Privacy Policy
Overview
Lullaly is built around privacy minimization. Your parenting moment and the story we generate for you are not saved. We collect only the anonymous signals we need to keep the service running and to understand whether it is useful.
Anonymous session cookie
We set a single cookie named sfk_visitor. It is HttpOnly, SameSite=Lax, Secure in production, and lasts up to 90 days. It holds an anonymous session identifier, not your name, email, or any story content.
On the server, the anonymous id is hashed with a stable secret using HMAC before it is used for analytics or rate limits.
IP addresses
Your raw IP address is used only to compute a hash for request rate limiting. We do not store the raw IP address in our database, logs, or analytics.
Your input and generated story
Your raw parenting input and the full generated story exist only in memory during the request. They are not written to the database, application logs, error trackers, or analytics events.
What we may save
We may store anonymous, aggregated signals such as:
- an anonymous visitor hash
- input language and length
- normalized topic category
- safety action taken
- generation status, latency, provider, model, tokens, and estimated cost
- allowlisted interaction events and structured feedback
Retention
Data retention follows the project’s documented cleanup process. We do not claim automatic deletion unless it is part of the retention-cleanup workflow that is run manually after review.
Analytics and tracking
Analytics failures do not block story generation. We do not use third-party advertising or marketing tracking scripts.
Contact
Contact information is shown only when a feedback email is configured for this deployment.