Privacy Policy
Effective date: March 1, 2026
Story Magic ("we", "us", or "our") operates storymagicapp.net and app.storymagicapp.net (collectively, the "Service"). This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and the choices you have. By using the Service you agree to the practices described here.
1. Information We Collect
1.1 Information you provide
- Account data — name, email address, and password when you create an account via Clerk.
- Billing data — payment card details are collected and stored by Stripe. We receive only a tokenised reference and the last four digits of your card; we never store full card numbers.
- Script content — the screenplays and text you upload or paste for audio generation.
- Voice samples — audio recordings you upload for voice cloning (Pro and Creator plans).
- Communications — emails or messages you send to our support team.
1.2 Information collected automatically
- Usage data — pages visited, features used, generation job status, timestamps, and referring URLs.
- Device data — IP address, browser type, operating system, and device identifiers.
- Cookies and similar technologies — see our Cookie Policy for details.
1.3 Information from third parties
- Clerk — authentication provider. We receive a user ID, email, and profile metadata.
- Stripe — payment processor. We receive subscription status, plan tier, and billing history.
- ElevenLabs — text-to-speech provider. Script text and voice parameters are transmitted to ElevenLabs to generate audio. ElevenLabs processes this data under their own privacy policy.
2. How We Use Your Information
- Provide, operate, and maintain the Service.
- Process payments and manage your subscription.
- Generate audio from your scripts using our AI pipeline.
- Send transactional emails (account verification, receipts, job completion notifications).
- Respond to support requests.
- Detect, investigate, and prevent fraudulent or unauthorised activity.
- Improve our models, features, and user experience using aggregated, anonymised usage data.
- Comply with legal obligations.
We do not use your script content or voice samples to train AI models unless you give explicit, separate consent.
3. Legal Bases for Processing (EEA / UK Users)
Where GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract performance — processing necessary to deliver the Service you signed up for.
- Legitimate interests — security monitoring, fraud prevention, service improvement (where our interests are not overridden by your rights).
- Legal obligation — compliance with applicable laws.
- Consent — marketing communications and optional analytics cookies (you can withdraw at any time).
4. How We Share Your Information
We do not sell your personal data. We share information only as follows:
- Service providers — Clerk (auth), Stripe (payments), ElevenLabs (TTS), OpenAI / Groq (LLM), Supabase (file storage), Upstash (caching), Sentry (error monitoring), Render.com (infrastructure). Each operates under its own data processing agreement.
- Legal requirements — when required by law, subpoena, or to protect the rights, safety, or property of Story Magic or others.
- Business transfers — in connection with a merger, acquisition, or sale of assets, with appropriate confidentiality obligations.
- Team members — if you use collaboration features, team members you invite can see the scripts and audio in shared projects.
5. Data Retention
- Free plan — scripts and generated audio are deleted after 7 days of inactivity.
- Starter plan — projects retained for 30 days of inactivity.
- Pro plan — projects retained for 90 days.
- Creator plan — unlimited storage; retained until you delete or cancel your account.
- Account data — retained for the life of your account plus 90 days after deletion to allow recovery.
- Billing records — retained for 7 years for legal and tax compliance.
- Voice clones — retained while your subscription is active; deleted within 30 days of account deletion.
6. Security
We implement industry-standard measures including TLS encryption in transit, AES-256 encryption at rest, isolated job sandboxing for script processing, and role-based access controls. No method of transmission over the internet is completely secure; we cannot guarantee absolute security.
7. International Transfers
Our servers are located in the United States (Oregon, via Render.com). If you access the Service from the EEA, UK, or another jurisdiction, your data may be transferred to and processed in the US. We rely on Standard Contractual Clauses and other approved mechanisms where required.
8. Your Rights
Depending on your location, you may have the right to:
- Access a copy of the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data (subject to legal retention obligations).
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time for consent-based processing.
- Lodge a complaint with your local data protection authority.
To exercise these rights, email privacy@storymagicapp.net. We will respond within 30 days.
9. Children's Privacy
The Service is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@storymagicapp.net and we will delete it promptly.
10. Cookies
We use cookies and similar technologies. See our Cookie Policy for the full list of cookies and how to manage them.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will notify you by email and update the effective date above. Your continued use of the Service after changes constitutes acceptance of the revised policy.
12. Contact Us
For privacy questions or to exercise your rights:
Story Magic
Email: privacy@storymagicapp.net