DRAFT — Pending review by qualified privacy counsel
TaleKin Privacy Policy
1. Scope and controller
This Policy covers talekin.co and the TaleKin services controlled by Future Insight Co., Limited, RM A1, 11/F, Winner Building, 36 Man Yue Street, Hung Hom, Hong Kong. It does not cover third-party services that act independently and provide their own notices.
For child information, read this Policy together with the Children’s Privacy Policy.
2. Information we may collect
- Adult account information, such as an email address, phone number, sign-in identifier, account status, and communication preferences.
- Child profile information provided by an adult, such as a name or nickname, age range, and family-provided descriptions.
- Creative material, such as photos, voice recordings, interests, story ideas, and family messages.
- TaleKin creations, such as character art, prompts needed to create it, stories, storyboards, illustrations, audio, and reading records.
- Technical and safety information, such as device data, IP address, timestamps, logs, authentication events, and reports.
- When commerce launches, transaction and fulfillment data, such as order number, amount, payment status, and shipping information. Payment card details should be handled by the payment provider rather than stored by TaleKin.
3. Why we use information
We use information to provide the features an adult selects, create and organize family content, maintain accounts, operate and secure the service, prevent abuse, provide support, process purchases when available, and comply with law.
We do not need a child’s school, precise location, direct contact details, government identification, or health information to create a story. Please do not provide those details.
4. Legal bases in Europe and the United Kingdom
Where the GDPR or UK GDPR applies, the intended bases are: contract for account and purchased services provided to the adult account holder; consent for optional uses of a child’s likeness or voice and non-essential communications; legal obligation for tax, fraud, and regulatory records; and legitimate interests for proportionate security, abuse prevention, and support.
We will not rely on legitimate interests where a child’s rights and interests override ours. A documented processing-by-processing legal-basis map, child-consent analysis, DPIA, and any required EU or UK representative appointment must be completed before this Policy becomes effective.
5. AI and automated processing
To create content you request, TaleKin may process photos, prompts, story material, and optional audio through automated systems. These systems create content; they are not intended to make legal, educational, medical, credit, or similarly significant decisions about a child.
Before effectiveness, TaleKin must verify and disclose whether each provider retains submitted material, permits human review, or uses material for model improvement. This draft does not promise that a provider never trains on data until contracts and settings support that statement.
6. Service providers and other recipients
We may provide the minimum information needed to cloud hosting, image-generation, language-model, audio, background-removal, identity, email, payment, and fulfillment providers. We intend to require providers to act only for the contracted purpose and to follow confidentiality, security, retention, and deletion restrictions.
A current subprocessor list naming only providers actually used in production, their purposes, processing locations, and retention terms must be published before this Policy becomes effective. We may also disclose information when required by law, to protect a child or the service, or as part of a properly structured corporate transaction subject to appropriate safeguards.
7. International transfers
Information collected through talekin.co is intended to be stored and processed in the United States using infrastructure designated for the Global service and approved providers. Future Insight is based in Hong Kong. The effective Policy must identify the relevant processing locations and approved providers after the production data flow has been verified.
Global account, content, log, backup, and support workflows must remain segregated from the CN service environment. This regional separation must be verified through deployment settings, provider contracts, access controls, and data-flow testing before this Policy takes effect.
Where European personal data is transferred to a country without an adequacy decision, TaleKin must use an approved transfer mechanism, such as the European Commission’s Standard Contractual Clauses, and supplementary safeguards where appropriate. SCCs, UK transfer terms, and transfer impact assessments must be completed before this statement becomes effective.
8. Retention and deletion
TaleKin intends to keep personal information only for as long as reasonably necessary for the stated purpose. The production retention schedule must separately cover consent requests, verification codes, security logs, source photos, generated content, voice material, accounts, orders, and backups.
The current product does not yet have a verified end-to-end deletion process for database records, object storage, processors, and backups. Actual time periods and deletion controls must be implemented and published before this Policy takes effect. Legal obligations, disputes, and security investigations may justify limited longer retention.
9. Security
TaleKin uses measures intended to protect family content, including access controls and private object storage with time-limited links. No security measure can eliminate every risk. Before launch with real families, TaleKin must complete ownership checks, access-control review, incident response, and processor security review.
10. Your privacy rights
Depending on where you live, you may ask to access, copy, correct, delete, or restrict personal information; withdraw consent; object to certain processing; or close an account. A parent or guardian may exercise applicable rights for a child. We may verify identity and parental authority without requesting excessive information.
European users may have the right to complain to their local data protection authority. Hong Kong data subjects may have rights of access and correction under the Personal Data (Privacy) Ordinance. The effective Policy will provide a tested request channel and response process.
11. California privacy notice
If the CCPA applies to TaleKin, California residents may have rights to know, access, correct, delete, and obtain a copy of personal information; to limit or opt out of certain uses where applicable; and to receive equal service when exercising a right. The categories collected and purposes are described in Sections 2 and 3.
Before effectiveness, TaleKin must determine whether it meets the CCPA business thresholds and verify all analytics, advertising, vendor, sale, sharing, sensitive-information, and Global Privacy Control practices. This draft does not make an unverified “no sale or sharing” representation.
12. Cookies and analytics
TaleKin may use strictly necessary technologies for authentication, security, preferences, and service operation. Any non-essential analytics or advertising technology must be inventoried, disclosed, and placed behind any consent or opt-out mechanism required by applicable law before use on a child-directed or mixed-audience service.
13. Changes and contact
We will post an effective date and provide any notice or fresh consent required for a material change, especially one affecting children’s information.
Draft privacy contact: privacy@talekin.co. Written requests may be sent to Future Insight at the address in Section 1. The email and a public telephone number must be activated and verified before this Policy takes effect.