Privacy, retention and terms
Version 2026-09-01 · Dunbar Group & Associates · The Adventures of Lil’ Sass
What Lil’ Sass is, and is not
Lil’ Sass is a storytelling app. A child chooses a feeling, talks it through with a storybook character, and receives an illustrated book in which they are the hero and learn a simple physical way to feel the feeling all the way through.
It is not therapy, counselling, medical care or crisis support, and it does not replace any of them. The characters never diagnose, never give advice about medication or treatment, and never tell a child what to do about a person or a situation. If a child says something that suggests they are not safe, the story stops and they are shown how to reach a trusted grown-up and the helplines below.
Children under 13
A child under 13 never holds an account. A parent or guardian creates the account, confirms their email, and gives two separate, verifiable consents before any story can be made for that child:
1. Consent to collect and use the child’s information in the app.
2. Consent to send the child’s typed words to the AI services named below so the story can be written and drawn. This can be declined on its own; the profile is kept and only story-making is closed.
A parent can review, withdraw either consent, and delete everything at any time from “Me”. Withdrawal takes effect on the next request.
Who receives what
Anthropic (Claude)
Receives the words a child types in the interview (with their name replaced by a placeholder), the chosen feeling, and the paraphrased story notes, holding the conversation and writing the story.
Google (Gemini)
Receives each page's scene description and the hero's appearance as enumerated ids — never a name, never the child's own words, drawing the pictures.
Supabase
Receives the account, profiles, books and pictures, hosting the database and file storage.
Vercel
Receives requests to the app and its server functions, including request logs, hosting the app.
A child’s first name is replaced with a placeholder before anything leaves the browser, so no AI service receives it. Appearance travels as fixed option ids, never as free text.
What we keep, and for how long
Grown-up account (email, display name, consent record)
Where: Supabase (our database), US region
How long: Until you delete the account
Why: To sign you in, keep your books, and prove consent was on file
Deleted by: "Delete everything" under Me — immediate, and it removes everything below with it
Child profile (first name, age band, look, cape colour, favourite thing)
Where: Supabase
How long: Until you remove the profile or delete the account
Why: To make books for that child without re-entering their look
Deleted by: Remove under Profiles, or "Delete everything"
The words a child types in the interview
Where: Sent to Anthropic for the reply, with the name replaced by a placeholder. Not stored by us.
How long: Not retained by Lil’ Sass. Kept in the browser tab only until the book is written.
Why: To hold the conversation and paraphrase the story notes
Deleted by: Closing the tab. Anthropic’s own API retention applies to what it received.
Story notes (paraphrased facts the guide gathered)
Where: Passed to the story request; not stored after the book is written
How long: Until the book is written
Why: To write the story
Deleted by: Automatically
The finished book (text, scene descriptions, pictures)
Where: Supabase database and file storage; pictures are served from a public URL
How long: Until you delete the book or the account
Why: So you can read, re-read and order it
Deleted by: "Delete everything" — removes the pages and the picture files
Scene descriptions and appearance ids sent for pictures
Where: Sent to Google (Gemini). Never a name, never the child’s own words.
How long: Not retained by Lil’ Sass beyond the book
Why: To draw the pictures
Deleted by: Google’s own API retention applies to what it received
Safeguarding log entry (account id, profile id, book id, time — never the words)
Where: Supabase, admin-only
How long: 24 months
Why: So a disclosure of harm is never silently lost, and the grown-up alert can be traced
Deleted by: Automatically after 24 months; earlier on request
Server request logs
Where: Vercel
How long: Up to 30 days (Vercel’s window)
Why: To diagnose failures
Deleted by: Automatically
Your rights
You can see what we hold for your family under Profiles and My Books, withdraw consent under “A grown-up, please”, and delete everything under “Me”. Deleting removes your account, every profile, every book and its pictures, and cannot be undone. For anything else, email the address in your welcome message.
Terms, in plain words
Books are for personal, family and classroom use. The characters, the story structure and the artwork are © Christie Mann; the book you make is yours to read, print and share.
You must be 13 or older to hold an account. You are responsible for the children you add to it.
Stories are generated by AI from what a child says. We screen them, but a story may still be imperfect; read it with your child.
We may change this policy; the version number above changes when we do, and your consent record shows which version you agreed to.
If a child needs help now
Right now: If you or someone else is hurt or in danger right now, call 911 and a helper will come.
Feeling really sad or scared: If you feel really sad, scared, or like you don’t want to be here, you can call or text 988 any time, day or night, and a kind person will listen.
Someone hurting you: If someone is hurting you or not taking care of you, you can call, or text GO to 1-800-422-4453, and talk to someone who helps kids.
Not in the United States?: findahelpline.com can show you a kind helper in your own country.
Home
📖
My Books
👨‍👩‍👧
Profiles
💬
Sass
👤
Me