Legal
What we collect, why we collect it, who else sees it, how long we keep it, and how to get it back or have it removed.
Effective 5 August 2026
Storiefied serves two groups, and they are treated differently.
Sites built here record page views and clicks so their owner can see what is working. Alongside each event we store the page path, the referrer, a coarse location derived from network-level headers, and a short-lived session identifier.
Visitor IP addresses are never stored in the clear. They are salted and hashed on arrival, which lets us count a returning visitor without keeping something that identifies them.
If a site includes a form, whatever a visitor types into it is stored for that site’s owner to read. What a form asks for is the owner’s decision.
We do not sell personal data and we do not share it for advertising. It reaches these providers only so the service can run:
| Provider | What they do |
|---|---|
| Vercel | Application hosting, edge routing and TLS certificates |
| MongoDB Atlas | Primary database: accounts, projects, pages and analytics |
| Cloudflare R2 | Object storage for uploaded footage and the clips and frames derived from it |
| OpenAI | Support-chat replies only: the text you type to the help widget, nothing else |
| Gemini API — analysing uploaded footage to draft a story when you ask for one | |
| Brevo | Transactional email: welcome messages and password links, sent to your address |
When you ask for an AI story draft, the video itself is sent to Google's Gemini API, which watches it and writes the first version of the story — beats, copy, theme and fonts. Nothing is sent in the background: no upload reaches a model until you press Create (or ask for a redraft) on a project. Our upload to Google is deleted straight after the draft is written; how Google handles API data beyond that is governed by its own terms. The support chat is the only thing that reaches OpenAI, and only ever as the text you type into it. Your work is not used to train anyone’s model by us.
We may also disclose data where the law requires it, or to protect the service and its users from harm.
Our providers operate internationally, so your data may be processed outside your own country. Where that involves a transfer out of the UK or the European Economic Area, it relies on the safeguards those rules require, such as standard contractual clauses.
Closing an account starts deletion. Copies can persist briefly in routine backups, which expire on their own schedule.
Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to or restrict what we do with it, and ask for it in a portable format. You can also complain to your local data protection authority.
Write to privacy@storiefied.com and we will respond within the time the law allows. If your request concerns data collected by a site someone else built here, ask them first — we will help them act on it.
On Storiefied itself we use a cookie to keep you signed in, and one to remember which workspace you are working in. There are no advertising cookies.
A page protected by a password sets one more cookie recording that the password was entered, which expires on its own.
Published sites may set cookies of their own. That is the site owner’s decision and their notice to give.
The service is not for children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, tell us and we will remove it.
We will update this policy as the product changes, and the effective date at the top will move with it. Material changes get notice before they take effect.
Privacy questions go to privacy@storiefied.com. Everything else is on the contact page, and the terms explain the rest of the agreement.
We collect what the product needs to work. Nothing is sold.