Privacy Policy
Last updated: August 7, 2026
This Privacy Policy describes what information MagicPage collects when you use our service, how we use it, and your rights regarding your data. We built MagicPage for parents and carers — we take your privacy, and the privacy of the children in your care, seriously.
1. What We Collect
When you create an account and use MagicPage, we collect the following information:
Your Google identity
When you sign in via Google OAuth, we receive and store:
- Your Google account identifier (
google_id— Google's stable "sub" value) - Your email address
- Your display name from your Google profile
- Your profile avatar URL (
avatar_url)
We also generate a unique username for your account based on your Google profile. We do not store your Google password — authentication is handled entirely by Google.
Character data you create
For each character you create, we store:
- Character name and personality description
- Optional catchphrase
- Appearance description and chosen art style
- The generated character reference image, stored in our object storage (MinIO in development, Amazon S3 in production)
All character data is entered by you, the adult account holder. Children do not enter their own data.
Story content you generate
When you generate a story, we store:
- Your story prompt and any enhanced version of it
- Story settings (language, story type, reader age, writing style, length)
- The generated story text, block by block
- Generated story illustrations — stored in our object storage (MinIO/S3)
Usage counters
We track how many stories you have generated — both a lifetime count for the free tier and a daily count for paid plans. This is used to enforce story limits and to give you an accurate picture of your remaining allowance.
Billing data (coming with paid plans)
When paid subscription plans are available, billing is handled by Stripe. MagicPage does not store your payment card details — those are held securely by Stripe under their own privacy policy. We store only a Stripe subscription reference to manage your plan status.
2. What We Do NOT Collect
- Children's personal information directly. Children do not register for MagicPage and do not have accounts. All data is entered by the adult account holder.
- Passwords. We use Google OAuth only — we never see or store a password for your account.
- Payment card data. Card information is handled by Stripe and is never stored by MagicPage.
- Location data. We do not collect your precise or coarse location.
- Date of birth. We do not collect your date of birth or that of any child.
- Phone number. We do not collect your phone number.
3. Where Your Data Is Stored
Your account information, character data, story text, and usage counters are stored in a PostgreSQL database hosted on our servers.
Generated images (character illustrations and story illustrations) are stored in object storage — MinIO in our development environment and Amazon S3 in production. Images are not publicly accessible — access is via time-limited signed URLs generated on demand.
4. How We Use Your Data
- To operate your account and authenticate you via Google OAuth.
- To generate personalised illustrated stories based on your characters and prompts.
- To enforce your plan's story limits and track usage.
- To manage your subscription (when paid plans are active).
- To provide customer support if you contact us.
We do not sell your data to third parties. We do not use your story content or character descriptions to train AI models.
5. Children's Privacy
MagicPage is a service for adults. Children do not create accounts and do not interact with MagicPage directly. Adults enter character names and story prompts on behalf of the children in their care.
We do not knowingly collect personal information directly from children. Character descriptions you enter may include a child's name or personality traits — this information is treated with the same care as all other personal data under this policy.
If you believe a child has somehow created an account or submitted data directly, please contact us at hello@magicpage.ai and we will delete it promptly.
6. Your Rights and Data Deletion
You have the right to access, correct, or delete the personal data we hold about you.
You can request deletion of your account and all associated data (characters, stories, illustrations) at any time by contacting us. Your data is removed from our database and file storage automatically. When you make a deletion request, we soft-delete your account immediately (making it invisible) and then run an automated background job that permanently removes all database records and deletes every stored image file associated with your account.
If you are based in the European Economic Area or the United Kingdom, you have additional rights under GDPR / UK GDPR, including the right to data portability and the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at hello@magicpage.ai.
7. Cookies and Analytics
MagicPage uses a session cookie to keep you signed in. We do not use third-party advertising cookies or cross-site tracking cookies.
We may collect basic, anonymised technical metrics (such as page-load performance) to improve the service. We do not use Google Analytics or any third-party analytics platform that profiles individual users.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above. For significant changes, we will notify you by email or via an in-app notice. Continued use of MagicPage after changes are posted means you accept the updated policy.
9. Contact
If you have questions or requests about your data or this Privacy Policy, please contact us at hello@magicpage.ai.