Privacy Policy
Last updated: February 2026
1. Data Controller
The party responsible for data processing on this website is the operator of kiki-book.app as named in the imprint.
2. Collection and Storage of Personal Data
When you visit our website, the following data is automatically collected and stored:
- IP address of the requesting device
- Date and time of access
- Name and URL of the retrieved file
- Website from which the access originates (referrer URL)
- Browser used and, where applicable, the operating system
This data is used exclusively to ensure smooth operation of the website and to improve our services. No association with specific individuals is made. Legal basis: Art. 6(1)(f) GDPR.
3. Registration and User Account
(1) Registration is required to use our services. The following data is collected: email address and optionally a name.
(2) The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Data is stored for the duration of the contractual relationship and deleted after the expiry of statutory retention periods.
4. Book Creation and AI Processing
(1) To create personalized children's books, we process information entered by the customer (names, age group, story idea, character descriptions) as well as uploaded reference images.
(2) This data is transmitted to AI services (Google Gemini) for generating texts and illustrations. Processing is based on Art. 6(1)(b) GDPR (performance of a contract).
(3) Uploaded reference images are used exclusively for book creation and are not stored or shared for any other purpose after generation is complete.
5. Payment Processing
(1) Payment processing is handled by the payment service provider Stripe (Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA).
(2) Payment data is transmitted directly to Stripe during payment processing. We do not store complete credit card data. Legal basis: Art. 6(1)(b) GDPR.
(3) For more information about data protection at Stripe, please visit: https://stripe.com/privacy https://stripe.com/de/privacy
6. Hosting
This website is hosted by an external service provider (hosting provider). Personal data collected on this website is stored on the host's servers. Legal basis: Art. 6(1)(f) GDPR and Art. 28 GDPR (data processing agreement).
7. Cookies
(1) Our website uses technically necessary cookies that are required for the operation of the website and the provision of our services (e.g., session cookies for authentication).
(2) The legal basis for technically necessary cookies is Art. 6(1)(f) GDPR.
(3) We currently do not use any analytics or tracking cookies.
8. Rights of Data Subjects
You have the following rights with regard to your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.
9. Data Security
We use the widely adopted SSL (Secure Socket Layer) encryption method in combination with the highest level of encryption supported by your browser when visiting the website. All personal data is transmitted in encrypted form.
10. Currency and Amendments to this Privacy Policy
This privacy policy is currently valid as of February 2026. Due to the further development of our website or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy.
