Storyflow Logo

Storyflow

What's newWho uses storyflowAboutPricing
Login

Legal

Privacy Policy

This Privacy Policy explains how Storyflow collects, uses, shares, and protects information when you use our website, workspace, and related services.

Last updated: August 7, 2026

1. Information We Collect

We collect information you provide directly to Storyflow, such as your name, email address, account details, workspace content, messages, files, and billing-related information when you choose a paid plan.

We also collect technical information when you use Storyflow. We would rather list it precisely than describe it vaguely, so here is the full set and why each item exists.

  • Device and browser information, used to render the product correctly and to reproduce bugs you report.
  • Log data, including requests to our servers and error traces, used to keep the service running and to investigate faults and abuse.
  • Pages viewed and feature usage, used to understand which parts of the product are used and where they fail.
  • An approximate location derived from your IP address, at city or country level only. We do not collect GPS or precise device location.
  • Product analytics run only on our production website and app, never in development or testing, and an analytics profile is created only once you are signed in. Visitors who never sign in are not profiled.
  • We do not collect special category data such as health, biometric, or political data, we do not use your information for automated decisions that produce legal or similarly significant effects, and we do not sell it.

2. How We Use Information

We use your information for the purposes below and not for others. Where the law requires us to name a legal basis for processing, such as the GDPR, the basis for each purpose is given alongside it.

  • Running your account and workspace, including sign-in, saving and syncing your projects, and collaboration. Necessary to perform our contract with you.
  • Taking payment and managing subscriptions. Necessary to perform our contract with you and to meet our tax and accounting obligations.
  • Answering support requests you send us. Necessary to perform our contract with you.
  • Keeping the service secure and available, investigating faults, and preventing abuse. Our legitimate interest in operating a reliable service.
  • Understanding which features are used and where they fail, so we know what to build and fix. Our legitimate interest in improving the product.
  • Sending service messages such as security notices, billing notices, and changes to this policy. These are necessary to operate your account and are not marketing, so they cannot be switched off while your account is open.
  • Sending product announcements and marketing email. Consent where required, otherwise our legitimate interest. Every marketing email carries an unsubscribe link, and you can opt out at any time regardless of where you live.

3. Your Content

Your boards, notes, documents, files, prompts, and other project materials remain yours. We use this content only to operate Storyflow, provide requested features, troubleshoot issues, improve reliability, and comply with legal obligations.

When you use an AI feature, the prompt and the workspace context you submit are sent to a third-party AI provider so a result can be returned to you. Content you never put through an AI feature is not sent to an AI provider.

Storyflow does not train any model on your workspace content. If your organization needs written confirmation of how our AI providers handle submitted content, including whether it is retained or used for their own model training, ask us at [email protected] and we will give you the specifics for the provider in use rather than a general reassurance.

4. Sharing Information

We do not sell your personal information. We share information only when needed to run Storyflow, comply with the law, protect our rights, or complete a transaction you request.

  • Service providers that host, store, analyze, secure, or support Storyflow.
  • Payment processors that handle subscriptions and billing.
  • AI infrastructure providers when you use AI-powered features.
  • Legal, safety, or compliance recipients when disclosure is required or appropriate.

5. Service Providers We Use

We rely on a small number of established providers to run Storyflow. Each one receives only the information it needs for its specific function, and none of them are permitted to use your information for their own purposes.

  • Google (Firebase) - account authentication, including email and password sign-in and Google sign-in, and product measurement.
  • Stripe - subscription checkout, billing, and payment card handling. Storyflow does not store your full card details.
  • Intercom - the in-product support messenger and your support conversations.
  • PostHog - product analytics that tell us which features are used and where the product fails.
  • Affonso - referral and affiliate attribution, loaded only on our public marketing site.
  • Object storage and a content delivery network - storing and serving the files, images, and exports you upload.
  • AI providers - processing the prompts and workspace context you submit when you use AI features, so we can return a result.

6. Where Your Information Is Processed

Storyflow is used from many countries, and the providers listed above operate internationally. This means your information can be processed outside the country you are in, including in the United States.

Where information is transferred out of the United Kingdom or the European Economic Area, we rely on the transfer mechanisms our providers make available for that purpose, such as the European Commission's Standard Contractual Clauses or an adequacy decision covering the receiving country.

If your organization needs to know the specific region a particular category of data is stored in before it can approve Storyflow, ask us at [email protected] and we will confirm it rather than have you assume.

7. Business and Enterprise Customers

If you are evaluating Storyflow for a company, we would rather tell you plainly where we stand than imply more than we can support. Storyflow is an early-access product built by a small team. We have not completed a SOC 2, ISO 27001, or comparable third-party audit, and we do not currently offer single sign-on, SAML, enforced two-factor authentication, audit logs, or a customer-managed encryption option.

What we do offer is the transparency on this page: a named list of every service provider that touches your data, a clear description of what we collect and why, and a direct line to the people who build the product. If your organization needs a data processing agreement, a security questionnaire completed, specific retention or deletion commitments, or information about where data is stored, contact us at [email protected] and we will tell you what we can and cannot commit to.

8. Cookies and Analytics

Storyflow uses cookies, local storage, and similar technologies. There are three kinds, and we would rather name them than group them together.

  • Strictly necessary - keeping you signed in, holding your session, and remembering interface preferences such as color mode. The product cannot work without these.
  • Analytics - understanding which features are used and where they fail. These run on our production site and app only.
  • Referral attribution - a cookie set on our public marketing site when you arrive through a referral or affiliate link, so the referrer can be credited. It lasts 30 days by default and is not set inside the product.
  • You can control or clear cookies through your browser settings. Blocking the strictly necessary ones will stop you being able to sign in and use the product.

9. Data Security

We use appropriate technical and organizational measures designed to protect your information from unauthorized access, loss, misuse, or alteration, in the sense meant by Article 32 of the GDPR. No internet service can be guaranteed to be completely secure.

In practice this means the following, described so you can judge it rather than take our word for it.

  • Traffic between your browser or app and Storyflow is encrypted in transit using HTTPS.
  • Account data and uploaded files are held with infrastructure providers that encrypt data at rest.
  • Sign-in is handled by Firebase Authentication. Storyflow never receives or stores your password, and new email sign-ups are sent a verification email.
  • Sign-in options today are email and password, or Google. Single sign-on, SAML, and enforced two-factor authentication are not available yet.
  • Anything you share by link can be set to view-only or comment-only, and can be protected with a password that a visitor must enter before the board, document, or tactic will load.
  • Please keep your login credentials safe, and notify us at [email protected] if you believe your account has been compromised.

10. Data Retention

We keep your account and workspace content for as long as your account is open, because that content is the product. We do not silently delete your work.

When you ask us to delete your account, we delete your account and its workspace content from our live systems. Copies can persist in encrypted backups for a limited period after that until those backups age out on their normal cycle, and we do not restore deleted accounts from them.

We keep billing and transaction records for as long as tax and accounting law requires us to, which is longer than the account itself. Support conversations and security logs are kept only as long as they are useful for handling your request and protecting the service.

If your organization needs exact retention periods in writing for its records, ask us at [email protected].

11. Your Rights

Depending on where you live, you have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. Where we rely on your consent, you can withdraw it at any time, and withdrawing it does not affect processing that already happened.

To make a request, contact us at [email protected]. We may need to verify your identity first. We aim to respond within one month, which is the deadline the GDPR sets, and we will tell you if a request is complex enough to need longer.

Exercising these rights costs nothing and we will not treat you differently for using them. If you are in the United Kingdom or the European Economic Area and you are not satisfied with how we have handled your information, you have the right to complain to your national data protection authority.

12. Children

Storyflow is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so we can take appropriate action.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the updated date and, where appropriate, provide additional notice.

14. Contact

Questions about this Privacy Policy can be sent to [email protected].