Privacy Policy

Last updated: January 2026

Data Controller

Responsible for data processing on this website:

Dwayne Ellsworth
Romeostraße 19
76359 Marxzell
Deutschland
E-Mail: info@story-craft.eu

Data We Collect

We only collect data necessary for our service: email address and name during registration, your writing projects and texts, and technical data like IP address and browser information for security and app functionality.

Legal Basis

We process your data based on the following legal grounds under Art. 6 GDPR: contract performance (Art. 6(1)(b)) for account data and writing projects, legitimate interest (Art. 6(1)(f)) for security and functionality, and consent (Art. 6(1)(a)) for optional services like AI features.

Data Retention

We only store your data for as long as necessary for the respective purposes:

  • Account data (email, name): Until you delete your account, then 30 days in backup
  • Writing projects and texts: Until you delete your account, then 30 days in backup
  • Payment data: 10 years after end of contract (legal retention requirement under German tax law §147 AO)
  • Technical logs (IP addresses): 90 days
  • AI interactions: Not stored after processing

Cookies

We only use technically necessary cookies. No consent is required for these under GDPR Art. 6(1)(f).

The following cookies are used:

  • Authentication cookies (sb-*): Store your login session and enable access to protected areas. These cookies are set by Supabase and are essential for using the app. Duration: Session.
  • Language cookie (locale): Stores your preferred language (German/English) so you don't have to select it on every visit. Duration: 1 year.
  • Theme cookie (theme): Stores your light/dark mode preference. Duration: Persistent in browser.

We do not use any tracking, analytics, or advertising cookies.

Third-Party Services and International Transfers

We use the following third-party services to provide our service:

  • Vercel Inc. (USA) for website hosting and delivery
  • Supabase (EU data center Frankfurt) for authentication and data storage
  • Stripe Inc. (USA) for secure payment processing
  • Anthropic (USA) for AI text features (Claude)
  • OpenAI (USA) for AI image generation – data is not used for training

Supabase stores your data in the EU (Frankfurt). For US service providers, data transfer is based on:

  • EU-US Data Privacy Framework (Vercel, Stripe, OpenAI)
  • Standard Contractual Clauses under Art. 46(2)(c) GDPR (Anthropic, additionally for Stripe)

Your texts are not used by Anthropic (Claude) or OpenAI to train AI models.

Your Rights

Under the GDPR, you have the following rights:

  • Access to your stored data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability – you can export your projects at any time (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw consent at any time with effect for the future (Art. 7(3) GDPR)

To exercise your rights, contact info@story-craft.eu.

Right to Complain

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR. The supervisory authority responsible for us is the State Commissioner for Data Protection Baden-Württemberg, Germany.

Privacy Contact

For privacy-related questions, reach us at info@story-craft.eu.

Privacy Policy | StoryCraft