StoryWith AI ("we", "us", "the service") provides a writing studio for novelists and non-fiction authors. This policy explains what information we collect, why, and what control you have over it.
The short version.
- Your manuscripts are yours. We process them only to provide the service.
- We don't train AI on your content. Ever.
- We never exchange your data for money, and there are no ads in the product. You can switch our marketing pixels off at any time.
- Only you, the people you invite to a book, and — if you move that book into an organization — its members can read it.
- You can download your data as one machine-readable file, export any book as Markdown, and delete your account at any time.
Hard limits.
- Train AI models on your manuscripts, prose, comments, or feedback.
- Exchange your personal data for money, or let anyone buy, rent, or license it.
- Share your unpublished work with anyone beyond the collaborators you invite and the organization you place a book in.
- Send your manuscripts or their contents to advertising or analytics tools.
- Read your manuscripts manually outside of explicit support requests you initiate.
1. Information we collect
Account information
When you sign up we collect your email address, display name, and authentication identifiers from your sign-in provider (e.g., Google). We do not store passwords. Authentication is handled by Supabase, our identity provider.
Manuscript content
Your manuscripts, characters, world entries, scenes, comments, sources, citations, argument maps, and any other content you create or import is stored in our database. You own this content. We process it only to provide the service to you and your invited collaborators. We treat unpublished manuscripts as confidential and do not access them outside of explicit support requests you initiate.
Voice recordings
When you dictate an idea into the Idea Vault, we keep the recording alongside its transcript so you can hear back what you said. Recordings are stored privately, readable only by you, and are deleted when you delete the idea or your account. Dictation anywhere else in the app is transcribed and the audio is discarded immediately.
Usage analytics
We log basic usage metrics (page visits, AI feature invocations, error events) to understand how the product is used and to detect abuse. These are aggregated and not tied to identifying information beyond the minimum needed to attribute usage to your account for billing purposes.
Payment information
Subscription billing is processed by Stripe, our payment processor. Stripe handles your payment details directly; we never see or store your full credit card number. We receive your subscription tier, status, and renewal date from Stripe.
Cookies and local storage
We use cookies and browser local storage for two kinds of purpose. Strictly-necessary cookies keep the service working (your sign-in session, active book, focus-mode and language preferences, and similar interface state) and are always on. We also use non-essential, third-party analytics and advertising cookies to understand how the product is used and to measure our marketing: Google Analytics, the Meta (Facebook) pixel and the TikTok pixel on our public marketing pages, and PostHog product analytics inside the app. In the EEA, the UK and Switzerland we ask for your consent before any of them load. Everywhere else they load by default and you can switch them off at any time using the control below, or the same control in Settings. The Meta and TikTok pixels support cross-context behavioural advertising, which some privacy laws — California's among them — treat as a sale or share of personal information; switching them off is how you opt out. We never exchange your data for money, and your manuscripts and their contents are never sent to any of these tools.
2. How we use your information
- To provide the service: render your books, run analyzers, store your work.
- To run AI features on your explicit action: send manuscript excerpts and prompts to our AI provider.
- To process payments and manage your subscription via Stripe.
- To send transactional notifications (reader feedback events, password resets, billing receipts).
- To improve the product through aggregate analytics, never tied to identified individuals or specific manuscript content.
- To detect and prevent abuse (illegal content, spam, security threats).
3. AI processing in detail
AI features (outline generation, scene insights, continuity scans, fact-check, etc.) send relevant excerpts of your content to the Vercel AI Gateway, which routes each request to the underlying model provider — currently Google Gemini models, the only model family we have configured. Image features (covers, character portraits, scene frames, world art) go to Leonardo instead, and their prompts are built from your prose, so excerpts reach Leonardo too. Specifically:
- What we send: the smallest necessary slice of your content for the feature you invoked: an active scene, a chapter synopsis, a citation excerpt. Never your entire manuscript unless you trigger a book-wide scan.
- Training data, never: we do not use your content to train AI models. How our AI providers handle the requests we send them is governed by their own published terms and data-processing policies, which are theirs to state rather than ours to restate. We will publicly notify users at least 30 days in advance of any change to this stance, and you will have the option to opt out and export your data before any such change takes effect.
- Retention at the AI provider: our AI providers may retain a request briefly for abuse prevention and quality monitoring. The retention period and the deletion timeline are set by those providers' own published terms, not by us.
- Output ownership: AI-generated content (covers, blurbs, query letters, suggestions) is yours to use, modify, or discard, subject to the model provider's terms which prohibit illegal or infringing uses. See our Terms of Service for details on AI output ownership.
- No automatic AI runs: AI features run only when you ask for them — from a button in the app, or from an application you have connected and explicitly authorized to act on your account, which keeps that access until the authorization is revoked; “Who we share information with” below explains how to revoke it. Nothing runs on a schedule, and we don't analyze your work in the background.
4. Who we share information with
Two different things can put your writing in someone else's hands, and only one of them is our choice. The providers listed below are sub-processors: we selected them to run StoryWith AI, and they handle your data under our instructions and this policy. An application you connect and authorize yourself — an outside AI client acting on your account — is not one of them: when it asks for a scene it receives your prose on your instruction, and what that application then does with your writing is governed by its own terms and privacy policy, not ours. You see what it will be able to do before you approve it. To end that access, revoke the connection inside the application itself — disconnecting StoryWith AI there is what revokes it — or email us at the address in the contact section and we will revoke it for you; authorizing the same application again replaces the earlier connection rather than adding a second one. Settings does not list your connected applications yet. Our sub-processors are:
Providers that receive manuscript content
- Supabase: database hosting, authentication, and file storage. Your manuscripts and everything else you write are stored here, encrypted at rest. (sub-processor)
- Vercel: application hosting and the Vercel AI Gateway. Vercel serves the app, and when you invoke a text AI feature it receives the manuscript excerpt in that request and routes it to the model provider. (sub-processor)
- Google (Gemini models): the AI models themselves. Google Gemini is currently the only model family we have configured, so the excerpts routed through the Vercel AI Gateway are processed by Google to produce the result you asked for. Google's analytics and advertising tags are a separate service, listed in the group below, and they never receive your writing. (sub-processor)
- Leonardo: image generation for covers, character portraits, scene frames, and world art. Image prompts are built from your prose, so Leonardo receives prose-derived excerpts alongside the visual description. (sub-processor)
Providers that never receive manuscript content
- Stripe: payment processing and subscription management. Sees your billing details and subscription state, never your writing. (payment processor)
- Resend: delivery of account and notification email — reader feedback events, sign-in codes, billing receipts, support replies. Sees your email address and the contents of the messages we send you, never your manuscripts. (sub-processor)
- Upstash: Redis rate-limit counters. Sees an account or request identifier and a count, and no content of any kind. (sub-processor)
- Cloudflare: the bot check on our sign-in and sign-up screen (Cloudflare Turnstile). Your browser loads Cloudflare's challenge each time that screen opens, and when you sign in or create an account our server sends Cloudflare the challenge token together with your IP address so it can be verified. Sees that token, your IP address, and request metadata — never your manuscripts. (sub-processor)
- PostHog: product analytics. Receives page and feature-usage events from your browser, subject to the cookie choice described above, and receives from our servers your account identifier attached to subscription lifecycle events, which we keep as first-party billing records. Never manuscript content. (sub-processor)
- Meta: advertising measurement. Alongside the browser pixel described above, our servers send Meta a one-way hash of your email address — never the address itself — plus Meta's own click identifiers, for two conversions only: sign-up, which follows your cookie choice, and a completed purchase, which we keep as a first-party billing record. Never manuscript content. (sub-processor)
- Google (Analytics and Ads): website analytics and advertising measurement — a different Google service from the Gemini models above. Google Analytics and the Google Ads tag run in your browser on our public pages and the sign-in screen, subject to the cookie choice described above, and report page views with any sharing or invite token stripped from the address. The Google Ads tag also runs on the billing pages inside the app — the only signed-in pages we mount it on, because their addresses carry no manuscript identifier — where it reports a completed purchase identified by its Stripe checkout reference. Never manuscript content. (sub-processor)
- TikTok: advertising measurement for our TikTok campaigns. The TikTok pixel runs in your browser on our public pages and the sign-in screen only, subject to the cookie choice described above, and reports page views. It never loads inside the app, so no manuscript address or content reaches TikTok. (sub-processor)
Each provider operates under their own privacy terms and data processing agreements. We never exchange your personal data for money. We do not share your manuscripts with third parties for any purpose other than serving your explicit requests through these providers.
Collaborators and organizations
When you invite a collaborator (co-author, editor, reviewer) to a book, they will be able to read and, depending on the role you grant, edit and comment on that book's content — that book alone, not your other books. Organizations work differently, and it matters: an organization is a shared workspace, so moving a book into one gives every member of that organization access to it without a separate invitation, with edit and comment rights following their role there. Books you keep in your personal workspace are never included. Neither collaborators nor organization members can see your account information or billing details. Roles are: editor (full read/write/comment), commenter (read + comment), viewer (read-only).
Reader feedback sessions
When you create a reader feedback session and share its link, the readers you invite see only the excerpts you've explicitly added to the session. They cannot see your full manuscript, your other books, or any other personal information beyond what you choose to display in the session.
Legal compliance
We may disclose information when required by law, valid legal process, or to protect our rights, property, or safety. We will notify affected users where legally permitted to do so.
5. Storage, security, and retention
Data is stored in Supabase's managed Postgres database with row-level security (RLS) policies enforcing access control at the database layer. Your manuscripts are programmatically inaccessible to other users. Data in transit is protected with TLS 1.2 or higher. Data at rest is encrypted by Supabase using AES-256.
We retain your account and content for as long as your account is active. If you delete a book, it is permanently removed from our active database within 30 days; backup copies in our disaster-recovery system are overwritten within 90 days.
In the unlikely event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the incident, in accordance with applicable law (e.g., GDPR Article 33).
6. Your rights
You have the right to:
- Access the personal data we hold about you. You can download it yourself at any time from the “Your data” section in Settings, which produces one machine-readable JSON file: your profile, the books you own with their chapters, scenes, characters and world, your analyzer results, reader feedback on your sessions, your billing and usage history, and links to your uploaded files. For anything that file does not cover, ask us at the contact email below.
- Export your manuscripts and other content in a portable form. The “Your data” export in Settings is the machine-readable copy of your whole account (JSON); any individual book also exports as Markdown, and bibliographies export from the Sources page (non-fiction). The account export covers the books you own and your own contributions to other authors' books — the comments, notes and tasks you wrote — but not manuscripts other authors shared with you, because that writing is theirs.
- Correct inaccurate information by editing your account settings.
- Delete your account and associated content. Email privacy@mail.storywith.ai to initiate deletion. Confirmed deletions complete within 30 days.
- Object or restrict processing where applicable.
- Lodge a complaint with your local data protection authority (e.g., a supervisory authority in the EU under GDPR, the California Attorney General under CCPA).
- Withdraw consent for any processing based on consent, at any time.
7. International data transfers
StoryWith AI's infrastructure is global. Your data may be processed in regions other than your country of residence, primarily the United States and the European Union. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards where required by law for cross-border transfers.
8. Children
StoryWith AI is not directed to individuals under 16 years of age. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
Who operates StoryWith AI
StoryWith AI is owned and operated by Silotech, UAB (formerly SAAKURU TECHNOLOGIJOS, UAB), trading as SiloTech, registered in Vilnius, Lithuania. The same company publishes our mobile apps, including the Android app ai.storywith.app on Google Play. You can reach us at support@mail.storywith.ai.
9. Changes to this policy
We may update this Privacy Policy as the service evolves. The "Last updated" date at the top of this page reflects the most recent revision. Material changes, particularly any change to our AI training stance, will be communicated via email or in-app notice at least 30 days before they take effect, with a clear option to export your data and close your account before the change applies.
10. Contact us
Questions about this policy or about your data? Email privacy@mail.storywith.ai.