StoryScribe privacy policy

This page is a launch-ready structure for a privacy policy, not final legal advice. Replace placeholders and generic processor language with your real practices before you go live.

Last reviewed draft: 2026-06-28

Important draft notice

This privacy policy is a structural draft for StoryScribe. Review it with your legal team before publishing because GDPR compliance, retention rules, processor lists, and consent practices must match your actual product and operations.

What data StoryScribe may collect

A typical whiteboard-video SaaS may collect account details, billing details, uploaded media, project content, usage analytics, support conversations, and device or browser diagnostics. Remove any category your product does not actually collect, and add any category that is missing.

How data is used

Data is generally used to provide the service, secure accounts, process payments, improve reliability, answer support requests, prevent abuse, and understand product usage. If you use data for AI model training, advertising, or separate research, state that explicitly and obtain any required permissions.

Cookies and similar technologies

StoryScribe may use strictly necessary cookies for authentication and preferences, plus optional analytics or marketing technologies if you enable them. Your live site should pair this section with an accurate consent mechanism where required.

Third-party services

If you rely on analytics providers, payment processors, hosting vendors, email tools, or customer support platforms, list them clearly and explain why they process data on your behalf. This draft intentionally avoids naming vendors you have not confirmed.

Data retention

Keep personal data only as long as needed for the service, legal obligations, dispute handling, and security purposes. Publish your real retention windows once they are defined across account data, billing records, support logs, and deleted projects.

User rights and GDPR

If StoryScribe serves users in the EU, people may have rights to access, correct, export, delete, restrict, or object to certain processing. The final policy should explain how to make a request, how identity is verified, and which legal bases apply.

International transfers

If data moves outside the EEA or UK, disclose the transfer mechanisms you rely on, such as adequacy decisions or standard contractual clauses. Do not publish a generic statement here without validating your real infrastructure.

Security

Describe the practical controls you actually use, such as encryption in transit, access restrictions, logging, backup policies, and incident response processes. Avoid making exaggerated promises like “fully secure” or “guaranteed protected.”

Contact for privacy requests

Publish the real privacy contact email or portal used for access and deletion requests. If StoryScribe has a legal entity, include the correct controller information and mailing details.