Privacy Policy
Version 1.0 · Effective date: 2026-07-06
This Privacy Policy is published in Czech and English. The Czech version is legally authoritative; this English text is a courtesy translation. In case of any discrepancy the Czech version prevails.
1. Introduction & scope
This Privacy Policy explains how we process your personal data when you use the OnceWonder service at oncewonder.com ("Service"). It forms part of your agreement with us together with our Terms & Conditions. It applies to visitors, registered users, and people whose images appear in photographs uploaded to the Service. Capitalised terms not defined here have the meaning given in the Terms.
2. Data controller & contact
The controller of your personal data is Marek Janda, self-employed entrepreneur, place of business Božetická 3396/8, 143 00 Praha 12 – Modřany, Czech Republic, IČ 71071539, DIČ CZ8208150192, registered in the Czech trade register (živnostenský rejstřík) ("we", "us", "Controller").
For any privacy question or to exercise your rights, contact us at marek@oncewonder.com. Given the nature and scale of our processing we have not appointed a Data Protection Officer and, as a controller established in the Czech Republic, we are not required to designate an EU representative.
3. What personal data we collect
- Account data — your e-mail address and a securely hashed password (we never store your password in readable form), and optional preferences such as your chosen display language and currency.
- Uploaded photographs and descriptions — the images you upload for characters, locations and items, together with any names and notes you provide, and the AI-generated text descriptions derived from them.
- Book and story content — titles, instructions, characters, locations, items and the generated story pages you create.
- Generated content — the AI-generated images and story text produced for you.
- Orders and billing data — the credits you buy, prices, currency, and invoice records. Card and payment details are entered directly with our payment provider (Stripe) and are not stored by us; we keep order snapshots and payment status.
- Affiliate and promo data — where applicable, promo codes and related earnings records.
- Usage and technical data — session identifiers, security tokens, log data, and an approximate country derived from your IP address (used to pick a default display currency; see section 12). We do not use third-party analytics or advertising trackers. We keep our own privacy-preserving, self-hosted analytics: aggregated counts of page and API requests, a coarse device type (mobile or desktop), an approximate country, and a short-lived record of your IP address used only to count unique daily visitors.
4. Purposes & legal bases
We process your data for the following purposes and on the following legal bases under Article 6(1) GDPR:
- Providing the Service (accounts, uploads, AI generation, storing your Books) — performance of a contract, Art. 6(1)(b).
- Processing purchases and granting credits — performance of a contract, Art. 6(1)(b).
- Issuing invoices and keeping accounting and tax records — legal obligation, Art. 6(1)(c).
- Securing the Service, preventing fraud and abuse, and keeping logs — legitimate interests, Art. 6(1)(f).
- Choosing a default currency from your approximate location — legitimate interests, Art. 6(1)(f).
- Responding to your requests and support enquiries — legitimate interests or performance of a contract, Art. 6(1)(f)/(b).
Where we ever rely on your consent for a specific optional processing activity, you may withdraw it at any time without affecting processing already carried out.
5. Photographs — special note
The photographs you upload are personal data and may show identifiable people. We process them only to provide the Service — to generate descriptions and to produce re-styled, AI-generated illustrations from them. We do not use your photographs for facial recognition, biometric identification, or to build any biometric template, and we do not knowingly process special-category data.
Please do not upload photographs revealing sensitive information (for example health, religious or political information) or images you are not entitled to process. Where a photograph depicts another identifiable person — and especially a child — you must have that person's (or their guardian's) consent before uploading it, as set out in the Terms.
6. AI processing
To generate descriptions, story text and illustrations, we send the relevant inputs (your photographs, names, notes and prompts) to specialised third-party AI providers who process them on our behalf to return the generated result: Google (image generation) and OpenRouter (text generation and image descriptions). We send only what is needed to perform the generation you requested.
To the best of our knowledge these providers process the data to deliver the service and subject to their own terms; we do not control their internal retention, and we encourage you to review their privacy policies. AI output is produced automatically, but this does not constitute a decision producing legal or similarly significant effects about you under Article 22 GDPR.
7. Payments
Payments are processed by Stripe. When you pay, your card and payment details are provided directly to Stripe and are processed under Stripe's terms and privacy policy; we do not receive or store your full card details. We store the resulting order record (credits, amount, currency, status) and issue a tax document as required by law.
8. Recipients & sub-processors
We do not sell your personal data. We share it only with processors and recipients who help us run the Service:
- Google — AI image generation (United States).
- OpenRouter — AI text generation and image descriptions (United States).
- Stripe — payment processing (United States / Ireland, EU).
- Amazon SES — sending transactional e-mail such as password resets (EU region).
- Hosting — our own dedicated server in the Czech Republic (EU).
- Public authorities — where required by law.
Your approximate country is determined on our own server using a locally embedded database (MaxMind GeoLite2); no data is sent to MaxMind for this.
9. International transfers
Your data is stored primarily in the European Union (our server is located in the Czech Republic). Some processors listed in section 8 are located in the United States; when we transfer personal data to them, we rely on appropriate safeguards under Chapter V GDPR — such as the EU Standard Contractual Clauses and/or the provider's certification under an applicable EU adequacy framework. You can ask us for more detail about the safeguards that apply.
10. Retention
- Account and content data (including uploaded photographs and generated content) — for as long as your account exists. When you delete your account, this data is deleted from the Service; residual copies in encrypted backups are removed within 30 days at the latest.
- Invoices and accounting records — retained for 10 years as required by Czech tax and accounting law, even after account deletion.
- Sessions and password-reset tokens — expire automatically (sessions after their validity period; reset tokens shortly after issue or use).
- Security logs — kept for a limited period for security and troubleshooting, then deleted or anonymised.
- Analytics data — IP addresses used for visitor counting are kept only briefly (shortly after the end of each UTC day they are irreversibly aggregated into counts that contain no IP address); the aggregated counts are retained indefinitely.
11. Your rights
Subject to the conditions in the GDPR, you have the right to access your data; rectify inaccurate data; erase data (the "right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent where processing is based on consent.
You can exercise most rights directly — for example by editing your account and content in the app. To delete your account, use the account-deletion option in your account settings (or, if you prefer, contact us at marek@oncewonder.com); we erase your personal data and content, while orders and invoicing records are retained as required by Czech tax and accounting law (see section 10). We will respond within the statutory time limit (generally one month). Exercising your rights is free unless a request is manifestly unfounded or excessive.
12. Cookies
We use only strictly necessary cookies required to operate the Service, so no cookie-consent banner is required:
- session — keeps you logged in (HttpOnly, Secure).
- csrf and xsrf-token — protect forms and API requests against cross-site request forgery.
- lang — remembers your chosen language.
We do not use analytics, advertising, or third-party tracking cookies. Your approximate country is derived from your IP address at request time (see section 8) and is not stored in a cookie. Our own analytics is cookieless — it uses no cookies at all.
13. Security
We protect your data with appropriate technical and organisational measures, including hashing passwords with a strong algorithm (Argon2id), serving the Service over encrypted HTTPS/TLS, access controls on our infrastructure, and hosting within the EU. No method of transmission or storage is completely secure, but we work to protect your data and to address any incident appropriately.
14. Children
The Service is intended for adults (18+) and is not directed to children as users. We do not knowingly create accounts for children. Photographs uploaded to the Service may depict children; where they do, the person uploading them is responsible for having the consent of the child's parent or legal guardian, as set out in the Terms. If you believe a child has provided us with personal data as a user, contact us and we will delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time (for legal, technical, or business reasons). We will publish the updated version with a new effective date and, for material changes, notify registered users by e-mail or in-app a reasonable time before they take effect. The current version and its effective date are shown at the top of this page.
16. Complaints & supervisory authority
If you have a concern about how we handle your data, please contact us first at marek@oncewonder.com. You also have the right to lodge a complaint with the Czech supervisory authority — the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz — or with the supervisory authority in your EU/EEA country of residence.