U.S. Photo & AI Policy

A plain-language notice about child photos, personalization data, generative AI, and deletion

Effective date: August 27, 2026 · Version: us-1.1

Our core commitments

  • Your child's photo is used to create and fulfill the personalized book you request.
  • We do not use child photos or child-personalization information to train or fine-tune general-purpose AI models, and we do not opt in to AI-provider training programs for this data.
  • We do not sell child photos or child-personalization information, and we do not share them with advertisers for targeted advertising.
  • We do not use facial recognition to identify or authenticate your child, and we do not create or store a face-geometry template or facial-recognition embedding.
  • Original photos are automatically deleted approximately 30 days after upload. You can delete a book or your whole account yourself at any time, subject to limited legal, safety, support, and backup exceptions.

This Photo & AI Policy supplements the TaleCoco Privacy Policy and Terms of Service. It explains, in plain language, what happens when an adult uploads a child's photograph or personalization information to create a personalized book at https://talecoco.com/us.

1. Only an Authorized Adult May Upload a Child's Photo

You must be at least 18 years old to upload a photo. By uploading a child's photo or personalization information, you confirm that you are the child's parent or legal guardian, or that you have the parent or legal guardian's permission to provide the information and authorize its use for the personalized product you requested.

Children should not upload their own photos or personal information to TaleCoco. If we learn that a child under 13 submitted information directly, we will take reasonable steps to stop the collection and delete the information, subject to limited legal and security exceptions.

2. What We Receive

Depending on the product, an adult may provide:

  • one or more photos showing the child's face or appearance;
  • photos of other family members you add as characters (for example a sibling, parent, or grandparent, including adults) or of a pet;
  • the child's first name or nickname;
  • age or age range, and gender selection if you choose to provide it;
  • story choices, a dedication message, and other personalization details; and
  • adult purchaser information such as your email address and, for printed books, the recipient's name, phone number, and shipping address.

Please do not upload nude or intimate images of a child, government identification, medical records, financial information, school records, account credentials, or other information that is unnecessary to create the book.

3. How We Use a Child's Photo

We use the photo only as reasonably necessary to provide the service the adult requested, including to:

  • analyze visible appearance for artistic character generation;
  • generate personalized illustrations, previews, and book pages;
  • perform automated or limited human safety and quality checks;
  • prepare print-ready or downloadable files;
  • fulfill, deliver, support, correct, or reprint the order; and
  • investigate fraud, abuse, security incidents, prohibited content, or legal claims when necessary.

We do not use the child's photo for unrelated advertising, public galleries, social-media posts, testimonials, or promotional materials unless the adult gives a separate, specific permission for that use.

4. How Generative AI Is Involved

TaleCoco uses generative AI to turn a source photo and personalization instructions into an illustrated character and story scenes. This requires transmitting relevant input to AI service providers acting on our behalf. Our current processing uses the OpenAI API (illustration and text generation) and the Google Gemini API (story text). We may use additional or replacement providers as the product evolves, and we will update this Policy when we do.

Before generation, our own servers run an automated face-detection step solely to locate and crop the face in the photo so the illustration focuses on the child. This step does not identify anyone and does not store any face-geometry data.

Our standard configuration and policy are that customer API inputs and outputs are not used to train or improve general-purpose provider models. We do not opt in to provider programs that use your child's photo or generated book content for general model training. Providers may keep limited abuse-prevention or security logs for a limited period under their API terms (for OpenAI, currently up to 30 days).

5. We Do Not Train AI Models on Your Child's Photo

TaleCoco does not use Child Photo Data or Child Personalization Information to train or fine-tune a TaleCoco general-purpose AI model. We also do not sell this data to model developers or license it as a training dataset.

If we ever wanted to offer an optional program that used a customer's photo or generated content for a materially different model-improvement purpose, we would provide a separate, clear opt-in. Participation would not be required to purchase a book, and refusing would not reduce the quality or price of the core service.

6. Facial Recognition and Biometric Templates

A photo necessarily contains visible facial features. TaleCoco uses those visible features as an artistic reference while the illustration is generated, but we do not use facial recognition to determine who a person is, authenticate an account, track a person, or match the person against a database.

Under our current design, the photo is not converted into a stored face-geometry template or facial-recognition embedding. We do not keep per-child face vectors, and we do not use face data for login, duplicate detection, or matching the same person over time. The photo itself is retained only for the short period described in Section 7.

If our system changes so that we begin collecting or processing a biometric identifier as defined by applicable law, we will update our disclosures and obtain any additional consent required before beginning that processing.

7. Photo Retention and Deletion

Data / situationOur approach
Original photo (whether or not you place an order)Automatically deleted from TaleCoco storage approximately 30 days after upload. Deletion is on this fixed schedule regardless of order status. If you request a correction or reprint after the photo has been deleted, we may ask you to upload the photo again.
AI provider security/abuse logsMay be retained for a limited provider-controlled period under the provider's API terms (for OpenAI, currently up to 30 days). We do not opt in to general model training.
Encrypted backupsA deleted file or record may remain in routine encrypted backups for up to 7 additional days before backup rotation removes it, unless legal preservation is required.
Generated book and character files, and personalization informationRetained to support re-download, order history, support, and reprints. Automatically deleted 24 months after your last order or account activity if you have not used your account in that time, and deleted earlier when you delete the book or your account. See the Privacy Policy for the full retention schedule.

We may temporarily preserve information beyond the normal deletion schedule when reasonably necessary to investigate a safety issue, fraud, chargeback, security incident, or legal dispute, or when law requires preservation. We limit such preservation to the information reasonably needed for that purpose.

8. Human Review

Most processing is automated, but authorized TaleCoco personnel or trusted service providers may view a photo or generated page when reasonably necessary for safety review, quality control, troubleshooting, a correction or reprint request, or investigation of prohibited content. Access is limited to personnel who need it for their role and is subject to confidentiality and security controls.

We do not use routine human review of child photos as a source of public training examples or marketing material.

9. Advertising and Analytics

We do not send a child's name, child photo, private personalization prompt, or generated book page to advertising platforms for targeted advertising. We may use analytics and advertising tools to measure how adult purchasers interact with the website, such as whether a visitor reached checkout or completed an order. Those events use adult-level device or transaction identifiers (for example an order number, order value, and the identifiers of the books involved) and do not include child-content fields. When an order is completed, our server also sends Meta hashed (SHA-256) versions of the purchaser's email address, phone number, name, and city, state, ZIP code, and country, with the IP address and browser information of the order, so that Meta can measure our advertising — never the child's name, photo, or book content.

If applicable state law treats these adult disclosures as a "sale" or "sharing," the adult purchaser can opt out at any time using the "Do Not Sell or Share My Personal Information" link in our website footer or the Global Privacy Control browser signal; opting out stops the browser pixels, and orders placed while opted out are not reported to Meta by our server. See our Privacy Policy, Section 7.

10. Security

We use safeguards designed to protect uploaded photos and generated content, including access controls, encrypted network transmission, encryption at rest, vendor security controls, and retention limits. Photos and generated files for the U.S. service are stored on Google Cloud infrastructure located in the United States; print-ready files for hardcover books are transmitted to our printing partner in the Republic of Korea for production. No internet or storage system can be guaranteed completely secure. Please upload photos using a trusted device and network and keep your account credentials private.

11. Your Control

You can delete your entire account yourself in My Page, and you can delete books you have not purchased from My Books. Account deletion is immediate and permanent, and removes your photos, generated books (including purchased books), and personalization information from our active systems (order and payment records are kept only as described in the Privacy Policy). You may also request access, correction, or deletion of a purchased book or other information by contacting support@talecoco.com or by sending a 1:1 inquiry in My Page. A verified parent or legal guardian may also contact us about child-related information. We may ask for reasonable information to verify the request and to avoid disclosing a child's data to the wrong person.

If you delete a book or your account before an order has been generated, printed, corrected, or reprinted, we may be unable to complete the requested service. We will explain that consequence before processing the deletion when relevant.

12. Safe Photo Guidelines

For the best privacy and generation results, upload only the minimum photo needed: a clear image of the child, without school badges, home addresses, documents, computer screens, medical information, or unrelated people in the background. Remove location metadata from a photo when possible. If another child or adult appears in the photo or is added as a character, make sure you have permission to provide their image as well.

13. Changes to This Policy

We may update this Policy when our AI providers, retention controls, or product features change. If we make a material change that expands how existing child photos or child-personalization information are used, we will provide additional notice and seek new consent where required. We will not treat silence or continued use as permission for an unrelated model-training or advertising use of previously collected child photos.

14. Contact

Carve Co., Ltd. (TaleCoco Privacy Team)
2F Unit 178A, 106 Jangdae-ro, Yuseong-gu, Daejeon, Republic of Korea

Website: https://talecoco.com/us

Privacy requests and customer support: support@talecoco.com