Draft · pending legal review · 2026-05-21

This page is a first-draft policy. It is published so the footer doesn’t link to a 404 and so we can show parents what we’re working with. The wording below has not been reviewed by counsel and is subject to material change before launch.

Last updated · 2026-05-21 · v0.1 (draft)

Privacy Policy

Hezaro1 is a bilingual children’s storybook used by families. A parent holds the account; a child reads. This policy describes what we collect, why we collect it, who we share it with, and the rights you and your child have over that data.

01

What we collect

We try to collect the minimum needed to render the dashboard, personalise the reader, and show your child their progress. Concretely:

Parent account

  • Email — for sign-in, account recovery, and the weekly digest.
  • Name — optional, used to greet you in the dashboard.
  • Authentication metadata — session tokens, password hash (if applicable), and identifiers from the auth provider you signed in with.

Per child

  • Display name — what the dashboard calls them. Can be a nickname.
  • Age and age band (4–7, 7–10, 10–14) — used to pick stories appropriate to reading level.
  • Avatar tone — a colour swatch, not a photo.

We do not collect child email addresses, phone numbers, geolocation, photographs, or audio recordings.

Reading events

  • Which story (by slug) was opened.
  • Which page within that story.
  • How long it was open (duration).
  • The timestamp.

Vocabulary learnings

  • The Farsi word the child interacted with.
  • The story it appeared in.
  • The English meaning shown.
  • The timestamp.

02

How we use it

  • To render the parent dashboard (streaks, weekly stats, vocabulary lists).
  • To personalise the reader for the active child (their age band, their vocabulary history).
  • To compute streaks, time-read totals, and the Sunday weekly digest email.
  • To improve the product internally — for example, noticing that 80% of children skip a chapter and rewriting it.
  • To respond to support requests you initiate.

We do not use any of this data for behavioural advertising, ad-tech profiling, or third-party marketing. We do not sell data. We do not rent data. We do not run ads.

03

Who we share it with

We use a small set of vendors (“sub-processors”) to actually operate the service. Each row below lists what gets sent and why.

Supabase

Sub-processor

Primary data store — Postgres (account + child profiles + reading events + vocabulary), Auth (when `AUTH_PROVIDER=supabase`), and Storage (avatars, narration audio).

Pending legal review.

Clerk

Sub-processor

Parent identity provider when `AUTH_PROVIDER=clerk`. Stores email, password hash, and session metadata. No child data ever reaches Clerk.

Pending legal review.

Replicate

Sub-processor

LLM hosting for story-bible drafts and Gemini-family TTS for narration audio. Receives story text and voice prompts — never child profile data.

Pending legal review.

ElevenLabs

Sub-processor

Sound-effects synthesis. Receives short text prompts describing a sound (e.g. "thunder, distant"). No personal data.

Pending legal review.

OpenAI

Sub-processor

Image generation (gpt-image-1 / gpt-image-2) for illustration drafts. Receives illustration prompts only — never personal data.

Pending legal review.

MidJourney (via Discord)

Sub-processor

Illustration prompting pipeline. Prompts are submitted to a private Discord channel; finished images are downloaded back into Supabase Storage. No personal data sent.

Pending legal review.

Telegram

Sub-processor

Staff operational alerts only. No family data, no child data, no reading data is sent through Telegram.

Pending legal review.

Vercel

Sub-processor

Hosting and the edge network that serves the site. Logs request metadata (IP, user-agent, path) per industry-standard retention. Does not access application data.

Pending legal review.

Supabase region:pending legal review — we’ll publish it here once confirmed.

04

How long we keep it

Pending legal review:retention policy is in development. The rough shape we’re aiming at: parent account data retained for the lifetime of the account; child reading events aggregated and decayed after a window TBD; deletion on request honoured within a window TBD. Final numbers pending counsel sign-off.

05

Your rights

As the parent who holds the account, you can:

  • Accessthe data we hold for your family — visible inside your dashboard.
  • Exporta copy — export endpoint coming with COPPA-02 (/dashboard/account/export, not yet live).
  • Deleteyour account and all child profiles — account-deletion flow coming with COPPA-02 (/dashboard/account, not yet live). In the interim, email the contact below and we will action it manually.
  • Objectto specific processing, or rectify inaccurate data — email the contact below.

EU/UK residents: these rights derive from GDPR / UK-GDPR. US residents in California: equivalent rights derive from CCPA / CPRA. Residents elsewhere: we extend the same rights to all users regardless of jurisdiction.

06

Children's data

Hezaro1 is designed for children. The product cannot work without storing some information about each child reader. We treat that data with the following commitments:

  • We collect child data only with parental consent. The parent creates the child profile from inside their own authenticated account; there is no separate child sign-up.
  • We never target advertising at children. We do not run ads at all.
  • We do not share child data with third parties except the sub-processors listed above, and only the minimum each one needs to do its job (e.g. Supabase stores it; Replicate never sees it).
  • The parent can delete or export child data at any time— see “Your rights” above. Once tooling lands these actions will be self-service from the dashboard; until then we honour them manually within a reasonable window.
  • We comply with COPPA (US) and GDPR-K(EU/UK) as they apply to a service intended for children. If you believe we’ve fallen short on either, please tell us using the contact below and we will investigate.

07

Cookies

We use a small number of first-party cookies that are essential to the service (auth session, active-child preference, parent-PIN grace). We do not set third-party tracking cookies. See our Cookie Policy for the full list.

08

Changes to this policy

We’ll update this page when our practices change. For non-material changes (e.g. fixing a typo, clarifying wording) we’ll bump the “Last updated” date at the top.

For material changes— for example, adding a new sub-processor that receives personal data, or starting to collect a new category of information — we’ll re-prompt the parent for consent inside the dashboard before the change takes effect for that family.

09

Contact

For privacy questions, deletion requests, or to report a concern, email privacy@pardis.app. (This address may change while our mail setup is finalized.)

Postal address: to be published— jurisdiction and registered entity pending counsel sign-off.