martym

Privacy

What happens to my kid's photos?

The honest answer first, then the full legal notice. Version 1.1 · prepared 13 August 2026 · effective when published

Plain language. The formal notice with every detail follows below.

The short answers

  • Photos do one job: painting your child consistently in your book. Nothing else.
  • Never published. A reference photo never appears in a book, never on the public shelf, never anywhere outside your family's account.
  • Never sold. Not to anyone, for anything, ever.
  • Never used to train AI models — not ours, and we contract our providers so it is not theirs either.
  • But painting does send the picture somewhere, and you deserve to know that. To paint your child, the reference has to reach the AI services that do the painting. We name every one of them below, send the minimum, and do not enable production processing until the required processor and transfer safeguards are in place. That is the one thing it would be easy to gloss over, and we would rather be precise than comfortable.
  • Deletable at any time. Delete a photo, a child's profile, or the whole account — it goes, from our storage too.
  • A child's profile is the most sensitive thing here, and it never leaves your account or enters a published book. If you tell us what your child is frightened of so the story can help, that part is optional, we ask for separate consent, and you can withdraw it at any time.
  • Nothing is stored on your device for measurement unless you say yes. If we ask and you refuse, this site behaves exactly as it did before — no cookie, no tag, nothing sent. The Studio, where you sign in, sets only what is strictly needed to keep you signed in. You can change your answer at any time from the footer.
Publication gate. The controller and monitored privacy address are complete. Production processing of children's photographs must remain disabled until the company has recorded a data protection impact assessment and accepted the relevant data-processing and international-transfer safeguards with every provider that receives those photographs.

1. Who is responsible

1.1 The controller of your personal data is MARTYM sp. z o.o., ul. Radna 10 lok. 15, 00-341 Warszawa, Poland, NIP 5253100303, KRS 0001257482 ("we", "Martym").

1.2 Privacy contact: hello@martym.com. A human answers, and you can write in Polish or English.

1.3 We have not appointed a Data Protection Officer. We review that decision as the scale and nature of processing changes. Questions and rights requests go to the contact in §1.2.

1.4 You can complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa — at any time, and without asking us first.

1.5 This notice covers both martym.com and the Studio and Reader at app.martym.com. It is written as a combined art. 13 and art. 14 GDPR notice, because you give us information about your child — so for your child's data we are also telling you what art. 14 requires, including that the source of that data is you.

2. What we process, why, and on what legal basis

2.1 We keep this list short on purpose. We do not collect data "just in case".

WhatWhyLegal basis
Your name, email and passwordless or external-provider identifier where usedTo create and run your account, sign you in, and contact you about your booksPerformance of our contract with you — art. 6(1)(b)
Your story, answers, manuscripts, notes and instructionsTo write, illustrate, assemble and narrate your bookPerformance of our contract — art. 6(1)(b)
Your child's reference photographsTo paint your child consistently as the book's heroYour consent — art. 6(1)(a), given as the holder of parental responsibility, withdrawable at any time (§3)
The child's first name, age band, pronoun, interestsTo make the story fit the child it is forYour consent — art. 6(1)(a)
Optional sensitive context — what your child fears or is growing through, including anything about health or disabilityOnly to steer the story, if you choose to tell usYour separate explicit consent — art. 9(2)(a). Entirely optional; the product works without it (§4)
Payment and invoice data (not your card number)To take payment, issue invoices, keep tax recordsContract — art. 6(1)(b); and our legal obligations under Polish tax and accounting law — art. 6(1)(c)
Publishing a book to the public shelfTo show your finished book to other readers, if you ask us toYour consent — art. 6(1)(a). Never a default, and revocable: unpublishing takes it down
Technical logs, error reports, abuse signalsTo keep the Service working, secure, and not abusedOur legitimate interests — art. 6(1)(f). You may object; ask us for the balancing assessment
Marketing emailWe send none today. If we ever do, it will be opt-in onlyConsent — art. 6(1)(a), plus the separate consent Polish electronic-communications law requires

2.2 Giving us your email and your story is necessary to make a book — without them there is no contract we can perform. Everything about your child is optional in the legal sense: you can decline, and the consequence is only that the book will be less precisely about them.

3. Your child's photographs

3.1 We ask for photographs for one reason: so that the child in the pictures looks like your child, on page 3 and again on page 43.

3.2 We rely on your consent, not on the contract, even though you are buying a book. That is deliberate. Your child is the person the data is about, and they did not sign anything; basing this on "we need it to perform the contract" would be treating a child's image as a term of someone else's purchase. Consent can be withdrawn, which is the protection that matters here.

3.3 You may withdraw that consent at any time, by deleting the photograph, deleting the child's profile, or writing to us. Withdrawal stops further use immediately. It does not undo pictures already painted and delivered to you — those are your book — and it does not make earlier processing unlawful.

3.4 Where the photograph actually goes. Painting requires sending the reference to the AI service that paints. Concretely: the image is transmitted to our image-generation provider (§5), which runs the model that produces the illustration. We send the minimum needed and do not attach your child's name to it. We send a child's photograph only where the provider's contract, settings and retention controls meet the promises in this notice; otherwise that processing remains disabled.

3.5 What never happens. A reference photograph is never published, never placed in a book, never shown on the public shelf, never sold, never used in our marketing — even with your permission — and never used to train a model.

3.6 We do not use face recognition. We do not compare your child's face against any database, we do not build a face template to identify them, and we do not use these photographs to recognise anyone anywhere. The photograph conditions a painting; it does not identify a person. That is why we treat it as ordinary — if highly sensitive — personal data rather than biometric data, and we have written down that reasoning so a regulator can check it.

3.7 Only upload a photograph of a child in your care. The Terms make this your promise (§11 there); here it is the practical point that we cannot know whose child is in a picture, so the judgement has to be yours.

4. The child's profile

4.1 A child's profile can hold a first name, an age band, a pronoun, interests, and — only if you choose — what your child is frightened of or working through, which is what lets a story genuinely help.

4.2 That last part may amount to health data or similarly sensitive information about your child. So it is separate, optional, and asked for with its own explicit consent, never bundled with anything else, and the book can be made without it. You can delete it on its own at any time.

4.3 Where this text goes. So that we can write and check chapters against what you asked for, the story brief — which can include this context — is sent to our text providers (§5). It is never printed, never published, and never part of a book's visible content.

4.4 Profiles live at family level, inside your account, and are not shared with other customers, ever.

5. Who else sees the data

5.1 We use a small number of specialist providers, each processing only on our instructions under a written data processing agreement. We name all of them, because "trusted partners" is not a disclosure.

ProviderWhat it doesWhat it receives
Google or another supported identity provider, where you choose itSign-inYour email, name and provider identifier
StripePaymentsYour email and payment details. We never receive your card number
OpenAIDrafting proseYour story brief and chapter text, which can include the child's first name and the optional context of §4
AnthropicChecking and editing proseThe same material, for review
fal.ai — which runs models supplied by Google and Black Forest LabsPainting illustrations and checking likenessReference images, including a child's photograph where you have provided one, plus the picture description
ElevenLabsNarrationThe chapter text to be read aloud
Google Cloud — data stored in the EU, region europe-central2 (Warsaw)Hosting and file storageEverything, at rest

5.1a Other people see a book only because you decided they should. There are exactly two ways that happens, and both are your choice, made per book: publishing it to the Library, where anyone with a membership can read it (Terms §13), and sharing it with one named account you nominate by email (Terms §13a). Neither happens by default, and no lapse, failed payment, change of plan or end of a free trial ever publishes or shares anything. Reference photographs are never part of either.

5.1b When you share a book, we tell the person you named that it is waiting, and we tell you when they last opened it — nothing else about them. When you take a share back, the book leaves their shelf; a copy they had already downloaded stays with them, exactly as your own downloads stay with you.

5.2 We may also disclose data to public authorities where the law requires it, and to professional advisers under a duty of confidence. If our business were ever transferred, your data would move with it and your rights would be unaffected — we would tell you.

5.3 We do not sell personal data, we run no advertising networks and no ad pixels, and we share nothing with data brokers.

6. Sending data outside the EEA

6.1 Several providers above are established in the United States, so making your book may involve transferring data outside the European Economic Area. Before a provider receives personal data, we verify and record an applicable GDPR Chapter V safeguard.

  • Where the receiving entity is validly certified, we may rely on the European Commission's EU–US Data Privacy Framework adequacy decision.
  • Otherwise we use the European Commission's Standard Contractual Clauses, supplemented by an assessment and additional measures where required.
  • fal.ai receives no child's photograph in production until its data-processing terms, processing locations and transfer safeguard have been accepted and recorded.

6.2 You can ask us for a copy of the safeguards that apply to any transfer, and we will send it.

7. Automated child-safety screening

7.1 We tell you this because it would be easy to leave out. AI providers that process images generally run automated screening for child sexual abuse material, and providers established in the United States are legally obliged to report suspected material to the authorities there. So when a reference image is sent for painting, it may be screened automatically by that provider, and that provider may report a confirmed match, as its law requires.

7.2 This exists to protect children and we would not want it removed. We are telling you it happens because a privacy notice that omitted it would be incomplete.

8. AI and automated decisions

8.1 The Service is built on AI, described in §5 and in the Terms. No automated decision is made about you that has legal effects or similarly significantly affects you within the meaning of art. 22 GDPR. AI drafts text and pictures; you approve them; nothing about your rights, your money or your access is decided by a model.

8.2 Automated checks do screen for prohibited content and abuse. If such a check ever restricts your account, a person reviews it and you can contest it — the Terms (§13.7 there) say how.

9. How long we keep things

  • Reference photographs — the shortest retention of anything here. We keep them while your book project is being made or revised, and delete them when you delete a photograph, delete the profile, or close your account.
  • The child's profile — until you delete it or close the account.
  • Your books, illustrations and print files — for as long as you have an account, because they are the product you bought and you may want them years later.
  • An account whose free trial ends — remains open unless you delete it. The shelf rests, but projects and books are not automatically deleted. The same retention periods in this section continue to apply; see Terms §14a.
  • Account data — while the account exists, then only as long as needed to handle any outstanding claim.
  • Payment and accounting records — for the period Polish tax and accounting law requires, currently five years counted from the end of the relevant year. We cannot delete these earlier, even at your request, because the law says so.
  • Technical and security logs — a short period, measured in months, unless a specific incident requires keeping them longer.

10. Your rights

10.1 You have the right to: access your data and get a copy; correct it; have it erased; restrict how we use it; object to processing based on our legitimate interests; receive your data in a portable format; and withdraw any consent at any time without affecting what was lawful before.

10.2 Write to the privacy contact in §1.2. We answer within one month, and if a request is genuinely complex we may take up to two months more — we will tell you within the first month if so. We do not charge for this.

10.3 Two honest limits on erasure, so it is not oversold:

  • We can delete from our systems and instruct our providers to delete from theirs. We cannot un-deliver a copy you already downloaded or a book already printed — and by design we cannot reach into your device, which is the same promise that makes your book yours forever.
  • Payment and accounting records must be kept for the statutory period (§9). GDPR itself allows this where a legal obligation requires it.

10.4 You can also complain to the President of the Personal Data Protection Office (§1.4), or go to court.

11. The child's rights, and who exercises them

11.1 Your child is a data subject with the full set of rights in §10, even though they never signed up and never used the Service. Until a child can act for themselves, the holder of parental responsibility exercises those rights on their behalf — in practice, you.

11.2 As a child grows up they may want their own say. If a young person asks us to delete pictures of themselves from an account they are not the holder of, we will take that seriously, engage with the account holder, and act on it where the law entitles them to it.

11.3 Our Service is offered to adults. It is not directed at children, children do not create accounts, and we do not knowingly collect data from a child directly.

12. Cookies

12.1 This website sets no cookies of its own, and it stores nothing on your device for measurement unless you have explicitly agreed. Fonts and images are served from our own domain, so simply visiting this site does not tell any third party that you were here.

12.2 The Studio — app.martym.com — uses only strictly necessary session and sign-in cookies. They keep you signed in and protect passwordless or external-provider sign-in and device linking against abuse. They are used only when the relevant flow needs them and are strictly necessary to provide a service you explicitly asked for, so under Polish electronic-communications law they do not require consent — but you should still know they exist, which is why they are here.

12.3 Measurement, and what it may do. We measure in two layers, and they are governed differently.

12.4 Layer one is cookieless and needs no consent. We may use Plausible Analytics (Plausible Insights OÜ, Estonia — EU-hosted) to count page visits. It sets no cookie, stores nothing on your device, assigns you no identifier, and cannot follow you between sites. Because it stores nothing, Polish electronic-communications law does not require consent for it, and refusing measurement does not switch it off — there is nothing about you in it to switch off.

12.5 Layer two asks first, always. If we run Google Analytics 4 (Google Ireland Limited), it loads only after you have agreed, and every consent signal starts at “denied”. Until you agree, no analytics or advertising cookie is written and nothing is sent. If you refuse, nothing loads at all and this site is byte-for-byte the site it was before we asked. You can withdraw your agreement at any time from the Measurement choice link in the footer, and withdrawing is exactly as easy as agreeing was.

12.6 What we never send. A reading link to one of your books is itself the key to that book, so no address under /reader-content/ is ever sent to any measurement or advertising service — and the reading app carries no measurement code at all, on any platform. Studio addresses have every book and account identifier stripped out before they leave us. We never send an email address, a child's name, a book title, or any part of a story. We do not upload contact lists to any advertising network and we do not use Customer Match or similar audience products.

12.7 Advertising measurement. If you arrive from an advertisement, the address you arrive on carries a click identifier from the advertising network. We store it against your account so we can tell which advertisement led to a purchase. It is sent back to that network only if you agreed to advertising storage at the banner; if you refused, or were never asked, it is never sent. It is a click reference, not a profile: we send the click identifier, the amount and the currency, and nothing about you.

12.8 The cookie table. This is everything that may be stored on your device by us or on our behalf.

NameSet byPurposeLifetimeConsent
martym-consentmartym.com (local storage) Remembers your measurement answer so we do not ask twice Until you clear itNot required — it records your choice
martym-namemartym.com (local storage) The name you typed into the live preview. It never leaves your browser Until you clear itNot required — strictly necessary
Session and sign-in cookiesapp.martym.com Keeps you signed in; protects passwordless and provider sign-in and device linking Session, or up to 30 days if you stay signed in Not required — strictly necessary
_ga, _ga_<id>Google Analytics 4 Distinguishes visits so we can count them and see which pages help families Up to 2 yearsOnly with your consent
_gcl_auGoogle (conversion linker) Remembers that an advertisement led you here, so a purchase can be attributed to it. Only appears once advertising conversion tracking is switched on Up to 90 daysOnly with your consent
— none —Plausible Analytics Counts page visits without storing anything on your device Not required — stores nothing

12.9 Where this data goes. Plausible processes in the European Union. Google Analytics is provided by Google Ireland Limited and may involve transfers outside the European Economic Area; those transfers rely on the European Commission's standard contractual clauses together with the EU–US Data Privacy Framework where it applies. Google is our processor for analytics, and we have a data-processing agreement with it. Our legal basis for layer two is your consent (Art. 6(1)(a) GDPR); for layer one and for the strictly necessary cookies it is our legitimate interest in running and securing the service (Art. 6(1)(f)). Analytics data is retained for 14 months.

13. Security

13.1 Data is encrypted in transit. Access is limited to those who need it. Each family's data is separated at the application layer, and that separation is enforced by automated tests as well as by review. Sign-in is passwordless or delegated to a supported identity provider, so we do not store an account password. A device you link for reading gets read-only access and can never author, purchase or delete.

13.2 No system is perfect. If a breach ever puts your rights at serious risk, we will tell the supervisory authority within 72 hours and tell you without undue delay, in plain language: what happened, what it means for you, and what we did.

14. Changes to this notice

14.1 If we change how we handle data, we will update this page and, where the change matters to you, tell you by email before it takes effect. Adding a new provider that receives your child's data is exactly such a change.

14.2 Version 1.1, prepared 13 August 2026 and effective when published. Earlier versions are kept and available on request.

Questions

Write to us any time at hello@martym.com. A human answers. If you think we have this wrong, tell us; we would rather fix it than defend it.