Privacy Policy
Last updated: 22 August 2026
Notice at Collection (Summary)
- Who: Story Glider Limited (Malta) operates StoryGlider.com.
- What we collect: account information (email, name), content you create or upload, usage data, and technical data such as IP address and device information.
- Why: to provide and improve the Service, authenticate and support you, ensure security, comply with law, and (only if you opt in) measure aggregated usage.
- Sale/Sharing: we do not sell your personal information or share it for cross-context behavioral advertising.
- Sensitive data: we do not ask for special-category or sensitive personal data; please do not upload other people's personal, biometric, or voice/likeness data without their consent.
- Retention: we keep personal data while your account is active and for limited periods required by law (see Data Retention below).
- Your controls: access, export, correct, and delete your data from Profile; we honor Global Privacy Control signals.
1. Introduction
Story Glider Limited ("we," "us," or "our") operates StoryGlider.com ("the Service"). We are committed to protecting your privacy and ensuring transparency about how we collect, use, and safeguard your personal information.
Data Controller:
Story Glider Limited
The Watercourse, Central Business District- Zone 2
Mdina Road, CBD 2010, Malta
Registration: C 114108
Email: hello@storyglider.com
Privacy: privacy@storyglider.com
This Privacy Policy explains our practices regarding the collection, use, and disclosure of your personal data when you use our Service, in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (required)
- Name (optional)
- Clerk User ID (unique identifier)
- Account role and permissions
2.2 Content and Project Data
When you use our Service, we collect and store:
- Script Projects: Video topics, formats, scripts, keywords, audience information, YouTube metadata, AI-generated content, and project configurations
- Research Library: Uploaded documents, research queries, content, tags, and search statistics
- Ad Templates: Template names, descriptions, and configuration settings
- File Uploads: Documents and files you upload to the Service (stored securely in cloud storage)
2.3 Usage Data
We automatically collect information about how you use the Service:
- Project creation and modification timestamps
- Last viewed dates for projects
- Sharing tokens and expiration dates
- Feature usage patterns
2.4 Technical Data
We collect technical information automatically:
- IP address
- Browser type and version
- Device information
- Cookies and similar tracking technologies (see our Cookie Policy)
3. How We Use Your Information
We use your personal information for the following purposes:
- Service Provision: To provide, maintain, and improve our Service
- Account Management: To create and manage your account, authenticate you, and provide customer support
- Content Processing: To process your content, generate AI-powered scripts and materials, and store your projects
- Communication: To send you service-related notifications, updates, and respond to your inquiries
- Analytics: To analyze usage patterns, improve our Service, and develop new features
- Security: To detect, prevent, and address technical issues, fraud, or security threats
- Legal Compliance: To comply with legal obligations and enforce our Terms of Service
We process personal data only where we have a legal basis: to perform our contract with you (providing the Service and your account); to comply with legal obligations (for example tax and accounting records); based on your consent (optional analytics and cookies); and, where applicable, our legitimate interests in security, fraud prevention, and improving the Service in a way that does not override your rights.
4. Data Storage and Security
We use industry-standard security measures to protect your data:
- Database: Your account and project data are stored in secure PostgreSQL databases hosted by NeonDB, with encrypted connections
- Authentication: User authentication is handled by Clerk, which uses industry-standard security protocols
- File Storage: Personal uploads (research documents, chat reference images, character photos, channel avatars) are stored as private files and served only after you sign in. Generated media such as clips may use unguessable public URLs so the production tools can display them — do not share those links if a file contains personal data
- Encryption: Data is encrypted in transit using TLS/SSL and at rest using encryption standards
While we implement appropriate technical and organizational measures to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your information.
Security incidents: If we become aware of a breach of personal data that is likely to result in a risk to your rights and freedoms, we will notify relevant supervisory authorities and affected users as required by applicable law (including the GDPR), describing the nature of the incident, likely consequences, and measures we have taken or propose to take.
5. Third-Party Services (Subprocessors)
We rely on trusted third-party service providers (subprocessors) to deliver the Service. These fall into the following categories:
- Authentication: to create and secure your account
- Hosting, storage, and infrastructure: to run the Service, store your files, and operate our database, queues, and rate limiting
- AI and media providers: to generate scripts, images, video, voiceovers, music, and to power research and media processing when you use those features
- Analytics: cookieless, privacy-friendly usage measurement (only when you opt in)
For a complete, current list of each provider, what it is used for, the data it processes, and a link to its privacy policy, see our Subprocessors page.
We only share the data necessary for these services to function and require them to protect your data in accordance with applicable data protection laws. Each provider has its own privacy policy, which we encourage you to review.
We do not use your content to train our own machine-learning models. When you use generation features, prompts and uploads are sent to the third-party AI providers listed on the Subprocessors page so they can return a result. Those providers process that data under their own terms.
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our Service and store certain information. For detailed information about the cookies we use and your choices regarding cookies, please see our Cookie Policy.
For optional usage measurement we use Vercel Web Analytics, which is cookieless and does not build advertising profiles. Analytics is off by default and only runs if you opt in via our cookie banner or preferences. We also honor Global Privacy Control (GPC) and Do Not Track browser signals, keeping non-essential analytics off when those are present.
7. Your Rights (GDPR)
Under the GDPR and other applicable data protection laws, you have the following rights:
- Right of Access: You can request a copy of the personal data we hold about you
- Right to Rectification: You can update your name and email in your account profile, or contact us for other corrections
- Right to Erasure: You can request deletion of your personal data ("right to be forgotten"). Signed-in users can start erasure from Profile (Delete account). This removes your data from our application databases and deletes your authentication account with our provider (Clerk), subject to the exceptions below
- Right to Restrict Processing: You can request that we limit how we use your data
- Right to Data Portability: Signed-in users can download a machine-readable JSON export of personal data we store in our databases from Profile (Download my data). You can also contact us for a copy
- Right to Object: You can object to processing of your data for certain purposes
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time
For requests you cannot complete in the app, or to exercise any right not listed with a self-service option, contact us at hello@storyglider.com. We will respond within one month, or inform you if an extension is needed under GDPR.
You also have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you reside, work, or where an alleged infringement occurred. In Malta, this is the Office of the Information and Data Protection Commissioner.
7.1 United States state privacy rights
Depending on your state of residence, US state privacy laws may apply to you, including the California Consumer Privacy Act as amended by the CPRA (California), the VCDPA (Virginia), the CPA (Colorado), the CTDPA (Connecticut), the UCPA (Utah), the TDPSA (Texas), and similar laws in other states. Subject to those laws and their exceptions, you may have the right to:
- Know / access: the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of recipients
- Delete: personal information we have collected about you
- Correct: inaccurate personal information
- Portability: obtain a copy of your personal information in a portable, machine-readable format
- Opt out: of the "sale" or "sharing" of personal information and of targeted advertising
- Limit: the use and disclosure of sensitive personal information
- Opt out of profiling: in furtherance of decisions that produce legal or similarly significant effects, where applicable
- Non-discrimination: we will not discriminate against you for exercising your rights
We do not sell your personal information and do notshare it for cross-context behavioral advertising or targeted advertising. Because we do not sell or share, there is no "Do Not Sell or Share" sale to opt out of; we nonetheless honor opt-out preference signals such as Global Privacy Control (GPC) for analytics and any future sharing.
How to exercise: signed-in users can access, export, correct, and delete data directly from Profile, or contact us at hello@storyglider.com. You may use an authorized agent to submit a request on your behalf where the law allows. We will verify your request (typically by confirming control of your account email) before acting and will respond within the timeframes required by applicable law.
Appeals: if we decline your request, you may appeal by replying to our decision or emailing hello@storyglider.com with the subject "Privacy Appeal". If your appeal is denied, you may contact your state attorney general.
8. Data Retention
We retain your personal data for as long as necessary to:
- Provide the Service to you
- Comply with legal obligations
- Resolve disputes and enforce our agreements
As a general guide, our retention periods are:
- Account and profile data: for as long as your account is active; deleted when you delete your account
- Content, projects, and uploaded files: until you delete them, or when you delete your account
- Billing, credit (KWZ), and transaction records: retained in minimized form for up to the period required by applicable tax and accounting law (typically up to 6–7 years)
- Security and audit logs: typically up to 12 months, then deleted or anonymized
- Consent records: kept for as long as needed to demonstrate compliance
- Encrypted backups: roll off automatically within our infrastructure providers' backup cycles (generally within ~30 days)
When you delete your account through Profile, we erase your personal data from our application databases and request deletion of your authentication account without undue delay. Residual copies in encrypted backups may persist for a limited period in line with our infrastructure providers' backup cycles, then roll off automatically. We may retain certain information where required by law (for example tax or accounting records) or for the establishment, exercise, or defence of legal claims.
Content you have published or made available to other users (for example shared links or stock library contributions that have been merged into shared catalogues) may continue to be processed where necessary to operate those features; contact us if you need help with a specific case.
9. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where our third-party service providers operate. We ensure that appropriate safeguards are in place:
- Standard Contractual Clauses approved by the European Commission
- Data Processing Agreements with third-party providers
- Compliance with GDPR requirements for international transfers
International transfers are not based on your browsing or account signup alone. We rely on the safeguards above (including Standard Contractual Clauses) rather than browsewrap consent.
10. Children's Privacy
Our Service is not intended for children under 13 years of age, and we do not knowingly collect personal information from children under 13. In the European Economic Area, the minimum age at which a person can consent to online services ranges from 13 to 16 depending on the member state; if you are under the applicable age in your country, you must have your parent or guardian's consent to use the Service.
If you are a parent or guardian and believe your child has provided us with personal information without the required consent, please contact us immediately. If we become aware that we have collected such information without an appropriate legal basis, we will take steps to delete it.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated Privacy Policy on StoryGlider.com
- Updating the "Last updated" date at the top of this page
- Sending an email notification to registered users when possible
Your continued use of the Service after such changes constitutes acceptance of the updated Privacy Policy.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Story Glider Limited
The Watercourse, Central Business District- Zone 2
Mdina Road, CBD 2010, Malta
Registration: C 114108
Email: hello@storyglider.com
Privacy: privacy@storyglider.com
Website: StoryGlider.com