Back to your private studio

Your family’s photos belong to your family.

This local pilot is operated by Connected Consulting. Accounts are for adults, not children. Upload only photos you are authorized to share.

What this app stores

Your account contact information, story instructions, consent record, project stage, and reference photos are used to prepare and manage your book. Avoid birth dates, school names, home addresses, medical information, and other unnecessary identifying details in your story.

How photos are handled

The uploader converts photos into resized PNG images. The server validates the image and removes metadata, including embedded location fields. Photos and customer/story details are encrypted at rest using authenticated AES-256-GCM. Passwords are salted and hashed; session cookies are not available to page scripts. This is not end-to-end encryption: the studio owner can access photos to prepare your order.

Original photo uploads expire after 30 days, with cleanup at server startup and hourly while running. You can remove a photo, delete a project, or delete your account in the private studio. The current pilot has no automatic backups. Future hosting and backups need a documented retention and deletion policy before public launch.

Location maps

City, state or region, and country are optional and stored only when you opt in. We do not request device location or a street address. An owner-initiated map link sends the city search to OpenStreetMap. Your name, child information, photos, and story are not included in that link.

Payments and third parties

Stripe hosts checkout under Connected Consulting. This app does not receive or store payment card details. It sends an opaque project reference for reconciliation, not child names or photos. Stripe keeps its separate transaction records, which are not erased by deleting your studio account. No photos are automatically sent to an AI service, advertising system, or public gallery by this intake app. Any production workflow involving another service needs an appropriate disclosure and authorization before use.

Pilot limits

This is a local pilot, not a statement of regulatory certification. A public release still needs verified HTTPS hosting, email verification and recovery, independent security review, documented production providers and backups, and customer support and commercial policies. Checkout stays unavailable until payment links and verified payment notifications are configured.