Legal
Privacy policy
What we collect, why we collect it, who else sees it, how long we keep it, and how to get it back or have it removed.
Effective 5 August 2026
Two kinds of people in this policy
Storiefied serves two groups, and they are treated differently.
- Customers — people with an account who build sites here. We decide how their data is handled, so we are the controller of it.
- Visitors to a published site — people who land on a site a customer built. The customer decides what happens on their site; we process that data on their behalf. Questions about a specific site go to whoever runs it.
What we collect from customers
- Account details: your name, email address and a hashed password. We never store the password itself, and we cannot recover it for you.
- If you sign in with Google, the profile information that provider returns — name, email and avatar. We do not receive your Google password.
- Workspace and project content: pages, blocks, themes, domains and everything else you build.
- Uploads: the video and GIF files you send us, and the frames extracted from them.
- Operational records: job history for transcoding, including failures and the reason a file could not be processed.
- Billing details for paid plans, handled by our payment provider. Card numbers do not reach our servers.
What is collected on published sites
Sites built here record page views and clicks so their owner can see what is working. Alongside each event we store the page path, the referrer, a coarse location derived from network-level headers, and a short-lived session identifier.
Visitor IP addresses are never stored in the clear. They are salted and hashed on arrival, which lets us count a returning visitor without keeping something that identifies them.
If a site includes a form, whatever a visitor types into it is stored for that site’s owner to read. What a form asks for is the owner’s decision.
Why we are allowed to hold it
- To perform our contract with you: running your account, storing your work, publishing your sites, and taking payment.
- For our legitimate interests: keeping the service secure, preventing abuse, fixing faults, and understanding which features get used.
- To meet legal obligations, such as keeping financial records.
- With your consent, where consent is what the law requires — and you can withdraw it at any time.
Who else sees it
We do not sell personal data and we do not share it for advertising. It reaches these providers only so the service can run:
| Provider | What they do |
|---|---|
| Vercel | Application hosting, edge routing and TLS certificates |
| MongoDB Atlas | Primary database: accounts, projects, pages and analytics |
| Cloudflare R2 | Object storage for uploaded video and extracted frames |
| OpenAI | AI drafting, when you use a feature that calls a model |
Content you type is sent to a model provider only when you use an AI feature. Nothing is sent in the background, and your work is not used to train anyone’s model by us.
We may also disclose data where the law requires it, or to protect the service and its users from harm.
Where it is stored
Our providers operate internationally, so your data may be processed outside your own country. Where that involves a transfer out of the UK or the European Economic Area, it relies on the safeguards those rules require, such as standard contractual clauses.
How long we keep it
- Account and workspace content: for as long as the account is open.
- Uploads and extracted frames: until you delete them, or the account closes.
- Analytics events: kept in a rolling window sized for the reports we show, then removed.
- Form submissions: until the site owner deletes them.
- Records we must keep for legal or accounting reasons: for as long as that obligation lasts.
Closing an account starts deletion. Copies can persist briefly in routine backups, which expire on their own schedule.
Your rights
Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to or restrict what we do with it, and ask for it in a portable format. You can also complain to your local data protection authority.
Write to privacy@storiefied.com and we will respond within the time the law allows. If your request concerns data collected by a site someone else built here, ask them first — we will help them act on it.
Cookies
On Storiefied itself we use a cookie to keep you signed in, and one to remember which workspace you are working in. There are no advertising cookies.
A page protected by a password sets one more cookie recording that the password was entered, which expires on its own.
Published sites may set cookies of their own. That is the site owner’s decision and their notice to give.
Children
The service is not for children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, tell us and we will remove it.
Changes and contact
We will update this policy as the product changes, and the effective date at the top will move with it. Material changes get notice before they take effect.
Privacy questions go to privacy@storiefied.com. Everything else is on the contact page, and the terms explain the rest of the agreement.