FiabaryBack to home
Legal document

Privacy Policy

Information notice under Article 13 of Regulation (EU) 2016/679 (GDPR)
and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018

Version 1.4 - Last updated: May 7, 2026

1. Data Controller

Controller: Covency Srls

Project: Fiabary

Website: https://fiabary.app

Registered office: Piazza Giacomo Matteotti, 52 - Modena

Privacy contact: gdpr@covency.it

The Controller determines the purposes and means of processing personal data collected through the Fiabary service.

2. Personal Data Processed

2.1 Data Provided Directly by the User

  • Account data: name, email address, password hash, language and login information.
  • Profile data: phone number, avatar, preferences, family and shipping details where provided.
  • Child profile data: name or nickname, date of birth, interests, descriptive notes and related memories.
  • Diary content: texts, phrases, photos, drawings, audio notes, generated stories and illustrations.
  • Support content: messages, attachments and information provided when contacting support.
  • Billing and payment data: subscription and payment identifiers managed through Stripe. Full card data is not stored on Fiabary servers.
  • Print order data: recipient name, shipping address, phone number, selected print options and book PDF files needed to fulfill the order.

2.2 Data Collected Automatically

  • Technical logs, IP address, browser, device, operating system, language, session and security events.
  • Usage data such as pages visited, features used, errors, limits and operational events.
  • Cookies and similar technologies necessary for authentication, security, preferences and analytics where enabled.

Data about minors

The Service is intended for adults. Data about children is entered by the parent or legal guardian, who is responsible for deciding what information and images to upload and whether to share them with invited family members.

3. Purposes and Legal Bases

  • Account creation and authentication: performance of the contract and security obligations.
  • Provision of diary, story, AI, export and sharing features: performance of the contract.
  • Subscription and payment management: performance of the contract and legal/accounting obligations.
  • Physical print order fulfillment: performance of the contract and pre-contractual measures requested by the User.
  • Support and communications: performance of the contract and legitimate interest in assisting Users.
  • Fiabary newsletters and promotional communications: optional consent, revocable at any time. Partner marketing is not included.
  • Security, abuse prevention, moderation and fraud prevention: legitimate interest and legal obligations.
  • Analytics and service improvement: legitimate interest or consent where required.
  • Legal compliance and defense of rights: legal obligations and legitimate interest.

4. AI Processing and Content Generation

Fiabary uses AI services to generate stories, transcribe voice notes, create illustrations, moderate uploaded media and assist with profile or content generation. Only the data necessary for the requested function is sent to the relevant provider.

Generated outputs may contain inaccuracies and should be reviewed by the User. The Controller does not use children's content for advertising profiling. Processing is carried out to provide the requested Service features and to keep the platform safe.

5. Sharing and Invited Guests

Users may invite trusted people to view selected diary content. Guests receive read-only access to the content explicitly shared by the User. The User may revoke access at any time from the dashboard.

Guests must keep the content confidential and must not disclose, reproduce or download it outside the Service without the User's consent.

6. Recipients and Processors

Personal data may be processed by authorized personnel and by providers appointed as processors or acting as independent controllers where required by law. Main categories include:

  • Hosting, database, storage and infrastructure providers.
  • Authentication, email, support and notification providers.
  • Payment provider Stripe, Inc. for payment and subscription management.
  • AI providers used for generation, transcription, moderation and assistance features.
  • On-demand print partner for physical book production and shipping.
  • Security and anti-abuse providers, including Cloudflare Turnstile where used.
  • Public authorities, courts or advisors where required by law or necessary to protect rights.

Stripe, Inc. (USA) - Payment management

Used to process subscriptions, one-off payments and customer portal access. Card data is processed by Stripe and does not transit through Fiabary servers. Transfers to the USA rely on the safeguards provided under GDPR, including Standard Contractual Clauses where applicable.

On-demand print partner (USA) - Physical book printing and shipping

Used to produce and ship the physical book ordered by the User. To fulfill the order, the necessary shipping details and book PDF files are transmitted to the print partner. Book content is used only for order fulfillment. Further details about the appointed partner may be requested from the Controller.

7. Transfers Outside the European Economic Area

The following processors may process personal data in countries outside the European Economic Area (primarily the United States). All transfers are based on the EU Standard Contractual Clauses approved by the European Commission under Art. 46(2)(c) GDPR, or - where applicable - on the EU-U.S. Data Privacy Framework adequacy decision (July 2023). Where a provider is certified under the DPF, the certification can be verified at dataprivacyframework.gov.

ProcessorCountryPurposeSafeguard
OpenAI, L.L.C.USAStory generation, image moderation, vision-based character description, voice transcription, illustration generationSCCs (Art. 46.2.c GDPR); no training on customer data
Fal Inc.USAIllustration generation (Seedream and other generative models)SCCs (Art. 46.2.c GDPR); no training on customer data
Stripe, Inc.USA (via Stripe Payments Europe Ltd. - Ireland)Payments and subscription managementSCCs (Art. 46.2.c GDPR) and DPF certification
Lulu Press, Inc.USAOn-demand printing and shipping of physical booksSCCs (Art. 46.2.c GDPR)
Cloudflare, Inc.USATurnstile anti-bot protection on auth pagesSCCs (Art. 46.2.c GDPR) and DPF certification
Google LLCUSAOptional "Sign in with Google" OAuth authenticationSCCs (Art. 46.2.c GDPR) and DPF certification
Meta Platforms, Inc.USA (via Meta Platforms Ireland Ltd.)Optional "Sign in with Facebook" OAuth authenticationSCCs (Art. 46.2.c GDPR) and DPF certification

The following processors operate within the European Economic Area and do not require additional Art. 46 GDPR safeguards: VHosting Solution S.r.l. (Italy - application hosting and database; declared compliant with ISO 27001, ISO 27017, ISO 27018 and NIS2), Hetzner Online GmbH (Germany - VPS for PDF rendering), Freepik Company S.L. (Spain - alternative illustration generation via Magnific API).

The User has the right to request a copy of the safeguards applicable to extra-EEA transfers and the list of currently engaged sub-processors by contacting the Controller at the address indicated in section 13.

8. Retention Periods

  • Account and profile data: for the duration of the account and then for the period necessary to comply with legal obligations or defend rights.
  • Diary content: until deleted by the User or until account deletion, subject to backup rotation and legal retention obligations.
  • Payment and accounting data: for the retention period required by tax and accounting law.
  • Support tickets: for the time necessary to handle requests and document assistance.
  • Security logs: for the time reasonably necessary to protect the Service and investigate abuse.
  • Print order data and related files: for the period necessary to fulfill the order, manage support, comply with legal obligations and document the transaction.
  • Temporary technical caches: generated PDFs are automatically deleted 30 days after last generation; optimized image caches are deleted after 60 days, via automated cron.
  • Inactive accounts: accounts with no sign-in for 24 consecutive months are subject to automated deletion with anonymization of personal data and physical removal of uploaded files.

Account deletion - whether requested by the User or triggered by inactivity - entails physical removal of media files (photos, audio, illustrations) from the Controller's filesystem and from all related technical caches, in addition to anonymization of personal data in the database.

9. Data Subject Rights

Under the GDPR, Users may exercise the rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent where processing is based on consent. Requests may be sent to gdpr@covency.it.

Users also have the right to lodge a complaint with the competent supervisory authority. In Italy, this is the Garante per la protezione dei dati personali.

10. Cookies and Similar Technologies

The Service uses strictly necessary technical cookies (always active) and, only with your consent, third-party marketing cookies (Meta Pixel). The full list follows:

CookiePurposeDurationThird party
next-auth.session-tokenAuthenticated user sessionSession / 30 daysNo
next-auth.csrf-tokenCSRF protection during the OAuth sign-in flowSessionNo
next-auth.callback-urlSecure redirect at the end of the OAuth flowSessionNo
next-auth.pkce.code_verifier, next-auth.state, next-auth.nonceOAuth sign-in flow security parameters (anti-CSRF and anti-replay)Short-term (flow duration)No
fiabary_signup_consentCarries Terms & Privacy consent collected before OAuth sign-upShort-term (flow duration)No
fiabary_mfaMFA verification completed for the current session12 hoursNo
fiabary_trusted_deviceTrusted device to reduce repeated MFA checks30 days (revocable)No
fiabary_post_verify_exemptMarks the current session as already verified after a post-login action (e.g. email confirmation), avoiding redirect loopsSessionNo
fiabary_link_intentSecure linking of a second sign-in method to an existing accountShort-termNo
fiabary_impersonationAdministrator support operations in impersonation mode (authorized staff only, recorded in an immutable audit log)Session / short-termNo
cf_clearance and similarAnti-bot security (Cloudflare Turnstile) on sign-in, registration and password-recovery pagesSession / short-termCloudflare, Inc. (USA)
_fbp and similar (Meta Pixel)Marketing: measurement and optimisation of advertising campaigns on Facebook/Instagram. Loaded only after the User's consent given through the cookie banner; can be withdrawn at any time.Up to 3 monthsMeta Platforms Ireland Ltd.
_ttp and similar (TikTok Pixel)Marketing: measurement and optimisation of advertising campaigns on TikTok. Loaded only after the User's consent given through the cookie banner; can be withdrawn at any time.Up to 13 monthsTikTok Technology Limited (Ireland)

Technical cookies and anonymous statistics do not require consent: usage statistics are collected through an internal cookieless system that does not install any analytics cookie on the User's device and does not store the IP address in clear text. Marketing cookies (Meta and TikTok Pixel) are installed only after the User's explicit consent, given through the cookie banner, and can be withdrawn at any time via the "Cookie preferences" link in the footer.

Pursuant to Art. 122 of Italian Legislative Decree 196/2003 and the ePrivacy rules, technical cookies do not require prior consent; marketing cookies are used only with the User's consent. The Meta Pixel shares data with Meta Platforms Ireland Ltd. and the TikTok Pixel with TikTok Technology Limited (with possible transfer outside the EEA under the applicable safeguards).

11. Security Measures

The Controller adopts technical and organizational measures designed to protect personal data, including access controls, MFA, authentication, backups, logging, moderation, security monitoring and rate limiting on AI endpoints. Specifically:

  • At-rest encryption of media files: all images, audio recordings and illustrations uploaded or generated on behalf of the User are stored on the Controller's filesystem encrypted with authenticated AES-256-GCM. The encryption key is held only in the application server's environment variables and is not accessible to the hosting provider's personnel nor included in database backups.
  • Physical file deletion: when content is deleted (a moment, story, child profile or family member) or when the account itself is deleted, related media files are physically removed from the Controller's filesystem, from PDF caches and from optimized image caches, and become unrecoverable after the standard backup rotation.
  • Passwords stored hashed using bcrypt; HTTPS/TLS in transit; database backups.

No system can guarantee absolute security; Users must protect their credentials and report suspected unauthorized access. In case of a personal data breach posing a risk to data subjects, the Controller will notify the supervisory authority within 72 hours as required by GDPR.

11-bis. Consent Tracking

Pursuant to art. 7 § 1 GDPR, the Controller keeps proof of consent and acceptance of the Terms of Service and this Privacy Policy. For each acceptance (initial sign-up, OAuth sign-in, re-acceptance following a policy update) the Controller records: date and time of acceptance and parental guardianship statement; version of the Privacy Policy and Terms accepted; IP address and browser identifier (user-agent) of the device used; method of acceptance (direct sign-up, OAuth, re-acceptance following an update); identifier of any administrator who triggered a re-acceptance request.

Users may review their consent status and acceptance history at any time from the "Privacy & consents" section of their account, and download a JSON consent receipt as personal proof.

12. Changes to this Privacy Policy

The Controller may update this Privacy Policy to reflect legal, technical or service changes. Material updates will be communicated through the Service or by email where appropriate.

13. Contacts

Privacy requests: gdpr@covency.it

Legal matters: info@covency.it

Registered office: Piazza Giacomo Matteotti, 52 - Modena

© 2026 Fiabary@2026 - Covency Srls - All rights reserved

Terms of Service · Back to home