Skip to main content

Safety and Children's Privacy

How WhimKid is designed for adult operators, handles children's images and stories, and supports privacy requests.

Last updated:

WhimKid is an AI storybook tool designed for adults. A parent, guardian, family member, or other adult creates the account and operates the product; children are the intended readers. This page explains the product controls and privacy commitments that apply to children's images, names, voices, and story content.

This page is product information, not legal advice. Privacy obligations depend on the facts of a service, the people using it, and the laws that apply to them. If you need advice about a specific family, school, business, or jurisdiction, consult a qualified professional.

Adult-operated product design

Children do not need a WhimKid account to read a book. The creation flow, billing flow, sharing settings, and account controls are intended for adults. We do not design the service to ask children to create profiles, submit personal information, or communicate with strangers.

Adults are responsible for the information they enter. Before uploading a photograph, name, voice sample, or other identifying detail about a child, confirm that you have the authority and permission required for that use. Choose the minimum information needed to make the requested book, and remove unnecessary metadata from images when practical.

COPPA context

The Children's Online Privacy Protection Act, commonly called COPPA, applies to certain online services directed to children under 13 and to services that have actual knowledge that they are collecting personal information from a child under 13. The Federal Trade Commission explains that an adult uploading information about a child to a general-audience service is a different situation from a child providing information through a child-directed account.

WhimKid is designed around adult operation and does not knowingly collect personal information directly from a child through a child-operated account. This product design does not remove an adult's responsibility to use images and information lawfully, and it does not decide whether a particular use is covered by COPPA or another privacy law.

For background, see the Federal Trade Commission COPPA guidance and the FTC COPPA FAQ.

Article 8 of the General Data Protection Regulation addresses consent for information society services offered directly to a child. Where consent is the legal basis, Article 8 sets a default age of 16 for a child's own consent. An EU Member State may set a lower age in its law, but that age cannot be below 13.

WhimKid is designed for an adult to operate the account and create the book. Adults should not ask a child to create a WhimKid account or provide personal information directly. When an adult uploads a child's information, the adult remains responsible for having an appropriate legal basis and any required permission. This page does not make a jurisdiction-specific declaration that every possible use is compliant with GDPR, the GDPR-K rules used to describe children's data protection, or local law.

Read the official GDPR text for Article 8 and the European Data Protection Board information on children and data protection.

What information may be involved

A book may contain a story idea, a child's first name, a character description, a reference photograph, generated illustrations, narration text, narration audio, and details about the people or places described in the story. A photograph can reveal more than the face shown in it, including other people, school uniforms, locations, or image metadata.

Use a photo with a simple background when possible. Avoid uploading documents, school records, medical information, precise addresses, or other sensitive details that the book does not need. Review generated pages before sharing them because AI output can include an unintended name, likeness, setting, or story detail.

How child content is processed

WhimKid uses uploaded content to provide the requested storybook workflow. This can include storing a reference image, sending prompts and selected images to an AI provider, generating text or illustrations, producing narration, saving edits, and preparing an export. Our Privacy Policy lists the categories of providers and the types of data involved.

WhimKid does not use uploaded images or story content to train its own machine learning models. Third-party providers process data needed to return a requested result under their own terms and data practices. Provider policies can change, so do not upload information that you are not permitted to send to the relevant service.

Retention and deletion

Child reference images and generated derivatives remain while they are attached to your account or story, unless you delete them earlier. The current product does not promise a fixed automatic deletion period for these files. This clear limitation is important: delete child material when you no longer need it, rather than relying on an automatic expiry that may not exist.

You can delete available images, characters, and stories from the account. For a request covering an account, story, image, or other child-related content, email support@whimkid.com from the account email. Tell us what should be deleted and provide enough information for us to locate it without sending additional sensitive data. We may need to verify the request. Deleted content can remain for a limited period in encrypted backups while those backups rotate, as described in the Privacy Policy.

Sharing controls

Books are private until an account holder creates a share link. A share link can have a password and an expiry date, and the owner can revoke it. Anyone who obtains the link and password can view the shared book, so a link should be treated like a shared secret.

Search engines receive noindex instructions for share pages, but noindex is not an access control and does not stop a person who has the link from opening the page. Check every page before sharing, especially when a book contains a child's full name, face, school, location, or voice.

Reporting a concern

If you see a child using an account, receive a request about children's data, discover an image that should not be present, or believe a shared book creates a safety risk, contact support@whimkid.com. Include the relevant account email or share link when safe to do so. Do not email additional child photographs unless support asks for them through a suitable process.

We may remove content, disable a share link, restrict an account, or investigate a report when necessary to protect people, comply with law, or operate the service safely.

Is WhimKid designed for children to create accounts?
No. WhimKid is designed for adults to create and manage books for children. Children are readers, not account holders or operators.
How does WhimKid address COPPA?
WhimKid does not knowingly collect personal information directly from children through a child-operated account. Adults create accounts and are responsible for any child images or information they upload.
What does GDPR Article 8 mean for WhimKid?
GDPR Article 8 concerns consent for information society services offered directly to a child. It sets a default age of 16 when consent is the legal basis, while EU Member States may lower that age to no less than 13. WhimKid is designed for adult operation.
Do I need permission before uploading a child photo?
Yes. Upload only a photo you have the right to use, and obtain permission from the child’s parent or legal guardian when required. Do not upload another person’s photo based on assumption.
Does WhimKid use children’s photos to train its own models?
WhimKid does not use uploaded images or story content to train its own machine learning models. AI service providers process content to return the requested result under their own terms and data practices.
How long are child reference images kept?
Child reference images and generated derivatives remain while they are attached to your account or story, unless you delete them earlier. The current product does not promise a fixed automatic deletion period for these files.
Can I delete a child’s content?
Yes. Delete images, characters, or stories from the account where the relevant controls are available. For a broader deletion request, email support@whimkid.com from the account email.
Are shared books private by default?
Books are private until you create a share link. A share link may use a password and expiry date, but anyone with the link and password can view the book. A noindex instruction is not an access control.