Storyloom is built local-first: with no account, your projects never leave your browser. When you opt into cloud features, this page explains exactly what is stored, where, and how it's protected — plus how to report anything that looks wrong.
Our approach, in order: store less (data we never collect can't leak), keep the user in control (local-first by default, explicit action required for anything to reach the cloud), and enforce on the server (every sharing and plan rule is enforced by database row-level security, not by the page). Secrets — the AI provider key, payment webhooks — live only in server-side functions; the published site contains no credentials beyond a public API identifier that is designed to be public.
Projects, preferences, version history and the fragment library are stored in your browser's local storage on your device. They are never transmitted to us. Clearing site data deletes them — export regularly.
Saved cloud projects, workspace and project membership, comments/reviews/suggestions/notifications you create, your email address, and plan status are stored in our database (hosted on Supabase infrastructure). Access is governed by row-level security: a project is readable only by its owner and the people (or workspace members) it was explicitly shared with. Live co-editing traffic flows through the same authenticated channels.
Billing is handled by Stripe. Card numbers never touch our servers or our database — we store only your plan, its period, and a customer reference.
When you click ✦ Generate with AI, the form you filled in is sent through our server-side function to the model provider to produce the skeleton, and the call is counted against your monthly allowance. Your board is not used to train models, and we don't send your project — only the generator form.
Sign-in uses one-time magic links — there are no passwords to steal, reuse or crack. Links are single-use, expire quickly, and only work from the email address they were sent to; sessions are held as revocable tokens in your browser and can be ended any time with Sign out. Protect the inbox behind your account as you would any passwordless login. Collaborators must have signed in at least once before they can be added to a project — sharing is by exact account email, so a typo can't silently expose a project to a stranger.
Last updated: August 2026 · This policy covers the hosted Storyloom site and its cloud features.
To provide the product: syncing and sharing your projects, enforcing plan limits, sending sign-in links and the notification emails you opt into, and preventing abuse. We do not sell personal data, do not run third-party advertising, and do not use your content to train AI models.
You, the people you share a project or workspace with (with the role you gave them), and infrastructure providers acting as processors (Supabase for the database, Stripe for billing, our email provider for digests, the AI provider for skeleton requests you initiate).
Cloud content stays until you delete it (deleting a project removes it for everyone). To delete your account and its data, email us from your account address — we remove account records and cloud content within 30 days, except minimal billing records we must keep for tax and accounting law.
You can export your projects at any time (File ▸ Export). Depending on where you live (e.g. GDPR/CCPA regions) you may have rights to access, correct, delete, or port your personal data, and to object to processing — email us and we'll honour them.
Storyloom's cloud features aren't directed at children under 13 (or the minimum age in your country); don't create an account if you're under it.
If this policy changes materially we'll note it here with a new date. Questions: mondaeatughonu@gmail.com.
Found something? Please tell us privately first. Email mondaeatughonu@gmail.com with the subject line starting SECURITY: — include steps to reproduce, the impact you believe it has, and how we can reach you.