Privacy Policy
Last updated: June 8, 2026
This Privacy Policy explains how Once Upon a Prompt ("the Game", "we", "us", or "our")
collects, uses, and protects your information when you use our mobile and desktop applications and our website
at ouapstory.com (together, the "Service"). By creating an account or using
the Service, you agree to the practices described here.
1. Information We Collect
We collect only the information needed to run the Game:
- Account information. Your email address and a password. Your password is never stored in
plain text — only a securely hashed version is kept.
- Profile information (optional). A display name, an avatar emoji, and a personal motto, if
you choose to set them.
- Content you create. The stories, story turns, titles, and votes you submit while playing.
This content is part of cooperative gameplay and is visible to the other players in the same game room.
- AI-assisted writing. When you use the optional AI helper (opening sentences, continuation
suggestions, hints, and titles), the relevant story text and your request are sent to our AI provider
(OpenAI) to generate a suggestion. Your email and account identity are not sent with these requests.
- Technical and log data. Standard server logs such as your IP address, request timestamps,
and basic device/browser information, kept for security, abuse prevention, and troubleshooting.
2. What We Do Not Do
- We do not sell or rent your personal data.
- We do not show third-party advertising.
- We do not use third-party advertising or tracking/analytics SDKs to profile you.
- We do not use your stories to train AI models — our AI provider does not train its models
on data submitted through its API.
3. How We Use Your Information
- To create and maintain your account and authenticate you.
- To operate core gameplay: rooms, turns, branches, voting, and PDF export of completed stories.
- To provide optional AI-assisted writing features by sending the relevant story text to our AI provider
and returning its generated suggestion to you.
- To send transactional emails — account verification codes, password-reset links, and turn notifications.
These are sent through our email (SMTP) provider and are not marketing messages.
- To keep the Service secure, prevent abuse, and fix problems.
4. How Your Information Is Shared
- With other players. Content you contribute to a shared story (and your display name/avatar)
is visible to other members of that game room. This is inherent to a cooperative storytelling game.
- With service providers (sub-processors). We use a hosting provider (servers located in the
European Union), an email delivery provider, and an AI provider (OpenAI) that generates writing suggestions
from the story text you submit. These providers process data only to deliver their part of the Service.
- For legal reasons. We may disclose information if required by law or to protect the rights,
safety, and security of our users and the Service.
5. Data Location and Retention
Your data is stored on servers located in the European Union. We keep account and story data for as long as
your account is active. Temporary records such as pending registrations and password-reset tokens expire
automatically after a short period. You may request deletion of your account and associated personal data at
any time (see "Your Rights" below). Some processing — specifically AI text generation by our AI provider
(OpenAI) — may take place on servers outside the European Union, including in the United States, under
appropriate safeguards for such international transfers.
6. Security
All traffic between the apps and our servers is encrypted using HTTPS/TLS. Passwords are stored only as secure
hashes. While no system can be guaranteed perfectly secure, we take reasonable technical measures to protect
your information.
7. Children's Privacy
The Service is not directed to children under 13 (or under the minimum age required in your country, such as 16
in parts of the European Economic Area). We do not knowingly collect personal data from children below that
age. If you believe a child has provided us personal data, please contact us so we can remove it.
8. Your Rights
Depending on your location (including under the EU/UK GDPR), you have the right to access, correct, export, or
delete your personal data, and to object to or restrict certain processing. To exercise any of these rights —
including deleting your account — email us at the address below and we will respond within a reasonable
timeframe.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the
top of this page. Significant changes may also be announced within the Service.
10. Contact Us
If you have questions about this Privacy Policy or your data, contact us at
ouap.app@gmail.com.