U.S. Privacy Policy

How TaleCoco handles purchaser information, child personalization data, photos, generated content, and website data

Effective date: August 27, 2026 · Version: us-1.1

This Privacy Policy explains how Carve Co., Ltd., operating TaleCoco ("TaleCoco," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information when you use https://talecoco.com/us, create a personalized-book preview, place an order, communicate with us, or otherwise use our Services.

This Policy is designed for our United States service and is intended to work together with our Terms of Service and Photo & AI Policy. State privacy rights may vary. Where a state law provides rights beyond this Policy, we will honor those rights to the extent the law applies to us.

1. Adult-Directed Service and Information About Children

TaleCoco is an adult-directed e-commerce and creative service. Account creation, photo upload, preview generation, and checkout are intended for adults age 18 or older. Children may be the subjects of personalized books, but they are not intended to submit information directly to TaleCoco.

The U.S. Children's Online Privacy Protection Act (COPPA) generally concerns personal information collected online from children under 13. TaleCoco is designed so that a parent, legal guardian, or other authorized adult provides any information about a child. If we learn that a child under 13 directly submitted personal information to us, we will take reasonable steps to stop the collection and delete the information, subject to legal, security, fraud-prevention, or dispute-preservation requirements.

Even when COPPA does not apply to information an adult submits about a child, we treat child-related information as high-sensitivity data and apply the safeguards and purpose limitations described below.

2. Categories of Information We Collect

CategoryExamples
Purchaser and account informationYour email address and the name and identifier provided by your login provider (Google), or your email address when you sign in with a one-time email code; account identifier; preferences. For printed books, the recipient's name, telephone number, and shipping address.
Child personalization informationChild's first name or nickname, age or age range, gender selection if provided, story choices, a dedication message, and other details you choose to provide for personalization.
Photo dataPhotographs you upload for character generation, including the child's photo and any photos of other family members (including adults) or pets you add as characters. We ask you not to upload unnecessary metadata or sensitive documents.
Generated contentAI-generated portraits, characters, scenes, story text, page layouts, previews, digital books, and print-ready files.
Order and transaction informationProducts ordered, order number, price, discounts, payment status, shipping status, refund/reprint history, and limited payment-related information supplied by the payment processor. We do not receive your full payment-card number.
Communications and support1:1 inquiries, support requests, and information you send to resolve an order or technical issue. Reviews you choose to post, including any photos you attach, are displayed publicly on our website.
Device and usage dataIP address, browser/device type, operating system, pages or features used, timestamps, referring URLs, security events, and approximate location inferred from IP address.
Cookies and similar technologiesIdentifiers used for authentication, security, preferences, analytics, attribution, and, where enabled, advertising for adult purchasers. We do not place child names, child photos, prompts, or generated book pages into advertising-event parameters.

3. Sources of Information

We collect information: (a) directly from you; (b) automatically from your browser or device; (c) from payment, login, printing, shipping, customer-support, analytics, fraud-prevention, and other service providers; and (d) from another adult who is authorized to create a book for a child. We do not purchase lists of children's personal information.

4. How We Use Information

  • create accounts, authenticate users, and maintain account preferences;
  • generate personalized previews, stories, illustrations, digital books, and print files;
  • review generated content and uploaded photos for quality, safety, fraud, prohibited content (including automated screening for third-party copyrighted characters), and technical problems;
  • process orders, payments, printing, fulfillment, shipping, refunds, and reprints;
  • provide customer service, troubleshoot problems, and respond to privacy requests;
  • secure the Services and prevent fraud, abuse, prohibited content, and unauthorized access;
  • measure site performance and understand how adult purchasers use our website and conversion funnel;
  • send transactional communications and, with your consent, marketing emails to adult purchasers;
  • comply with legal obligations, enforce agreements, and establish, exercise, or defend legal claims; and
  • conduct corporate transactions such as a merger, financing, acquisition, or sale, subject to applicable law and protections for personal information.

We do not use Child Photo Data or Child Personalization Information to create advertising profiles about the child.

5. Photo and AI Processing

To create personalized illustrations and story text, we transmit the photo and relevant personalization instructions to AI service providers acting on our behalf. Our current AI processing uses the OpenAI API (illustration and text generation) and the Google Gemini API (story text). We will update this Policy if we add or replace providers. We configure AI processing so that customer API inputs and outputs are not used for general model training, and our standard policy is not to opt in to such training.

Before generation, our own servers run an automated face-detection step solely to locate and crop the face in the photo. This step does not identify anyone and does not store face-geometry data.

AI service providers may maintain limited security, abuse-prevention, or operational logs for a limited period under their API terms (for OpenAI, currently up to 30 days). We evaluate provider controls and seek to minimize retention consistent with safety, security, and service requirements.

More detail appears in our Photo & AI Policy.

6. When We Disclose Information

We may disclose personal information to the following categories of recipients only as reasonably necessary for the stated purposes:

Recipient categoryPurpose / limitation
AI and image-processing providersGenerate personalized characters, images, and text. Current providers: OpenAI (OpenAI API) and Google (Gemini API).
Cloud and infrastructure providersHost applications, databases, images, files, security systems, and backups. Our U.S. service runs on Google Cloud infrastructure located in the United States.
Payment processorPayPal authorizes and settles payments and manages fraud screening, refunds, and payment disputes. PayPal handles payment-card data under its own terms and security obligations.
Printing and fulfillment providersOur printing partner in the Republic of Korea produces and packages personalized physical products, and our international parcel consolidator prepares them for shipment to the United States. Print-ready files are prepared by our team and transmitted to the printing partner in Korea; the consolidator receives the recipient's name, phone number, and shipping address.
Carriers and logistics providersU.S. carriers (currently USPS and GOFO, depending on your delivery address) deliver physical products and provide tracking.
Email and communications providersSend sign-in codes, order messages, and service communications (currently Zoho ZeptoMail).
Analytics and advertising providersMeasure adult-user site activity and evaluate marketing (currently Meta Pixel and Conversions API, and the X Pixel). We prohibit transmission of Child Photo Data, Child Personalization Information, private prompts, or generated book pages for targeted advertising.
Professional advisers and authoritiesLawyers, accountants, insurers, regulators, courts, law enforcement, or other parties when reasonably necessary for legal compliance, safety, or claims.
Corporate transaction counterpartiesPotential or actual buyers, investors, lenders, successors, or advisers in a corporate transaction, subject to appropriate confidentiality and legal requirements.

7. Sale, Sharing, and Targeted Advertising

We do not sell Child Photo Data or Child Personalization Information. We do not share those child-related categories with advertisers for cross-context behavioral or targeted advertising, and we do not use them to profile a child for advertising.

We may use advertising and analytics technologies for adult purchasers. Through them we share event data about your use of the Services (page views, checkout steps, and completed purchases, together with the order value, currency, order number, and the identifiers of the books involved) plus the online identifiers those providers set in your browser. When an order is completed, our server also sends Meta a purchase event that includes hashed (SHA-256) versions of the purchaser's email address, telephone number, name, and city, state, ZIP code, and country, together with the IP address and browser information of the order, so that Meta can measure our advertising. We never include the child's name, photo, or book content. Depending on the law of your state, these disclosures may be considered a "sale," "sharing," or processing for "targeted advertising" even when no money is paid for the data.

You may opt out at any time using the "Do Not Sell or Share My Personal Information" link in our website footer. Choosing it stops the browser pixels, and orders you place while opted out are not reported to Meta by our server. We also honor the Global Privacy Control browser signal as an opt-out for the browser that sends it. Opting out does not affect marketing emails, which are sent only with your separate consent and can be unsubscribed at any time.

We do not knowingly sell or share for targeted advertising the personal information of a consumer we know is under 16.

8. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy, taking account of product functionality, customer support, security, legal obligations, and the sensitivity of the data. Our current U.S. retention schedule is:

Data typeRetention approach
Original photos (child, family members, pets)Automatically deleted from TaleCoco storage approximately 30 days after upload, whether or not an order is placed. If you need a correction or reprint after that, we may ask you to upload the photo again.
AI provider copies/logsSubject to the provider's API controls. We do not opt in to general model training. Limited abuse/security logs may be retained for a short period, such as up to 30 days.
Child personalization information and generated book assetsRetained while needed to provide re-download, support, and reprint functionality. Automatically deleted 24 months after your last order or account activity unless you continue to use your account, and deleted earlier when you delete the book or your account.
Account informationUntil you delete your account. You can delete your account yourself in My Page; deletion is immediate and permanent, except for the records described in the next two rows.
Order, accounting, tax, and payment recordsAt least 7 years from the order date, as required for tax, accounting, chargeback, anti-fraud, and legal obligations; while your account remains active, your order history stays available to you. When you delete your account, these records are kept in a separate archive that no longer contains your photos or generated content and are automatically deleted at the end of the 7-year period.
Consent recordsRecords of the consents you gave (including the date, IP address, and browser information) are kept as evidence for 7 years, then deleted. After account deletion they are no longer linked to your account.
Customer-support records1:1 inquiries, including any attachments, are retained while your account exists and are deleted when you delete your account, unless a dispute or legal obligation requires longer retention.
Product-usage eventsPage views and feature-usage events used to improve the Services (which do not include IP addresses) are retained while your account exists and are disconnected from your account when you delete it.
Security and technical logsInfrastructure logs are retained for approximately 30 days, with longer preservation if reasonably necessary to investigate a security incident, fraud, abuse, or legal claim.
BackupsDeleted data may persist in encrypted backups for up to 7 additional days before routine backup rotation removes it, unless legal preservation is required.
Advertising/analytics identifiersAccording to our configured vendor retention periods and applicable law; we seek to minimize retention and do not include child content in these systems.

9. Facial Recognition and Biometric Information

TaleCoco uses photos to create artistic illustrations. We do not use facial recognition to authenticate or identify individuals, and we do not create or maintain a face-geometry template, facial-recognition embedding, or other biometric identifier. The AI system references visible characteristics in a photo while generating an illustrated likeness; the photo is then deleted on the schedule above. This is different from using a biometric identifier for identity verification, duplicate detection, or matching a person over time, none of which we do.

If our technology changes so that we collect or process biometric identifiers as defined by applicable law, we will provide any additional notice and consent required before beginning that processing.

10. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, encryption at rest, logging, vendor controls, and data-minimization practices. No system can guarantee absolute security. You are responsible for protecting your account credentials and for using a secure device and network when uploading photos.

If we experience a security incident involving personal information, we will investigate and provide notifications to affected individuals or authorities when required by applicable law.

11. International Processing and Transfers

TaleCoco is operated by Carve Co., Ltd., a company based in the Republic of Korea. Photos, generated content, and account data for the U.S. service are stored on Google Cloud infrastructure in the United States, but our team accesses and processes that information from Korea, print-ready files for hardcover books are transmitted to our printing partner in Korea, our parcel partner operates in Korea, and our AI and other service providers may process information in the United States or other countries. As a result, personal information may be transferred to and processed in jurisdictions whose privacy laws differ from those of your U.S. state. We use contracts and other safeguards as appropriate for our relationships with service providers and remain responsible for our own obligations under applicable law.

12. Your Privacy Choices and Rights

Depending on your state of residence and whether the relevant law applies to TaleCoco, you may have rights to:

  • confirm whether we process your personal information and access or obtain a copy of it;
  • correct inaccurate personal information;
  • delete personal information, subject to legal exceptions;
  • obtain portable data where applicable;
  • opt out of sale, sharing, or targeted advertising as those terms are defined by applicable law;
  • opt out of certain profiling that produces legal or similarly significant effects (we do not use child photos for such profiling);
  • limit or withdraw consent for certain sensitive-data processing where applicable; and
  • appeal our denial of a privacy request where state law provides an appeal right.

You can delete your entire account yourself in My Page at any time, and you can delete books you have not purchased from My Books; purchased books are removed when you delete your account or on request. To exercise any other privacy right, contact support@talecoco.com or send a 1:1 inquiry in My Page. We may request information reasonably necessary to verify your identity, authority, or relationship to the account or child. We will respond within the period required by applicable law, typically within 45 days where such a period applies, subject to lawful extensions. We will not unlawfully discriminate against you for exercising privacy rights.

For child-related data submitted by an adult, the adult who submitted the data, or a verified parent/legal guardian where appropriate, may request access, correction, or deletion even when a specific state law does not require us to provide that right, subject to security and legal limitations.

13. California Privacy Notice

This section supplements the rest of this Policy for California residents when the California Consumer Privacy Act (CCPA), as amended, applies to TaleCoco. If TaleCoco does not meet an applicable statutory threshold, we may still voluntarily honor substantially similar requests where operationally reasonable.

In the preceding 12 months, depending on how you used the Services, we may have collected the following California categories of personal information: identifiers; customer records information; characteristics such as age or age range supplied for personalization; commercial information; internet or other electronic network activity; approximate geolocation inferred from IP address; audio/visual information including uploaded photographs; and inferences inherent in personalization choices. We use and disclose these categories for the business and commercial purposes described in this Policy.

We do not sell Child Photo Data or Child Personalization Information. We do not share those categories for cross-context behavioral advertising. Adult website identifiers and, on purchase, hashed purchaser contact and address information (see Section 7) may be disclosed to advertising or analytics partners in ways that California law may define as "sharing"; California residents can opt out through the "Do Not Sell or Share My Personal Information" link in our website footer or by enabling the Global Privacy Control signal in their browser, and we stop those disclosures for that browser and for orders placed while opted out.

California residents may have rights to know/access, correct, delete, obtain information about categories and sources, opt out of sale/sharing, limit certain uses of sensitive personal information where applicable, use an authorized agent, and be free from unlawful discrimination. We do not currently offer a financial incentive program that requires a CCPA notice of financial incentive.

14. Privacy Rights in Other U.S. States

Residents of states with comprehensive privacy laws, including states that provide rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising or sale, or appeal a denial, may exercise those rights through the methods above when the law applies. Rather than maintain separate privacy policies for each state, TaleCoco uses this nationwide Policy and adds state-specific procedures when a material difference in law requires them.

Where a state treats personal data of a known child as sensitive data, TaleCoco's service design requires an adult to provide the child information and affirm authority to do so. We process that child-related information only for the requested personalization, fulfillment, support, safety, and legal purposes described here, and not for targeted advertising to the child.

15. Universal Opt-Out Signals and Do Not Track

We recognize the Global Privacy Control (GPC) browser signal as a request to opt out of sale/sharing and targeted advertising for the browser or device that sends the signal; when the signal is present our advertising pixels and server-side event forwarding are disabled for that browser. Because there is no uniform legal standard for legacy "Do Not Track" browser signals, we do not respond to them unless applicable law requires otherwise. A universal opt-out signal does not disable strictly necessary cookies used for security, authentication, fraud prevention, or basic service functionality.

16. Authorized Agents and Appeals

If applicable law allows an authorized agent to submit a request for you, we may require proof of the agent's authority and may ask you to verify your identity directly. If we deny a request and your state provides an appeal right, you may appeal by replying to our decision or emailing support@talecoco.com with the subject "Privacy Appeal." We will provide any regulator contact information required by applicable law if an appeal is denied.

17. Cookies and Analytics

We use necessary cookies for authentication, security, session continuity, checkout functions, and preferences. We may also use analytics and advertising technologies (currently Meta Pixel and Conversions API, and the X Pixel) to understand adult-user acquisition and site performance. We configure analytics and marketing events to exclude child names, child photos, private prompts, and generated book images. You can opt out using the footer link described in Section 7 or the Global Privacy Control signal.

18. Changes to This Privacy Policy

We may update this Policy as our Services, providers, technology, or legal obligations change. We will post the updated version, revise the Effective Date, and provide additional notice for material changes where required. If a change would materially expand how we use previously collected child photos or child personalization data, we will seek additional consent where required and will not rely on a silent policy update to authorize a materially incompatible use.

19. Contact Us

Carve Co., Ltd. (TaleCoco Privacy Team)
2F Unit 178A, 106 Jangdae-ro, Yuseong-gu, Daejeon, Republic of Korea

Website: https://talecoco.com/us

Privacy requests and customer support: support@talecoco.com

For fastest handling, include your order number or account email when relevant, but do not email sensitive documents or child photos unless our support team specifically requests them through a secure method.