Bajoo
GDPR

Privacy policy

Last updated: 8 July 2026

1. Data controller

The data controller is Bajoo (the "Controller"), operator of the bajoobajoo.com service.

Contact for data protection matters: [email protected]

2. Scope of collected data

Within the Service we collect the following data:

  • Registration data: email address, password (stored hashed, scrypt).
  • Child data: name, date of birth - solely for personalising story content. We derive the age from the date of birth to fit the story's length, vocabulary and theme to the child's developmental stage.
  • Generated content: stories, audio tracks and illustrations stored on the User's account - accessible only to them.
  • Technical data: IP address, browser information - solely for security and diagnostics.
  • Anonymous traffic stats: pageviews and navigation paths (self-hosted by us, no cookies, no user identifiers).

3. Purpose of processing

We process personal data for the following purposes:

  • Providing the Service (Art. 6(1)(b) GDPR).
  • Ensuring security and preventing abuse (Art. 6(1)(f) GDPR).
  • Communication with the User (Art. 6(1)(f) GDPR).

4. Protection of children data

The security of children's data is our priority. We apply the following measures:

  • Child data (name, date of birth) is used solely to personalise stories and is not shared with third parties in any way that could identify the child.
  • We never collect child data without the knowledge and consent of a parent/guardian.
  • AI-generated content passes through multi-layer safety moderation.
  • Child mode provides limited access protected by a parent-set PIN.

5. Data sharing

Personal data may be transferred to the following categories of entities only to the extent necessary to provide the Service:

  • Cloudflare - hosting, infrastructure and the AI Gateway (processing on EU servers). All AI model calls below are routed through Cloudflare AI Gateway, which manages quotas and call logs.
  • Anthropic (Claude AI) - story content generation. Story parameters (child age, type, theme) and - if the parent provides them - hero names are sent; we do not send your email, date of birth or any other identifying data.
  • Google (Gemini, Cloud Text-to-Speech, Cloud Speech-to-Text) - illustration and narration audio generation, and timing alignment for bilingual "first-steps" stories. Story text is sent, no identifying data.
  • Murf.ai - fallback narration provider (used only when the primary provider returns an error). Only story text is sent.
  • ElevenLabs - deep fallback narration provider (used rarely when both of the above fail). Only story text is sent.

Anthropic, Google, Murf.ai and ElevenLabs are US-based providers - transfers to them rely on the EU Standard Contractual Clauses (SCCs) approved by the European Commission. We send only story content and parameters, never your email or date of birth.

6. Your rights (GDPR)

Under GDPR, the User has the following rights:

  • Right of access to your data.
  • Right to rectification.
  • Right to erasure ("right to be forgotten").
  • Right to restrict processing.
  • Right to data portability.
  • Right to object to processing.
  • Right to lodge a complaint with a supervisory authority.

To exercise the above rights, please contact: [email protected]

7. Cookies and local storage

The Service uses the following mechanisms on the User's device:

  • Session cookies - to keep the logged-in User signed in (strictly necessary, attributes httpOnly, Secure, SameSite=None, Partitioned; no consent required).
  • Browser localStorage - interface preferences: language, child mode, day/night theme. The data stays on your device and is not sent to the server.
  • Android app (Capacitor) - session token and a cached copy of your profile stored in the device's secure preferences (Capacitor Preferences); downloaded story audio and illustrations kept in the app's filesystem (Capacitor Filesystem) for offline reading.
  • Traffic stats (Rybbit) - anonymous pageview and navigation analytics. No cookies, no user identifiers, no browser fingerprinting.

We do not use third-party advertising or analytics cookies.

8. Retention period

We retain personal data for the duration of using the Service. After an account is deleted, data is removed within 30 days, except for data that we are required by law to retain.

9. Changes to the privacy policy

The Controller reserves the right to amend this privacy policy. Users will be notified of material changes via the Service.