Privacy policy
Last updated: 27 August 2026
Daily Story writes a short story for you every day and turns it into a practice session. This page explains, in plain language, what the service does with your data and what you can ask us to do about it.
Who is responsible for your data
Controller: Henoch Schmohe, self-employed professional (trabajador autónomo, Spain).
Tax ID (NIF): X4159627P
Registered address: Calle Hermandad de San Isidro 3, 28670 Villaviciosa de Odón, Madrid, España
Contact: henoch@hsmart.dev
AI is part of the service
Your stories, the corrections to your writing and the feedback on your speaking are generated by an artificial intelligence system. You are interacting with AI, not with a teacher reading your work.
The AI model used is Google Gemini, accessed through the Gemini API. AI output can be wrong: treat corrections and explanations as practice material, not as authoritative language advice.
What we collect
Your account. Your email address, your name if you give one, and either a hashed password or the fact that you signed in with Google. Sign-in sessions last 30 days.
Your practice profile. The language you are learning, the language you want explanations in, your level, your chosen topics and style, session length and new-word density.
Your work. Every daily story generated for you, your answers to the comprehension questions, the text you write, and the feedback and transcripts produced from what you said out loud.
Usage counters. The number of AI requests and tokens your account uses, so the service can be kept within a workable budget.
Narration audio. The spoken version of each story, cached so it is not regenerated every time you press play.
We do not run advertising, we do not profile you, and there are no third-party analytics or tracking cookies on this site. The only cookie is the one that keeps you signed in.
Why we process it, and on what legal basis
- To create your account, run your daily sessions and keep your archive: performance of the contract you enter into when you sign up (art. 6.1.b GDPR).
- To send password reset and email verification messages: performance of that same contract.
- To count AI usage, prevent abuse and keep the service running safely: our legitimate interest in a service that is not abused and does not collapse under cost (art. 6.1.f GDPR).
We do not sell your data and we do not use your writing or your recordings to train AI models.
Who else processes your data
These providers process data on our behalf, only to make the service work:
- Vercel (hosting and server logs).
- Neon (the PostgreSQL database that holds your account, profile, sessions and work).
- Google (the Gemini API, which generates stories, narration, writing feedback and speaking feedback; and Google Sign-In, if you choose that way in).
- Cloudflare R2 (private storage for cached narration audio, when enabled).
- Resend (delivery of password-reset and verification emails).
When you tap a word to look it up, that single word is sent to Wikimedia's Wiktionary API. No account information goes with it.
Where your data is stored
The database is hosted in the European Union, in Amazon Web Services' Frankfurt region (eu-central-1). Cached narration audio, when object storage is enabled, is held in a private Cloudflare R2 bucket in the EU jurisdiction.
Requests to the Gemini API and emails sent through Resend may be processed outside the European Economic Area. Those transfers rely on the European Commission's standard contractual clauses, which are part of the providers' terms.
What we send to the AI
To generate a story we send your practice profile and a short summary of your recent work. To give you writing feedback we send the text you wrote. To give you speaking feedback we send the audio you recorded.
Your recordings are not kept in our database. They are sent for analysis and only the resulting transcript and feedback are stored in your session, so you can read them again in your archive.
How long we keep it
Your account and everything in it stays for as long as your account exists, because the archive of past sessions is the point of the product.
There is currently no self-service delete button. Write to henoch@hsmart.dev from the address you signed up with and your account and all your sessions will be deleted within 30 days.
Your rights
You can ask for access to your data, correction of anything wrong, erasure, restriction of processing, portability of what you have written, and you can object to processing based on legitimate interest. Write to henoch@hsmart.dev and you will get an answer within one month.
If you are not satisfied, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (www.aepd.es), or to the supervisory authority where you live.
Age
This service is not aimed at children. If you are under 14, do not create an account without a parent or guardian.
Changes
If this policy changes in a way that matters, the date at the top changes with it. Significant changes will be announced in the app.