Privacy policy

Last updated 11 October 2026.

Who we are

Once Upon This Time is run by Den Ouden Consultancy, Utrecht, the Netherlands. We decide what happens to the data described here, which makes us its controller under the General Data Protection Regulation (GDPR). Questions about your data are welcome at support@onceuponthistime.com.

The short version: you never need an account, we do not show ads, and we do not use analytics or tracking of any kind.

What we keep, and why

The books

When you begin a book, we keep what you typed (a line about what is on your mind, and how you would like to appear in the story) with the book, because the book is written from it. Before anything you typed reaches the writer, a privacy step removes names, places, dates and other details that could point to a real person. Your name never appears in the story.

Every book joins the public library, where others can read it. The library shows a book’s title and story, never who made it. To have a book you made taken out of the library, write to us with its link; it then stays readable only by that link.

Your browser’s id

The first time you visit, your browser gets a random id, kept in a cookie (boy_reactor_id, for one year) and in your browser’s local storage. It is how we know which books this browser made, read, reacted to and bought. It says nothing about who you are.

Reading and reactions

We keep the reactions you place on sentences, and which books this browser opened and when, so the story can answer your reactions and the homepage can show what you were reading.

Your language

A cookie (once-upon-this-time:reader-language) remembers the language you picked. Local storage also remembers the last scene the homepage showed.

Buying a book

Payment is handled by Stripe; we never see your card details. From Stripe we receive and keep your email address, the amount, Stripe’s reference for the payment, and the language you were reading in. We also keep the ids of the browsers the book is open in (at most three). We use your email address only to send you the links to your books.

Sign-in links

A link to your book works once and for seven days. We store only a scrambled form (a hash) of each link, never the link itself. When you ask us to email your books again, we keep a hash of the address and the time of the last email, so that we send at most one a day.

Server logs

Like any website, our server writes technical logs (requests, errors and timings, which can include your IP address) to keep the site safe and working. They are kept for a short time only.

Who else handles your data

  • Stripe processes payments.
  • Resend sends the emails with your links.
  • The AI model that writes the book.When that model is run by an outside provider (Anthropic), it receives the privacy-filtered text and the story so far, to write and translate pages. It does not receive your email address or your browser’s id.

The site itself runs on our own server in the Netherlands. Some of the companies above are based in the United States; transfers to them rely on the EU-US Data Privacy Framework or the European Commission’s standard contractual clauses.

On what grounds

We handle purchase data and send your links because you bought a book from us (performance of a contract). We keep purchase records for seven years because Dutch tax law requires it (legal obligation). Everything else (the books, the browser id, reactions, logs) serves our legitimate interest in running the site as it is meant to work and keeping it safe from abuse.

How long we keep it

A book, and what was typed to begin it, is kept for as long as the book exists. Purchase records are kept for seven years. Your browser’s id and language cookie expire after one year, or sooner when you clear them.

Your rights

You may ask to see the data we hold about you, to correct or delete it, to limit or object to its use, or to receive it in a portable form. Because there are no accounts, tell us your browser’s id or the email address you paid with, so we can find it. If you think we handle your data wrongly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Changes

When this policy changes, the date at the top changes with it.