Privacy notice
Effective 2026-09-10 · version 2026-09-15
This notice explains what Story Builder does with your personal data. It is written against what the software actually does — if you find a difference between this page and the product, the difference is a bug and we want to hear about it.
Who is responsible
Exalink
Ukraine
Questions about this notice, or about your data: the contact form.
What we collect, and why
Your account
When you register we store your email address, the username you choose, and a hash of your password — never the password itself. If you sign in with Google, we receive your name and email address from Google instead. We also record when you registered and, if you set them, your timezone and avatar.
We need this to give you an account. Without it there is no product.
Your sessions
Staying signed in means storing, per device, a session token with the device identifier, the browser's user agent and the IP address it last connected from. This is how "sign out everywhere" can work and how we notice a stolen session.
Expired sessions are deleted automatically twice a day. An account keeps at most five live sessions; older ones drop off.
What you write
Manuscripts, characters, locations, events, plans, maps, notes, images — everything you create in the product is stored so we can give it back to you. We do not read it, we do not train anything on it, and it is not shared with anyone unless you publish it or invite a collaborator.
Content belongs to the owner of the project it is in, which is the person who created that project. That matters here for one reason: when you delete your account, work you contributed to somebody else's project stays with them, unlinked from you. The terms set out why.
Collaboration
Shared projects record who is a member and what role they hold. Chat messages and comments carry the author's username and account id, because that is what makes a conversation legible.
Reading
When you read a published story while signed in, we record which chapters you have read, how long you spent, how far you scrolled, how many times you returned, and the dates. Two things use it: your own continue-reading, and the aggregate statistics an author sees about their story. An author never sees you individually.
We send: address verification, invitations, replies to your comments, and new-chapter digests for stories you follow. Each type can be switched off separately in your settings, and every message carries an unsubscribe link. We keep your preferences and the date of your last digest.
Logs
Our servers write technical logs to diagnose failures and abuse. Log lines can contain your account id and details of the request that failed.
What we do not do
- No advertising, no advertising networks, and nothing sold to anyone.
- No analytics or tracking scripts. There is no Google Analytics, no tag manager, no pixel.
- No third-party code in your browser at all: our fonts are served from our own servers, not from a font CDN.
- No profiling and no automated decisions that affect you.
Cookies and local storage
We set three cookies, all strictly necessary to sign you in and keep you signed in. They are HTTP-only, restricted to this site, and sent over HTTPS in production. A fourth token protects forms against cross-site request forgery.
Your browser also stores your own preferences locally — theme, recently opened items, panel positions, sidebar state. Those never leave your device.
Because none of this is used for advertising or analytics, there is no consent banner. Turning any of it off would mean not being able to sign in.
Who else processes your data
We use a small number of providers to run the service. Each processes data only on our instructions:
| Provider | What they handle |
|---|---|
| Our database host | Everything stored in the product |
| Amazon Web Services | Images and files you upload, and their delivery |
| Resend | Sending email |
| Sign in with Google, if you use it | |
| BetterStack | Application logs |
Some of these providers are headquartered outside the European Economic Area. Where data leaves the EEA, the transfer relies on the European Commission's standard contractual clauses, or on an adequacy decision where one covers the provider. Ask us at the contact form for the details of any particular transfer.
How long we keep it
| Account and your own content | Until you delete it, or the account closes |
| What you contributed to someone else's project | Kept, unlinked from you — it belongs to that project's owner |
| Deleted projects | Restorable for a limited window, then permanently erased with their images |
| Sessions | Until expiry; cleaned twice daily |
| Password reset links | One hour |
| Reading records | While the account exists |
| Logs | Under our log provider's retention |
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to processing based on our legitimate interests. You can also complain to your data protection authority.
Write to the contact form. We answer within one month.
One limit worth stating plainly: erasure removes your account and everything in your own projects, and unlinks — rather than deletes — what you contributed to projects belonging to other people. The text stays because it is theirs; the connection to you does not. If you think a specific piece should be removed rather than unlinked, tell us and we will weigh your request against the project owner's rights and answer either way.
Deletion and export are handled manually today. Self-service is being built; until it exists, one email to that address does the same job.
Children
Story Builder is for people aged 16 and over. We do not knowingly keep accounts for anyone younger; if you believe a child has an account, write to us and we will remove it.
Changes
When this notice changes materially we will ask you to read the new version the next time you sign in. The version and date at the top always say which one you are reading.