Legal · Privacy

Privacy Policy

Last updated 2026-07-30

This page describes what data Storylab collects, why we collect it, the third parties we share it with, and the choices available to you. We have tried to keep it readable — if any section is unclear, write to the address in section 11.

1. What this policy covers

This policy applies to the Storylab web app and to the Storylab subscription programme that is delivered through it. It covers the data we collect when you sign up, when you enrol cohorts, when you make a payment, and when you use the service.

It does not cover third-party sites that we link to from the Storylab app — those sites have their own policies, and we encourage you to read them.

2. Data we collect

We collect three kinds of data:

Account data. The email address and profile fields you supply through the signup or login forms, and the organisation details you add when you enrol a cohort. We keep this data inside the Storylab account system; we do not buy, append, or import data from third-party enrichment providers.

Payment data.Card or bank details are collected by Stripe through hosted Checkout and never reach Storylab’s servers. We retain only the payment-event metadata that Stripe returns — the plan, the billing period, the amount, and the date of each charge — so we can show your billing history in your Account area.

Usage data. Programme participation, session activity within the Storylab app, standard server logs, and the aggregate product analytics that Polsia Analytics already collects across the platform. We use this to keep the service running, to fix bugs, and to understand which parts of the programme are landing.

3. Why we collect it (lawful basis)

We process your data on the following bases, depending on the activity:

Performance of contract. To deliver the subscription, run the quarterly programme, and process your payment.

Legitimate interests. To operate, secure, and improve Storylab — for example, identifying and fixing reliability incidents, or detecting fraudulent sign-ups.

Consent. For any marketing emails we send and for non-essential cookies. You can withdraw consent at any time without affecting the subscription itself.

Legal obligation. To meet tax, invoicing, and accounting rules that apply to a paid subscription service.

4. Third-party processors

We share data only with the parties needed to run the service. Today, those are:

Better Auth. Authentication and account management. Better Auth holds your sign-in data and session state on our behalf.

Stripe / Polsia Connect. Payment processing, billing portal, and webhook delivery. Stripe collects card and bank details directly; Storylab only receives payment-event metadata.

Render.Hosting infrastructure for the Storylab app and database. Data at rest and in transit is protected by Render’s platform controls.

We do not sell your data, and we do not share it with advertisers.

5. Cookies

Storylab uses a small number of cookies. Authentication cookies, set by Better Auth, are essential — they keep you signed in. A theme-preference cookie remembers whether you are reading the site in light or dark mode.

If we add non-essential analytics cookies in the future, we will prompt for consent before they are set, and you will be able to decline without losing access to the service.

6. Retention

While your subscription is active, we retain your account, payment-event metadata, and programme participation data so that your cohorts and reporting continue to work, and so that your billing history stays visible in your Account area.

After cancellation: [operator to specify the retention window for cancelled accounts — e.g. “account records retained for 24 months for tax/ invoicing and reactivation, then permanently deleted; anonymised aggregate reporting may be retained indefinitely”].

7. Your rights

You have the right to access the personal data Storylab holds about you, to correct it, to download a copy, and to ask for it to be deleted. In practice:

Access & update. Sign in and visit your Account area, or your profile page, to see and change what we hold.

Export. Write to the address in section 11 and we will send a portable copy of your account and participation data.

Deletion. Close your account from the Account area, or write to the address in section 11, and we will delete your personal data subject to the retention rules in section 6.

8. International transfers

Storylab is hosted in [operator to specify the hosting region — e.g. “the United States”]. Some of the third-party processors listed in section 4 may process data in additional regions in order to deliver the service. Where personal data leaves the region where you are based, we rely on the standard contractual clauses or other lawful safeguards that the relevant processor has put in place.

9. Security

We apply reasonable administrative, technical, and physical safeguards to protect your data. Authentication is handled through Better Auth, which signs in over HTTPS and uses industry-standard session handling; passwords are never stored in plain text. Payments are routed through Stripe’s hosted flow, so card and bank details never pass through Storylab’s servers.

No system is perfectly secure. If we ever become aware of a breach that affects your personal data, we will tell you in line with the rules that apply to the regions our subscribers are in.

10. Changes to this policy

If we make material changes to this policy, we will post the updated version here with a revised “Last updated” date. Continued use of Storylab after the revised date indicates that you have read the new policy. Non-material changes (typo fixes, contact-address updates) take effect on posting.

11. Contact / DPO

Questions about this policy, requests to exercise your rights, or reports of a privacy incident should be sent to privacy@storylab.app — replace this address with the operator’s real contact before public launch, and add a named data-protection officer if your jurisdiction requires one.

That’s the policy in full.

If you would rather talk it through, write to the address in section 11 — the same way you would if you spotted a typo in this page.