宝贝绘本(BabyBook)隐私政策
一、引言
宝贝绘本(BabyBook,海外版名称为 StoryStar)是一款面向家庭的 AI 个性化绘本定制应用。我们高度重视用户隐私,特别是家庭用户隐私保护。本隐私政策旨在向您说明我们如何收集、使用、存储和保护您的个人信息。
二、我们收集的信息
1. 设备标识符
- 收集内容:匿名设备 ID(device_id)
- 用途:用于关联订单记录和生成记录,无需登录注册
- 存储方式:iOS Keychain 安全存储
- 保留时间:长期保留,用于订单查询和恢复
2. 照片
- 收集内容:用户主动上传的 1 张照片
- 用途:仅用于 AI 生成专属绘本
- 存储方式:上传至后端临时目录,生成完成后立即删除;订单记录中仅保留照片临时 URL 字符串(用于生成重试和故障排查),不包含实际图片文件
- 保留时间:图片文件不保留,生成成功或最终失败后立即删除;URL 字符串随订单记录长期保留
- 上传前同意:在照片离开设备上传前,App 会以清晰、显著的方式向您说明照片的用途、共享对象(下述第三方 AI 服务)与删除策略,只有在您主动勾选同意后,照片才会被上传
3. 人脸检测数据(Face Data)
- 收集内容:本 App 使用 Apple 官方 Vision 框架的
VNDetectFaceRectanglesRequest,在您的设备本地检测照片中"是否存在人脸"及人脸所在的矩形区域,用于校验您上传的是包含清晰人物的有效照片
- 明确不做的事:
- 不提取、不生成、不存储任何人脸特征数据(不生成 face mesh 面部网格、facial landmark 面部特征点、facial map 面部映射、faceprint 面纹或任何面部几何/建模数据)
- 不使用 TrueDepth 摄像头或深度数据
- 不进行人脸识别、人脸比对、身份认证
- 不用于广告、营销,不用于构建用户画像或识别用户身份
- 处理位置:全部在设备本地完成,检测结果仅为"人脸数量"这一临时判断,不上传服务器、不与任何第三方共享、不做任何存储
- 保留时间:不保留。检测在内存中即时完成,判断结束后随即丢弃
4. 生成结果图片
- 收集内容:AI 生成并经服务端合成排版的绘本成品图(整图与分页图)
- 用途:供客户端下载、重新下载并本地制作 PDF
- 存储方式:成品图在服务端保留 72 小时(供您下载与意外中断后恢复下载),到期由系统自动删除;AI 生成的原始中间图在合成完成后立即删除;客户端下载后的文件仅保存在您设备的本地 Documents 目录
- 保留时间:服务端成品图保留 72 小时后自动删除;客户端本地文件由您自行管理
5. 订单信息
- 收集内容:订单 ID、设备 ID、绘本 ID、支付交易 ID、Apple 支付收据、金额、订单状态、时间戳、失败错误信息
- 用途:用于订单状态查询、支付验证、售后服务、财务对账
- 存储方式:后端 PostgreSQL 数据库
- 保留时间:长期保留,用于财务对账和客服处理
6. 示例照片
- 收集内容:应用内展示的示例照片
- 用途:仅用于向用户说明功能使用方法,以及 App Store 审核截图展示
- 存储方式:打包在 App 本地资源中
- 保留时间:随 App 版本保留
- 授权说明:示例照片中的人物为开发者自有素材,已获得相关授权,不会用于其他任何目的
三、我们不收集的信息
- 我们不会收集用户的姓名、手机号、邮箱、地址等个人身份信息
- 我们不会收集用户的精确地理位置
- 我们不会收集用户的通讯录、短信、通话记录等敏感信息
- 我们不会追踪用户在 App 外的行为
四、AI 生成内容
- 用户上传的照片仅用于生成绘本,生成完成后立即从服务器删除
- AI 生成的原始中间图在绘本合成完成后立即从服务器删除
- 合成后的绘本成品图在服务器保留 72 小时供下载,到期自动删除
- 生成的 PDF 文件仅保存在用户设备的本地 Documents 目录,不上传云端
- 卸载 App 后,本地 PDF 文件将无法恢复
五、第三方 AI 服务与数据共享
1. 第三方 AI 服务(照片共享对象)
为生成您的专属绘本,我们需要将您上传的照片发送给第三方 AI 图像生成服务进行处理:
- 服务提供商:火山引擎豆包 Seedream(Volcano Engine Doubao Seedream,由北京火山引擎科技有限公司提供)
- 共享内容:您上传的 1 张照片,以及绘本模板图
- 共享目的:仅用于生成以照片人物为主角的绘本图像
- 处理方式:照片作为 AI 图像生成的参考素材传入,用于生成绘本;我们与该服务商约定,照片仅在本次生成用途范围内使用,不用于其它任何目的
- 删除策略:生成完成(或最终失败)后,照片立即从我们的服务器删除,不作留存
- 用户同意:照片上传前,App 会以清晰、显著的方式提示上述共享,只有在您主动勾选同意后才会上传和共享
- 同等保护:我们要求该第三方服务提供商对您的数据提供不低于本隐私政策的保护水平,且仅在您同意的范围内使用
除上述为实现核心功能所必需的第三方 AI 服务外,我们不会将用户的任何数据出售、出租或分享给其他第三方,除非:
- 获得用户的明确同意
- 法律法规要求
- 为了保护我们的合法权益
2. 撤回同意与删除
- 您可以选择不勾选同意,此时照片不会被上传,但将无法使用绘本生成功能
- 由于照片在生成后即被删除、不作留存,无需额外的删除请求;如对已产生的订单记录有疑问,可通过本政策末尾的邮箱联系我们查询或删除
六、儿童隐私保护
本应用为面向家长/成人用户的绘本定制工具,由家长或成人操作使用,并非供儿童独立使用的应用。我们理解用户上传的照片主体可能是儿童,因此对涉及儿童的信息采取以下保护措施:
- 监护人同意:上传照片前,我们会要求操作者确认其为照片中儿童的家长或监护人,并同意本次上传;只有主动确认并同意后照片才会被上传
- 数据最小化:仅上传 1 张照片,仅用于绘本生成,生成完成后立即从服务器删除,不作留存、不建立儿童档案或画像
- 不做面部识别:设备端人脸检测仅判断"照片中是否有人脸",不识别身份、不提取面部特征(详见第二节第 3 条)
- 无广告与追踪:应用内不含任何第三方广告、不含第三方分析 SDK、不进行跨应用追踪
- 合规承诺:我们遵守《儿童在线隐私保护法》(COPPA)、《通用数据保护条例》(GDPR)等适用的儿童隐私法律法规,不会在未取得监护人同意的情况下收集或使用儿童个人信息
- 我们不会故意收集 13 岁以下儿童用于登录、社交或其它非绘本生成目的的个人信息
七、数据安全
- 使用 HTTPS 加密传输数据
- 使用 iOS Keychain 安全存储设备 ID
- 后端 API 使用设备认证保护
- 定期进行安全审查
八、用户权利
- 用户可以随时删除本地已下载的 PDF 绘本
- 用户可以联系我们查询或删除订单记录
- 用户可以通过 iOS 系统设置管理相机和相册权限
九、权限说明
相机权限
- 用途:拍摄照片用于生成绘本
- 说明:用户可以选择拒绝,改用相册选择照片
相册权限
- 用途:选择照片用于生成绘本,保存生成的 PDF/图片到相册
- 说明:用户可以选择拒绝,但部分功能将受限
十、隐私政策更新
我们可能会不时更新本隐私政策。更新后的政策将在 App 内或相关页面公布,重大变更会显著提示用户。
十一、联系我们
如果您对本隐私政策有任何疑问或建议,请通过以下方式联系我们:
- 邮箱:babybooksupport@163.com
StoryStar Privacy Policy
1. Introduction
StoryStar (known as 宝贝绘本 / BabyBook in China) is an AI-powered personalized storybook app designed for families. We take user privacy seriously — especially the privacy of families. This Privacy Policy explains how we collect, use, store, and protect your information.
2. Information We Collect
2.1 Device Identifier
- What: An anonymous device ID (device_id)
- Purpose: To link your orders and generation records — no sign-up or login required
- Storage: Securely stored in the iOS Keychain
- Retention: Kept long-term for order lookup and recovery
2.2 Photos
- What: One photo that you actively choose to upload
- Purpose: Used solely to generate your personalized storybook with AI
- Storage: Uploaded to a temporary directory on our backend and deleted immediately after generation completes. Our order records keep only the temporary URL string (for generation retries and troubleshooting) — never the actual image file
- Retention: The image file itself is never kept; it is deleted immediately once generation succeeds or permanently fails. The URL string is retained with the order record
- Consent before upload: Before any photo leaves your device, the App clearly explains how the photo will be used, who it is shared with (the third-party AI service described below), and how it is deleted. Your photo is uploaded only after you actively check the consent box
2.3 Face Detection Data
- What: The App uses Apple's official Vision framework (
VNDetectFaceRectanglesRequest) to detect, entirely on your device, whether a photo contains a face and where the face rectangle is — solely to verify that you are uploading a valid photo with a clearly visible person
- What we explicitly do NOT do:
- We do not extract, generate, or store any facial feature data (no face mesh, facial landmarks, facial maps, faceprints, or any facial geometry/modeling data)
- We do not use the TrueDepth camera or any depth data
- We do not perform facial recognition, face matching, or identity verification
- We do not use it for advertising, marketing, user profiling, or identifying users
- Where it is processed: Entirely on-device. The result is nothing more than a temporary face count — it is never uploaded to any server, never shared with any third party, and never stored
- Retention: None. Detection happens in memory and is discarded immediately
2.4 Generated Result Images
- What: The finished storybook images (full grid and individual pages) generated by AI and composed on our server
- Purpose: For the App to download, re-download, and create your PDF locally
- Storage: Finished images are kept on our server for 72 hours (so you can download them or resume after an interruption), then automatically deleted. Raw AI intermediate images are deleted immediately after composition. Files downloaded by the App are stored only in the local Documents directory on your device
- Retention: Server-side finished images are automatically deleted after 72 hours; local files on your device are managed by you
2.5 Order Information
- What: Order ID, device ID, book ID, payment transaction ID, Apple payment receipt, amount, order status, timestamps, and failure error information
- Purpose: Order status lookup, payment verification, customer support, and financial reconciliation
- Storage: A PostgreSQL database on our backend
- Retention: Kept long-term for financial reconciliation and customer support
2.6 Sample Photos
- What: Sample photos displayed inside the App
- Purpose: Only to demonstrate how the App works, and for App Store review screenshots
- Storage: Bundled locally within the App
- Retention: Kept with the App version
- Authorization: The people in sample photos are the developer's own materials, used with proper authorization, and will not be used for any other purpose
3. Information We Do NOT Collect
- We do not collect your name, phone number, email address, or home address
- We do not collect your precise geographic location
- We do not collect your contacts, text messages, or call history
- We do not track your behavior outside the App
4. AI-Generated Content
- Your uploaded photo is used only to generate your storybook and is deleted from our server immediately after generation
- Raw AI intermediate images are deleted from our server immediately after the storybook is composed
- Composed finished images are kept on the server for 72 hours for download, then automatically deleted
- Generated PDF files are stored only in the local Documents directory on your device and are never uploaded to the cloud
- If you uninstall the App, local PDF files cannot be recovered
5. Third-Party AI Service & Data Sharing
5.1 Third-Party AI Service (Who Your Photo Is Shared With)
To generate your personalized storybook, we need to send your uploaded photo to a third-party AI image generation service:
- Provider: Volcano Engine Doubao Seedream (provided by Beijing Volcano Engine Technology Co., Ltd.)
- What is shared: The one photo you upload, together with the storybook template image
- Purpose: Solely to generate storybook images starring the person in your photo
- How it is processed: The photo is passed in as reference material for AI image generation. Under our agreement with the provider, the photo is used only for this single generation purpose and nothing else
- Deletion: Once generation completes (or permanently fails), your photo is immediately deleted from our server with no retention
- Your consent: Before upload, the App clearly and prominently explains this sharing. Upload and sharing happen only after you actively check the consent box
- Equal protection: We require this third-party provider to protect your data at a level no lower than this Privacy Policy and to use it only within the scope you have consented to
Other than the third-party AI service strictly necessary for the core feature, we do not sell, rent, or share any user data with any other third party, except:
- With your explicit consent
- When required by law or regulation
- To protect our legitimate rights and interests
5.2 Withdrawing Consent & Deletion
- You may choose not to consent — in that case your photo will not be uploaded, but the storybook generation feature will be unavailable
- Because photos are deleted immediately after generation with no retention, no separate deletion request is needed. If you have questions about existing order records, contact us via the email at the end of this policy to query or delete them
6. Children's Privacy
StoryStar is a storybook creation tool designed for parents and adult users. It is operated by parents or adults — it is not an app for children to use independently. We understand that the subject of an uploaded photo may be a child, so we apply the following protections to information involving children:
- Guardian consent: Before a photo is uploaded, we require the person operating the App to confirm that they are the parent or guardian of the child in the photo and to consent to the upload. The photo is uploaded only after active confirmation and consent
- Data minimization: Only one photo is uploaded, used only for storybook generation, and deleted from our server immediately after generation. No retention, no child profiles, no profiling
- No facial recognition: On-device face detection only determines "whether a face exists in the photo." It does not identify anyone and does not extract facial features (see Section 2.3)
- No ads or tracking: The App contains no third-party advertising, no third-party analytics SDKs, and no cross-app tracking
- Compliance: We comply with applicable children's privacy laws and regulations, including the Children's Online Privacy Protection Act (COPPA) and the General Data Protection Regulation (GDPR). We never knowingly collect or use children's personal information without guardian consent
- We do not knowingly collect personal information from children under 13 for login, social, or any purpose other than storybook generation
7. Data Security
- All data is transmitted over HTTPS encryption
- The device ID is stored securely in the iOS Keychain
- Backend APIs are protected with device authentication
- We conduct regular security reviews
8. Your Rights
- You can delete downloaded PDF storybooks from your device at any time
- You can contact us to query or delete your order records
- You can manage camera and photo library permissions in iOS Settings
9. Permissions
Camera
- Purpose: To take a photo for storybook generation
- Note: You may decline and choose a photo from your library instead
Photo Library
- Purpose: To select a photo for storybook generation, and to save generated PDFs/images to your library
- Note: You may decline, but some features will be limited
10. Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions will be published in the App or on this page, and material changes will be prominently highlighted.
11. Contact Us
If you have any questions or suggestions about this Privacy Policy, please contact us:
- Email: babybooksupport@163.com