Privacy Policy

Last updated: 30 August 2026

This policy explains what personal data JellyFireEngine (“we”, “us”) collects, why, and what choices you have. JellyFireEngine provides free daily branching stories for children. Stories can be read without an account; an account is only for a parent or guardian who wants to save preferences and, in future, bookmarks.

Who this is for

Accounts are intended for adults. Children do not need an account to read, and we do not knowingly collect personal data from children. If you believe a child has created an account, email us at [email protected] and we will delete it.

What we collect

  • If you sign in with Google: your email address, name, profile picture, and your Google account identifier.
  • If you sign in with Apple: your email address (which may be an Apple private-relay address), and your name the first time you authorise us.
  • If you register with an email and password: your email address, an optional display name, and your password stored only as a secure hash (we never see the plain password).
  • Automatically: a session cookie so you stay signed in, and short-lived server logs (such as IP address, browser type, and timestamps) used to operate and protect the service.
  • In future: the stories you bookmark, once that feature is available.

We do not use analytics or advertising trackers, we do not collect location data, and there are no paid plans, so we do not collect payment information. Your light/dark theme choice is stored in your browser and never sent to us.

How we use it

  • To create your account and keep you signed in.
  • To save and show your preferences and bookmarks.
  • To respond to your support requests.
  • To keep the service running, debug problems, and prevent abuse.

Legal bases (UK / EU GDPR)

We process your data to perform the contract of providing the account you asked for, for our legitimate interests in running a secure service, and with your consent where the law requires it. You can withdraw consent at any time.

Who we share it with

  • Google and Apple — only during sign-in, to verify your identity.
  • Our infrastructure providers who host the application and database on our behalf and process data only on our instructions.
  • Authorities or advisers where we are legally required to disclose information.

We do not sell your personal data and we do not share it for advertising. Some providers may process data outside the UK/EEA under appropriate safeguards such as Standard Contractual Clauses.

How long we keep it

Account data is kept until you delete your account. When you delete your account we remove it from our live systems promptly and from backups within 30 days. Server logs are kept for a short period and then deleted.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our use of your data, and to receive a copy of it. You can delete your account and all associated data yourself from your account page, or contact us at [email protected]. If you are in the UK you can also complain to the Information Commissioner’s Office (ico.org.uk).

Cookies

We use a single strictly-necessary cookie, jelly_user_session, to keep you signed in. It is not used for tracking or advertising, so no cookie banner is required.

Security

Passwords are hashed, traffic is encrypted in transit (HTTPS), and access to personal data is limited to what is needed to run the service.

Changes to this policy

We may update this policy from time to time. We will change the date at the top, and for significant changes we will give more prominent notice.

Contact

Questions about privacy: [email protected].