Privacy
Last updated 9 August 2026
This page says what we keep, why we keep it, and how to make us stop. It describes what the software actually does rather than what a policy template usually says.
What we store
Your account. An email address, a username and display name, and a password that is stored only as a salted scrypt hash — we cannot read it and cannot tell you what it is. If you sign in with Google we store the identifier Google gives us and your profile picture URL, never a Google password.
Your writing.The stories you play, the scenarios you write, your story cards, memory and author’s notes. Private stories are visible only to you and anyone you invite to a shared table.
Your use of the models. For each turn: which storyteller answered, how many tokens it read and wrote, how long it took, and what it cost. This is what the credit meter is calculated from.
The age check, if you take it. If you turn on 18+ mode we keep the date of birth you submitted, every attempt including the ones that failed, your browser user-agent string, and a salted one-way hash of your IP address. We do not store the address itself, and the hash cannot be turned back into one without a secret that never leaves the server. We keep this because an age check that leaves no record cannot be accounted for afterwards.
What we do not store
We do not store your IP address in readable form, we do not use advertising or analytics trackers, we do not sell anything to anyone, and we set no cookies for advertising. The only cookies are the one that keeps you signed in and two short-lived ones used during Google sign-in, which are deleted the moment it finishes.
Who else sees it
The text of a turn is sent to the model provider that generates the narration, because that is how the story gets written. It is sent without your name, email or account identifier attached.
Illustrations are generated by a third-party image service, and the scene description is sent to it as part of the image URL your browser requests.
Our database and hosting are operated by Supabase and Vercel respectively. If you enable the optional wider moderation layer on a deployment, passages are sent to OpenAI’s moderation endpoint to be classified.
Deleting things
You can delete any story from your library, and deleting one removes its passages, story cards, illustrations and membership records together. The cost ledger keeps an anonymous row with the story reference removed, because we need to know what we spent.
To delete your whole account and everything in it, email us and we will do it. We have not built a self-serve button for this yet, and we would rather say so than pretend otherwise.
Where this is incomplete
We are a new and small service. This notice describes the system honestly, but it has not been reviewed by a lawyer, and we do not yet have a named data controller, a formal retention schedule or a documented process for the access and portability requests that UK and EU law entitles you to make. If you want your data, ask and we will send it.