FableShip FableShip Magical Fairy Tales Create Story
Terms and Conditions Privacy Policy Newsletter Terms

Fableship Privacy Policy

In force since: 8/23/2026 Version: 2026-08-23

Read in: English Polski Deutsch Français Italiano Español Русский Türkçe

This Privacy Policy (hereinafter: the “Policy”) contains information on the processing of your personal data in connection with the use of the “Fableship” application, operating at the Internet address fableship.com (hereinafter: the “Application”).

Any capitalised terms not otherwise defined in this Policy have the meaning given to them in the Terms and Conditions.

1. Personal data Controller

The Controller of your personal data is Piotr Klimaszewski, conducting business activity under the firm Codeenable Piotr Klimaszewski (address for service: ul. Orląt Lwowskich 7 lok. 9, 71-340 Szczecin, Poland), entered in the Central Register and Information on Business Activity (CEIDG) kept by the minister competent for the economy, tax identification number NIP: 8471402340, statistical number REGON: 519644425 (hereinafter: the “Controller”).

2. Contact with the Controller

In all matters related to the processing of personal data you can contact the Controller via:

  • e-mail – at: office@codeenable.com,
  • postal mail – at: ul. Orląt Lwowskich 7 lok. 9, 71-340 Szczecin, Poland.

The person responsible on the Controller's side for matters relating to the protection of personal data is Piotr Klimaszewski.

The Controller has not appointed a Data Protection Officer, as none of the conditions set out in Article 37(1) of the GDPR applies. All matters concerning personal data should be addressed directly to the Controller, in the manner indicated above.

3. Personal data protection measures

The Controller applies modern organisational and technical safeguards to ensure the best possible protection of your personal data and guarantees that it processes them in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: the “GDPR”), the Polish Act of 10 May 2018 on the Protection of Personal Data and other personal data protection regulations.

The safeguards applied include in particular: encryption of connections using TLS, storage of passwords solely as cryptographic hashes, two-step sign-in, access control to resources based on managed identities, encryption of data at rest on the infrastructure provider's side, and the delivery of image files solely through time-limited, signed URLs.

4. Children's data

The Application creates stories for children, but an account in the Application may be created only by an adult acting as a parent or legal guardian. The Controller does not direct the Application to children and does not collect data directly from children.

A child's data (name, age, gender, description of appearance, avatar) is entered into the Application by the parent or legal guardian in order to personalise a story. The basis for processing that data is Article 6(1)(b) of the GDPR – performance of the agreement concluded with the parent or guardian, whose declaration of acting in that capacity is a condition for creating an account.

The Controller draws your attention to the fact that:

  • a child's data is used solely to generate and display a story and to store it in the parent's library,
  • a child's data is not used to train artificial intelligence models or for marketing purposes,
  • a story is not publicly available unless the parent publishes it themselves; publishing a story means making the names and characteristics contained in it available on a public subpage, and you should therefore consider before publishing whether this is in the child's best interests,
  • the parent may at any time delete a child's profile, withdraw the publication of a story and delete the account together with all its data.

The Controller recommends entering only a first name (without a surname) in a child's profile and avoiding any data that is not needed to create a story.

5. Information on the personal data processed

The use of the Application requires the processing of your personal data. Below you will find detailed information about the purposes and legal grounds of processing, as well as the period of processing and whether providing the data is obligatory or voluntary.

5.1. Conclusion and performance of the Account Service Agreement

  • Data processed: first name and surname, e-mail address, password (stored solely as a cryptographic hash), preferred language, time zone, date of last sign-in, a record of the consents given and of the version of the documents accepted.
  • Legal basis: Article 6(1)(b) of the GDPR – processing is necessary for the performance of the Account Service Agreement concluded with the data subject or in order to take steps to conclude it.
  • Provision of data: is a condition for concluding and performing the agreement (provision is voluntary, but the consequence of failure to provide the data will be the inability to conclude and perform the agreement, including the creation of an Account).
  • Period of processing: until the limitation period for claims under the Account Service Agreement expires.

5.2. E-mail confirmation, two-step sign-in and Account security

  • Data processed: e-mail address, one-time verification codes (stored solely as cryptographic hashes), the date and number of sign-in attempts, the session security stamp.
  • Legal basis: Article 6(1)(b) of the GDPR (performance of the agreement) and Article 6(1)(f) of the GDPR – the legitimate interest of the Controller in ensuring the security of Accounts and preventing unauthorised access.
  • Provision of data: is necessary in order to use an Account.
  • Period of processing: verification codes – until they are used or expire; other data – for the period during which the Account is held.

5.3. Conclusion and performance of the Application Use Agreement (story generation)

  • Data processed: data from a child's profile (name, age, gender, description of appearance, avatar), data of secondary characters (name and role, e.g. “mum”, “dog”), the chosen theme, illustration style and tone of the story, the text of the “magic ingredient”, the generated story text and illustrations, and the history of generation requests.
  • Legal basis: Article 6(1)(b) of the GDPR – processing is necessary for the performance of the Application Use Agreement.
  • Provision of data: is a condition for generating a story (provision is voluntary, but the consequence of failure to provide the data will be the inability to use this functionality).
  • Period of processing: until the limitation period for claims under the Application Use Agreement expires, but no longer than 30 days after the Account is deleted.

5.4. Content moderation and ensuring content is safe for children

  • Data processed: the content you enter into the Application and the content generated, together with the result of their automated assessment.
  • Legal basis: Article 6(1)(f) of the GDPR – the legitimate interest of the Controller in ensuring that the content created in the Application is suitable for children and does not infringe the law, and Article 6(1)(c) of the GDPR as regards the obligations arising from the DSA.
  • Provision of data: follows from the use of the story generation functionality.
  • Period of processing: for the period during which the story to which the assessment relates is stored.

5.5. Publication of a story on a publicly accessible subpage

  • Data processed: the title, text and illustrations of the story, including the names and characteristics of the characters supplied by you, and the number of views.
  • Legal basis: Article 6(1)(a) of the GDPR – your consent expressed by performing the act of publication, and Article 6(1)(b) of the GDPR as regards the technical making available of the story.
  • Provision of data: entirely voluntary; publication never happens automatically.
  • Period of processing: until you withdraw the publication, the Controller blocks the publication, or the Account is deleted.

5.6. Settlement of purchases of credit packages

  • Data processed: first name and surname or business name, address, tax identification number (where applicable), transaction history and credit balance.
  • Legal basis: Article 6(1)(b) of the GDPR (performance of the agreement) and Article 6(1)(c) of the GDPR (obligations arising from tax and accounting law).
  • Provision of data: is necessary in order to make a purchase and to issue an accounting document.
  • Period of processing: 5 years counted from the end of the calendar year in which the tax payment deadline fell.

5.7. Delivery of the newsletter and commercial information

  • Data processed: e-mail address, first name, a record of the consent given and of the date it was given or withdrawn.
  • Legal basis: Article 6(1)(a) of the GDPR – your consent, and Article 6(1)(f) of the GDPR – the legitimate interest of the Controller in informing you about new features and promotions available in the Application.
  • Provision of data: entirely voluntary; withholding consent does not affect your ability to use the Application.
  • Period of processing: until consent is withdrawn or an effective objection is raised.

5.8. Conducting the complaint procedure

  • Data processed: first name and surname, e-mail address, the content of the complaint.
  • Legal basis: Article 6(1)(c) of the GDPR – compliance with a legal obligation to which the Controller is subject, including responding to a complaint (Article 7a of the Consumer Rights Act) and giving effect to the rights arising from the provisions on liability for the non-conformity of a digital service with the agreement.
  • Provision of data: is a condition for receiving a response to the complaint.
  • Period of processing: for the duration of the complaint procedure and, where the above rights are exercised, until they become time-barred.

5.9. Handling notices and appeals concerning illegal content (DSA)

  • Data processed: first name and surname or business name, contact details including e-mail address, the content of the notice or appeal.
  • Legal basis: Article 6(1)(c) of the GDPR – compliance with a legal obligation to which the Controller is subject, including providing a mechanism for notifying content (Article 16 of the DSA) and handling appeals (Article 20 of the DSA).
  • Provision of data: is a condition for receiving a response to the notice or appeal.
  • Period of processing: for the duration of the procedure and then until claims become time-barred.

5.10. Handling queries submitted to the Controller

  • Data processed: first name, e-mail address, other data contained in the message.
  • Legal basis: Article 6(1)(f) of the GDPR – the legitimate interest of the Controller in responding to the query received.
  • Provision of data: voluntary, but necessary in order to receive a response.
  • Period of processing: until an effective objection is raised or the purpose of the processing is achieved.

5.11. Compliance with obligations related to the protection of personal data

  • Data processed: first name and surname, the contact details provided by you.
  • Legal basis: Article 6(1)(c) of the GDPR – compliance with obligations arising from personal data protection law, including giving effect to the rights granted to you.
  • Period of processing: until the limitation periods for claims for infringement of personal data protection regulations expire.

5.12. Establishing, exercising or defending against legal claims

  • Data processed: first name and surname or business name, e-mail address, address, tax identification number (where applicable), history of use of the Application.
  • Legal basis: Article 6(1)(f) of the GDPR – the legitimate interest of the Controller in establishing, exercising or defending against claims.
  • Period of processing: until the limitation periods for claims expire.

5.13. Administration of the Application and ensuring its proper operation

  • Data processed: IP address, server date and time of the request, information about the browser and operating system, the address of the requested subpage, the response code, processing time and the request correlation identifier. This data is saved automatically in so-called server logs and in the Azure Application Insights service each time the Application is used.
  • Legal basis: Article 6(1)(f) of the GDPR – the legitimate interest of the Controller in ensuring the correct and secure operation of the Application, diagnosing failures and detecting abuse.
  • Provision of data: is technically necessary in order to provide the service.
  • Period of processing: up to 90 days and, where abuse or a security incident is detected, until the matter is resolved.

6. Profiling and automated decision-making

The Controller does not carry out profiling for marketing purposes and does not build profiles of users' preferences. The Controller does not take decisions concerning you based solely on automated processing which would produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR.

The Application uses automated processing of content for moderation purposes, as described in point 5.4 above. Its result may be a refusal to generate a story or the blocking of a publication. In every such case you may ask the Controller for the decision to be reviewed by a human, on the terms described in the Terms and Conditions.

7. Recipients of personal data

The recipients of personal data will be the following external entities cooperating with the Controller:

  • Microsoft Ireland Operations Limited – the provider of the Microsoft Azure cloud infrastructure on which the Application is hosted (application servers, database, file storage, message queues), and of the Azure AI Content Safety (content moderation), Azure Translator (translation of content for generation purposes) and Azure Application Insights (telemetry and diagnostics) services,
  • Google Cloud EMEA Limited – the provider of the Google Vertex AI service, within which the Gemini model used to generate story text and illustrations operates,
  • the provider of the e-mail delivery service – as regards e-mail addresses and the content of transactional messages,
  • providers of online payment systems – as regards the data necessary to process payments for credit packages,
  • the entity providing accounting services – as regards the data contained in accounting documents,
  • entities providing the Controller with technical support and maintenance services for the Application.

In addition, personal data may be transferred to public or private entities where such an obligation arises from generally applicable law, a final court judgment or a final administrative decision.

8. Transfer of personal data to a third country

As a rule, the Controller processes personal data within the European Economic Area. The Application's infrastructure is located in Microsoft Azure regions situated within the European Union, and the artificial intelligence model is invoked in a Google Cloud region situated within the European Union.

Since the providers referred to in point 7 belong to groups of companies headquartered in the United States, access to data from the territory of a third country cannot be ruled out, in particular for the purposes of technical support. The basis for such a transfer is:

  • Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU–US Data Privacy Framework, to the extent that the provider concerned has certified to it, and
  • the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, together with additional safeguards.

You may obtain from the Controller a copy of the data transferred to a third country.

9. Data subject rights

In connection with the processing of personal data, you have the following rights:

  • the right to be informed what personal data concerning you is processed by the Controller and to receive a copy of that data (the so-called right of access). Issuing the first copy of the data is free of charge; for subsequent copies the Controller may charge a fee;
  • if the processed data becomes outdated or incomplete (or is otherwise incorrect), you have the right to request its rectification;
  • in certain situations you may ask the Controller to erase your personal data, for example where the data is no longer needed by the Controller for the purposes of which it has informed you, where you have effectively withdrawn your consent to the processing (unless the Controller has the right to process the data on another legal basis), where the processing is unlawful, or where the need to erase the data arises from a legal obligation;
  • if personal data is processed by the Controller on the basis of consent or in order to perform an agreement concluded with it, you have the right to transfer your data to another controller;
  • if personal data is processed by the Controller on the basis of your consent, you have the right to withdraw that consent at any time (the withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal);
  • if you believe that the processed personal data is incorrect, that its processing is unlawful, or that the Controller no longer needs certain data, you may request that for a specified period the Controller performs no operations on the data but merely stores it;
  • you have the right to object to the processing of personal data based on the Controller's legitimate interest. In the event of an effective objection, the Controller will cease to process the personal data for that purpose;
  • you have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland) if you believe that the processing of personal data infringes the provisions of the GDPR.

You can exercise a significant part of the above rights yourself in the Application: profile data can be changed in the account settings, a child's profile and a story can be deleted in the relevant view, marketing consent can be switched on and off in your profile, and the entire account together with its data can be deleted in the account settings section.

10. Cookies and browser storage

The Controller informs that the Application uses cookies and browser storage installed on your end device to the extent necessary for it to operate.

The Application does not use cookies for analytical or marketing purposes. The Controller does not use tracking tools such as Google Analytics, Meta Pixel or similar, does not embed third-party profiling scripts in the Application and does not share data about your activity with advertising entities. For this reason the Application does not display a cookie consent banner – only strictly necessary files are used, the use of which does not require consent.

The mechanisms used are:

  • lang (cookie, provider: the Controller) – remembers the interface language you have chosen for the Application. Storage period: 12 months or until deleted.
  • preferred-lang (cookie, provider: the Controller) – remembers the language you have chosen when browsing the public article and published story pages. Storage period: 12 months or until deleted.
  • Browser session storage (sessionStorage) – stores the authentication token that keeps you signed in while you use the Application. The data is deleted automatically when the browser tab is closed.
  • Browser local storage (localStorage) – stores the state of the story wizard so that an accidental page refresh does not discard the data you have entered. The data remains on your device until the story has been created or you clear your browser data.

Through most commonly used browsers you can check whether cookies have been installed on your end device, delete installed cookies and block their installation in the future. Disabling or restricting the use of cookies and browser storage may, however, cause serious difficulties in using the Application, in particular making it impossible to sign in.

11. Final provisions

  1. To the extent not regulated by this Policy, the generally applicable provisions on the protection of personal data shall apply.
  2. The Controller may amend this Policy where the scope or manner of processing changes, where service providers change, or where the law changes. The Controller will give notice of an amendment by publishing the amended version in the Application and, in the case of material changes, by e-mail.
  3. This Policy is made available in Polish and English and, in addition, in translations into German, French, Italian, Spanish, Russian and Turkish. The authentic versions are the Polish and English versions; the remaining language versions are provided for information only.
  4. This Policy is effective from 23 August 2026.
FableShip FableShip

Creating magical, personalized stories for children with the power of AI.

Quick Links

  • Home
  • How It Works
  • Features
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Cookies
  • GDPR

Support

  • Help Center
  • Contact Us
  • Feedback
  • Parent Guide

Newsletter

Get new story ideas and tips.

© 2026 FableShip — Made with for Stories

Child Safe Secure