Privacy Policy
Effective July 22, 2026 · Last updated August 2, 2026
This Privacy Policy explains how TableHQ LLC ("Company",
"we", "us", or "our") collects, uses, discloses, and retains
personal information when a family uses Anecdote FYI at anecdote.fyi,
including its private photo library, collection workspace, contribution studio,
and exports (together, the "Services").
TableHQ LLC is responsible for the personal information described in this policy. Privacy questions and requests may be sent to support@anecdote.fyi.
The Services are adult-managed and can include kid-led contributions. An adult family owner or guardian creates the workspace, connects a private photo library, organizes collections, chooses which private renditions and prompts a child can access, and controls export and deletion. We do not sell personal information, show behavioral advertising, use family content to train models, or provide session replay.
This policy is a notice about our practices, not a waiver of a privacy right. Depending on where you live, applicable law may give adults and children additional rights.
1 Scope and family roles
This policy applies to personal information processed through the Services. It also describes information held only by the browser while a family uses local speech, photo, grammar, or handwriting features.
The first verified adult family member is normally the owner. The owner can manage guardians, transfer ownership, export family data, and permanently delete the workspace. Other guardians can manage the library, collections, private renditions, child profiles, contributions, invitations, review, recovery, and exports. A child sees only that child's active profile, assigned contribution queue, private renditions, and entries. A guardian can also open a restricted child session on a shared device.
This policy does not govern a provider-controlled authorization or identity page, checkout page, linked website, or a downloaded JSON, PDF, printout, or photo once it is outside the Services. The person who downloads, prints, or shares a copy is responsible for handling it appropriately.
2 Information we collect
2.1 Adult accounts, family members, and invitations
We process:
-
Adult account names, email addresses, internal user and organization identifiers, authentication method, role, account timestamps, and access or revocation status.
-
Child profile names, internal identifiers, assignments, and access status. A child email address is optional and is used only when a guardian invites the child to a separate verified account.
-
Invitation recipient name, email address, role, inviter, associated child profile, expiration, and acceptance or revocation status. We store a digest of the one-time invitation token rather than the usable token.
-
A keyed digest of the guardian exit code, the supervised-child selection, and failed-code controls in the signed-in browser's signed session cookie when a guardian opens a restricted child session.
The ordinary child profile does not ask for a date of birth, school, home address, telephone number, or precise location.
2.2 Photo references, private renditions, and story content
We process information an authorized family member adds to the workspace, including:
-
For a photo left in Dropbox, opaque Dropbox account and file identifiers, the source revision, availability state, and collection membership. Anecdote's server does not receive that photo's path, filename, thumbnail, or bytes.
-
For a photo explicitly made shareable or preserved, normalized private photo bytes, file type, byte size, title, story position, and an optional capture date. A legacy record may instead contain a public HTTPS photo link chosen by a guardian.
-
Collections, their ordered photo membership, collection-specific captions and prompts, and the child profiles invited to contribute to each collection.
-
Authored notes or stories attached to a photo or collection; a raw spoken transcript or typed memory; the author-reviewed text; handwriting-recognition text; and the processed handwriting image.
-
Submitted, approved, returned, skipped, archived, deleted, and review states; prior entry versions; and the user and time associated with creation or review.
-
Collection title, year, dedication, theme, paper size, order, archive state, and timestamps.
Photos, notes, captions, and handwriting can reveal information about children and other people shown or described in them. Guardians decide what to add and which family members may access it. A live Dropbox photo remains available only to the connected adult browser. A child receives a photo only after a guardian explicitly creates a private rendition and includes it in a shared collection.
2.3 Dropbox connection and photo preparation
A guardian can connect a Full Dropbox app using Dropbox's authorization page.
The app requests read-only files.metadata.read and files.content.read
permissions. Anecdote uses Authorization Code with PKCE and an online access
token: the token is kept in that browser's session storage, is not sent to or
stored by Anecdote's server, has no refresh token, and is cleared when the
guardian disconnects, signs out, clears site storage, or closes the applicable
browser session. Connecting another browser requires another Dropbox login.
Starting a supervised child session also clears the Dropbox connection from that
tab before the device is handed to the child.
The connected browser requests folder metadata, thumbnails, and photo bytes directly from Dropbox. Anecdote's server normally receives only opaque Dropbox account and file identifiers, source revisions, availability state, authored annotations, and collection context. The OAuth callback handles the short-lived code in the browser; callback responses are not cacheable, use a no-referrer policy, and application request logs omit the callback query.
When a guardian chooses Make shareable, the browser downloads that one source photo, converts it to a supported format, limits its dimensions, and removes source metadata before uploading a private rendition to Anecdote. Before normalization, the browser reads only available capture-date fields. We retain the resulting calendar date, not location, camera, or other source metadata. A single private rendition may be reused in several collections. We record the Dropbox revision used to create it and do not silently replace it when the source changes; a guardian must explicitly refresh the rendition.
Device photo uploads use the same browser normalization. A guardian can correct or clear a retained capture date.
2.4 Local speech, grammar, photo, and handwriting processing
Speech transcription, grammar checking, perspective correction, ink cleanup, and handwriting recognition run in the browser. The original audio recording is held in temporary browser memory and discarded after transcription. The server receives the resulting transcript only when an adult saves a story or a child saves a draft or completed memory. Raw audio is not uploaded to us.
Model files may be served by us or downloaded by the browser from a model-file hosting provider when first needed, then cached on the device. A remote model request can disclose ordinary request information such as an IP address, browser details, and requested model file to that provider. The request does not contain the child's recording, photo, caption, or handwriting, and the provider does not perform inference on that content for us.
2.5 Drafts, versions, and browser storage
As a child moves through the memory workflow, we may store a server-side text checkpoint containing the workflow stage and available transcript, caption, or recognized text. A processed handwriting draft may also remain in the current browser's IndexedDB storage so a refresh or connection loss does not force the child to repeat the camera step.
When a memory is redone, we retain its prior text and handwriting as a recovery version. A memory keeps no more than 20 prior versions.
2.6 Reliability diagnostics
During pilots, we collect a restricted reliability event containing a fixed event name, workflow stage, success, error or cancellation outcome, duration, time, and internal workspace, collection, user, or child identifiers as applicable. These events help us diagnose device and workflow failures.
The diagnostics endpoint does not accept captions, transcripts, filenames, links, recordings, photos, handwriting, or recognized writing.
2.7 Technical information
When a browser requests the Services, our systems and infrastructure providers may process technical information needed to deliver and protect them. This can include IP address, browser and device type, operating system, requested URL, referring URL, request time, response status, and security or error information. We also process limited display preferences such as theme, color scheme, and time zone.
We do not run third-party audience measurement or session replay on Anecdote pages.
2.8 Communications, support, and payments
We process email addresses and delivery information to send authentication, invitation, access, security, and support messages. We also process the information a person includes in a support, feedback, safety, billing, or privacy request.
If the Services offer a paid plan, trial, or checkout, we and a payment processor may process customer, checkout, subscription, invoice, price, payment-status, refund, dispute, and fraud-prevention information. The payment processor collects payment-card and billing details on pages it controls. We do not store full card numbers or card security codes in the Anecdote FYI application database.
3 Sources of information
We receive information:
-
From family owners and guardians, when they create a workspace, add or invite members, upload or import photos, make assignments, review content, choose settings, or contact us.
-
From children under adult authorization and supervision, when they use an assigned photo to create, review, write, or submit a memory.
-
From other invited family members, when they accept access or participate according to their role.
-
From browsers and devices, through ordinary network requests, essential cookies, local processing, preferences, and restricted diagnostics.
-
From optional providers, when a guardian initiates Dropbox authorization, an identity flow, checkout, or another provider-controlled feature. Live Dropbox library responses go directly to the connected browser as described in Section 2.3.
4 How we use information
We use personal information to:
- Create, authenticate, secure, and support family accounts and invitations.
- Apply owner, guardian, and child permissions and show each child only the assigned family material that child is allowed to use.
- Store and organize opaque photo references, collections, explicit private renditions, drafts, notes, memories, handwriting, and recovery versions.
- Run local-assisted workflows and create family JSON exports, printable layouts, and PDFs requested by authorized family members.
- Send service, invitation, security, access, and support communications.
- Diagnose failures, maintain reliability, prevent fraud or abuse, enforce our Terms of Service, and protect families and the Services.
- Process a paid plan, trial, refund, dispute, or subscription where offered.
- Comply with legal obligations and establish, exercise, or defend legal claims.
We do not use child content for advertising, behavioral profiling, or model training. We do not make solely automated decisions about a child that produce legal or similarly significant effects.
5 Cookies, device storage, and controls
We use first-party cookies and browser storage for these purposes:
-
en_sessionkeeps a user signed in, carries short-lived authentication and supervised-session state, and protects account flows. It is an essential, HTTP-only session cookie. -
en_themeand client-hint storage remember display preferences so pages can match the browser. -
anecdote-fyi-draftsIndexedDB storage holds up to 12 processed handwriting drafts on that browser and removes a draft when it is saved, when it is more than 30 days old and next checked, or when newer drafts exceed the limit. -
Anecdote's Dropbox session-storage entries hold the PKCE transaction while connecting and, after authorization, the online Dropbox access token and opaque account identifier for the current browser session.
-
The browser cache may retain application files and local-processing model files according to browser settings.
A provider may use cookies on an authorization, identity, or checkout page it controls when a guardian chooses to interact with it; that provider's policy governs those cookies.
You can block or delete cookies and site storage through the browser. Blocking the essential session cookie prevents sign-in. Clearing site storage removes local drafts, cached model files, and the local Dropbox connection from that browser but does not delete content already saved to the family workspace or change anything in Dropbox.
We do not use advertising cookies or sell or share browser activity for cross-context behavioral advertising. Because we do not conduct that sale or sharing, a Global Privacy Control signal does not change how the Services operate. Essential service, authentication, security, and family-content operations also do not change in response to Do Not Track.
6 How we disclose information
We do not sell or rent personal information and do not share it for cross-context behavioral advertising. We disclose information only as follows. The Services do not provide a public child profile, public feed, or built-in public posting feature.
6.1 Authorized family members
The family owner and guardians can access and manage the workspace. A child can access only that child's active profile, assigned contribution queue, approved private renditions, and associated entries. Guardians decide collections, contributors, and invitations. A guardian's approval can place a child's memory in a printable keepsake or PDF available to authorized family members.
Removing a family member revokes access but does not automatically erase memories that person already created or reviewed. The family owner and remaining guardians continue to control that content until it is deleted.
6.2 Service providers
Providers may process information as needed to help us operate and protect the Services, including:
-
Amazon Web Services (AWS) for hosting, database, storage, backup, network, monitoring, and security infrastructure.
-
Google for optional identity services, and PurelyMail for verification, invitation, access, security, and support email delivery.
-
Stripe for checkout, billing, fraud prevention, refunds, disputes, and transaction events where paid access is offered.
-
Dropbox for the guardian-authorized, browser-held, read-only photo-library connection. Live library requests go from the browser to Dropbox; Dropbox provides the OAuth authorization page and photo API under its own terms and privacy policy.
-
Hugging Face for remote model-file delivery when the browser needs a model that we are not serving directly. Child content is not included in that model-file request.
These providers receive only the information reasonably needed for their role and may process it in countries where they operate. A provider's own policy applies when it acts independently or when a person interacts directly with a provider-controlled page.
6.3 Legal, safety, and business purposes
We may disclose information:
-
To comply with law, regulation, subpoena, court order, or another valid legal process.
-
To protect a child or another person's rights, safety, security, or property; investigate fraud, exploitation, or abuse; or protect the Services.
-
To professional advisers such as lawyers, accountants, auditors, or insurers where reasonably necessary and subject to appropriate confidentiality obligations.
-
In connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and appropriate protection of the information.
-
At the direction or with the authorization of the family owner, guardian, or person to whom the information relates, as applicable.
We may use and disclose information that has been aggregated or de-identified so it cannot reasonably be linked to a person. We do not attempt to re-identify it except to test whether de-identification measures work or as permitted by law.
7 Children and parental controls
The Services are designed for an adult-managed family activity. A child may not create or own an unsupervised family workspace. An adult who creates a child profile or authorizes a child's participation represents that the adult is the child's parent or legal guardian, or otherwise has authority to make those decisions and provide any permission required by law.
The family owner and guardians can:
-
Decide whether a child has a separate verified account or uses a restricted session on a guardian's shared device.
-
Choose which collections a child can contribute to, create the private renditions that child can retrieve, and remove or skip an assignment.
-
Review a submitted memory, approve it for the collection, or return it for the child to redo. Guardians cannot silently rewrite a child's submitted words.
-
Correct profile, photo, and collection information; download a complete family data export; delete or restore private renditions and collections; revoke a family member's access; and ask us for privacy assistance.
-
Permanently purge a private rendition or collection when it is no longer needed by a shared collection, or have the family owner permanently delete the entire workspace.
-
Stop future collection from a child by ending the child's access and contacting us about deletion. The child may no longer be able to use features that require the deleted information.
The family owner should contact us before allowing a child to submit personal information if the adult cannot provide the authorization required where the family lives. A privacy policy and Terms of Service do not replace a separate direct notice or verifiable parental-consent step where one is legally required.
If you believe a child participated without appropriate adult authorization, contact us. We will investigate, restrict further collection where appropriate, and delete information where required. We may ask for information reasonably needed to verify the requester's identity and authority to act for the child.
8 Legal bases for processing
Where applicable law requires a legal basis, we rely on:
-
Contract, to create an adult-requested family workspace, authenticate authorized users, provide the requested features, process an offered paid plan, and respond to support requests.
-
Consent or parental authorization, where required for a child's participation, optional provider interaction, or another specific activity. Consent may be withdrawn for future processing, subject to information we must retain or process on another lawful basis.
-
Legitimate interests, to secure and improve the Services, enforce family-role boundaries, diagnose reliability, prevent fraud and abuse, maintain appropriate records, and establish or defend legal claims, where those interests are not overridden by a person's rights.
-
Legal obligations, including child-safety, tax, accounting, consumer-protection, and lawful disclosure requirements.
9 Retention and deletion
We retain information only for as long as reasonably necessary for the purpose described in this policy:
-
Workspace content generally remains while the family workspace is active so the family can continue editing and exporting it. Opaque Dropbox references and annotations remain until removed or the workspace is deleted. Trashed private renditions and collections remain recoverable until a guardian restores or permanently purges them, or the workspace is deleted. Anecdote prevents deletion of a private rendition while an active shared collection still needs it.
-
Removed members lose access, but the child profile or user audit record and already-authored or reviewed memories remain so the family can preserve the collection and, for a child profile, restore access. A guardian can contact us about deletion that is not available in the dashboard.
-
Server-side drafts expire 30 days after their last update and are deleted during subsequent workspace activity. Local handwriting drafts are pruned from the browser as described in Section 5.
-
Prior memory versions remain with the current memory, up to the 20-version limit, until the related content is permanently purged or the workspace is deleted.
-
Original audio is discarded from temporary browser memory after transcription and is not uploaded to us.
-
Pilot diagnostics are eligible for deletion after 90 days and are physically removed during subsequent workspace activity.
-
Invitation links expire after seven days and may be revoked sooner. The invitation record and its unusable token digest may remain with the workspace to show who was invited and whether access was accepted or revoked.
-
Security, request, and error records remain for the shorter period reasonably needed to operate, diagnose, and protect the Services, unless an incident or legal obligation requires longer retention.
-
Support communications and payment records, where applicable, may remain for the period needed to resolve a request and satisfy tax, accounting, fraud-prevention, contract, dispute, and legal obligations.
The family owner can permanently delete the workspace from the dashboard. That action cancels active subscriptions where applicable, removes collection content, profiles, invitations, diagnostics, logins, and users from the active application database, and disables the organization. Limited organization, payment, accounting, fraud-prevention, or legal records may remain without collection content where needed for an applicable obligation.
Backups and provider systems may retain protected residual copies for a limited period after deletion. A family should also delete downloaded exports, PDFs, printouts, provider copies, and browser storage separately because we cannot delete copies outside our control.
10 International processing
We and our providers may process information in the United States and other countries whose laws may differ from those where a family lives.
Where applicable law requires a transfer mechanism or safeguard for personal information sent across borders, we use an available lawful mechanism and take appropriate steps to protect the information. Contact us for more information about safeguards relevant to your information.
11 Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information. These include role-scoped access, private image routes, browser-held Dropbox tokens, signed session cookies, hashed invitation tokens, transport security, file and size validation, metadata removal for new private renditions and photo uploads, restricted child route data, and content-security controls.
No internet transmission, device, storage system, or security measure is perfectly secure. We cannot guarantee absolute security. Family members should protect email login links, invitation links, Anecdote and Dropbox sessions, and guardian exit codes; use trusted devices; disconnect Dropbox on shared devices; and avoid sharing private exports or PDFs unintentionally. Contact us promptly if you believe an account or workspace has been compromised.
12 Rights and choices
Depending on where a person lives and subject to legal exceptions, that person or an authorized parent or guardian may have the right to:
-
Know whether we process personal information and access or receive a copy of it.
-
Correct inaccurate information.
-
Delete information and prevent further collection or use.
-
Receive information provided to us in a portable format.
-
Restrict or object to certain processing.
-
Withdraw consent for future processing where consent is the legal basis.
-
Opt out of a sale, cross-context behavioral advertising, or certain profiling. We do not currently conduct those activities.
-
Receive equal service and not be discriminated against for exercising an applicable privacy right.
Many requests can be completed through guardian controls, the family export, or workspace deletion. A request may also be sent to support@anecdote.fyi. Describe the request and, if possible, write from the account email. We may need to verify identity, workspace membership, and authority to act for a child before disclosing or deleting private family information.
We will respond within the period required by applicable law. Some information may be exempt from a request, and deleting information essential to the Services may require closing an account or workspace. If we deny a request, we will explain why and provide an appeal method where required. A person may also complain to the privacy or data-protection authority where that person lives.
12.1 U.S. state disclosures
For U.S. state laws that use defined categories, we may have collected the following during the preceding 12 months:
-
Identifiers, such as a name, email address, IP address, internal user or child ID, invitation record, and payment-customer ID where applicable.
-
Commercial information, such as a trial, subscription, price, payment, refund, or dispute record where paid access is offered.
-
Internet or electronic activity, such as requested pages, browser and device categories, preferences, diagnostics, and security or error events.
-
Audio, visual, and user-generated information, such as private family photos, transcripts, captions, handwriting images, and collection content. The original audio recording is not uploaded to us.
-
Sensitive personal information, where a family photo or authored memory reveals information treated as sensitive under applicable law. We do not use that information to infer sensitive characteristics, advertise, or train models.
We collect these categories from the sources in Section 3, use them for the purposes in Section 4, and disclose them to the family, provider, and legal recipient categories in Section 6. We have not sold these categories or shared them for cross-context behavioral advertising.
13 Third-party services and family copies
The Services may link to or open optional providers, help pages, or other sites we do not control. Visiting them may allow the third party to receive ordinary request information. Review its policy before providing information.
A live Dropbox photo is not copied into Anecdote merely because a guardian browses, annotates, or adds it to a collection. Dropbox controls the original, and changing or deleting it can make the live source unavailable in Anecdote.
Choosing Make shareable creates a separate normalized private rendition in the family workspace. Later changing or deleting the Dropbox original does not silently change that rendition, and deleting the rendition does not delete the Dropbox original. Likewise, a JSON export, PDF, printed keepsake, screenshot, or downloaded image is a separate copy controlled by the person who created or received it.
14 Changes to this policy
We may update this policy as the Services, providers, or legal requirements change. The date at the top identifies the current version. If a change materially affects how we use information already collected, we will provide reasonable notice through the Services, a direct adult communication, or email when required by law. We will seek new authorization or consent where required before materially changing how child information is collected, used, or disclosed.
15 Contact
The organization responsible for this policy is TableHQ LLC.
For privacy, child-safety, or data requests, email support@anecdote.fyi.