Privacy
What happens to my kid's photos?
The honest answer first, then the full legal notice. Version 1.1 · prepared 13 August 2026 · effective when published
Privacy
The honest answer first, then the full legal notice. Version 1.1 · prepared 13 August 2026 · effective when published
Plain language. The formal notice with every detail follows below.
1.1 The controller of your personal data is MARTYM sp. z o.o., ul. Radna 10 lok. 15, 00-341 Warszawa, Poland, NIP 5253100303, KRS 0001257482 ("we", "Martym").
1.2 Privacy contact: hello@martym.com. A human answers, and you can write in Polish or English.
1.3 We have not appointed a Data Protection Officer. We review that decision as the scale and nature of processing changes. Questions and rights requests go to the contact in §1.2.
1.4 You can complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa — at any time, and without asking us first.
1.5 This notice covers both martym.com and the Studio and Reader at app.martym.com. It is written as a combined art. 13 and art. 14 GDPR notice, because you give us information about your child — so for your child's data we are also telling you what art. 14 requires, including that the source of that data is you.
2.1 We keep this list short on purpose. We do not collect data "just in case".
| What | Why | Legal basis |
|---|---|---|
| Your name, email and passwordless or external-provider identifier where used | To create and run your account, sign you in, and contact you about your books | Performance of our contract with you — art. 6(1)(b) |
| Your story, answers, manuscripts, notes and instructions | To write, illustrate, assemble and narrate your book | Performance of our contract — art. 6(1)(b) |
| Your child's reference photographs | To paint your child consistently as the book's hero | Your consent — art. 6(1)(a), given as the holder of parental responsibility, withdrawable at any time (§3) |
| The child's first name, age band, pronoun, interests | To make the story fit the child it is for | Your consent — art. 6(1)(a) |
| Optional sensitive context — what your child fears or is growing through, including anything about health or disability | Only to steer the story, if you choose to tell us | Your separate explicit consent — art. 9(2)(a). Entirely optional; the product works without it (§4) |
| Payment and invoice data (not your card number) | To take payment, issue invoices, keep tax records | Contract — art. 6(1)(b); and our legal obligations under Polish tax and accounting law — art. 6(1)(c) |
| Publishing a book to the public shelf | To show your finished book to other readers, if you ask us to | Your consent — art. 6(1)(a). Never a default, and revocable: unpublishing takes it down |
| Technical logs, error reports, abuse signals | To keep the Service working, secure, and not abused | Our legitimate interests — art. 6(1)(f). You may object; ask us for the balancing assessment |
| Marketing email | We send none today. If we ever do, it will be opt-in only | Consent — art. 6(1)(a), plus the separate consent Polish electronic-communications law requires |
2.2 Giving us your email and your story is necessary to make a book — without them there is no contract we can perform. Everything about your child is optional in the legal sense: you can decline, and the consequence is only that the book will be less precisely about them.
3.1 We ask for photographs for one reason: so that the child in the pictures looks like your child, on page 3 and again on page 43.
3.2 We rely on your consent, not on the contract, even though you are buying a book. That is deliberate. Your child is the person the data is about, and they did not sign anything; basing this on "we need it to perform the contract" would be treating a child's image as a term of someone else's purchase. Consent can be withdrawn, which is the protection that matters here.
3.3 You may withdraw that consent at any time, by deleting the photograph, deleting the child's profile, or writing to us. Withdrawal stops further use immediately. It does not undo pictures already painted and delivered to you — those are your book — and it does not make earlier processing unlawful.
3.4 Where the photograph actually goes. Painting requires sending the reference to the AI service that paints. Concretely: the image is transmitted to our image-generation provider (§5), which runs the model that produces the illustration. We send the minimum needed and do not attach your child's name to it. We send a child's photograph only where the provider's contract, settings and retention controls meet the promises in this notice; otherwise that processing remains disabled.
3.5 What never happens. A reference photograph is never published, never placed in a book, never shown on the public shelf, never sold, never used in our marketing — even with your permission — and never used to train a model.
3.6 We do not use face recognition. We do not compare your child's face against any database, we do not build a face template to identify them, and we do not use these photographs to recognise anyone anywhere. The photograph conditions a painting; it does not identify a person. That is why we treat it as ordinary — if highly sensitive — personal data rather than biometric data, and we have written down that reasoning so a regulator can check it.
3.7 Only upload a photograph of a child in your care. The Terms make this your promise (§11 there); here it is the practical point that we cannot know whose child is in a picture, so the judgement has to be yours.
4.1 A child's profile can hold a first name, an age band, a pronoun, interests, and — only if you choose — what your child is frightened of or working through, which is what lets a story genuinely help.
4.2 That last part may amount to health data or similarly sensitive information about your child. So it is separate, optional, and asked for with its own explicit consent, never bundled with anything else, and the book can be made without it. You can delete it on its own at any time.
4.3 Where this text goes. So that we can write and check chapters against what you asked for, the story brief — which can include this context — is sent to our text providers (§5). It is never printed, never published, and never part of a book's visible content.
4.4 Profiles live at family level, inside your account, and are not shared with other customers, ever.
5.1 We use a small number of specialist providers, each processing only on our instructions under a written data processing agreement. We name all of them, because "trusted partners" is not a disclosure.
| Provider | What it does | What it receives |
|---|---|---|
| Google or another supported identity provider, where you choose it | Sign-in | Your email, name and provider identifier |
| Stripe | Payments | Your email and payment details. We never receive your card number |
| OpenAI | Drafting prose | Your story brief and chapter text, which can include the child's first name and the optional context of §4 |
| Anthropic | Checking and editing prose | The same material, for review |
| fal.ai — which runs models supplied by Google and Black Forest Labs | Painting illustrations and checking likeness | Reference images, including a child's photograph where you have provided one, plus the picture description |
| ElevenLabs | Narration | The chapter text to be read aloud |
| Google Cloud — data stored in the EU, region europe-central2 (Warsaw) | Hosting and file storage | Everything, at rest |
5.1a Other people see a book only because you decided they should. There are exactly two ways that happens, and both are your choice, made per book: publishing it to the Library, where anyone with a membership can read it (Terms §13), and sharing it with one named account you nominate by email (Terms §13a). Neither happens by default, and no lapse, failed payment, change of plan or end of a free trial ever publishes or shares anything. Reference photographs are never part of either.
5.1b When you share a book, we tell the person you named that it is waiting, and we tell you when they last opened it — nothing else about them. When you take a share back, the book leaves their shelf; a copy they had already downloaded stays with them, exactly as your own downloads stay with you.
5.2 We may also disclose data to public authorities where the law requires it, and to professional advisers under a duty of confidence. If our business were ever transferred, your data would move with it and your rights would be unaffected — we would tell you.
5.3 We do not sell personal data, we run no advertising networks and no ad pixels, and we share nothing with data brokers.
6.1 Several providers above are established in the United States, so making your book may involve transferring data outside the European Economic Area. Before a provider receives personal data, we verify and record an applicable GDPR Chapter V safeguard.
6.2 You can ask us for a copy of the safeguards that apply to any transfer, and we will send it.
7.1 We tell you this because it would be easy to leave out. AI providers that process images generally run automated screening for child sexual abuse material, and providers established in the United States are legally obliged to report suspected material to the authorities there. So when a reference image is sent for painting, it may be screened automatically by that provider, and that provider may report a confirmed match, as its law requires.
7.2 This exists to protect children and we would not want it removed. We are telling you it happens because a privacy notice that omitted it would be incomplete.
8.1 The Service is built on AI, described in §5 and in the Terms. No automated decision is made about you that has legal effects or similarly significantly affects you within the meaning of art. 22 GDPR. AI drafts text and pictures; you approve them; nothing about your rights, your money or your access is decided by a model.
8.2 Automated checks do screen for prohibited content and abuse. If such a check ever restricts your account, a person reviews it and you can contest it — the Terms (§13.7 there) say how.
10.1 You have the right to: access your data and get a copy; correct it; have it erased; restrict how we use it; object to processing based on our legitimate interests; receive your data in a portable format; and withdraw any consent at any time without affecting what was lawful before.
10.2 Write to the privacy contact in §1.2. We answer within one month, and if a request is genuinely complex we may take up to two months more — we will tell you within the first month if so. We do not charge for this.
10.3 Two honest limits on erasure, so it is not oversold:
10.4 You can also complain to the President of the Personal Data Protection Office (§1.4), or go to court.
11.1 Your child is a data subject with the full set of rights in §10, even though they never signed up and never used the Service. Until a child can act for themselves, the holder of parental responsibility exercises those rights on their behalf — in practice, you.
11.2 As a child grows up they may want their own say. If a young person asks us to delete pictures of themselves from an account they are not the holder of, we will take that seriously, engage with the account holder, and act on it where the law entitles them to it.
11.3 Our Service is offered to adults. It is not directed at children, children do not create accounts, and we do not knowingly collect data from a child directly.
12.1 This website sets no cookies of its own, and it stores nothing on your device for measurement unless you have explicitly agreed. Fonts and images are served from our own domain, so simply visiting this site does not tell any third party that you were here.
12.2 The Studio — app.martym.com — uses only strictly necessary session and sign-in cookies. They keep you signed in and protect passwordless or external-provider sign-in and device linking against abuse. They are used only when the relevant flow needs them and are strictly necessary to provide a service you explicitly asked for, so under Polish electronic-communications law they do not require consent — but you should still know they exist, which is why they are here.
12.3 Measurement, and what it may do. We measure in two layers, and they are governed differently.
12.4 Layer one is cookieless and needs no consent. We may use Plausible Analytics (Plausible Insights OÜ, Estonia — EU-hosted) to count page visits. It sets no cookie, stores nothing on your device, assigns you no identifier, and cannot follow you between sites. Because it stores nothing, Polish electronic-communications law does not require consent for it, and refusing measurement does not switch it off — there is nothing about you in it to switch off.
12.5 Layer two asks first, always. If we run Google Analytics 4 (Google Ireland Limited), it loads only after you have agreed, and every consent signal starts at “denied”. Until you agree, no analytics or advertising cookie is written and nothing is sent. If you refuse, nothing loads at all and this site is byte-for-byte the site it was before we asked. You can withdraw your agreement at any time from the Measurement choice link in the footer, and withdrawing is exactly as easy as agreeing was.
12.6 What we never send. A reading link to one of your books
is itself the key to that book, so no address under /reader-content/ is ever sent
to any measurement or advertising service — and the reading app carries no measurement
code at all, on any platform. Studio addresses have every book and account identifier stripped
out before they leave us. We never send an email address, a child's name, a book title, or any
part of a story. We do not upload contact lists to any advertising network and we do not use
Customer Match or similar audience products.
12.7 Advertising measurement. If you arrive from an advertisement, the address you arrive on carries a click identifier from the advertising network. We store it against your account so we can tell which advertisement led to a purchase. It is sent back to that network only if you agreed to advertising storage at the banner; if you refused, or were never asked, it is never sent. It is a click reference, not a profile: we send the click identifier, the amount and the currency, and nothing about you.
12.8 The cookie table. This is everything that may be stored on your device by us or on our behalf.
| Name | Set by | Purpose | Lifetime | Consent |
|---|---|---|---|---|
martym-consent | martym.com (local storage) | Remembers your measurement answer so we do not ask twice | Until you clear it | Not required — it records your choice |
martym-name | martym.com (local storage) | The name you typed into the live preview. It never leaves your browser | Until you clear it | Not required — strictly necessary |
| Session and sign-in cookies | app.martym.com | Keeps you signed in; protects passwordless and provider sign-in and device linking | Session, or up to 30 days if you stay signed in | Not required — strictly necessary |
_ga, _ga_<id> | Google Analytics 4 | Distinguishes visits so we can count them and see which pages help families | Up to 2 years | Only with your consent |
_gcl_au | Google (conversion linker) | Remembers that an advertisement led you here, so a purchase can be attributed to it. Only appears once advertising conversion tracking is switched on | Up to 90 days | Only with your consent |
| — none — | Plausible Analytics | Counts page visits without storing anything on your device | — | Not required — stores nothing |
12.9 Where this data goes. Plausible processes in the European Union. Google Analytics is provided by Google Ireland Limited and may involve transfers outside the European Economic Area; those transfers rely on the European Commission's standard contractual clauses together with the EU–US Data Privacy Framework where it applies. Google is our processor for analytics, and we have a data-processing agreement with it. Our legal basis for layer two is your consent (Art. 6(1)(a) GDPR); for layer one and for the strictly necessary cookies it is our legitimate interest in running and securing the service (Art. 6(1)(f)). Analytics data is retained for 14 months.
13.1 Data is encrypted in transit. Access is limited to those who need it. Each family's data is separated at the application layer, and that separation is enforced by automated tests as well as by review. Sign-in is passwordless or delegated to a supported identity provider, so we do not store an account password. A device you link for reading gets read-only access and can never author, purchase or delete.
13.2 No system is perfect. If a breach ever puts your rights at serious risk, we will tell the supervisory authority within 72 hours and tell you without undue delay, in plain language: what happened, what it means for you, and what we did.
14.1 If we change how we handle data, we will update this page and, where the change matters to you, tell you by email before it takes effect. Adding a new provider that receives your child's data is exactly such a change.
14.2 Version 1.1, prepared 13 August 2026 and effective when published. Earlier versions are kept and available on request.
Write to us any time at hello@martym.com. A human answers. If you think we have this wrong, tell us; we would rather fix it than defend it.