Privacy Policy
Last updated: June 14, 2026
PictureToSay is a picture-based communication, memory, and speech-coaching app for families. This policy explains what data we collect, where it lives, and the choices you have.
Who we are
PictureToSay is operated by the PictureToSay team. You can reach us at info@picturetosay.com or support@picturetosay.com.
Data we collect
- Account: email address, display name, and password hash (managed by our authentication provider).
- Profile & care links: caregiver/patient role, optional language and accessibility preferences, and links between caregiver and patient accounts that you create.
- Content you create: speech cards, memory cards, routines, practice items, saved sentences, and medication schedules โ including any text, emoji, photo, or recorded audio you add.
- Generated audio: when you use AI text-to-speech, the resulting audio file is stored so it can be replayed without re-generating.
- Usage data: basic counters such as monthly voice generation counts and storage used, so we can apply plan limits.
- Billing data: if you subscribe, our payments provider (Stripe) processes your payment and returns a customer/subscription identifier. We do not store full card details on our servers.
- Contact form: if you write to us through the contact page, we keep the name, email, and message you sent so we can reply.
Where your data is stored
Application data is stored in our managed backend powered by Supabase (PostgreSQL database, authentication, and object storage), operated on our behalf. Database rows are protected by row-level security so each family's records are isolated to the accounts that own or are linked to them.
- Photos & recorded voices uploaded for memory cards, speech cards, and family content are stored in a private
family-mediabucket in Supabase Storage. Files are only accessible through signed URLs granted to authorized accounts. - AI-generated audio is stored in a private
generated-audiobucket and served the same way. - Backups and infrastructure logs are retained by our backend provider for operational and security purposes.
How we use your data
- To run the app: showing your cards, playing audio, sending medication reminders, and coordinating between caregivers and patients you have explicitly linked.
- To enforce plan limits (e.g. number of cards, voice generations).
- To respond to support questions you send us.
- To protect the service from abuse and to comply with the law.
We do not sell your personal data. We do not use your family content to train external AI models.
Third-party processors
- Supabase โ database, authentication, file storage.
- Stripe โ subscription billing (only when you upgrade).
- ElevenLabs / Lovable AI โ text-to-speech generation, called from our servers; only the text you ask to be spoken is sent.
- Email delivery provider โ used to send caregiver alerts, reminders, and contact-form replies.
Audio & photo uploads
Audio recordings and photos you upload are stored privately and shown only to you and the family/caregiver accounts you have linked. You can delete any card or recording from inside the app at any time; deleting the card removes the associated file from storage.
Children
PictureToSay is intended to be set up and managed by an adult caregiver. If an account is used by a minor (for example a child with autism or a developmental disability), a parent or legal guardian is responsible for that account.
Your rights
- Access, correct, export, or delete your data โ write to support@picturetosay.com.
- Delete your account from the app's Settings; we will remove your personal records and uploaded files from active storage. Backups roll off on our provider's standard schedule.
- Withdraw consent for optional features such as AI voice generation at any time by stopping use of those features.
Security
We use encryption in transit (HTTPS) and at rest, role-based access controls, and database row-level security policies. No system is perfectly secure; please use a strong unique password and contact us immediately if you suspect your account has been compromised.
Changes to this policy
We may update this policy as the product evolves. Material changes will be posted on this page with an updated date.
Contact
Questions or requests: info@picturetosay.com ยท support@picturetosay.com