There is no public feed
No discovery, no directory, no way to search for a family or a child. Nothing you save is visible to anybody until you create a share yourself.
Storygarden holds photographs of children, recordings of their voices, and things they said once. That is not ordinary data, and the product is built accordingly. This page explains how, in plain words.
No discovery, no directory, no way to search for a family or a child. Nothing you save is visible to anybody until you create a share yourself.
We do not sell or rent your data, do not build advertising profiles, and do not track you across other apps or sites. Families paying for the product is the entire business model.
Export everything you have saved, or delete everything — including from the web, without installing anything.
Mechanisms rather than reassurances. Each of these is something in the code, not an intention.
Every row is checked against the account asking for it at the database itself, not in the app. That means a bug in the app — or somebody calling the API directly — still cannot read another family’s memories.
Photos, videos, and recordings live in private storage. They are shown to you through links that are generated at the moment you open them and expire shortly after. There is no permanent public address for a picture of your child.
A share link is a long random token, and only a one-way hash of it is stored — which is why a lost link is replaced rather than looked up. You can add a passcode, and revoking a link takes effect immediately.
The app never asks for it, location permissions are blocked outright in the Android build, and location data is stripped from photographs when they are uploaded.
A notification appears on a locked screen where anyone nearby can read it, so they deliberately carry no child’s name, no message text, and no picture. The one exception is a calendar reminder, which carries the title of the event you asked to be reminded about.
Texted message bodies are deleted after 30 days, abandoned uploads after 24 hours, and exports after 7 days — by a scheduled job. A retention policy nobody executes is not a policy.
When you text a memory in, the text may be sent to Anthropic to suggest a title, a date, or which child it is about. That is the only place a model is involved, and the rules below are enforced in code rather than by policy.
Text Capture is a separate subscription and off by default. Without it, no text you write ever reaches an AI provider at all.
Only the memories you selected, for as long as you leave the link on. Memories you save afterwards are not added to it.
Not your other children, not your settings, not your billing, not your phone number, and not a memory you did not include.
Being in someone’s family does not show you their children’s timelines. A timeline has to be shared separately, on purpose.
Turned on per share, and turning them off blocks new ones immediately. Existing comments are not silently deleted when you do.
Storygarden holds no security certification and has not been through a third-party audit. No system is perfect, and if something goes wrong that affects you, we will tell you.
The full legal detail — what is stored, who processes it, how long it is kept — is in the privacy policy. This page is the readable summary; that one is the document.
Questions are genuinely welcome at support@story-garden.app.
There is nothing to configure to make Storygarden private. That is the default, and sharing is the deliberate exception.