Privacy Policy

What Storylines stores, what never leaves your computer, and what you can ask us to do about it.

Last updated 1 September 2026

1.Who we are

Storylines is operated by [Legal name], [organisation number], [postal address], Sweden. We are the data controller for the personal data described here.

For any question about this policy or your data, write to [email protected].

2.Your writing stays on your computer

Storylines reads your manuscript files directly from your own machine through your browser's File System Access API. Your prose is never uploaded to our servers and we never store it. If you disconnect the folder, we have nothing left of your text.

What we do store is the metadatathat lets you see your story's structure from another device. Some of that metadata is derived from your writing, so we want to be precise rather than reassuring:

  • Scene and chapter titles, and the order you put them in
  • Character names, locations, subplots and story arcs you or the AI identified
  • Timeline dates, point-of-view, status, word and sentence counts
  • File paths and file hashes, so we can tell when a file changed
  • Short excerpts — the opening and closing few words of each scene, stored as anchors so we can find that scene again after you edit the file
  • Scene summaries, if you run AI analysis. These are descriptions of what happens in a scene, generated from your text.

Excerpts and summaries are not your manuscript, but they do describe it. Treat this list as the honest answer to “what would someone see if they got into the database?”

3.What else we collect

AccountEmail address, display name, avatar, and the dates you signed up and last signed in. Authentication is handled by Supabase; we never see your password.
UsageHow many AI tokens you have used in the current period, and your remaining allowance. We do not keep the prompts or the responses.
BillingYour Stripe customer and subscription identifiers, and a record of any credit packs you bought. We never see or store your card details — see Payments.
Your own API keyIf you choose to add an Anthropic API key, it is encrypted with AES-256-GCM before it is stored and is never sent back to your browser. See Your own API key.
SupportMessages you send us, and any invite request you submit, so we can reply.

Administrators of Storylines can see account details and project metadata in order to run the service and answer support requests. They cannot see your manuscript files, and every time an administrator views a user's account or projects it is written to an audit log.

4.Why we are allowed to process it

ContractRunning your account, storing your project metadata, taking payment and providing support. Without this data there is no service to give you.
ConsentAI analysis, and storing your own Anthropic API key. Both are optional and only happen when you ask for them. You can withdraw either at any time.
Legitimate interestKeeping the service secure, preventing abuse, and keeping an administrator audit log.
Legal obligationKeeping accounting records for transactions.

5.AI analysis

AI analysis is optional and never runs on its own. When you trigger it, the scenes you selected are sent to Anthropic for processing. Only those scenes are sent, and only at that moment.

Anthropic processes the text to produce the result and does not use it to train their models. Storylines stores only what comes back as metadata — summaries, character names, timeline suggestions — never the text you sent.

Every organisation and visualisation feature works without AI. If you never run an analysis, no part of your writing ever leaves your computer.

6.Your own API key

Premium subscribers can add their own Anthropic API key, after which analyses run on their Anthropic account instead of a Storylines allowance.

The key is encrypted with AES-256-GCM using a key held only on the server, and is decrypted only at the moment an analysis calls Anthropic. It is never written to logs and never returned to your browser — the profile page shows only a masked fragment. Deleting it removes it from the database entirely, and you can do that whether or not you are still on Premium.

While your own key is in use, your usage is billed by Anthropic directly and we do not record it.

7.Payments

Payments are processed by Stripe, which acts as the merchant of record for your purchase and appears on your statement and receipts as Link. Your card details go directly to Stripe and never reach Storylines.

Stripe is the controller of the payment data it collects, including your billing address, which it needs to calculate VAT. We receive only an identifier for your customer record and subscription, and the amount and date of each transaction.

8.Who else handles your data

We use a small number of providers, each doing one job:

SupabaseDatabase and authentication. Hosted in the EU.
VercelHosting, and aggregate visitor analytics. The analytics are anonymous, count page views rather than people, and set no cookies.
AnthropicAI analysis, only when you trigger it. United States.
ResendSending email — sign-up confirmations, billing notices, and replies to support.
StripePayments and tax, as merchant of record. United States and Ireland.

Transfers to providers outside the EU/EEA rely on the European Commission's Standard Contractual Clauses. We do not sell your data, and we do not share it with anyone for advertising.

9.Cookies

Storylines sets only the cookies it needs to keep you signed in. There are no advertising or tracking cookies, and no third-party trackers.

The cookie banner remembers your acknowledgement in your browser's local storage, not in a cookie, and that record never leaves your device.

10.How long we keep it

Account data and project metadata are kept for as long as your account exists. Delete your account from the profile page and the profile and everything linked to it — projects, metadata, usage, your saved API key — is deleted, your Stripe subscription is cancelled and your Stripe customer record is deleted.

Transaction records are kept for as long as Swedish accounting law requires. Administrator audit logs are kept so that access to accounts remains reviewable after the fact.

11.Your rights

Under the GDPR you can ask us to:

  • give you a copy of the personal data we hold about you
  • correct anything inaccurate
  • delete your data — which you can also do yourself, from the profile page
  • export your data in a portable format
  • restrict or object to how we process it
  • withdraw consent to AI analysis or to storing your API key, at any time

Write to [email protected] and we will respond within one month. If you think we have handled your data badly, you can complain to the Swedish Authority for Privacy Protection (IMY), imy.se.

12.Changes to this policy

If we change how we handle your data in a way that affects you, we will update this page and tell you by email before the change takes effect. The date at the top always reflects the current version.

See also our Terms of Service and the support page.