Privacy Policy
What Storylines stores, what never leaves your computer, and what you can ask us to do about it.
Last updated 1 September 2026
1.Who we are
Storylines is operated by [Legal name], [organisation number], [postal address], Sweden. We are the data controller for the personal data described here.
For any question about this policy or your data, write to [email protected].
2.Your writing stays on your computer
Storylines reads your manuscript files directly from your own machine through your browser's File System Access API. Your prose is never uploaded to our servers and we never store it. If you disconnect the folder, we have nothing left of your text.
What we do store is the metadatathat lets you see your story's structure from another device. Some of that metadata is derived from your writing, so we want to be precise rather than reassuring:
- Scene and chapter titles, and the order you put them in
- Character names, locations, subplots and story arcs you or the AI identified
- Timeline dates, point-of-view, status, word and sentence counts
- File paths and file hashes, so we can tell when a file changed
- Short excerpts — the opening and closing few words of each scene, stored as anchors so we can find that scene again after you edit the file
- Scene summaries, if you run AI analysis. These are descriptions of what happens in a scene, generated from your text.
Excerpts and summaries are not your manuscript, but they do describe it. Treat this list as the honest answer to “what would someone see if they got into the database?”
3.What else we collect
| Account | Email address, display name, avatar, and the dates you signed up and last signed in. Authentication is handled by Supabase; we never see your password. |
|---|---|
| Usage | How many AI tokens you have used in the current period, and your remaining allowance. We do not keep the prompts or the responses. |
| Billing | Your Stripe customer and subscription identifiers, and a record of any credit packs you bought. We never see or store your card details — see Payments. |
| Your own API key | If you choose to add an Anthropic API key, it is encrypted with AES-256-GCM before it is stored and is never sent back to your browser. See Your own API key. |
| Support | Messages you send us, and any invite request you submit, so we can reply. |
Administrators of Storylines can see account details and project metadata in order to run the service and answer support requests. They cannot see your manuscript files, and every time an administrator views a user's account or projects it is written to an audit log.
4.Why we are allowed to process it
| Contract | Running your account, storing your project metadata, taking payment and providing support. Without this data there is no service to give you. |
|---|---|
| Consent | AI analysis, and storing your own Anthropic API key. Both are optional and only happen when you ask for them. You can withdraw either at any time. |
| Legitimate interest | Keeping the service secure, preventing abuse, and keeping an administrator audit log. |
| Legal obligation | Keeping accounting records for transactions. |
5.AI analysis
AI analysis is optional and never runs on its own. When you trigger it, the scenes you selected are sent to Anthropic for processing. Only those scenes are sent, and only at that moment.
Anthropic processes the text to produce the result and does not use it to train their models. Storylines stores only what comes back as metadata — summaries, character names, timeline suggestions — never the text you sent.
Every organisation and visualisation feature works without AI. If you never run an analysis, no part of your writing ever leaves your computer.
6.Your own API key
Premium subscribers can add their own Anthropic API key, after which analyses run on their Anthropic account instead of a Storylines allowance.
The key is encrypted with AES-256-GCM using a key held only on the server, and is decrypted only at the moment an analysis calls Anthropic. It is never written to logs and never returned to your browser — the profile page shows only a masked fragment. Deleting it removes it from the database entirely, and you can do that whether or not you are still on Premium.
While your own key is in use, your usage is billed by Anthropic directly and we do not record it.
7.Payments
Payments are processed by Stripe, which acts as the merchant of record for your purchase and appears on your statement and receipts as Link. Your card details go directly to Stripe and never reach Storylines.
Stripe is the controller of the payment data it collects, including your billing address, which it needs to calculate VAT. We receive only an identifier for your customer record and subscription, and the amount and date of each transaction.
8.Who else handles your data
We use a small number of providers, each doing one job:
| Supabase | Database and authentication. Hosted in the EU. |
|---|---|
| Vercel | Hosting, and aggregate visitor analytics. The analytics are anonymous, count page views rather than people, and set no cookies. |
| Anthropic | AI analysis, only when you trigger it. United States. |
| Resend | Sending email — sign-up confirmations, billing notices, and replies to support. |
| Stripe | Payments and tax, as merchant of record. United States and Ireland. |
Transfers to providers outside the EU/EEA rely on the European Commission's Standard Contractual Clauses. We do not sell your data, and we do not share it with anyone for advertising.
10.How long we keep it
Account data and project metadata are kept for as long as your account exists. Delete your account from the profile page and the profile and everything linked to it — projects, metadata, usage, your saved API key — is deleted, your Stripe subscription is cancelled and your Stripe customer record is deleted.
Transaction records are kept for as long as Swedish accounting law requires. Administrator audit logs are kept so that access to accounts remains reviewable after the fact.
11.Your rights
Under the GDPR you can ask us to:
- give you a copy of the personal data we hold about you
- correct anything inaccurate
- delete your data — which you can also do yourself, from the profile page
- export your data in a portable format
- restrict or object to how we process it
- withdraw consent to AI analysis or to storing your API key, at any time
Write to [email protected] and we will respond within one month. If you think we have handled your data badly, you can complain to the Swedish Authority for Privacy Protection (IMY), imy.se.
12.Changes to this policy
If we change how we handle your data in a way that affects you, we will update this page and tell you by email before the change takes effect. The date at the top always reflects the current version.
See also our Terms of Service and the support page.