Privacy
Last updated: 14.09.2026
German is the binding contractual language. This English version is a service translation for convenience.
1. Controller
The controller for the processing of personal data on https://heldenflug.de is:
Tiamat UG (haftungsbeschränkt)
An der Strusbek 12
22926 Ahrensburg
Germany
Email: hallo@heldenflug.de
Represented by the managing director Ansgar Holtmann.
2. A word up front
With Heldenflug we build a product in which you entrust us with personal data — your name, your child's name, sometimes a photo. We take that seriously and handle this data as sparingly as possible. This policy describes in detail what we do and why.
3. What data we process
3.1 Access data when visiting the website
When you visit our website, your browser automatically transmits technical data to our server, which we store in log files: shortened IP address, date and time, requested page, transferred data volume, browser type and language, operating system, referrer URL.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest — secure operation). Retention: 7 days, then automatic deletion.
3.2 Account data (when you create a parent account)
Email address, display name, encrypted password (bcrypt hash), registration and last-login dates, email verification status.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). Retention: for as long as the account exists.
3.3 Data from the concept chat (ordering a book)
Your input about your child and story (name, age, favourite topics, character, favourite animal), optionally a photo of your child (see 3.4), the generated concept, and your revision requests.
Legal basis: Art. 6 (1) (b) GDPR. Retention: until at most 30 days after order completion; order records (title, price, invoice data) are archived 10 years pursuant to § 257 HGB / § 147 AO.
3.4 Photo of your child — special care
If you optionally upload a photo of your child:
- Processing solely to describe the looks and draw the illustrations
- Before that we remove embedded metadata such as location and camera data
- Storage on our own servers (Deutschland, see section 5.6)
- Automatic deletion 30 days after delivery of the finished book — for the uploaded photo and the copy we draw the book from. Photos from chats that never become a book, and photos of books that never ship, are deleted 30 days after the upload or after the book draft was created. No retention as training data, no sharing for model training
- The description of the looks derived from the photo (hair colour, eye colour, skin tone) stays part of the book concept for as long as the book is in your account
- To describe the looks we send the photo to the AI provider named in section 5.2, to draw the illustrations to the AI image generator named in section 5.3 — only for your book
Legal basis: Art. 6 (1) (a) GDPR (your explicit consent on upload) + Art. 9 (2) (a) GDPR.
You provide consent as the legal guardian and confirm it explicitly before the upload; we store the time and version of this consent. You can have the photo deleted at any time; if you request deletion, the affected book can no longer be generated — the order is cancelled and any payment refunded.
3.5 Payment data
Payment is processed via Stripe (see 5.1). We do not process or store card data ourselves — only the Stripe transaction ID and invoice data.
Legal basis: Art. 6 (1) (b) and (c) GDPR. Retention: 10 years pursuant to § 257 HGB.
3.6 Communication data (support emails)
Your email address, message content, date and time. Legal basis: Art. 6 (1) (f) GDPR. Retention: until the request is closed, max. 12 months.
3.7 Character library (children's books and audio stories)
In your account you can save characters and reuse them in children's books and audio stories: your child, family members, friends, pets and characters from your stories.
- We store the name, relationship, age, your description of the looks, a description derived from it and a drawn picture of the character.
- This stays stored until you remove the character or delete your account. When you remove a character, we delete its name, age, all descriptions and the drawn picture. A few technical details about the removed character remain: its type, relationship, time of consent, cost counter and the link to your account, plus a check value of the name, from which the name cannot be read directly. It stops the character from being created again on its own the next time you save. When you delete your account, we delete all characters completely.
- A name and description you already took over into a running audio series or a finished book stay there until you remove the character from the series or delete the book. Drawn pictures that are already part of finished books or episode covers stay part of that book or episode.
- A photo you upload for a character is only used to describe the looks and draw the picture. Before that we remove embedded metadata such as location and camera data. We delete the photo afterwards; it is not stored permanently on our side.
- Before the upload you explicitly confirm that we may send the photo to our AI providers for this. We store the time and version of this consent.
- Please only upload photos and descriptions of family members or other people with their consent.
- To create the description and the picture we share this information with the AI providers named in sections 5.2 (description from text and photo, checking the drawn pictures) and 5.3 (drawing the picture).
Legal basis: Art. 6 (1) (b) GDPR (providing the characters in your books and audio stories). For photos, Art. 6 (1) (a) GDPR (your explicit consent on upload) and Art. 9 (2) (a) GDPR (consent to processing biometric-like data, including of minors). You can withdraw your consent at any time with effect for the future.
4. AI-assisted processing — transparency under the EU AI Act
Heldenflug uses AI models (large language models and image generators) to create book content and illustrations from your input.
- What the AI does: proposes a concept, writes the story text and generates the illustrations.
- What the AI does NOT do: it does not train further on your data or your child's photo — we have contractually excluded this.
- Your control: you review and approve the concept before production; 3 revisions are included, then €9.90 each.
- Labelling: generated content is not labelled "AI-generated" inside the book; we communicate the AI creation transparently on the website and in this policy.
5. Processors (third parties processing data on your behalf)
We use the following providers. A data-processing agreement under Art. 28 GDPR exists for each. For providers outside the EU/EEA we use EU standard contractual clauses (Art. 46 GDPR).
5.1 Stripe — payment processing
Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (USA). Data: payment data, transaction ID, invoice data. https://stripe.com/privacy
5.2 Anthropic — AI language model
Anthropic PBC, San Francisco, USA. Data: your text input in the concept chat, character notes, uploaded photos (to describe the looks) and drawn pictures (for quality checks). Processed with a "no training on data" clause. https://www.anthropic.com/legal/privacy
5.3 AI image generator — illustrations and cover
WaveSpeed AI (USA) / Black Forest Labs GmbH (Germany, FLUX models). Data: story-text excerpts as image prompts, optionally a photo of your child.
5.4 Resend — transactional emails and, with your consent, promotional and reminder emails (see 5.7)
Resend, Inc., San Francisco, USA. Data: your email address and the transactional message content or, with your consent, promotional and reminder email content.
5.5 Signalyr — marketing analytics
Tiamat UG (haftungsbeschränkt), An der Strusbek 12, 22926 Ahrensburg. Pseudonymised usage data, cookieless, no plaintext IP storage. Hosted in Germany; data stays within Tiamat's infrastructure.
5.6 Hosting
netcup GmbH, Deutschland (EU / Germany). A data-processing agreement is in place.
5.7 Promotional and reminder emails
If you give us your consent, we occasionally send you emails about Heldenflug books and reminders about unfinished books. We collect this consent through a double opt-in process: after you tick the box, you receive a confirmation email. Only your click in that email makes the sign-up effective. Legal basis: Art. 6 (1) (a) GDPR (consent) in conjunction with § 7 (2) UWG.
If you have bought a book from us, we may also email you about similar own products without separate consent. We point this out during the order process. Legal basis: § 7 (3) UWG in conjunction with Art. 6 (1) (f) GDPR (legitimate interest in direct advertising, recital 47).
You can object at any time: through the unsubscribe link in any of these emails, through your email program's unsubscribe function, or under "Email settings" in your account. This costs you nothing beyond the transmission costs under the standard rates. An objection only ends advertising; you will still receive emails about your order, your account and your book because we need them to perform the contract (Art. 6 (1) (b) GDPR).
What we log. To be able to prove your consent (Art. 7 (1) GDPR), we store the time, IP address, browser identifier, language, the exact wording you agreed to, and the time of your confirmation click. We keep this information for as long as the consent is effective, and then for three years as evidence.
Delivery data. Our email provider Resend reports back to us via webhook whether an email was delivered, whether it bounced and whether you marked it as spam. We use this to suppress undeliverable addresses and act on complaints immediately. Legal basis: Art. 6 (1) (f) GDPR (deliverability and abuse prevention). We delete this data after 24 months.
No tracking pixel. We put neither a tracking pixel nor tracking parameters into the links of our emails — not in promotional emails and not in emails about your order. If Resend additionally reports that an email was opened or a link in it was clicked, we store that report alongside the other delivery data and only evaluate it in aggregate, to understand which of our emails are useful at all. This too is deleted after 24 months.
How we enforce the 24 months. An automated job deletes the delivery data once the period is up and, at the same time, removes the personal content from the send history of older emails — your child's name and the book title the email was assembled from. What remains is only the record that a particular email went out to you, and when; we need that so the same email is never sent twice. Your consent record (see "What we log") is not affected — we have to keep that longer.
6. Cookies and comparable technologies
We use functional cookies / local storage for your login session (cookie heldenflug_customer), language choice and concept-chat state. No tracking cookies, no third-party cookies, no advertising pixels. Signalyr operates cookieless.
Legal basis: Art. 6 (1) (f) GDPR / § 25 (2) TDDDG (strictly necessary). No consent banner is therefore required.
7. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), withdrawal of consent (Art. 7 (3)) and to lodge a complaint with a supervisory authority (Art. 77) — for Tiamat that is the ULD Schleswig-Holstein, Holstenstraße 98, 24103 Kiel (https://www.datenschutzzentrum.de). Contact: hallo@heldenflug.de. We respond within 30 days.
8. Data security
We use TLS encryption (HTTPS) for all connections, bcrypt password hashing, SSH-key authentication, a firewall, and Content-Security-Policy headers.
9. Changes to this policy
We update this policy when our processing practices change. We notify you of material changes by email. Last updated: 14.09.2026.