Privacy Policy
This Privacy Policy explains how StoryForge collects, uses, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
StoryForge ("we", "us", "our") is the data controller responsible for processing your personal data.
Contact: support@storyforge.cloud
2. Data We Collect
We collect and process the following categories of personal data:
Account Data
- Email address (for account creation and communication)
- Password (securely hashed using Argon2id algorithm)
- Account preferences and settings
Instagram Session Data
- Instagram session cookies you provide (sessionid, csrftoken, ds_user_id)
- Instagram username and account identifiers
- Target profile usernames for monitoring
Note: All Instagram session data is encrypted at rest using AES-GCM encryption.
Story Content Data
- Downloaded story media (images, videos) from monitored accounts
- Story metadata (timestamps, captions, stickers)
- AI-generated content suggestions based on monitored stories
Technical Data
- IP address and browser information
- Device type and operating system
- Usage logs and access timestamps
Payment Data
- Subscription status and plan information
- Transaction history
Note: Payment card details are processed directly by our payment provider and never stored on our servers.
3. Purpose and Legal Basis
We process your personal data for the following purposes and legal bases under GDPR Article 6:
| Purpose | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
| Story monitoring and content delivery | Contract performance (Art. 6(1)(b)) |
| AI content generation | Contract performance (Art. 6(1)(b)) |
| Payment processing | Contract performance (Art. 6(1)(b)) |
| Service improvement and analytics | Legitimate interest (Art. 6(1)(f)) |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
4. Data Storage and Security
Your data is stored on servers located in the European Union. We implement appropriate technical and organizational measures to protect your personal data, including:
- AES-GCM encryption for sensitive data at rest
- Argon2id password hashing
- TLS/HTTPS encryption for data in transit
- Regular security audits and updates
- Access controls and authentication mechanisms
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account data: Until you delete your account
- Instagram session data: Until you remove the session or delete your account
- Story content: According to your subscription plan retention period
- Technical logs: 90 days
- Payment records: As required by applicable tax and accounting laws (typically 7-10 years)
6. Third-Party Sharing
We may share your personal data with the following categories of recipients:
- Payment processors: To process subscription payments
- AI service providers: To generate content suggestions (data is anonymized where possible)
- Hosting providers: EU-based infrastructure providers
- Legal authorities: When required by law or to protect our legal rights
We do not sell your personal data to third parties.
7. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
Right of Access
Request a copy of your personal data
Right to Rectification
Correct inaccurate or incomplete data
Right to Erasure
Request deletion of your data ("right to be forgotten")
Right to Restrict Processing
Limit how we use your data
Right to Data Portability
Receive your data in a portable format
Right to Object
Object to processing based on legitimate interest
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at support@storyforge.cloud. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.
8. Cookies
We use cookies and similar technologies to:
- Essential cookies: Required for authentication and security (no consent required)
- Functional cookies: Remember your preferences
- Analytics cookies: Understand how you use our service (consent required)
You can manage your cookie preferences through your browser settings or our cookie consent banner.
9. International Data Transfers
Your data is primarily stored and processed within the European Union. If we transfer data outside the EU/EEA, we ensure adequate protection through Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
10. Children's Privacy
StoryForge is not intended for users under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. The "Last updated" date at the bottom indicates when this policy was last revised.
12. Contact Us
For any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Last updated: January 2026