Important draft notice
This privacy policy is a structural draft for StoryScribe. Review it with your legal team before publishing because GDPR compliance, retention rules, processor lists, and consent practices must match your actual product and operations.
What data StoryScribe may collect
A typical whiteboard-video SaaS may collect account details, billing details, uploaded media, project content, usage analytics, support conversations, and device or browser diagnostics. Remove any category your product does not actually collect, and add any category that is missing.
How data is used
Data is generally used to provide the service, secure accounts, process payments, improve reliability, answer support requests, prevent abuse, and understand product usage. If you use data for AI model training, advertising, or separate research, state that explicitly and obtain any required permissions.
Cookies and similar technologies
StoryScribe may use strictly necessary cookies for authentication and preferences, plus optional analytics or marketing technologies if you enable them. Your live site should pair this section with an accurate consent mechanism where required.
Third-party services
If you rely on analytics providers, payment processors, hosting vendors, email tools, or customer support platforms, list them clearly and explain why they process data on your behalf. This draft intentionally avoids naming vendors you have not confirmed.
Data retention
Keep personal data only as long as needed for the service, legal obligations, dispute handling, and security purposes. Publish your real retention windows once they are defined across account data, billing records, support logs, and deleted projects.
User rights and GDPR
If StoryScribe serves users in the EU, people may have rights to access, correct, export, delete, restrict, or object to certain processing. The final policy should explain how to make a request, how identity is verified, and which legal bases apply.
International transfers
If data moves outside the EEA or UK, disclose the transfer mechanisms you rely on, such as adequacy decisions or standard contractual clauses. Do not publish a generic statement here without validating your real infrastructure.
Security
Describe the practical controls you actually use, such as encryption in transit, access restrictions, logging, backup policies, and incident response processes. Avoid making exaggerated promises like “fully secure” or “guaranteed protected.”
Contact for privacy requests
Publish the real privacy contact email or portal used for access and deletion requests. If StoryScribe has a legal entity, include the correct controller information and mailing details.