Story Builder documentation

Privacy notice

Effective 2026-09-10 · version 2026-09-15

This notice explains what Story Builder does with your personal data. It is written against what the software actually does — if you find a difference between this page and the product, the difference is a bug and we want to hear about it.

Who is responsible

Exalink
Ukraine

Questions about this notice, or about your data: the contact form.

What we collect, and why

Your account

When you register we store your email address, the username you choose, and a hash of your password — never the password itself. If you sign in with Google, we receive your name and email address from Google instead. We also record when you registered and, if you set them, your timezone and avatar.

We need this to give you an account. Without it there is no product.

Your sessions

Staying signed in means storing, per device, a session token with the device identifier, the browser's user agent and the IP address it last connected from. This is how "sign out everywhere" can work and how we notice a stolen session.

Expired sessions are deleted automatically twice a day. An account keeps at most five live sessions; older ones drop off.

What you write

Manuscripts, characters, locations, events, plans, maps, notes, images — everything you create in the product is stored so we can give it back to you. We do not read it, we do not train anything on it, and it is not shared with anyone unless you publish it or invite a collaborator.

Content belongs to the owner of the project it is in, which is the person who created that project. That matters here for one reason: when you delete your account, work you contributed to somebody else's project stays with them, unlinked from you. The terms set out why.

Collaboration

Shared projects record who is a member and what role they hold. Chat messages and comments carry the author's username and account id, because that is what makes a conversation legible.

Reading

When you read a published story while signed in, we record which chapters you have read, how long you spent, how far you scrolled, how many times you returned, and the dates. Two things use it: your own continue-reading, and the aggregate statistics an author sees about their story. An author never sees you individually.

Email

We send: address verification, invitations, replies to your comments, and new-chapter digests for stories you follow. Each type can be switched off separately in your settings, and every message carries an unsubscribe link. We keep your preferences and the date of your last digest.

Logs

Our servers write technical logs to diagnose failures and abuse. Log lines can contain your account id and details of the request that failed.

What we do not do

  • No advertising, no advertising networks, and nothing sold to anyone.
  • No analytics or tracking scripts. There is no Google Analytics, no tag manager, no pixel.
  • No third-party code in your browser at all: our fonts are served from our own servers, not from a font CDN.
  • No profiling and no automated decisions that affect you.

Cookies and local storage

We set three cookies, all strictly necessary to sign you in and keep you signed in. They are HTTP-only, restricted to this site, and sent over HTTPS in production. A fourth token protects forms against cross-site request forgery.

Your browser also stores your own preferences locally — theme, recently opened items, panel positions, sidebar state. Those never leave your device.

Because none of this is used for advertising or analytics, there is no consent banner. Turning any of it off would mean not being able to sign in.

Who else processes your data

We use a small number of providers to run the service. Each processes data only on our instructions:

Provider What they handle
Our database host Everything stored in the product
Amazon Web Services Images and files you upload, and their delivery
Resend Sending email
Google Sign in with Google, if you use it
BetterStack Application logs

Some of these providers are headquartered outside the European Economic Area. Where data leaves the EEA, the transfer relies on the European Commission's standard contractual clauses, or on an adequacy decision where one covers the provider. Ask us at the contact form for the details of any particular transfer.

How long we keep it

Account and your own content Until you delete it, or the account closes
What you contributed to someone else's project Kept, unlinked from you — it belongs to that project's owner
Deleted projects Restorable for a limited window, then permanently erased with their images
Sessions Until expiry; cleaned twice daily
Password reset links One hour
Reading records While the account exists
Logs Under our log provider's retention

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to processing based on our legitimate interests. You can also complain to your data protection authority.

Write to the contact form. We answer within one month.

One limit worth stating plainly: erasure removes your account and everything in your own projects, and unlinks — rather than deletes — what you contributed to projects belonging to other people. The text stays because it is theirs; the connection to you does not. If you think a specific piece should be removed rather than unlinked, tell us and we will weigh your request against the project owner's rights and answer either way.

Deletion and export are handled manually today. Self-service is being built; until it exists, one email to that address does the same job.

Children

Story Builder is for people aged 16 and over. We do not knowingly keep accounts for anyone younger; if you believe a child has an account, write to us and we will remove it.

Changes

When this notice changes materially we will ask you to read the new version the next time you sign in. The version and date at the top always say which one you are reading.