Privacy Policy
Last updated: May 27, 2026
1. Introduction
Kutty Story (“we”, “us”, “our”) is committed to protecting your privacy and the privacy of your children. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our personalized storybook service at kuttystory.com.
This policy is compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and applicable data protection regulations.
2. Data We Collect
2.1 Account Information
When you create an account, we collect your name, email address, and optionally your phone number. If you sign in via Google, we receive your name, email, and profile picture from Google.
2.2 Child Information
To personalize storybooks, we collect your child's first name, nickname (optional), gender, age, and physical appearance attributes (skin tone, hair color, glasses preference). We also collect photographs of your child that you upload.
2.3 Order and Payment Data
We collect shipping addresses, order details, and transaction records. Payment processing is handled by Razorpay; we do not store your full credit card or debit card numbers on our servers.
2.4 Usage Data
We automatically collect device information, browser type, IP address, pages visited, and interaction data to improve our service.
3. How We Use Your Data
- Service Delivery: To create personalized storybooks featuring your child's likeness based on the photos and details you provide.
- Order Fulfillment: To process payments, print books, and deliver them to your address.
- Communication: To send order updates, delivery notifications, and customer support responses.
- Improvement: To improve our AI illustration quality, website performance, and user experience.
4. Children's Data Protection
We take special care with children's data as required by the DPDP Act:
- Photos and child details are collected only with verifiable parental consent.
- Child photographs are encrypted at rest and in transit using AES-256 encryption.
- Photos are used exclusively for generating storybook illustrations and are never shared with third parties for marketing or any other purpose.
- Uploaded photos are automatically deleted within 30 days of upload, unless you explicitly request earlier deletion.
- We do not track, profile, or serve advertising to children.
5. Data Storage and Security
Your data is stored on servers located in India and protected by industry-standard security measures including:
- AES-256 encryption for photos and sensitive data at rest.
- TLS 1.3 encryption for all data in transit.
- Access controls limiting data access to authorized personnel only.
- Regular security audits and vulnerability assessments.
6. Data Sharing
We share your data only with the following categories of service providers, strictly for the purpose of delivering our service:
- Print Partners: Printing facilities receive the final book PDF for printing. They do not receive raw photos.
- Shipping Partners: Courier services receive shipping address details for delivery.
- Payment Processor: Razorpay processes your payments securely.
- Cloud Infrastructure: Cloudflare R2 for CDN and storage, with data residency in India.
We never sell your personal data or your child's data to third parties.
7. Your Rights Under DPDP Act
As a Data Principal, you have the right to:
- Access: Request a summary of the personal data we hold about you and your child.
- Correction: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data and your child's data, subject to legal retention requirements.
- Withdraw Consent: Withdraw your consent for data processing at any time, understanding this may affect our ability to provide the service.
- Grievance Redressal: Lodge a complaint with our Data Protection Officer or the Data Protection Board of India.
8. Data Retention
- Photos: Automatically deleted within 30 days of upload.
- Account data: Retained while your account is active and for 90 days after deletion request.
- Order records: Retained for 7 years as required by Indian tax and commerce regulations.
9. Cookies
We use essential cookies for authentication and session management. We use analytics cookies (only with your consent) to understand usage patterns and improve our service. You can manage cookie preferences from your browser settings.
10. Data Protection Officer
For any privacy-related queries, concerns, or to exercise your rights, contact our Data Protection Officer:
- Email: info121.tph@gmail.com
- Address: No 6, Race Course Road, Kajamalai, Tiruchirappalli, Tamil Nadu 620023
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice on our website. Your continued use of the service after changes constitutes acceptance of the updated policy.
