StoryAloud — Privacy Policy
Last updated: 2026-08-29
StoryAloud turns PDF documents into audiobooks. This policy describes what the app collects, why, and how to get it deleted.
What we collect
- Account identity — when you sign in with Apple or Google, we receive a Cognito user ID (
sub) and, if you grant permission, your email address from the identity provider. This links your library, credits, and purchases to your account. - Connected accounts — you may optionally link Apple and Google to the same profile from Settings. Linking requires your explicit confirmation; we do not automatically merge accounts by email.
- Legacy device ID — if you used the app before account sign-in, we may merge your prior anonymous device data into your account once, at your request.
- PDF files — uploaded to AWS S3 for text extraction and audio generation; processed by AWS Bedrock, AWS Translate, and our text-to-speech provider (Runpod).
- Purchase data — App Store and Google Play receipts, validated server-side. We never receive or store your payment card details.
- Analytics — product events (paywall views, purchases, job creation) when enabled in production builds, tied to your Cognito user ID.
- Push token — the Expo push token for your device, stored on job records so we can tell you when a conversion finishes.
How we use data
- Provide PDF-to-audiobook conversion
- Manage the free tier, credits, and paid subscriptions
- Authenticate API requests via JWT tokens issued by AWS Cognito
- Improve the product via aggregated analytics
Where data is processed
Our infrastructure runs in AWS in the eu-west-1 (Ireland) region. Some subprocessors listed below process data outside the EU under their own standard contractual clauses.
Retention
- Uploaded PDFs are deleted automatically 7 days after upload.
- Generated audio and job metadata are kept while your account is active.
- Entitlements and credit balances are kept while your account is active.
- Deleting your account removes your entitlements and your job metadata.
Subprocessors
- Amazon Web Services — S3, Lambda, DynamoDB, Cognito, Bedrock, Translate
- Apple and Google — sign-in identity providers, and payment processing for purchases
- Runpod — GPU text-to-speech
- Expo — push notifications and application builds
- PostHog — product analytics, when enabled
Your rights
You can request access to, correction of, or deletion of your personal data, and you can withdraw consent for analytics at any time. Email privacy@storyaloud.com and we will respond within 30 days.
Children
StoryAloud is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects how we use your data, notify you in the app.