Skip to main content

Privacy Policy

This Privacy Policy explains how StoryForge collects, uses, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Data Controller

StoryForge ("we", "us", "our") is the data controller responsible for processing your personal data.

Contact: support@storyforge.cloud

2. Data We Collect

We collect and process the following categories of personal data:

Account Data

  • Email address (for account creation and communication)
  • Password (securely hashed using Argon2id algorithm)
  • Account preferences and settings

Instagram Session Data

  • Instagram session cookies you provide (sessionid, csrftoken, ds_user_id)
  • Instagram username and account identifiers
  • Target profile usernames for monitoring

Note: All Instagram session data is encrypted at rest using AES-GCM encryption.

Story Content Data

  • Downloaded story media (images, videos) from monitored accounts
  • Story metadata (timestamps, captions, stickers)
  • AI-generated content suggestions based on monitored stories

Technical Data

  • IP address and browser information
  • Device type and operating system
  • Usage logs and access timestamps

Payment Data

  • Subscription status and plan information
  • Transaction history

Note: Payment card details are processed directly by our payment provider and never stored on our servers.

3. Purpose and Legal Basis

We process your personal data for the following purposes and legal bases under GDPR Article 6:

PurposeLegal Basis
Account creation and authenticationContract performance (Art. 6(1)(b))
Story monitoring and content deliveryContract performance (Art. 6(1)(b))
AI content generationContract performance (Art. 6(1)(b))
Payment processingContract performance (Art. 6(1)(b))
Service improvement and analyticsLegitimate interest (Art. 6(1)(f))
Security and fraud preventionLegitimate interest (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a))

4. Data Storage and Security

Your data is stored on servers located in the European Union. We implement appropriate technical and organizational measures to protect your personal data, including:

  • AES-GCM encryption for sensitive data at rest
  • Argon2id password hashing
  • TLS/HTTPS encryption for data in transit
  • Regular security audits and updates
  • Access controls and authentication mechanisms

5. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account data: Until you delete your account
  • Instagram session data: Until you remove the session or delete your account
  • Story content: According to your subscription plan retention period
  • Technical logs: 90 days
  • Payment records: As required by applicable tax and accounting laws (typically 7-10 years)

6. Third-Party Sharing

We may share your personal data with the following categories of recipients:

  • Payment processors: To process subscription payments
  • AI service providers: To generate content suggestions (data is anonymized where possible)
  • Hosting providers: EU-based infrastructure providers
  • Legal authorities: When required by law or to protect our legal rights

We do not sell your personal data to third parties.

7. Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

Right of Access

Request a copy of your personal data

Right to Rectification

Correct inaccurate or incomplete data

Right to Erasure

Request deletion of your data ("right to be forgotten")

Right to Restrict Processing

Limit how we use your data

Right to Data Portability

Receive your data in a portable format

Right to Object

Object to processing based on legitimate interest

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at support@storyforge.cloud. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.

8. Cookies

We use cookies and similar technologies to:

  • Essential cookies: Required for authentication and security (no consent required)
  • Functional cookies: Remember your preferences
  • Analytics cookies: Understand how you use our service (consent required)

You can manage your cookie preferences through your browser settings or our cookie consent banner.

9. International Data Transfers

Your data is primarily stored and processed within the European Union. If we transfer data outside the EU/EEA, we ensure adequate protection through Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.

10. Children's Privacy

StoryForge is not intended for users under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. The "Last updated" date at the bottom indicates when this policy was last revised.

12. Contact Us

For any questions or concerns about this Privacy Policy or our data practices, please contact us at:

support@storyforge.cloud

Last updated: January 2026