name and age you give belong to a real child — you are that child's parent or legal guardian, or you have their parent or guardian's permission, and that you consent to our using them for this purpose. That consent is separate from your acceptance of our Terms of Service — accepting the terms is not, on its own, consent to give us a child's information.
3.3 When you buy a publishing package
- Your full name, email address and telephone number
- Your child's name choice — full legal name, first name only, or a pen name. See below
- Your child's age, their pronouns, and a general physical description
- Your child's story
- A photograph of your child, a short biography, and their stated age, for the "About the Author" page
- Publisher marketing features, including a QR code or web link to Cochain Books' official social media channels, website or reader community, shown on the author page
- For packages including custom-likeness illustrations (Magic Maker and Dream Weaver): reference photographs — see section 6.2
- A delivery address, where we ship a physical item
How your child is named is your choice, and you make it as a standalone election. The Parental Consent & Publicity Release asks you to select one of three formats, which we then use on the cover, the title page, the copyright line and the retail listing:
- Full name — authorises publishing your child's legal surname, permanently
- First name only
- A pen name
The author photograph, biography and age are published, not kept private. They appear inside every copy of the book. Section 6.1 explains what publication means, how it differs from a private reference photograph, and why published material cannot be recalled once distributed.
3.4 Payment information
Payments are handled by Stripe, on Stripe's own pages. We never see or store a card number. We keep only Stripe's reference for your customer record and subscription, your subscription status, and the date your current period ends.
3.5 Story submissions are text
We accept stories as typed text, and for the publishing service also as a PDF or Word document. We do not accept audio recordings, voice notes, or photographs and scans of handwritten pages. (The May 2026 policy said we accepted voice and handwritten submissions. That was inaccurate and has been corrected.)
3.6 Records of what your account has used
Separately from your stories, we keep a short record each time your account creates a story or asks for narration — what happened, when, which account did it, and ordinary details of the request itself: which story it concerned, which option was chosen, how much text was involved, and whether it succeeded. Nothing about your child.
These records contain no child's name, no age, and no story text. They exist for three ordinary reasons: to count your monthly allowance, to work out what the service costs us to run, and to notice a pattern of use that looks automated rather than human.
They are deleted with your account. Unlike the records in section 8, there is no reason to keep them once you are gone.
4. What leaves our systems, and to whom
We use a small number of service providers, and we have chosen established companies rather than small ones. The third-party systems that process your or your child's data are listed here, together with a link to each provider's own privacy policy.
| Provider | What it does | What reaches it | Their privacy policy |
|---|---|---|---|
| Supabase | Database, sign-in, file storage | Everything described in section 3 | supabase.com/privacy |
| Vercel | Runs the story tool | Ordinary web request data, including IP address | vercel.com/legal/privacy-policy |
| Anthropic | Generates story text | Your child's first name, their age, and your story premise | anthropic.com/legal/privacy |
| OpenAI | Safety screening only | The text you write, and the story text we generate — which contains your child's first name. See below | openai.com/policies/privacy-policy |
| ElevenLabs | Generates narration audio | The story text, which contains your child's first name | elevenlabs.io/privacy-policy |
| Stripe | Payments | Your email, card and billing details — held by Stripe, not by us | stripe.com/privacy |
| Sign-in, if you choose it | See section 3.1 | policies.google.com/privacy | |
| Squarespace | Runs cochainbooks.com | Website analytics for the marketing site | squarespace.com/privacy |
| Amazon KDP | Publishing and distribution | Book metadata, including the author name you choose | amazon.com/privacy |
| IngramSpark | Publishing and distribution | Book metadata, including the author name you choose | ingramspark.com/privacy-policy |
| Adobe Sign | Electronic signature for publishing agreements and consent forms | The signed documents — the Author's name, the About the Author page proof, which contains the Author's photograph and biography, and your contact details | adobe.com/privacy/policy.html |
| Illustrators and editors | Publishing service | Your child's story, their pronouns and physical description, and reference photographs where applicable — under confidentiality agreement | — |
What we can promise, and what we cannot. Cochain Books does not sell personal information and does not share it for advertising. We disclose it only to the service providers we use to run the service, and to no one else, except where the law requires it. We can only promise this for our own conduct. The providers above receive data in order to do their jobs, and each of them handles it under its own privacy policy, which governs what they retain and what they do with it. We do not control those policies, and we ask you to read the ones that matter to you.
A note on the AI providers. Your child's first name and age are sent to Anthropic each time a story or a page is written, and the story text is sent to ElevenLabs when narration is generated. This is how the product works — it cannot write a story about your child without knowing their name.
Safety screening, and why your child's first name passes through it. Every page we generate is screened by OpenAI's moderation service before you see it. Because the page text is a story about your child, it contains their first name, and so their first name reaches that screening service — typically fifteen to twenty-five times over a full story, plus once for the outline.
We could strip the name out before screening. We have chosen not to, for two reasons.
The screen is a child-safety control, and we would rather it examined exactly the words you will read than a modified copy of them.
And the footprint is small. Here it matters which part of that is ours and which is not.
What we control, and have done: we have turned off every data-sharing option OpenAI offers us — model feedback, evaluation and fine-tuning data, and the sharing of inputs and outputs — and we do not switch on per-call logging, so nothing we send is retained at our request. We declined the free usage credits OpenAI offers in exchange for sharing.
What we do not control: OpenAI documents its moderation endpoint as retaining no content, and states that data sent to its API is not used to train its models by default. That is OpenAI's published position, not a setting of ours, and like every provider in the table above, what they do with what reaches them is governed by their policy rather than by us.
5. Cookies and tracking
The story tool sets no analytics or advertising cookies, and loads no third-party scripts. There is no Meta Pixel, no Google Analytics, no Tag Manager, and no session-recording or product-analytics tool of any kind. We verified this against the live application, not against our own documentation.
The tool stores two things in your browser, both first-party:
- Your sign-in session. It is what keeps you signed in. Our sign-in library may split it across more than one cookie, depending on its size.
- Which role you selected, for the duration of the browser tab. It is cleared when you close it.
You can block or delete cookies in your browser's settings. If you block the sign-in cookie, you will not be able to stay signed in to the story tool.
Our marketing site, cochainbooks.com, is a separate Squarespace site and does use ordinary website analytics. It never receives anything from the story tool.
6. Photographs — two kinds, treated differently
We may hold two entirely different kinds of photograph, and it matters which is which.
6.1 The author photograph and biography — published, and permanent
Every book we publish includes an "About the Author" page carrying a photograph of the child, a short biography, their stated age, their elected name format, and links or QR codes pointing to Cochain Books' official online platforms. These elements are published. They appear inside every copy sold, in print and in digital editions.
Publication is permanent. Once a book is printed and sold we cannot recall it from copies already in readers' hands. On request, or on revocation of publicity, we will remove the photograph, biography and name from future printings, and from digital editions where the retailer permits. Digital editions, metadata and retail search listings may remain searchable online indefinitely, across third-party platforms outside our control.
We ask for this explicitly and in writing, in the Parental Consent & Publicity Release, and you approve the exact layout proof — Schedule A — showing the final photograph, the biography text, the name as it will appear and the publisher links, before we publish anything.
It must show your child alone. If any other person appears in the photograph, you must warrant that you hold full legal authority and written consent to publish that person's image.
Retention. Published author photographs, biographies and approved names are kept for as long as the book remains in publication, because they form part of the published work. The 90-day timetable in section 6.2 does not apply to them.
6.2 Reference photographs — private, and deleted
Where your package includes a character drawn to resemble your child, we ask for reference photographs. These are never published. Here is exactly what happens to them.
A human illustrator uses the photograph as a visual reference. They separate your child from the background by hand, convert that outline into a line drawing, and then redraw and restyle it by hand until it matches our illustration style. What appears in the book is an illustration in our house style — not your child's photograph, and not a machine-generated likeness of it.
Your child's photograph is never submitted to any artificial-intelligence or generative image service, never used to train any model, and never processed by the generative AI features built into illustration software. Our illustrators are contractually prohibited from all of these, are given a written list of the specific features they must not use, and must confirm in writing on delivery that they have complied.
Reference photographs are shared only with the illustrator working on your book, under a confidentiality agreement. The illustrator must permanently delete them within 5 business days of final delivery, and we delete our own copies within 90 days of book completion.
The story tool does not accept photographs at all. There is no upload path, of either kind.
7. How long we keep things
We hold two different kinds of information, and they are treated differently.
7.1 Working data — deleted when you ask
This is what the service actively uses. If you ask us to delete it, we do.
| What | How long |
|---|---|
| Your account | Until you ask us to delete it |
| Your stories, generated text, narration audio and generated illustrations | Until you ask us to delete them |
| Reference photographs | 90 days after book completion, and 5 business days at the illustrator |
| Records of what your account has used (section 3.6) | 12 months, then deleted — and deleted with your account if that is sooner |
| Database backups | 7 days |
7.2 Records we keep to protect ourselves — not deleted on request
These are kept because we may need them to meet a legal obligation or to defend a claim. They are held separately from the working data above and are not used to run the service.
| What | How long |
|---|---|
| Financial and tax records | 7 years, as US tax law requires |
| The record that you accepted our terms | See section 8 |
| Signed publishing agreements and project emails | The 3-year term of the agreement, and then as needed for any live dispute |
| Signed Parental Consent & Publicity Release forms, and the Schedule A proof attached to each | For as long as the book is distributed, and then for as long as a claim could be brought |
| Manuscripts and print-ready files for published books | Currently retained, so the book can be reprinted — see below |
| Records of automated safety and moderation blocks | See the paragraph below |
We retain records of automated safety and moderation blocks (including submitted prompts and timestamps) for up to 90 days for filter optimization. Records involving severe violations, potential harm to minors, or illegal conduct are preserved in isolated storage for at least 12 months to satisfy mandatory federal reporting and legal compliance obligations. These security and compliance records are exempt from user deletion requests.
On published books. Once a book is published and listed for sale, we currently retain the manuscript and print-ready files so that it can be reprinted and so that we can meet our obligations to the retailers who list it. We deliberately do not describe this as permanent. If you ask us to remove a published book, tell us and we will discuss what is possible — some of it is in the retailers' hands, not ours.
8. Your rights, and how to use them
You may ask us to:
- tell you what we hold about you and your child, and give it to you in a readable form
- correct anything wrong
- delete your account and the working data in section 7.1
- withdraw consent to marketing or publicity, at any time
- delete reference photographs immediately, without waiting for the 90 days
Email info@cochainbooks.com. We aim to respond within 10 business days, and in all cases within 45 days. We do not charge for this, and we will not treat you differently for asking.
If you are a Texas resident, the Texas Data Privacy and Security Act gives consumers rights of this kind. We honour them for everyone, wherever you live, rather than sorting our customers by state.
Three things we want to be honest about.
Deletion is done by us, not by a button. There is currently no delete-my-account control in the story tool. When you ask, we delete your account, your stories, the generated text, and the narration audio and illustration files held in our storage. Deleted data remains recoverable from our database backups for up to 7 days afterwards, and is then gone.
Two classes of record survive deletion.
The first is proof that you agreed to something.
Whenever you accept one of our documents, confirm that you are 18 or over, or give consent to use a child's first name and age, we record what you agreed to, which version of the wording, and when — together with the IP address and browser it came from. Those records are kept after your account is deleted, detached from your name and email.
They are kept because they are our only evidence that the thing was agreed, at the time it was agreed. A record that disappears when an account is deleted cannot prove anything, which defeats the purpose of keeping it.
What survives is the fact of the agreement. These agreement records contain no child's name, no age, and no story, and nothing about you beyond the IP address and browser named above.
The second is a record of something our safety filters blocked, and only where it was severe.
Most blocks are ordinary — a word the filter did not like, something off-topic. Those records are kept for up to 90 days to improve the filter, and they are deleted with your account.
A small number are not ordinary. Where a block involves a severe violation, potential harm to a minor, or conduct that may be illegal, we are required by federal law to preserve the record — the text itself, the time, and the account and network details — for at least twelve months, and to report some of it. Those records are moved to separate, restricted storage, and a deletion request does not reach them.
We would rather say this plainly than bury it. Unlike the agreement records above, a preserved safety record can contain the text that was blocked, which may include a child's first name. Only one person here can read them, and only for that legal purpose.
Nothing else survives deletion.
Removing a published book is a separate question from deleting your data. Deleting your account removes your data from our systems. It does not automatically withdraw a book that is already listed for sale by Amazon or a bookshop, because those listings are not ours to control. See section 7.2.
9. Security
Access to stories is enforced by the database itself, not only by the application: your account can read your own stories and no one else's. Generated audio and images are held in private storage and served through links that expire.
Access to customer stories is restricted to authorised personnel who require it for support, troubleshooting and publishing setup, through the database administration tools. We do not read stories otherwise.
10. Children's information
A child never deals with us. You do. The account holder is an adult — the child's parent or legal guardian, or someone acting with their permission — and every piece of information we hold about a child was given to us by that adult.
What we collect depends entirely on which of our two services you are using.
The story tool: a first name and an age. Nothing else. There is no field for a surname, and nothing is published anywhere.
The publishing service: what it takes to publish a book. Your child's story, their stated age, a general physical description, a photograph and a short biography for the About the Author page, publisher links shown on that page, the author name format you elect, and — for custom-likeness packages only — reference photographs.
We never ask for a child's date of birth, home address, school, personal telephone number, or personal email address, for either service.
One honest qualification. The box where you describe what the story should be about is free text, and we cannot stop you typing something into it that we did not ask for. Please do not put a surname, a school, an address, or anything else identifying into that box — we do not want it, and it would end up in the story. If you have already done so, email us and we will remove it.
On surnames and legal names, plainly. The story tool holds no surname and has nowhere to put one. The publishing service does hold a legal surname, and publishes it permanently — but only where you expressly elect "full name" on the Parental Consent & Publicity Release. A published book carries its author's name, and that is what the publishing package delivers. If you would rather your child's surname were not published, elect first name only or a pen name, and we will use that election everywhere the book appears: the cover, the title page, the copyright line, and the retail listings on Amazon and IngramSpark.
We treat everyone under 18 the same way. We do not operate one set of rules for children under 13 and another for teenagers. The stricter treatment applies to all of them.
Consent is asked for explicitly. Before you can create a story in the tool, you must tick a required box confirming that — if the first name and age you give belong to a real child — you are that child's parent or legal guardian, or you have their parent or guardian's permission, and that you consent to our using them. If the name you give is made up rather than a real child's, nothing in that box applies to you. For the publishing service, consent and final approval are given by signing the Parental Consent & Publicity Release with the About the Author page proof attached — and that must be signed by the child's parent or legal guardian. Someone else may pay for the package as a gift, but only a parent or guardian can give us permission to publish a child's name, biography and photograph, and nothing goes to print or to a retailer until they have.
On whether a first name is identifying. A first name and an age, on their own, would not usually identify a particular child. We are not going to lean on that, because your account — your name, your email, your payment record — sits alongside it, and a child's information that is linked to an identified parent may well be identifying in practice. We therefore handle a child's first name and age as personal information about that child, and ask for consent accordingly.
We do not use a child's information to advertise to anyone, and we do not build a profile of a child. In the story tool it is used to write and narrate that child's story and nothing else. In the publishing service it is used to make, distribute and promote their book, as you have authorised in writing.
If you believe we hold information about a child that you did not provide and did not consent to, contact us at info@cochainbooks.com and we will delete it.
11. Changes to this policy
We will post any new version on this page with a new version number and effective date, and keep the superseded version available on request. Please check this page from time to time, and before making any decision that depends on it. Continuing to use the service after a new version is posted means you accept it.
This version supersedes the policy of May 2026. The material changes are: story submissions are text only; the story tool, its providers and its data flows are described for the first time; Google, Anthropic, OpenAI, ElevenLabs, Vercel, Supabase and Stripe are named and linked; the reference-photo section describes the actual illustration process; retention is separated into working data and records kept for legal purposes; and deletion, the surviving acceptance record and the treatment of children's information are described honestly.
12. Contact
Cochain LLC d/b/a Cochain Books 5826 New Territory Blvd PMB 3027, Sugar Land, TX 77479 info@cochainbooks.com · (346) 588-5426