Storyloom
Security & Privacy

Your stories are yours. Here's how we treat them.

Storyloom is built local-first: with no account, your projects never leave your browser. When you opt into cloud features, this page explains exactly what is stored, where, and how it's protected — plus how to report anything that looks wrong.

Security statementHow we handle dataAccount securityPrivacy policyReport a vulnerability

Security statement & mindset

Our approach, in order: store less (data we never collect can't leak), keep the user in control (local-first by default, explicit action required for anything to reach the cloud), and enforce on the server (every sharing and plan rule is enforced by database row-level security, not by the page). Secrets — the AI provider key, payment webhooks — live only in server-side functions; the published site contains no credentials beyond a public API identifier that is designed to be public.

How we handle data

Local projects (no account)

Projects, preferences, version history and the fragment library are stored in your browser's local storage on your device. They are never transmitted to us. Clearing site data deletes them — export regularly.

Cloud projects (signed in)

Saved cloud projects, workspace and project membership, comments/reviews/suggestions/notifications you create, your email address, and plan status are stored in our database (hosted on Supabase infrastructure). Access is governed by row-level security: a project is readable only by its owner and the people (or workspace members) it was explicitly shared with. Live co-editing traffic flows through the same authenticated channels.

Payments

Billing is handled by Stripe. Card numbers never touch our servers or our database — we store only your plan, its period, and a customer reference.

AI generation

When you click ✦ Generate with AI, the form you filled in is sent through our server-side function to the model provider to produce the skeleton, and the call is counted against your monthly allowance. Your board is not used to train models, and we don't send your project — only the generator form.

What we don't do

Account security

Sign-in uses one-time magic links — there are no passwords to steal, reuse or crack. Links are single-use, expire quickly, and only work from the email address they were sent to; sessions are held as revocable tokens in your browser and can be ended any time with Sign out. Protect the inbox behind your account as you would any passwordless login. Collaborators must have signed in at least once before they can be added to a project — sharing is by exact account email, so a typo can't silently expose a project to a stranger.

Privacy policy

Last updated: August 2026 · This policy covers the hosted Storyloom site and its cloud features.

What we collect

How we use it

To provide the product: syncing and sharing your projects, enforcing plan limits, sending sign-in links and the notification emails you opt into, and preventing abuse. We do not sell personal data, do not run third-party advertising, and do not use your content to train AI models.

Who can see your content

You, the people you share a project or workspace with (with the role you gave them), and infrastructure providers acting as processors (Supabase for the database, Stripe for billing, our email provider for digests, the AI provider for skeleton requests you initiate).

Retention & deletion

Cloud content stays until you delete it (deleting a project removes it for everyone). To delete your account and its data, email us from your account address — we remove account records and cloud content within 30 days, except minimal billing records we must keep for tax and accounting law.

Your rights

You can export your projects at any time (File ▸ Export). Depending on where you live (e.g. GDPR/CCPA regions) you may have rights to access, correct, delete, or port your personal data, and to object to processing — email us and we'll honour them.

Children

Storyloom's cloud features aren't directed at children under 13 (or the minimum age in your country); don't create an account if you're under it.

Changes

If this policy changes materially we'll note it here with a new date. Questions: mondaeatughonu@gmail.com.

Report a vulnerability or security issue

Found something? Please tell us privately first. Email mondaeatughonu@gmail.com with the subject line starting SECURITY: — include steps to reproduce, the impact you believe it has, and how we can reach you.

🛡 Report a security issue