Privacy Policy
Effective July 22, 2026
This Privacy Policy explains how TableHQ LLC ("Company",
"we", "us", or "our") collects, uses, discloses, and retains
personal information when a family uses Anecdote FYI at anecdote.fyi,
including its family workspace, child studio, imports, and exports (together,
the "Services").
TableHQ LLC is responsible for the personal information described in this policy. Privacy questions and requests may be sent to support@anecdote.fyi.
The Services are parent-managed and kid-led. An adult family owner or guardian creates the workspace, chooses its members and private photos, decides which photos each child can access, and controls export and deletion. We do not sell personal information, show behavioral advertising, use child content to train models, or provide session replay.
This policy is a notice about our practices, not a waiver of a privacy right. Depending on where you live, applicable law may give adults and children additional rights.
1 Scope and family roles
This policy applies to personal information processed through the Services. It also describes information held only by the browser while a family uses local speech, photo, grammar, or handwriting features.
The first verified adult family member is normally the owner. The owner can manage guardians, transfer ownership, export family data, and permanently delete the workspace. Other guardians can manage editions, photos, child profiles, assignments, invitations, review, recovery, and exports. A child sees only that child's active profile, assigned photo queue, and entries. A guardian can also open a restricted child session on a shared device.
This policy does not govern a provider-controlled picker, identity page, checkout page, linked website, or a downloaded JSON, PDF, printout, or photo once it is outside the Services. The person who downloads, prints, or shares a copy is responsible for handling it appropriately.
2 Information we collect
2.1 Adult accounts, family members, and invitations
We process:
-
Adult account names, email addresses, internal user and organization identifiers, authentication method, role, account timestamps, and access or revocation status.
-
Child profile names, internal identifiers, assignments, and access status. A child email address is optional and is used only when a guardian invites the child to a separate verified account.
-
Invitation recipient name, email address, role, inviter, associated child profile, expiration, and acceptance or revocation status. We store a digest of the one-time invitation token rather than the usable token.
-
A keyed digest of the guardian exit code, the supervised-child selection, and failed-code controls in the signed-in browser's signed session cookie when a guardian opens a restricted child session.
The ordinary child profile does not ask for a date of birth, school, home address, telephone number, or precise location.
2.2 Family photos and story content
We process information a guardian or child adds to the workspace, including:
-
Private photo bytes, filename, file type, byte size, title, story position, and an optional capture date. A legacy record may instead contain a public HTTPS photo link chosen by a guardian.
-
The child profiles assigned to a photo and the status and order of each assignment.
-
A raw spoken transcript or typed memory, the child-reviewed caption, handwriting-recognition text, and the processed handwriting image.
-
Submitted, approved, returned, skipped, archived, deleted, and review states; prior entry versions; and the user and time associated with creation or review.
-
Edition title, year, dedication, theme, paper size, order, archive state, and timestamps.
Photos, captions, and handwriting can reveal information about children and other people shown or described in them. Guardians decide what to add and which family members may access it. New photos remain guardian-only unless a guardian explicitly assigns them to a child.
2.3 Photo preparation and optional imports
New photo files are normalized in the browser before upload. This process changes them to a supported format, limits their dimensions, and removes source metadata. Before normalization, the browser reads only available capture-date fields so the private library can group a photo by month. We retain the resulting calendar date, not location, camera, or other source metadata. A guardian can correct or clear the date.
If a guardian enables an optional third-party photo picker, the browser loads the provider's picker only after that choice. The provider may then process the guardian's account interaction, ordinary request data, and the files the guardian selects under its own privacy policy. The browser downloads temporary links for only the selected files. We do not request a full-library access token, and the temporary links are not stored in our database or application logs. They are discarded from the import queue after the normalized private copies are uploaded or the import ends.
2.4 Local speech, grammar, photo, and handwriting processing
Speech transcription, grammar checking, perspective correction, ink cleanup, and handwriting recognition run in the browser. The original audio recording is held in temporary browser memory and discarded after transcription. The server receives the resulting transcript only when a draft or completed memory is saved. Child audio is not uploaded to us.
Model files may be served by us or downloaded by the browser from a model-file hosting provider when first needed, then cached on the device. A remote model request can disclose ordinary request information such as an IP address, browser details, and requested model file to that provider. The request does not contain the child's recording, photo, caption, or handwriting, and the provider does not perform inference on that content for us.
2.5 Drafts, versions, and browser storage
As a child moves through the memory workflow, we may store a server-side text checkpoint containing the workflow stage and available transcript, caption, or recognized text. A processed handwriting draft may also remain in the current browser's IndexedDB storage so a refresh or connection loss does not force the child to repeat the camera step.
When a memory is redone, we retain its prior text and handwriting as a recovery version. A memory keeps no more than 20 prior versions.
2.6 Reliability diagnostics
During pilots, we collect a restricted reliability event containing a fixed event name, workflow stage, success, error or cancellation outcome, duration, time, and internal workspace, collection, user, or child identifiers as applicable. These events help us diagnose device and workflow failures.
The diagnostics endpoint does not accept captions, transcripts, filenames, links, recordings, photos, handwriting, or recognized writing.
2.7 Technical and audience-measurement information
When a browser requests the Services, our systems and infrastructure providers may process technical information needed to deliver and protect them. This can include IP address, browser and device type, operating system, requested URL, referring URL, request time, response status, and security or error information. We also process limited display preferences such as theme, color scheme, and time zone.
When configured, a cookie-free audience-measurement system records limited page-visit, referrer, browser, device, approximate-country, session-timing, and performance categories on public marketing and legal pages so we can understand aggregate use and improve the Services. It honors the browser's Do Not Track preference and excludes URL query strings and fragments. Authentication, family-workspace, profile, invitation, export, photo, and handwriting routes are blocked before events are sent.
Audience measurement does not receive names, email addresses, photos, captions, transcripts, handwriting, filenames, form values, invitation tokens, or the contents of a family workspace. It does not use analytics cookies or record a replay of a session.
2.8 Communications, support, and payments
We process email addresses and delivery information to send authentication, invitation, access, security, and support messages. We also process the information a person includes in a support, feedback, safety, billing, or privacy request.
If the Services offer a paid plan, trial, or checkout, we and a payment processor may process customer, checkout, subscription, invoice, price, payment-status, refund, dispute, and fraud-prevention information. The payment processor collects payment-card and billing details on pages it controls. We do not store full card numbers or card security codes in the Anecdote FYI application database.
3 Sources of information
We receive information:
-
From family owners and guardians, when they create a workspace, add or invite members, upload or import photos, make assignments, review content, choose settings, or contact us.
-
From children under adult authorization and supervision, when they use an assigned photo to create, review, write, or submit a memory.
-
From other invited family members, when they accept access or participate according to their role.
-
From browsers and devices, through ordinary network requests, essential cookies, local processing, preferences, and restricted diagnostics.
-
From optional providers, when a guardian initiates a photo picker, identity flow, checkout, or other provider-controlled feature.
4 How we use information
We use personal information to:
- Create, authenticate, secure, and support family accounts and invitations.
- Apply owner, guardian, and child permissions and show each child only the assigned family material that child is allowed to use.
- Store and organize private photos, drafts, memories, handwriting, editions, and recovery versions.
- Run local-assisted workflows and create family JSON exports, printable layouts, and PDFs requested by authorized family members.
- Send service, invitation, security, access, and support communications.
- Diagnose failures, maintain reliability, prevent fraud or abuse, enforce our Terms of Service, and protect families and the Services.
- Process a paid plan, trial, refund, dispute, or subscription where offered.
- Comply with legal obligations and establish, exercise, or defend legal claims.
We do not use child content for advertising, behavioral profiling, or model training. We do not make solely automated decisions about a child that produce legal or similarly significant effects.
5 Cookies, device storage, and controls
We use first-party cookies and browser storage for these purposes:
-
en_sessionkeeps a user signed in, carries short-lived authentication and supervised-session state, and protects account flows. It is an essential, HTTP-only session cookie. -
en_themeand client-hint storage remember display preferences so pages can match the browser. -
anecdote-fyi-draftsIndexedDB storage holds up to 12 processed handwriting drafts on that browser and removes a draft when it is saved, when it is more than 30 days old and next checked, or when newer drafts exceed the limit. -
The browser cache may retain application files and local-processing model files according to browser settings.
The audience-measurement feature described above does not set analytics cookies and is disabled when the browser sends Do Not Track. A provider may use cookies on a page or picker it controls when a guardian chooses to interact with it; that provider's policy governs those cookies.
You can block or delete cookies and site storage through the browser. Blocking the essential session cookie prevents sign-in. Clearing site storage removes local drafts and cached model files from that browser but does not delete content already saved to the family workspace.
We do not use advertising cookies or sell or share browser activity for cross-context behavioral advertising. Because we do not conduct that sale or sharing, a Global Privacy Control signal does not change how the Services operate. Essential service, authentication, security, and family-content operations also do not change in response to Do Not Track.
6 How we disclose information
We do not sell or rent personal information and do not share it for cross-context behavioral advertising. We disclose information only as follows. The Services do not provide a public child profile, public feed, or built-in public posting feature.
6.1 Authorized family members
The family owner and guardians can access and manage the workspace. A child can access only that child's active profile, assigned photo queue, and associated entries. Guardians decide assignments and invitations. A guardian's approval can place a child's memory in a printable keepsake or PDF available to authorized family members.
Removing a family member revokes access but does not automatically erase memories that person already created or reviewed. The family owner and remaining guardians continue to control that content until it is deleted.
6.2 Service providers
Providers may process information as needed to help us operate and protect the Services, including:
-
Hosting, database, storage, backup, network, monitoring, and security providers.
-
Authentication and email-delivery providers for optional sign-in, verification, invitations, and support.
-
A payment processor for checkout, billing, fraud prevention, refunds, disputes, and transaction events where paid access is offered.
-
An optional photo-picker provider when a guardian enables and opens its interface.
-
A model-file hosting provider when the browser needs a model that we are not serving directly. Child content is not included in that model-file request.
These providers receive only the information reasonably needed for their role and may process it in countries where they operate. A provider's own policy applies when it acts independently or when a person interacts directly with a provider-controlled page.
6.3 Legal, safety, and business purposes
We may disclose information:
-
To comply with law, regulation, subpoena, court order, or another valid legal process.
-
To protect a child or another person's rights, safety, security, or property; investigate fraud, exploitation, or abuse; or protect the Services.
-
To professional advisers such as lawyers, accountants, auditors, or insurers where reasonably necessary and subject to appropriate confidentiality obligations.
-
In connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and appropriate protection of the information.
-
At the direction or with the authorization of the family owner, guardian, or person to whom the information relates, as applicable.
We may use and disclose information that has been aggregated or de-identified so it cannot reasonably be linked to a person. We do not attempt to re-identify it except to test whether de-identification measures work or as permitted by law.
7 Children and parental controls
The Services are designed for an adult-managed family activity. A child may not create or own an unsupervised family workspace. An adult who creates a child profile or authorizes a child's participation represents that the adult is the child's parent or legal guardian, or otherwise has authority to make those decisions and provide any permission required by law.
The family owner and guardians can:
-
Decide whether a child has a separate verified account or uses a restricted session on a guardian's shared device.
-
Choose which photos a child can retrieve and remove or skip an assignment.
-
Review a submitted memory, approve it for the collection, or return it for the child to redo. Guardians cannot silently rewrite a child's submitted words.
-
Correct profile and photo information, download a complete family data export, delete or restore photos and editions, revoke a family member's access, and ask us for privacy assistance.
-
Permanently purge a photo or edition, or have the family owner permanently delete the entire workspace.
-
Stop future collection from a child by ending the child's access and contacting us about deletion. The child may no longer be able to use features that require the deleted information.
The family owner should contact us before allowing a child to submit personal information if the adult cannot provide the authorization required where the family lives. A privacy policy and Terms of Service do not replace a separate direct notice or verifiable parental-consent step where one is legally required.
If you believe a child participated without appropriate adult authorization, contact us. We will investigate, restrict further collection where appropriate, and delete information where required. We may ask for information reasonably needed to verify the requester's identity and authority to act for the child.
8 Legal bases for processing
Where applicable law requires a legal basis, we rely on:
-
Contract, to create an adult-requested family workspace, authenticate authorized users, provide the requested features, process an offered paid plan, and respond to support requests.
-
Consent or parental authorization, where required for a child's participation, optional provider interaction, or another specific activity. Consent may be withdrawn for future processing, subject to information we must retain or process on another lawful basis.
-
Legitimate interests, to secure and improve the Services, enforce family-role boundaries, diagnose reliability, prevent fraud and abuse, maintain appropriate records, and establish or defend legal claims, where those interests are not overridden by a person's rights.
-
Legal obligations, including child-safety, tax, accounting, consumer-protection, and lawful disclosure requirements.
9 Retention and deletion
We retain information only for as long as reasonably necessary for the purpose described in this policy:
-
Workspace content generally remains while the family workspace is active so the family can continue editing and exporting it. Trashed photos and editions remain recoverable until a guardian restores or permanently purges them, or the workspace is deleted.
-
Removed members lose access, but the child profile or user audit record and already-authored or reviewed memories remain so the family can preserve the collection and, for a child profile, restore access. A guardian can contact us about deletion that is not available in the dashboard.
-
Server-side drafts expire 30 days after their last update and are deleted during subsequent workspace activity. Local handwriting drafts are pruned from the browser as described in Section 5.
-
Prior memory versions remain with the current memory, up to the 20-version limit, until the related content is permanently purged or the workspace is deleted.
-
Original audio is discarded from temporary browser memory after transcription and is not uploaded to us.
-
Pilot diagnostics are eligible for deletion after 90 days and are physically removed during subsequent workspace activity.
-
Invitation links expire after seven days and may be revoked sooner. The invitation record and its unusable token digest may remain with the workspace to show who was invited and whether access was accepted or revoked.
-
Security, request, and error records remain for the shorter period reasonably needed to operate, diagnose, and protect the Services, unless an incident or legal obligation requires longer retention.
-
Support communications and payment records, where applicable, may remain for the period needed to resolve a request and satisfy tax, accounting, fraud-prevention, contract, dispute, and legal obligations.
The family owner can permanently delete the workspace from the dashboard. That action cancels active subscriptions where applicable, removes collection content, profiles, invitations, diagnostics, logins, and users from the active application database, and disables the organization. Limited organization, payment, accounting, fraud-prevention, or legal records may remain without collection content where needed for an applicable obligation.
Backups and provider systems may retain protected residual copies for a limited period after deletion. A family should also delete downloaded exports, PDFs, printouts, provider copies, and browser storage separately because we cannot delete copies outside our control.
10 International processing
We and our providers may process information in the United States and other countries whose laws may differ from those where a family lives.
Where applicable law requires a transfer mechanism or safeguard for personal information sent across borders, we use an available lawful mechanism and take appropriate steps to protect the information. Contact us for more information about safeguards relevant to your information.
11 Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information. These include role-scoped access, private image routes, signed session cookies, hashed invitation tokens, transport security, file and size validation, metadata removal for new photo uploads, restricted child route data, and content-security controls.
No internet transmission, device, storage system, or security measure is perfectly secure. We cannot guarantee absolute security. Family members should protect email login links, invitation links, sessions, and guardian exit codes; use trusted devices; and avoid sharing private exports or PDFs unintentionally. Contact us promptly if you believe an account or workspace has been compromised.
12 Rights and choices
Depending on where a person lives and subject to legal exceptions, that person or an authorized parent or guardian may have the right to:
-
Know whether we process personal information and access or receive a copy of it.
-
Correct inaccurate information.
-
Delete information and prevent further collection or use.
-
Receive information provided to us in a portable format.
-
Restrict or object to certain processing.
-
Withdraw consent for future processing where consent is the legal basis.
-
Opt out of a sale, cross-context behavioral advertising, or certain profiling. We do not currently conduct those activities.
-
Receive equal service and not be discriminated against for exercising an applicable privacy right.
Many requests can be completed through guardian controls, the family export, or workspace deletion. A request may also be sent to support@anecdote.fyi. Describe the request and, if possible, write from the account email. We may need to verify identity, workspace membership, and authority to act for a child before disclosing or deleting private family information.
We will respond within the period required by applicable law. Some information may be exempt from a request, and deleting information essential to the Services may require closing an account or workspace. If we deny a request, we will explain why and provide an appeal method where required. A person may also complain to the privacy or data-protection authority where that person lives.
12.1 U.S. state disclosures
For U.S. state laws that use defined categories, we may have collected the following during the preceding 12 months:
-
Identifiers, such as a name, email address, IP address, internal user or child ID, invitation record, and payment-customer ID where applicable.
-
Commercial information, such as a trial, subscription, price, payment, refund, or dispute record where paid access is offered.
-
Internet or electronic activity, such as requested pages, browser and device categories, preferences, diagnostics, and security or error events.
-
Audio, visual, and user-generated information, such as private family photos, transcripts, captions, handwriting images, and collection content. The original audio recording is not uploaded to us.
-
Sensitive personal information, where a family photo or authored memory reveals information treated as sensitive under applicable law. We do not use that information to infer sensitive characteristics, advertise, or train models.
We collect these categories from the sources in Section 3, use them for the purposes in Section 4, and disclose them to the family, provider, and legal recipient categories in Section 6. We have not sold these categories or shared them for cross-context behavioral advertising.
13 Third-party services and family copies
The Services may link to or open optional providers, help pages, or other sites we do not control. Visiting them may allow the third party to receive ordinary request information. Review its policy before providing information.
An imported photo becomes a separate private copy in the family workspace. Changing or deleting the source provider's original does not change that copy. Likewise, a JSON export, PDF, printed keepsake, screenshot, or downloaded image is a separate copy controlled by the person who created or received it.
14 Changes to this policy
We may update this policy as the Services, providers, or legal requirements change. The date at the top identifies the current version. If a change materially affects how we use information already collected, we will provide reasonable notice through the Services, a direct adult communication, or email when required by law. We will seek new authorization or consent where required before materially changing how child information is collected, used, or disclosed.
15 Contact
The organization responsible for this policy is TableHQ LLC.
For privacy, child-safety, or data requests, email support@anecdote.fyi.