Privacy Policy
Effective September 4, 2026. This Privacy Policy describes how Neal Hannon, doing business as StoryVue ("StoryVue," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use the StoryVue websites, applications, and related services (the "Service"). For purposes of the EU and UK General Data Protection Regulation, StoryVue is the data controller of the personal information described in this Policy.
In brief: we collect what is needed to operate the Service and nothing more. We run no advertising trackers. Site usage is measured with Cloudflare Web Analytics, a cookieless service that stores nothing on your device and does not profile visitors across sites. We do not sell personal information, we do not share it for advertising, and we do not use your content to train artificial-intelligence models.
1. Information we collect
Account information. Your email address and a password. Passwords are stored only as a secure hash by our authentication provider; we never have access to your password in plain text.
Content. The stories and related material you create, upload, or store in the Service, including entities, connections, timelines, notes, manuscripts, images, fonts you upload, and the earlier versions of that material that the Service keeps so you can restore them. Storing this material is the purpose of the Service.
Billing information. If you purchase a subscription, payment is processed by our payment processor, Stripe. Stripe collects your payment card details directly; we never receive or store full card numbers. We receive and retain subscription status, transaction records, and processor-issued identifiers associated with your account.
Technical and log information. Standard technical data (such as IP address, browser type, and request timestamps) recorded by our infrastructure providers in routine server logs, retained for a limited period for security, fraud prevention, and reliability.
Campaign attribution. If you arrive at StoryVue from one of our own advertisements or campaign links, the address of that link can carry campaign labels and a click identifier added by the advertising platform (“utm” parameters, or a click ID from a platform such as Google, Meta, or Reddit). If you then create an account, we record those values, the referring page, the time of that first visit, and whether the account was created on a touch-screen device, as part of your account record. We use this only to measure which of our own advertising brings writers to StoryVue. It records nothing about your activity on any other site, it is never shared or disclosed for advertising, and it is deleted with your account. If you arrive without such a link, nothing is recorded.
Usage measurement. We measure site usage with Cloudflare Web Analytics. For each page view, the visitor’s browser sends Cloudflare the page address, the referring page, and standard browser and device information, which Cloudflare reports to us only in aggregate (counts of visits, pages, browsers, and countries). The service uses no cookies, stores nothing on your device, and does not build profiles of individual visitors or follow them across sites.
Storage on your device. The Service keeps several things in your browser. All of it is functional; none of it is used for advertising or cross-site tracking, and we do not use advertising or cross-site tracking cookies.
- Your sign-in session, so that you stay signed in between visits.
- Interface preferences, such as your light or dark theme, the editor’s focus mode, and the width of the editor panel.
- Short-lived state for the current tab, such as whether the guided tour has already been shown in this session.
- Campaign labels from the link that brought you here, kept in your browser until you create an account, so that an account created on a later visit can still be matched to the advertisement that introduced you — see Campaign attribution above. Nothing is transmitted unless you sign up.
- A working copy of your stories. So that signing in does not re-download everything, the Service keeps a copy of your projects in your browser’s storage. This can include the full text of your manuscripts. The copy is tied to your account, and it is deleted when you sign out or when a different account signs in on the same browser. If you used StoryVue before accounts existed, a database from that period may also remain in your browser until the Dashboard’s one-time migration uploads and deletes it.
Because that copy lives on the device rather than only on our servers, signing out matters on a shared or public computer.
Correspondence. If you contact us, we keep the correspondence and the address you wrote from so we can respond and keep a record of the request.
2. How we use information
We use personal information only to:
- provide, operate, and maintain the Service, including authentication, storage, and synchronization of your Content;
- process subscriptions, payments, and trials, and send transactional messages (such as receipts, password resets, and material changes to the Service or its terms);
- secure the Service, prevent abuse and fraud, and enforce our Terms of Service;
- understand aggregate site usage (which pages are visited, and how often) so we can maintain and improve the Service;
- respond to your requests and support inquiries;
- measure the effectiveness of our own advertising, using the campaign attribution described in Section 1; and
- comply with legal obligations.
We do not sell personal information, disclose it for cross-context behavioral advertising, or use your Content to train artificial-intelligence or machine-learning models.
3. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we process personal information on the following legal bases: performance of a contract (providing the Service you signed up for, including billing); legitimate interests (securing the Service, preventing abuse, measuring aggregate site usage and the effectiveness of our own advertising, and keeping records proportionate to those purposes); legal obligation (tax, accounting, and lawful requests); and consent, where we ask for it, which you may withdraw at any time.
4. How we disclose information
Service providers. We disclose information to the infrastructure and payment providers that operate parts of the Service on our behalf: Supabase (database, authentication, and file storage), Cloudflare (site delivery, network security, and cookieless site analytics), and Stripe (payment processing). Each processes personal information only to provide its service and under its own contractual and legal obligations.
Legal requirements. We may disclose information if we reasonably believe it is required by law, regulation, legal process, or a governmental request, or where necessary to protect the rights, property, or safety of StoryVue, our users, or the public.
Business transfers. If StoryVue is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy or to protections no less restrictive, and we will provide notice of any resulting change in control or use.
At your direction. Features you invoke yourself, such as exporting a story to a file, disclose data where you choose to send it.
5. Security and storage
Data is encrypted in transit, and access to stories in the database is enforced with row-level security, so your Content is readable by your account and no other. We limit our own access to the substance of your Content as described in the Terms of Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; we encourage you to use a strong, unique password and to keep independent exports of work you care about.
One caveat about images: uploaded images are served from unlisted URLs so that they can render in your own exports. They are not listed or discoverable anywhere, but anyone who obtained an exact link could view that image. Do not upload images that must remain strictly confidential.
Fonts you upload are stored privately and served only to your signed-in account, and are never shared with another account.
6. International transfers
Our providers may store and process personal information in the United States and other countries, which may have data-protection laws different from those in your jurisdiction. Where information originating in the EEA, UK, or Switzerland is transferred to a country not deemed adequate, our providers rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention and deletion
We keep personal information for as long as your account is active, and afterward only as long as necessary for the purposes described in this Policy (for example, transaction records we must retain for tax and accounting purposes). Deleting a story from the Dashboard moves it to the Trash, where it and its images and version history are kept for seven days so you can restore it; after that a nightly process removes the story, its images, and its history from the live database. Earlier versions of your stories are kept for the period you choose in the Service (from one week to three months, or none), and versions you name yourself are kept until you delete them. Storage freed by removed versions is reclaimed within about a day. To delete your entire account and all associated data, contact us at contact@storyvue.app; we will act on verified requests within the time required by applicable law. Copies in our providers' routine backups expire on a rolling schedule after deletion. The working copy held in your own browser (Section 1) is separate from all of this: it is cleared when you sign out, and deleting your account does not reach a device that is still signed in.
8. Your rights and choices
Regardless of where you live, you can export your stories at any time (Dashboard → Export), correct your Content in the app, and email us to request access to, correction of, or deletion of your personal information. We may need to verify your identity (normally by confirming control of the account email) before acting on a request, and we will not discriminate against you for exercising your rights.
EEA and UK residents additionally have the rights of access, rectification, erasure, restriction, data portability, and objection under the GDPR/UK GDPR, the right to withdraw consent where processing is based on consent, and the right to lodge a complaint with their local supervisory authority.
9. California privacy rights
In the terms of the California Consumer Privacy Act as amended by the CPRA: in the last 12 months we have collected the categories of personal information described in Section 1 (identifiers such as email address, IP address, and advertising click identifiers on accounts created from our own campaign links; commercial information such as subscription records; internet-activity information in server logs; and the user-provided content you store), for the purposes described in Section 2, and disclosed them for business purposes to the service providers described in Section 4. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, we do not use or disclose sensitive personal information for purposes requiring a right to limit, and we do not use personal information for cross-context behavioral advertising or profiling that produces legal effects.
California residents have the right to know, access, correct, and delete the personal information we hold about them, and the right not to be discriminated against for exercising those rights. Submit requests to contact@storyvue.app. You may use an authorized agent; we will require proof of authorization and verification of your identity.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us and we will delete the account and its data.
11. Do Not Track and Global Privacy Control
We do not track users across third-party websites, so there is no cross-site tracking for a Do Not Track signal to switch off. Because we do not sell or share personal information, a Global Privacy Control signal requires no additional action from us, and we treat it as consistent with how we already operate.
12. Changes to this policy
We may update this Policy from time to time. If a change is material, we will provide reasonable advance notice in the app or by email before it takes effect. The effective date above reflects the current version.
13. Contact
Privacy questions or requests: Neal Hannon, doing business as StoryVue, contact@storyvue.app.